Skip to main content
Apostille 2026 Ready · Pre-book — 20% off →
Skip to content

Personal data protection (PDPA) programme

Quick answer

Policies, records of processing activities and consent forms aligned with the Personal Data Protection Act.

Key facts

Who it is for
Organisations holding customer, employee or partner data, and processors acting for others.
Authority involved
Personal Data Protection Committee Office
How it differs
Unlike publishing a privacy notice alone, this requires processing records and procedures that actually run.
Service areas
Bangkok, Khon Kaen, Udon Thani, Nong Khai and online nationwide

Document checklist

  • Inventory of personal data held and the purpose of each set
  • Contracts with third parties that access the data
  • Current privacy notice and consent forms
  • Security measures actually in place

Working steps

  1. Map data flows and the lawful basis for each activity
  2. Update the privacy notice and consent forms
  3. Build the record of processing activities
  4. Define procedures for data-subject requests and breach response
  5. Train the teams involved and review on a cycle

Cautions

  • Bundled consent covering every purpose in one clause rarely survives scrutiny
  • Cross-border transfers need separate conditions assessed before they start

Compare: with us vs. on your own

AspectWith our teamDoing it yourself
ScopePolicies, records of processing activities and consent forms aligned with the Personal Data Protection Act.Self-filing: you research the destination requirements, assemble the file and follow up at every counter yourself.
Authority to deal withPersonal Data Protection Committee Office, coordinated end to end by one accountable contact.You approach each authority separately and carry the risk if the sequence is wrong.
Documents requiredChecked before work starts: Inventory of personal data held and the purpose of each set · Contracts with third parties that access the data · Current privacy notice and consent formsMissing items are typically discovered at the counter, forcing a re-file.
Common riskKnown failure points are checked upfront, e.g. bundled consent covering every purpose in one clause rarely survives scrutinyProblems surface only after rejection, which usually means restarting the process.
Which to chooseUnlike publishing a privacy notice alone, this requires processing records and procedures that actually run.Reasonable when there is a single document, the destination states its requirements clearly, and no deadline is pressing.

Worked scenarios

First-time preparation

Situation: The requester falls within organisations holding customer, employee or partner data, and processors acting for others. and has never filed this type of matter, so it is unclear which file personal data protection committee office will accept.

Approach: Start by map data flows and the lawful basis for each activity, walk the checklist item by item before any work begins, then follow the sequence through to train the teams involved and review on a cycle.

Outcome: The result is a complete file at the first submission, avoiding repeat trips and retroactive corrections.

Previously rejected file

Situation: An earlier submission was returned; the most common cause in this type of work is bundled consent covering every purpose in one clause rarely survives scrutiny.

Approach: Trace back from the rejection point, fix the root cause, then re-check the second most common failure — cross-border transfers need separate conditions assessed before they start — before re-filing.

Outcome: The file can be re-filed without rebuilding it, with a written record of each correction for the authority.

Bundled with related work

Situation: Several matters within technology and organisational data governance are needed at once, and the same documents should not be submitted repeatedly.

Approach: Sequence the prerequisite item first, share one core document set, and split out only what each authority additionally requires.

Outcome: Fewer certified copies and fewer counter visits, while each individual file remains correct on its own.

Frequently asked questions

What is personal data protection (pdpa) programme and what does it cover?

Policies, records of processing activities and consent forms aligned with the Personal Data Protection Act. It sits within technology and organisational data governance, so it can be planned alongside related work without duplicating filings.

Who typically needs personal data protection (pdpa) programme?

Organisations holding customer, employee or partner data, and processors acting for others. If you are unsure whether your case qualifies, share the documents and the receiving authority so the scope can be assessed first.

Which documents are needed for personal data protection (pdpa) programme?

Normally: Inventory of personal data held and the purpose of each set · Contracts with third parties that access the data · Current privacy notice and consent forms · Security measures actually in place. The receiving authority may require additional items.

What are the working steps for personal data protection (pdpa) programme?

1) Map data flows and the lawful basis for each activity 2) Update the privacy notice and consent forms 3) Build the record of processing activities 4) Define procedures for data-subject requests and breach response 5) Train the teams involved and review on a cycle

What commonly goes wrong with personal data protection (pdpa) programme?

• Bundled consent covering every purpose in one clause rarely survives scrutiny • Cross-border transfers need separate conditions assessed before they start

How does personal data protection (pdpa) programme differ from the nearest alternative?

Unlike publishing a privacy notice alone, this requires processing records and procedures that actually run.

Which authority is involved in personal data protection (pdpa) programme?

Personal Data Protection Committee Office is the primary authority. Business services in Thailand map onto clearly separated authorities: company registration sits with the Department of Business Development, taxation with the Revenue Department, social security with the Social Security Office, certification of translations for overseas use with the Department of Consular Affairs (MFA), and signature certification with lawyers authorised under Lawyers Council regulations. Routing each task to the correct authority from the start is what prevents re-filing and rejection.

How do I start personal data protection (pdpa) programme?

Send the documents you hold, the intended use, and the receiving authority or destination country. We assess scope, flag missing items and propose a filing order that reduces rejection risk. Available in Bangkok, Khon Kaen, Udon Thani, Nong Khai and online nationwide.

Is personal data protection (pdpa) programme available outside Bangkok or from abroad?

Yes. Most matters begin with a scan review, with originals couriered only when required. Clients across all 77 provinces and overseas clients can proceed online, in many cases with a power of attorney.

What is the source of this information and when was it verified?

The content follows the published mandates of the responsible authorities and was last reviewed on 2026-08-17. Confirm current requirements with the receiving authority before filing, as forms and conditions change.

Why does personal data protection (pdpa) programme require "Inventory of personal data held and the purpose of each set"?

This item evidences a fact the receiving desk must verify before approval. If it is missing or inconsistent with the rest of the bundle, the file is usually returned at intake rather than at assessment.

Why does personal data protection (pdpa) programme require "Contracts with third parties that access the data"?

This item evidences a fact the receiving desk must verify before approval. If it is missing or inconsistent with the rest of the bundle, the file is usually returned at intake rather than at assessment.

Why does personal data protection (pdpa) programme require "Current privacy notice and consent forms"?

This item evidences a fact the receiving desk must verify before approval. If it is missing or inconsistent with the rest of the bundle, the file is usually returned at intake rather than at assessment.

Why does personal data protection (pdpa) programme require "Security measures actually in place"?

This item evidences a fact the receiving desk must verify before approval. If it is missing or inconsistent with the rest of the bundle, the file is usually returned at intake rather than at assessment.

What happens at step 1 of personal data protection (pdpa) programme?

Map data flows and the lawful basis for each activity This step must complete before the next one begins; working out of order usually forces a restart.

What happens at step 2 of personal data protection (pdpa) programme?

Update the privacy notice and consent forms This step must complete before the next one begins; working out of order usually forces a restart.

What happens at step 3 of personal data protection (pdpa) programme?

Build the record of processing activities This step must complete before the next one begins; working out of order usually forces a restart.

What happens at step 4 of personal data protection (pdpa) programme?

Define procedures for data-subject requests and breach response This step must complete before the next one begins; working out of order usually forces a restart.

What happens at step 5 of personal data protection (pdpa) programme?

Train the teams involved and review on a cycle This step must complete before the next one begins; working out of order usually forces a restart.

How do we prevent "Bundled consent covering every purpose i…"?

Check it before work starts: reconcile the data across every document in the bundle and confirm the destination authority's conditions in writing before any step that incurs real cost.

How do we prevent "Cross-border transfers need separate con…"?

Check it before work starts: reconcile the data across every document in the bundle and confirm the destination authority's conditions in writing before any step that incurs real cost.

How do I use personal data protection (pdpa) programme in Bangkok?

Book ahead at the Bangkok office, or send scans for review first and bring the originals in a single visit. This keeps clients travelling from nearby areas from making a second trip over missing paperwork.

How do I use personal data protection (pdpa) programme in Khon Kaen?

Book ahead at the Khon Kaen office, or send scans for review first and bring the originals in a single visit. This keeps clients travelling from nearby areas from making a second trip over missing paperwork.

How do I use personal data protection (pdpa) programme in Udon Thani?

Book ahead at the Udon Thani office, or send scans for review first and bring the originals in a single visit. This keeps clients travelling from nearby areas from making a second trip over missing paperwork.

How do I use personal data protection (pdpa) programme in Nong Khai?

Book ahead at the Nong Khai office, or send scans for review first and bring the originals in a single visit. This keeps clients travelling from nearby areas from making a second trip over missing paperwork.

How does personal data protection (pdpa) programme differ from document workflow digitisation, and should they be combined?

Policies, records of processing activities and consent forms aligned with the Personal Data Protection Act. By contrast, designing the document path from intake and verification through approval and archiving, so every step is auditable and re-filing is reduced. Both sit in technology and organisational data governance and share base documents, so planning them together avoids duplicate filings when the destination requires both.

How does personal data protection (pdpa) programme differ from electronic signatures and evidentiary record keeping, and should they be combined?

Policies, records of processing activities and consent forms aligned with the Personal Data Protection Act. By contrast, practices for electronic signing, supporting evidence retention, and identifying the cases that still require wet-ink documents with certification. Both sit in technology and organisational data governance and share base documents, so planning them together avoids duplicate filings when the destination requires both.

How does personal data protection (pdpa) programme differ from back-office systems integration, and should they be combined?

Policies, records of processing activities and consent forms aligned with the Personal Data Protection Act. By contrast, connecting accounting, HR and document systems so one dataset flows through without re-keying. Both sit in technology and organisational data governance and share base documents, so planning them together avoids duplicate filings when the destination requires both.

How does personal data protection (pdpa) programme differ from website and online-presence compliance, and should they be combined?

Policies, records of processing activities and consent forms aligned with the Personal Data Protection Act. By contrast, reviewing website claims, mandatory disclosures and organisational contact details so they match the facts and applicable requirements. Both sit in technology and organisational data governance and share base documents, so planning them together avoids duplicate filings when the destination requires both.

Which language should documents for personal data protection (pdpa) programme be in?

Follow the receiving authority. Thai documents used abroad normally need an English or local-language translation; foreign documents used in Thailand need a certified Thai translation.

Can someone act on my behalf for personal data protection (pdpa) programme?

In many cases yes, using a power of attorney that states the scope, with ID or passport copies of both parties. Some authorities still require the applicant in person for specific steps, so confirm before travelling.

What if the paperwork was rejected before?

Always obtain the reason in writing first, then check three things: name and date consistency across every document, a complete certification chain, and the destination authority's required format. Refile only after the order is corrected.

How is confidentiality handled for personal data protection (pdpa) programme?

Documents are used only as required to complete the matter, are not disclosed to third parties without consent, and working files are returned or destroyed on request once the matter closes.

Related services in this family

Services from other families that often follow

  • Translation, interpreting and language management

    Court and legal interpreting

    Interpreting for questioning, mediation, hearings and document signing before a lawyer or official.

  • Accounting, tax, audit and payroll

    Half-year and annual corporate income tax

    Preparation of profit estimates and corporate income-tax returns with tax-adjustment working papers.

  • Company formation, licensing and investment promotion

    Corporate change filings

    Filings for changes of directors, signing authority, registered address, objectives, capital and share transfers.

  • Legal services and dispute resolution

    Family and inheritance matters

    Divorce, child custody, marital property, wills and estate-administrator appointments.

  • Immigration and work authorisation

    Certificate of residence

    Obtaining a residence certificate for driving licences, bank accounts or other filings that require proof of address.

  • Certification, legalisation and clearance

    Police clearance certificate

    Application for a police clearance certificate from the Royal Thai Police, including fingerprinting and onward certification.

Browse the full business-services catalogue →

Content last reviewed: 2026-08-17