Personal Data Protection Act B.E. 2562 (2019)
Sets lawful bases, data-subject rights, controller duties and breach notification.
Practice area
Building data protection practices that match Thailand’s PDPA.

The Personal Data Protection Act B.E. 2562 (2019) requires data controllers to have a lawful basis for collecting, using and disclosing personal data, to give notice of purposes, to keep records of processing activities and to maintain appropriate security measures. We translate those requirements into workable documents and procedures — privacy notices, processor agreements and a route for handling data subject requests.
Mapping data flows and producing the core document set for a small to mid-sized organisation typically takes some weeks, depending on the number of departments and systems. Organisations handling sensitive data or transferring data abroad need longer.
Timeframes are indicative only and depend on the authority, the court calendar and the completeness of your documents.

Many organisations start by downloading template policies and then find they do not match daily operations — a notice promising one-year retention while the back-end never deletes anything, or a contact channel nobody monitors. Those gaps become the issue as soon as a data subject request arrives, which is why we work upward from the real process to the document, not the other way round.
What we hand over therefore includes the data flow map, records of processing, policies tied to the actual systems, and a request-handling procedure naming the responsible person and the time frame, together with sample response letters the team can use immediately.
Translation and certification work touches personal data directly: civil registration records, criminal record checks, marriage documents and health information. Organisations sending such files to an external provider should have a clear data processing agreement setting out the permitted use, the retention period and how data is destroyed when the matter closes.
Because the firm provides both the legal and the document work, our internal procedures limit access to the personnel handling that matter and set retention periods according to what each type of work genuinely requires.
Summarised for general understanding only. The application of each provision depends on the facts of your case.
Sets lawful bases, data-subject rights, controller duties and breach notification.
Provide operational detail such as security measures and records of processing.
These are constructed examples used to explain procedure. They are not client matters, and no outcome is implied or guaranteed.
Situation: A customer exercises the right to erasure, but accounting and tax law still require retention.
Usual approach: Separate legally mandated records from marketing data and reply in writing explaining the retained basis and retention period. (Hypothetical.)
Province pages set out the courts and authorities with jurisdiction locally, and answer the questions people in that area ask.
The Act applies to data controllers without a general exemption by business size, though what counts as appropriate measures scales with the risk and volume of data held.
It depends on the organisation’s activities as defined by the Act — for example large-scale processing requiring regular monitoring, or processing of sensitive data. We assess this organisation by organisation.
Yes where a lawful basis applies and only to the extent necessary for the stated purpose, with clear notice and a defined retention period. Keeping copies without a justification is a common exposure.
Tell us the facts and we will explain the options, the documents required and the realistic timeframe before you decide.