Skip to content
  • About
  • Accolades
  • Practices
    • China Desk
    • Corporate & Commercial
    • Corporate Services
    • Corporate, Commercial & Civil Litigation
    • Criminal
    • Cryptocurrency & Blockchain Disputes
    • Digital Assets, Web3 & Blockchain
    • Employment & Industrial Relations
    • Environmental, Social, and Governance (ESG)
    • Financial Services
    • FinTech
    • Funds, Private Equity & Emerging Technologies
    • India Desk
    • Insurance
    • International Arbitration
    • Maritime & Shipping
    • Mergers & Acquisitions
    • Private Client Disputes & Advisory
    • Probate, Wills & Estate
    • Real Estate & Construction
    • Regulatory & Compliance
    • Restructuring & Insolvency
    • Ship Sale & Purchase and Escrow Services
    • Tax
    • Vietnam Desk
    • White Collar Crime
    View all
    China Desk
    Corporate & Commercial
    Corporate Services
    Corporate, Commercial & Civil Litigation
    Criminal
    Cryptocurrency & Blockchain Disputes
    Digital Assets, Web3 & Blockchain
    Employment & Industrial Relations
    Environmental, Social, and Governance (ESG)
    Financial Services
    FinTech
    Funds, Private Equity & Emerging Technologies
    India Desk
    Insurance
    International Arbitration
    Maritime & Shipping
    Mergers & Acquisitions
    Private Client Disputes & Advisory
    Probate, Wills & Estate
    Real Estate & Construction
    Regulatory & Compliance
    Restructuring & Insolvency
    Ship Sale & Purchase and Escrow Services
    Tax
    Vietnam Desk
    White Collar Crime
  • People
  • Careers
  • Insights
  • Countries
    Offices
    • Singapore
    • Thailand
    • Malaysia
    • Australia
    Regional Desks
    • China
    • India
    • Vietnam
Enquiries
PDPA and Digital Transactions in Thailand: What Businesses Should Be Aware Of
  • Blog
  • | 8 July 2026

PDPA and Digital Transactions in Thailand: What Businesses Should Be Aware Of

Thailand’s PDPA, fully enforced since June 2022, requires businesses to collect personal data only with valid consent, appoint a Data Protection Officer where applicable, and report breaches within 72 hours. The Electronic Transaction Act governs the legal validity of e-signatures and digital contracts. In August 2025, the PDPC issued fines totalling THB 21.5 million across five cases. Businesses operating in or targeting Thailand, regardless of where they are based, must treat both laws as active, enforceable obligations.

Running a digital business in Thailand, or even just selling to Thai customers from abroad, means two pieces of legislation are almost certainly relevant: the PDPA in Thailand, which governs how personal data is collected, stored, used, and transferred, and the Electronic Transaction Act, which determines whether digital contracts and e-signatures hold up legally. PD Legal, a regional law firm with a dedicated Thailand practice, regularly advises businesses navigating the intersection of both frameworks. Neither law is especially new. What has changed is how seriously regulators are now treating non-compliance.

What Are the Core Compliance Obligations Under Thailand’s PDPA for Digital Businesses?

Most businesses focus on consent banners and privacy policies, but those are only the baseline. Practically, compliance covers several interconnected requirements:

  • Consent must be explicit and granular. A single checkbox does not satisfy the PDPA. Consent must be specific to each processing purpose and properly documented.
  • Data subject rights must be actionable. Access, correction, deletion, and objection requests require a real handling process, not just a policy that mentions them.
  • Breach notification is mandatory and time-bound. Failure to comply with the breach notification requirement may result in a fine of up to THB 3,000,000 (approximately USD 81,000).
  • Data Processing Agreements are required. When engaging third-party vendors, the absence of these contracts has featured repeatedly in PDPC enforcement cases.
  • Small businesses received partial relief in early 2025. Thailand’s PDPC published exemptions for small businesses from ROPA requirements under the PDPA, effective January and April 2025, though other obligations remain in force.

Documentation gaps and missing vendor contracts are consistently where businesses get caught.

How Does the Electronic Transaction Act Affect Digital Contracts in Thailand?

The Electronic Transaction Act B.E. 2544 (2001) gives e-signatures the same legal standing as traditional paper signatures, provided the ETA’s criteria are met. Finance and security documents add complexity, as sector-specific requirements from Thai financial regulators must be satisfied alongside the ETA. Thailand is also working on a proposed Electronic Transaction Bill that retains functional equivalence while introducing new notification and certification obligations. Businesses with established digital workflows should keep a close eye on its progress.

What Are the Rules for Cross-Border Transfer of Personal Data From Thailand?

On 25 December 2023, the PDPC published cross-border transfer notifications under Sections 28 and 29, enforceable from 24 March 2024. Data moving out of Thailand must go to countries with adequate protection standards or be covered by Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs). The problem is that the PDPC has yet to publish an adequacy list, so most transfers default to SCCs or BCRs, and those agreements need to be in place before data leaves, not after a breach surfaces.

What Penalties Has the PDPC Enforced and What Triggered Them?

On 1 August 2025, the PDPC announced eight administrative fines across five cases involving both public and private entities, totaling approximately THB 21.5 million, marking a clear shift from awareness-building to active compliance scrutiny. The cases revealed a consistent pattern of failures:

  • A cosmetics company was fined THB 2.5 million for failing to notify the PDPC of a data breach and for inadequate technical safeguards.
  • A government agency was penalized after engaging an unqualified service provider without a valid data processing agreement, exposing nearly 200,000 personal data records.
  • A private hospital faced orders related to mishandling of medical record destruction.

These recurring failures emphasize a broader issue: a lack of strategic commitment to data protection.

How Does Thailand’s PDPA Compare to the GDPR for Businesses Operating Across Both Regions?

Thailand’s PDPA shares similarities with the GDPR on cross-border data transfers, consent standards, and DPO requirements, which gives businesses with existing GDPR programs a useful foundation. That said, GDPR compliance does not equal PDPA compliance. Consent mechanisms built for European users may not satisfy Thailand’s specific thresholds, and the local enforcement structure introduces its own procedural requirements. Businesses that assume cross-compliance without a proper gap analysis tend to find the gaps at the worst possible time.

Why Work with PD Legal?

PD Legal Thailand brings hands-on regional experience to the full spectrum of data protection and digital transaction compliance, advising businesses across Southeast Asia on PDPA obligations, cross-border transfer frameworks, and Electronic Transaction Act requirements. The firm’s Regulatory & Compliance practice operates from Bangkok with integrated support across Singapore, Malaysia, and Australia, giving clients a single point of contact for multi-jurisdictional matters. Recognized as one of ALB’s Firms to Watch: Thailand 2025, PD Legal combines local regulatory knowledge with the depth of a regional practice built for the pace of modern commerce.

Conclusion

Thailand’s regulatory environment for data and digital transactions has moved well past the awareness stage. Businesses operating in or targeting Thailand need to treat PDPA compliance and Electronic Transaction Act obligations as operational priorities, not legal formalities. The fines, enforcement cases, and cross-border transfer rules are all active and expanding.

PD Legal Thailand offers practical, regionally informed legal support for businesses working through these requirements. From consent framework reviews to cross-border data transfer documentation, the team understands what regulators are actually looking for. Get in touch with PD Legal now to discuss your compliance position and what steps make sense for your business!

Legal Update (1)
  • Legal Update
  • | 23 July 2026

Federal Court Clarifies "Double-Hatting" Principle in Landmark Acexide Technology Ruling

1. Introduction The Federal Court of Malaysia’s recent decision in Acexide Technology Sdn Bhd & Anor v Chang Heng Keong (...)

More Insights
Find Us
  • Singapore

PDLegal LLC Singapore
1 Coleman Street 

#08-02 The Adelphi 

Singapore 179803

Tel: +65 6220 0325
Email: [email protected]

  • Thailand

PDLegal Asia (Thailand) Co., Ltd.
6th Floor, 6 O-NES Tower,
Sukhumvit Soi 6,
Khlong Toey, Bangkok 10110

Tel: +66 2 254 6415
Email: [email protected]

  • Malaysia

Tan, Siew & Lee (TSL Legal)
9-1, Level 9,
Wisma UOA Damansara II,
No. 6, Jalan Changkat Semantan,
Damansara Heights,
50490 Kuala Lumpur

Tel: +603 3009 7825
Email: [email protected]

  • Australia
PDLegal Australia
Level 3, Suite 12
58 Pitt Street
Sydney NSW 2000

Tel: +61 2 7813 7619
Email: [email protected]

Offices
  • Singapore
  • Thailand
  • Malaysia
  • Australia
Regional Desks
  • China
  • India
  • Vietnam
Follow Us
PDLegal LLC is a limited liability company registered in Singapore. The Firm is regulated by the Legal Services Regulatory Authority of Singapore. © All rights reserved 2026.
  • Privacy policy
  • Legal Notice
  • Cookie Policy
Cookies on our website

We use cookies on our site to remember you, show you content we think you will like and help you to use this site. For more details, please see our cookies policy.

Click ‘Accept’ to consent to cookies other than strictly necessary cookies or ‘Reject’ if you do not. You can change your mind at any time by visiting our cookie policy page.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
  • About
  • Accolades
  • Practices
    • China Desk
    • Corporate & Commercial
    • Corporate Services
    • Corporate, Commercial & Civil Litigation
    • Criminal
    • Cryptocurrency & Blockchain Disputes
    • Digital Assets, Web3 & Blockchain
    • Employment & Industrial Relations
    • Environmental, Social, and Governance (ESG)
    • Financial Services
    • FinTech
    • Funds, Private Equity & Emerging Technologies
    • India Desk
    • Insurance
    • International Arbitration
    • Maritime & Shipping
    • Mergers & Acquisitions
    • Private Client Disputes & Advisory
    • Probate, Wills & Estate
    • Real Estate & Construction
    • Regulatory & Compliance
    • Restructuring & Insolvency
    • Ship Sale & Purchase and Escrow Services
    • Tax
    • Vietnam Desk
    • White Collar Crime
    View all
  • People
  • Careers
  • Insights
  • Countries
    Offices
    • Singapore
    • Thailand
    • Malaysia
    • Australia
    Regional Desks
    • China
    • India
    • Vietnam
Enquiries