PDPA Thailand
Evidence request list. 38 controls, 38 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Breach and Enforcement
Per Thailand PDPA Section 37(4): breach notification + enforcement. Requirements include (a) implement Data Breach Notification - notify PDPC within 72 hours of becoming aware of breach unless unlikely to result in risk + notify affected data subjects where high risk + (b) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (c) operate Complaints Handling mechanism for data subjects + (d) maintain Compliance Monitoring and Auditing + Regulatory Reporting and Cooperation with PDPC + (e) maintain Enforcement and Penalties awareness including administrative penalties + criminal penalties + civil liability + (f) maintain documented breach log + incident response + tabletop exercises + (g) integrate with broader incident management.
- PDPA Thailand evidence for PDPATH-8
- DPO + DPIA + transfer assessment + breach notification partial
Consent
Per Thailand PDPA: consent + sensitive data handling. Requirements include (a) obtain Consent that is freely given + specific + informed + unambiguous + clearly distinguishable from other matters + with mechanism for withdrawal + (b) implement special protections for Sensitive Personal Data including health + biometric + genetic + race + religion + political + sexual orientation + criminal records + requiring explicit consent or specific legal basis per PDPA + (c) implement Children's Personal Data of Minors protections requiring parental consent per Thailand civil age + (d) maintain records of consent including how + when obtained + purpose + withdrawal + (e) integrate consent + sensitive data handling with privacy programme + (f) maintain change management for consent updates.
- PDPA Thailand evidence for PDPATH-2
- DPO + DPIA + transfer assessment + breach notification partial
Governance and Lifecycle
Per Thailand PDPA + PDPC: governance + lifecycle. Requirements include (a) appoint Data Protection Officer (DPO) where required (large-scale processing + sensitive data + monitoring) with defined responsibilities + reporting to highest management + (b) maintain Record of Processing Activities including purposes + categories + recipients + retention + safeguards + (c) implement Retention Limitation including retention schedules + secure deletion + anonymisation + (d) implement Direct Marketing and Communications safeguards including consent + opt-out + suppression lists + (e) deliver Personnel Training and Awareness programmes including role-based content + PDPA + privacy + security + breach response + (f) maintain documented governance + accountability framework.
- PDPA Thailand evidence for PDPATH-7
- DPO + DPIA + transfer assessment + breach notification partial
High-Risk Processing
Per Thailand PDPA + PDPC guidance: heightened safeguards for high-risk processing. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing including large-scale + sensitive + systematic monitoring + new technologies + AI per PDPC guidance + (b) implement Privacy by Design and Default across systems + processes + products + procurement + (c) implement Personal Data of Minors protections per the PDPA + (d) maintain documented DPIA + safeguards + risk assessments + (e) integrate privacy considerations into change management + (f) maintain ongoing review of high-risk processing.
- PDPA Thailand evidence for PDPATH-4
- DPO + DPIA + transfer assessment + breach notification partial
Individual Rights
Per Thailand PDPA Chapter 3: data subject rights. Requirements include (a) implement Data Subject Rights Handling including Access + Rectification + Erasure + Restriction + Object to Processing + Data Portability + (b) implement Right to Object + Withdrawal of Consent + (c) implement Automated Decisions and Profiling protections including human review + explanation + objection rights where applicable + (d) implement Accuracy and Up-to-date Data principle ensuring personal data is accurate + complete + (e) maintain mechanism for receiving + verifying + responding to requests within statutory timelines + (f) maintain records of requests + responses + decisions.
- PDPA Thailand evidence for PDPATH-3
- DPO + DPIA + transfer assessment + breach notification partial
Scope and Lawful Basis
Per Thailand PDPA B.E. 2562 (2019) Sections on scope + lawful basis + notice. Requirements include (a) determine scope including Extra-territorial Application - PDPA applies to processing of personal data of Thai data subjects even by controllers/processors outside Thailand + (b) establish Lawful Basis for Processing including consent + contract + legal obligation + vital interests + public interest + legitimate interests + (c) provide Privacy Notice to Data Subjects covering identity of controller + purposes + categories + recipients + retention + rights + transfer + (d) document applicability assessment + lawful basis + (e) maintain change management for notice and lawful basis updates + (f) align internal definitions and policies with PDPA Thailand and PDPC guidance.
- PDPA Thailand evidence for PDPATH-1
- DPO + DPIA + transfer assessment + breach notification partial
Security
Per Thailand PDPA Section 37: implement appropriate security measures. Requirements include (a) implement Security Measures including organisational + technical + physical measures appropriate to risk + (b) implement Encryption of personal data at rest + in transit + appropriate to classification + (c) implement Pseudonymization Techniques where appropriate + (d) implement Access Control for personal data including authentication + authorisation + audit + (e) conduct Regular Security Testing and Assessment + (f) integrate with broader information security programme + (g) maintain documented security measures aligned to PDPC guidance + minimum standards.
- PDPA Thailand evidence for PDPATH-5
- DPO + DPIA + transfer assessment + breach notification partial
Thailand PDPA Sections 19 to 26: Consent and Lawful Basis
Collection, use, or disclosure of personal data requires consent unless another lawful basis applies. Consent must be explicit, freely given, specific, and clearly evidenced.
- consent records
- lawful basis register
- consent UI screenshots
- consent withdrawal logs
- bundled consent
- pre-ticked boxes
- no withdrawal mechanism
- consent timestamp missing
Consent from minors under 10 requires holder of parental responsibility. Minors 10-20 require parental consent unless transaction is appropriate for age.
- age verification procedure
- parental consent records
- minor consent UX flow
- no age gate
- parental consent not captured
- age threshold misapplied
Personal data shall only be collected, used, or disclosed for purposes notified to the data subject prior to or at the time of collection.
- purpose register
- privacy notices
- purpose change consent records
- secondary use without new consent
- vague catch-all purposes
- purpose drift undetected
Collection of personal data shall be limited to that necessary for the lawful purposes of the data controller.
- data minimisation review
- field-level necessity justification
- form design audits
- over-collection on intake forms
- no periodic minimisation review
- optional fields treated as mandatory
Controllers must inform data subjects of purpose, categories collected, recipients, retention, rights, and contact details prior to or at collection.
- privacy notice (Thai and English)
- layered notice design
- notice version control
- just-in-time notices
- Thai language version missing
- recipients not disclosed
- retention period absent
- DPO contact omitted
Processing without consent permitted for research with safeguards, vital interest, contract performance, legal obligation, public interest, or legitimate interest.
- lawful basis assessment per processing activity
- legitimate interest assessments (LIA)
- contract necessity tests
- LIA missing balancing test
- lawful basis switched mid-processing
- no documented public interest rationale
Personal data collected prior to PDPA enforcement may continue to be processed for original purposes provided data subjects are notified of opt-out rights.
- legacy data inventory
- transition notice records
- opt-out mechanism evidence
- legacy purposes drift
- no opt-out for legacy data
- transition notice never sent
Processing of sensitive data (race, religion, sexual orientation, criminal record, health, disability, union, biometric, genetic) requires explicit consent or specified exceptions.
- sensitive data inventory
- explicit consent records
- exception applicability log
- enhanced safeguards documentation
- biometric/genetic data unflagged
- implicit consent for sensitive data
- no enhanced controls
Thailand PDPA Sections 27 to 29: Disclosure and Cross-Border Transfer
Disclosure of personal data to third parties requires consent or other lawful basis matching the original collection purpose.
- third party disclosure register
- consent records for disclosure
- purpose-matching log
- bulk data sharing without consent
- marketing partners undisclosed in notice
- purpose mismatch
Transfers outside Thailand require destination country to have adequate protection, or one of the exceptions, including binding corporate rules or standard contractual clauses approved by PDPC.
- transfer impact assessment
- PDPC-approved SCCs
- binding corporate rules
- adequacy decisions register
- transfer mapping
- transfers without legal basis
- no TIA for cloud providers
- SCCs not PDPC-approved format
- onward transfers untracked
Intra-group transfers within affiliated entities permitted where binding policies are approved and registered with the PDPC.
- intra-group transfer policy
- PDPC registration of BCRs
- affiliate compliance attestations
- BCRs not registered
- affiliates outside scope of policy
- no enforcement mechanism within group
Thailand PDPA Sections 30 to 36: Data Subject Rights
Data subjects have the right to access and obtain a copy of their personal data held by the controller and to request disclosure of acquisition source.
- DSAR procedure
- access request log
- identity verification protocol
- source disclosure register
- no Thai-language request channel
- source of data not tracked
- 30-day SLA breached
Data subjects may request personal data in a readable or commonly used machine-readable format and may request transfer to another controller.
- data export procedure
- machine-readable format spec
- portability request log
- only PDF provided
- transfer to third party unsupported
- derived data excluded incorrectly
Data subjects may object to processing including direct marketing, scientific or statistical research, or processing based on legitimate interest or public task.
- objection handling procedure
- marketing opt-out register
- objection register
- no opt-out from analytics
- objection not propagated to processors
- marketing list not updated
Data subjects may request deletion, destruction, or anonymisation of personal data where consent withdrawn, data no longer necessary, or unlawfully processed.
- erasure procedure
- anonymisation standard
- backup deletion protocol
- deletion certificates
- backups retain data indefinitely
- anonymisation not irreversible
- processors not instructed to delete
Data subjects may request restriction of processing pending accuracy verification, unlawful processing claims, or pending objection decisions.
- restriction flag in systems
- restriction handling SOP
- restriction request log
- no system-level restriction flag
- restricted data still used in analytics
- no expiry on restriction
Controllers shall ensure personal data is accurate, current, complete, and not misleading. Data subjects may request correction.
- data accuracy SOP
- rectification log
- periodic accuracy reviews
- self-service update portal
- stale customer records
- no proactive accuracy check
- downstream systems not updated
Personal data shall be deleted, destroyed, or anonymised when retention period expires or processing purpose is fulfilled.
- retention schedule
- automated deletion workflows
- anonymisation procedure
- destruction certificates
- indefinite retention defaults
- legal hold conflicts unresolved
- no anonymisation standard
Thailand PDPA Sections 37 to 40: Security, Breach and Processor Duties
Controllers shall implement appropriate security measures to prevent loss, unauthorised access, use, alteration, correction, or disclosure of personal data.
- ISMS documentation
- access control matrix
- encryption standards
- security policy
- PDPC security standard compliance evidence
- no encryption at rest
- shared admin credentials
- no access reviews
- PDPC minimum standard unmet
Where a breach is likely to result in high risk to rights and freedoms of data subjects, controllers must notify affected individuals with remedial measures.
- data subject notification template (Thai)
- risk assessment criteria
- communication channel records
- notification only in English
- remedial measures not communicated
- delayed notification
Controllers shall maintain a record of processing activities including categories of data, purposes, recipients, retention, security measures, and rights mechanisms.
- RoPA register
- processing activity inventory
- annual RoPA review
- RoPA-to-DPIA linkage
- RoPA outdated
- processor activities omitted
- no retention period documented
- Thai operations missing
Processors shall act only on documented instructions, implement security measures, maintain processing records, and notify controllers of breaches.
- data processing agreements (DPA)
- processor RoPA
- processor audit reports
- breach notification SLAs
- informal processor arrangements
- no DPA in place
- sub-processor flow-down missing
- Thai counterparties unaware of obligations
Thailand PDPA Sections 41 to 43: Data Protection Officer and PDPC
Controllers and processors must appoint a DPO where core activities involve large-scale sensitive data, systematic monitoring, or public authority processing.
- DPO appointment letter
- DPO job description
- DPO independence statement
- DPO contact in privacy notices
- DPO not registered with PDPC
- DPO reports to processing function
- no DPO for foreign entity
- DPO contact not published
The DPO shall advise on PDPA compliance, monitor compliance, cooperate with PDPC, and serve as contact point. The DPO must not be dismissed for performing duties.
- DPO activity reports
- DPO training records
- DPO independence protections
- PDPC liaison logs
- DPO has conflicting role
- no documented advisory output
- DPO under-resourced
The Personal Data Protection Committee has powers to investigate, issue orders, levy administrative fines, and publish guidelines and notifications.
- PDPC engagement log
- regulatory monitoring procedure
- notification subscription
- new PDPC notifications missed
- no regulatory horizon scan
- PDPC enquiries unhandled
Thailand PDPA Sections 5 to 7: Scope and Representative
PDPA applies to controllers and processors outside Thailand if they offer goods or services to, or monitor behaviour of, data subjects in Thailand.
- jurisdictional applicability assessment
- Thai data subject mapping
- local representative appointment record
- foreign entities not assessed
- no Thai representative
- monitoring activities not mapped
Personal data means any information relating to a natural person enabling identification, directly or indirectly, excluding information of deceased persons.
- personal data inventory
- data classification policy
- identifiability assessment
- data element catalogue
- pseudonymised data not classified
- indirect identifiers omitted
- no living-person scoping check
Foreign controllers and processors subject to PDPA must designate a representative in Thailand acting on their behalf without limitation.
- representative appointment deed
- representative contact in privacy notice
- PDPC notification of representative
- no Thai representative appointed
- representative authority limited
- PDPC not notified
Thailand PDPA Sections 95: Transition and Complaints
PDPA core provisions came into force 1 June 2022 following multiple postponements. All obligations are now actively enforced by the PDPC.
- PDPA compliance roadmap
- enforcement readiness assessment
- board-level PDPA reporting
- still treating PDPA as future obligation
- no executive sponsor
- no maturity assessment
Data subjects may lodge complaints with the PDPC. Controllers must facilitate internal complaint mechanisms and respond within statutory timeframes.
- complaint handling procedure
- complaint register
- PDPC complaint responses
- 30-day SLA tracking
- no Thai-language complaint channel
- SLA breached
- no root cause analysis
Transfer and Processor Management
Per Thailand PDPA cross-border transfer + processor provisions. Requirements include (a) implement Cross-Border Data Transfer restrictions - transfer personal data outside Thailand only where destination provides adequate protection (per PDPC determination) + binding corporate rules + standard contractual clauses + explicit consent + or other conditions per PDPA + (b) implement Cross-Border Transfer Safeguards documentation + transfer impact assessments + (c) implement Processor Engagement and Oversight via Data Processing Agreements ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (d) maintain inventory of cross-border flows + recipients + safeguards + (e) implement supplier + processor + sub-processor due diligence + (f) cooperate with PDPC on transfer matters.
- PDPA Thailand evidence for PDPATH-6
- DPO + DPIA + transfer assessment + breach notification partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the PDPA Thailand framework page.