Personal Data Protection Act B.E. 2562 (2019)
Sets lawful bases, data-subject rights, controller duties and breach notification.
Central Thailand — Bangkok
Building data protection practices that match Thailand’s PDPA.

Bangkok concentrates the courts, central government departments, embassies and most corporate head offices in Thailand. A legal matter arising in Bangkok therefore usually touches several authorities at once — the court with territorial jurisdiction, the Department of Business Development, the district land offices, the Immigration Bureau and the Department of Consular Affairs. Sequencing the steps correctly from the start saves far more time than correcting them later.
The Personal Data Protection Act B.E. 2562 (2019) requires data controllers to have a lawful basis for collecting, using and disclosing personal data, to give notice of purposes, to keep records of processing activities and to maintain appropriate security measures. We translate those requirements into workable documents and procedures — privacy notices, processor agreements and a route for handling data subject requests.
Jurisdiction and filing requirements should be confirmed for each matter, because practice and required attachments differ between offices.
| Court / authority | What it handles |
|---|---|
| Civil Court, Criminal Court and Bangkok municipal courts | Hear civil and criminal cases according to territorial jurisdiction in Bangkok |
| Central Labour Court | Dismissal, severance and employment-contract disputes |
| Central Administrative Court | Challenges to state orders and administrative action |
| Central Intellectual Property and International Trade Court | Trademark, copyright, patent and international trade cases |
| Central Bankruptcy Court | Bankruptcy and business rehabilitation |
| Legal Execution Department | Seizure, garnishment, auction and execution-stage mediation |
| Department of Business Development | Company registration and registered changes |
| Department of Consular Affairs, MFA | Legalisation of documents for overseas use |
| Immigration Bureau | Visas, extensions of stay and residence notification |
Mapping data flows and producing the core document set for a small to mid-sized organisation typically takes some weeks, depending on the number of departments and systems. Organisations handling sensitive data or transferring data abroad need longer.
Timeframes are indicative and depend on the court calendar and the authority handling the matter in Bangkok.
Summarised for general understanding only. The application of each provision depends on the facts of your case.
Sets lawful bases, data-subject rights, controller duties and breach notification.
Provide operational detail such as security measures and records of processing.
These are constructed examples used to explain procedure. They are not client matters, and no outcome is implied or guaranteed.
Situation: A customer exercises the right to erasure, but accounting and tax law still require retention.
Usual approach: Separate legally mandated records from marketing data and reply in writing explaining the retained basis and retention period. (Hypothetical.)

It depends on the case type and territorial jurisdiction. General civil and criminal cases go to separate courts, while labour, administrative, IP and bankruptcy matters each have a specialised court. We verify jurisdiction from the parties’ domicile and the place of the events before filing.
Not every hearing. With a proper appointment of counsel and power of attorney, your lawyer can act for you in many steps, but hearings where you must testify require your attendance. We tell you in advance which dates are mandatory.
Always start from the receiving authority’s requirement — it dictates whether you need signature certification, translation, MFA legalisation and embassy endorsement, and in what order. For Thailand, the Apostille Convention enters into force on 28 February 2027; until then MFA and embassy legalisation continues to apply.
The Act applies to data controllers without a general exemption by business size, though what counts as appropriate measures scales with the risk and volume of data held.
It depends on the organisation’s activities as defined by the Act — for example large-scale processing requiring regular monitoring, or processing of sensitive data. We assess this organisation by organisation.
Yes where a lawful basis applies and only to the extent necessary for the stated purpose, with clear notice and a defined retention period. Keeping copies without a justification is a common exposure.
Tell us the facts and we will explain which authority applies, what documents are needed and the realistic timeframe.