ตั้งแต่ปี 2006 เป็นต้นมา ใบอนุญาตทนายความไทย เลขที่ 3149/2556 +66 87 225 1340 (EN/FR) +66 87 414 9288 (TH) วาส

PDPA: Personal Data Protection Act B.E. 2562 (2019)

ตรวจสอบโดย ThaiLawOnline สำนักงานกฎหมายไทยที่ได้รับใบอนุญาตและดำเนินกิจการในประเทศไทยตั้งแต่ปี พ.ศ. 2549 ทนายความผู้รับผิดชอบสำนวน: วิชุดา อรรถเมธากุล, น.ม., ใบอนุญาตเนติบัณฑิตไทย เลขที่ 3149/2556.

อัปเดตล่าสุดเมื่อ 5 กันยายน 2569

เดอะ PDPA (พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562, the Personal Data Protection Act B.E. 2562 (2019), sometimes written Thai PDPA หรือ Thailand PDPA) is Thailand’s general data protection law, modelled on the European GDPR and fully in force since 1 June 2022. It regulates anyone who collects, uses or discloses information about an identifiable living person, requires a lawful basis for doing so, gives the individual rights over the data, and backs those rules with fines, damages and, for sensitive data, prison. A foreigner meets it as a business owner, an employer, a landlord and as the person whose passport is being photocopied.

What the Act requires of a data controller

Scope. The Act binds a data controller (who decides why and how data is used) and a data processor (who handles it on the controller’s instructions) established in Thailand, and by Section 5 also those abroad who offer goods or services to people in Thailand or monitor their behaviour. Purely personal or household use is outside it.

Lawful basis and sensitive data. Personal data may be collected only with consent or on another basis the Act lists: performance of a contract, a legal obligation, vital interests, a public task or the controller’s legitimate interests. Section 26 treats data on race, ethnicity, political opinion, religion, sexual behaviour, criminal record, health, disability, trade union membership, genetic and biometric data as sensitive, needing explicit consent unless a narrow exception applies. Controllers must tell people what is collected and why, keep it secure, notify the regulator of a breach within 72 hours, and honour requests to access, correct, delete or port the data.

Where a foreigner meets the PDPA in practice

Running a business. A Thai company with customers, staff or a website needs a privacy notice, consent wording for marketing, a record of processing (small businesses are partly exempt), contracts with processors such as payroll providers, and a data protection officer if it monitors people on a large scale or handles sensitive data as a core activity. Transfers abroad, including to a foreign head office, are allowed under Section 28 only to countries with adequate protection or under safeguards such as binding corporate rules or standard contract clauses.

As a landlord, host or condominium. Copying a tenant’s passport to file a ทีเอ็ม30 rests on a legal obligation and needs no consent, but keeping the copy for years, or a condominium juristic person sharing CCTV footage or resident lists, does not. The regulator is the Personal Data Protection Committee under the Ministry of Digital Economy and Society.

Penalties and how the PDPA differs from other laws

Administrative fines of up to 5,000,000 baht per breach are imposed by the Committee. Civil claims by the person affected allow the court to award punitive damages of up to twice the actual damage. Criminal liability under Section 79 attaches to unlawful use or disclosure of sensitive data that causes damage or is done for gain: up to 1 year’s imprisonment, a fine of up to 1,000,000 baht, or both, and where a company commits the offence its responsible director is liable unless it can be shown they were not involved.

The PDPA is not the พระราชบัญญัติอาชญากรรมทางคอมพิวเตอร์, which punishes hacking and false content online, and it is not defamation, which concerns reputation. A leaked customer list is a PDPA matter; a false post about a customer is defamation; breaking into the database is computer crime.

คำถามที่พบบ่อย

Does the PDPA apply to a small business or a foreign company in Thailand?

Yes to both. Any business in Thailand that holds personal data about customers or staff is a data controller, and Section 5 extends the Act to foreign companies that sell to or monitor people in Thailand. Small businesses get limited relief, mainly from the duty to keep a record of processing, not from the Act itself.

What are the penalties under the Thai PDPA?

Administrative fines of up to 5,000,000 baht per breach, civil damages including punitive damages of up to twice the actual loss, and for unlawful use of sensitive data up to 1 year in prison and a fine of up to 1,000,000 baht. Directors can be personally liable for a company’s offence.

Can a landlord in Thailand keep a copy of my passport under the PDPA?

The landlord may copy the passport to meet legal obligations such as the TM30 notification and to perform the lease, without separate consent. Keeping it beyond that purpose, sharing it or using it for anything else needs a lawful basis, and the tenant can ask what is held and request its deletion once the purpose has ended.

ดูเพิ่มเติม: พระราชบัญญัติอาชญากรรมทางคอมพิวเตอร์, การหมิ่นประมาท, ทีเอ็ม30, Director, corporate criminal liability in Thailand และ กฎหมายธุรกิจในประเทศไทย.

ข่าวสารกฎหมายไทย ฟรีทางอีเมล

อัปเดตข่าวสารกฎหมายไทยในภาษาเข้าใจง่าย ที่ส่งผลกระทบต่อชาวต่างชาติ: อสังหาริมทรัพย์, วีซ่า, การสมรส, ธุรกิจ และพินัยกรรม จดหมายข่าวสั้นเพียงฉบับเดียวต่อเดือน จากสำนักงานกฎหมายที่ดำเนินงานมาตั้งแต่ปี 2549 ไม่มีการส่งสแปม ยกเลิกรับได้ทุกเมื่อ.

เลื่อนขึ้น
WhatsApp LINE โทร จอง