ตรวจสอบโดย ThaiLawOnline สำนักงานกฎหมายไทยที่ได้รับใบอนุญาตและดำเนินกิจการในประเทศไทยตั้งแต่ปี พ.ศ. 2549 ทนายความผู้รับผิดชอบสำนวน: วิชุดา อรรถเมธากุล, น.ม., ใบอนุญาตเนติบัณฑิตไทย เลขที่ 3149/2556.
ปรับปรุงล่าสุดเมื่อ
พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล (พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562, the Personal Data Protection Act B.E. 2562 (2019), บางครั้งเขียนว่า Thai PDPA หรือ Thailand PDPA) is Thailand’s general data protection law, modelled on the European GDPR and fully in force since 1 June 2022. It regulates anyone who collects, uses or discloses information about an identifiable living person, requires a lawful basis for doing so, gives the individual rights over the data, and backs those rules with fines, ความเสียหาย and, for sensitive data, prison. A foreigner meets it as a business owner, an employer, a landlord and as the person whose passport is being photocopied.
สารบัญ
สิ่งที่พระราชบัญญตรัฐธรรมนูญกำหนดให้ผู้ควบคุมข้อมูลส่วนบุคคลต้องปฏิบัติ
Scope. The Act binds a data controller (who decides why and how data is used) and a data processor (who handles it on the controller’s instructions) established in Thailand, and by Section 5 also those abroad who offer goods or services to people in Thailand or monitor their behaviour. Purely personal or household use is outside it.
Lawful basis and sensitive data. Personal data may be collected only with consent or on another basis the Act lists: performance of a contract, a legal obligation, vital interests, a public task or the controller’s legitimate interests. Section 26 treats data on race, ethnicity, political opinion, religion, sexual behaviour, ประวัติอาชญากรรม, health, disability, trade union membership, genetic and biometric data as sensitive, needing explicit consent unless a narrow exception applies. Controllers must tell people what is collected and why, keep it secure, notify the regulator of a breach within 72 hours, and honour requests to access, correct, delete or port the data.
เมื่อชาวต่างชาติพบกับ พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล (PDPA) ในทางปฏิบัติ
Running a business. A Thai company with customers, staff or a website needs a privacy notice, consent wording for marketing, a record of processing (small businesses are partly exempt), contracts with processors such as payroll providers, and a data protection officer if it monitors people on a large scale or handles sensitive data as a core activity. Transfers abroad, including to a foreign head office, are allowed under Section 28 only to countries with adequate protection or under safeguards such as binding corporate rules or standard contract clauses.
As a landlord, host or condominium. Copying a tenant’s passport to file a ทีเอ็ม30 rests on a legal obligation and needs no consent, but keeping the copy for years, or a นิติบุคคลอาคารชุด sharing CCTV footage or resident lists, does not. The regulator is the Personal Data Protection Committee under the Ministry of Digital Economy and Society.
บทกำหนดโทษและความแตกต่างของ PDPA กับกฎหมายอื่นๆ
Administrative fines of up to 5,000,000 baht per breach are imposed by the Committee. Civil claims by the person affected allow the court to award punitive damages of up to twice the actual damage. Criminal liability under Section 79 attaches to unlawful use or disclosure of sensitive data that causes damage or is done for gain: up to 1 year’s imprisonment, a fine of up to 1,000,000 baht, or both, and where a company commits the offence its responsible director is liable unless it can be shown they were not involved.
The PDPA is not the พระราชบัญญัติอาชญากรรมทางคอมพิวเตอร์, which punishes hacking and false content online, and it is not defamation, which concerns reputation. A leaked customer list is a PDPA matter; a false post about a customer is defamation; breaking into the database is computer crime.
คำถามที่พบบ่อย
PDPA บังคับใช้กับธุรกิจขนาดเล็กหรือบริษัทต่างชาติในประเทศไทยหรือไม่
ใช่ทั้งสองข้อ ธุรกิจใดๆ ในประเทศไทยที่มีข้อมูลส่วนบุคคลของลูกค้าหรือพนักงานถือเป็นผู้ควบคุมข้อมูล และมาตรา 5 ขยายขอบเขตของพระราชบัญญัตินี้ไปยังบริษัทต่างชาติที่ขายสินค้าให้กับผู้คนในประเทศไทยหรือตรวจสอบพิกัดหรือพฤติกรรมของพวกเขา ธุรกิจขนาดเล็กได้รับการผ่อนปรนเพียงเล็กน้อย โดยหลักๆ คือได้รับการยกเว้นหน้าที่ในการจัดเก็บบันทึกรายการกิจกรรมการประมวลผล ไม่ใช่ได้รับการยกเว้นจากตัวพระราชบัญญัติเอง.
What are the penalties under the Thai PDPA?
Administrative fines of up to 5,000,000 baht per breach, civil damages including punitive damages of up to twice the actual loss, and for unlawful use of sensitive data up to 1 year in prison and a fine of up to 1,000,000 baht. Directors can be personally liable for a company’s offence.
ภายใต้กฎหมายคุ้มครองข้อมูลส่วนบุคคล (PDPA) ของประเทศไทย เจ้าของบ้านเช่าสามารถเก็บสำเนาหนังสือเดินทางของคุณได้หรือไม่
ผู้ให้เช่าอาจสำเนาหนังสือเดินทางเพื่อปฏิบัติตามข้อผูกพันทางกฎหมาย เช่น การแจ้ง ต.ม. 30 และเพื่อปฏิบัติตามสัญญาเช่า โดยไม่ต้องได้รับความยินยอมแยกต่างหาก การเก็บรักษาเกินกว่าวัตถุประสงค์ดังกล่าว การเปิดเผย หรือการนำไปใช้เพื่อการอื่น จำเป็นต้องมีฐานทางกฎหมาย และผู้เช่ามีสิทธิ์สอบถามถึงข้อมูลที่มีอยู่และขอให้ลบข้อมูลนั้นได้เมื่อสิ้นสุดวัตถุประสงค์แล้ว.
ดูเพิ่มเติม: พระราชบัญญัติอาชญากรรมทางคอมพิวเตอร์, การหมิ่นประมาท, ทีเอ็ม30, ผู้อำนวยการ, corporate criminal liability in Thailand และ กฎหมายธุรกิจในประเทศไทย.
ข่าวสารกฎหมายไทย ฟรีทางอีเมล
อัปเดตข่าวสารกฎหมายไทยในภาษาเข้าใจง่าย ที่ส่งผลกระทบต่อชาวต่างชาติ: อสังหาริมทรัพย์, วีซ่า, การสมรส, ธุรกิจ และพินัยกรรม จดหมายข่าวสั้นเพียงฉบับเดียวต่อเดือน จากสำนักงานกฎหมายที่ดำเนินงานมาตั้งแต่ปี 2549 ไม่มีการส่งสแปม ยกเลิกรับได้ทุกเมื่อ.