Skip to main content
Apostille 2026 Ready · Pre-book — 20% off →
Skip to content

Practice area

PDPA & Data Protection Compliance

Building data protection practices that match Thailand’s PDPA.

Attorneys reviewing a pdpa & data protection compliance matter in a Bangkok law firm boardroom

The Personal Data Protection Act B.E. 2562 (2019) requires data controllers to have a lawful basis for collecting, using and disclosing personal data, to give notice of purposes, to keep records of processing activities and to maintain appropriate security measures. We translate those requirements into workable documents and procedures — privacy notices, processor agreements and a route for handling data subject requests.

What this practice covers

  • Data flow mapping and records of processing activities
  • Drafting privacy policies, notices and consent forms
  • Data processing agreements with vendors
  • Procedures for handling data subject rights requests
  • Data breach response and notification procedures
  • Advice on cross-border transfers of personal data
  • Staff training and internal handbooks

How we work on your matter

  1. 1Initial case assessment of the business and the data it holds
  2. 2Interviewing each department to build the data flow map
  3. 3Identifying the lawful basis for each activity and the gaps to close
  4. 4Delivering the document set and procedures with training for the actual users
  5. 5Periodic review when services or vendors change

Documents to prepare

  • Inventory of systems and applications holding personal data
  • Contracts with vendors that access personal data
  • Forms and channels used to collect customer and employee data
  • Existing information security policies

Points to watch

  • Consent is not the only lawful basis; asking for it unnecessarily creates avoidable burden.
  • Sensitive data such as health and criminal records carries stricter conditions than ordinary data.
  • Having policy documents is not enough; practice must match them and be auditable.
  • Cross-border transfers must be assessed case by case against the statutory conditions.

Typical timeframe

Mapping data flows and producing the core document set for a small to mid-sized organisation typically takes some weeks, depending on the number of departments and systems. Organisations handling sensitive data or transferring data abroad need longer.

Timeframes are indicative only and depend on the authority, the court calendar and the completeness of your documents.

A Thai attorney explaining legal options to a client across a desk
Every matter starts with a consultation: we explain the realistic options before any filing is made.

From policy documents to auditable practice

Many organisations start by downloading template policies and then find they do not match daily operations — a notice promising one-year retention while the back-end never deletes anything, or a contact channel nobody monitors. Those gaps become the issue as soon as a data subject request arrives, which is why we work upward from the real process to the document, not the other way round.

What we hand over therefore includes the data flow map, records of processing, policies tied to the actual systems, and a request-handling procedure naming the responsible person and the time frame, together with sample response letters the team can use immediately.

Personal data in cross-border document work

Translation and certification work touches personal data directly: civil registration records, criminal record checks, marriage documents and health information. Organisations sending such files to an external provider should have a clear data processing agreement setting out the permitted use, the retention period and how data is destroyed when the matter closes.

Because the firm provides both the legal and the document work, our internal procedures limit access to the personnel handling that matter and set retention periods according to what each type of work genuinely requires.

Laws that govern this matter

Summarised for general understanding only. The application of each provision depends on the facts of your case.

Personal Data Protection Act B.E. 2562 (2019)

Sets lawful bases, data-subject rights, controller duties and breach notification.

PDPC subordinate notifications

Provide operational detail such as security measures and records of processing.

Example situations and how they are handled

These are constructed examples used to explain procedure. They are not client matters, and no outcome is implied or guaranteed.

Illustrative scenario: a customer demands full deletion

Situation: A customer exercises the right to erasure, but accounting and tax law still require retention.

Usual approach: Separate legally mandated records from marketing data and reply in writing explaining the retained basis and retention period. (Hypothetical.)

Advice for your specific situation

Businesses collecting customer data online

  • Make the processing records reflect the systems actually used, not a copied template.
  • Review vendor contracts — liability stays with the controller.

Every matter — what to do in the first 7 days

  • Gather every original document in one place, keep scanned copies, and note the date you received each one.
  • Write a dated timeline — the date you received a notice or learned of the event usually starts the limitation or appeal clock.
  • Do not sign a settlement, debt acknowledgement or withdrawal before a lawyer reviews it — it may extinguish existing rights.
  • Preserve digital evidence unaltered (full screenshots, original files, emails with headers) — edited files are easy to challenge.

This service in your province

Province pages set out the courts and authorities with jurisdiction locally, and answer the questions people in that area ask.

Frequently asked questions

Does the PDPA apply to small businesses?

The Act applies to data controllers without a general exemption by business size, though what counts as appropriate measures scales with the risk and volume of data held.

Do we need a Data Protection Officer?

It depends on the organisation’s activities as defined by the Act — for example large-scale processing requiring regular monitoring, or processing of sensitive data. We assess this organisation by organisation.

Can we keep copies of customers’ ID cards?

Yes where a lawful basis applies and only to the extent necessary for the stated purpose, with clear notice and a defined retention period. Keeping copies without a justification is a common exposure.

Other practice areas

Litigation & Court RepresentationCivil, criminal, labour, family, succession and land disputesCorporate & CommercialIncorporation, contracts, foreign business, BOI and complianceImmigration & Foreign NationalsVisas, work permits, residency and lawful statusIntellectual PropertyTrademarks, copyright, patents and enforcementLand & Real EstateTitle due diligence, sale, lease and transfer at the Land OfficeFamily & SuccessionMarriage, divorce, custody, wills and estate administrationMediation, Arbitration & EnforcementResolving disputes outside court and making awards effectiveNotarial Services & International DocumentsSignature and document certification, translation, consular and embassy legalisationBOI Promotion & Foreign Business LicensingStructuring foreign investment in Thailand correctly from day one.Tax, Accounting & Employer ComplianceKeeping every statutory tax and accounting deadline under control.Condominium & Foreign Property OwnershipChecking title, documents and transfer before a major payment is made.Employment & Labour LawAdvising employers and employees under the Labour Protection Act.Integrated Legal Support ServicesInterpreters, documents, agency runs and case tracking in one place.Judgment Enforcement & Asset TracingTurning a judgment into actual recovery through lawful tracing, seizure and attachment.M&A & Legal Due DiligenceChecking what you are buying and structuring the deal so it can actually close.Administrative Law & Appeals Against State DecisionsChallenging unfair administrative decisions through the correct procedure and deadlines.Cybercrime, Online Fraud & Asset RecoveryActing quickly when money is transferred by deception or rights are violated online.Company Secretarial & Corporate RegistrationsKeeping registrations, meetings and statutory records complete and on time.Wills, Succession & Estate AdministrationDrafting wills that hold up, and administering estates correctly under Thai law.Monthly Retainer Counsel for Businesses & ExpatriatesA standing legal team that knows your business, without hiring in-house staff.

Speak with an attorney about your matter

Tell us the facts and we will explain the options, the documents required and the realistic timeframe before you decide.