Skip to content

Evidence request lists

PDPA Thailand

Evidence request list. 38 controls, 38 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach and Enforcement

PDPATH-8
Data Breach Notification, Complaints, Compliance, Enforcement

Per Thailand PDPA Section 37(4): breach notification + enforcement. Requirements include (a) implement Data Breach Notification - notify PDPC within 72 hours of becoming aware of breach unless unlikely to result in risk + notify affected data subjects where high risk + (b) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (c) operate Complaints Handling mechanism for data subjects + (d) maintain Compliance Monitoring and Auditing + Regulatory Reporting and Cooperation with PDPC + (e) maintain Enforcement and Penalties awareness including administrative penalties + criminal penalties + civil liability + (f) maintain documented breach log + incident response + tabletop exercises + (g) integrate with broader incident management.

Artefacts an auditor will ask for
  • PDPA Thailand evidence for PDPATH-8
Where this commonly fails
  • DPO + DPIA + transfer assessment + breach notification partial

Consent

PDPATH-2
Consent Requirements and Special Consent for Sensitive Data

Per Thailand PDPA: consent + sensitive data handling. Requirements include (a) obtain Consent that is freely given + specific + informed + unambiguous + clearly distinguishable from other matters + with mechanism for withdrawal + (b) implement special protections for Sensitive Personal Data including health + biometric + genetic + race + religion + political + sexual orientation + criminal records + requiring explicit consent or specific legal basis per PDPA + (c) implement Children's Personal Data of Minors protections requiring parental consent per Thailand civil age + (d) maintain records of consent including how + when obtained + purpose + withdrawal + (e) integrate consent + sensitive data handling with privacy programme + (f) maintain change management for consent updates.

Artefacts an auditor will ask for
  • PDPA Thailand evidence for PDPATH-2
Where this commonly fails
  • DPO + DPIA + transfer assessment + breach notification partial

Governance and Lifecycle

PDPATH-7
DPO, Records of Processing, Retention, Marketing, Training

Per Thailand PDPA + PDPC: governance + lifecycle. Requirements include (a) appoint Data Protection Officer (DPO) where required (large-scale processing + sensitive data + monitoring) with defined responsibilities + reporting to highest management + (b) maintain Record of Processing Activities including purposes + categories + recipients + retention + safeguards + (c) implement Retention Limitation including retention schedules + secure deletion + anonymisation + (d) implement Direct Marketing and Communications safeguards including consent + opt-out + suppression lists + (e) deliver Personnel Training and Awareness programmes including role-based content + PDPA + privacy + security + breach response + (f) maintain documented governance + accountability framework.

Artefacts an auditor will ask for
  • PDPA Thailand evidence for PDPATH-7
Where this commonly fails
  • DPO + DPIA + transfer assessment + breach notification partial

High-Risk Processing

PDPATH-4
DPIA, Privacy by Design, Children's Data

Per Thailand PDPA + PDPC guidance: heightened safeguards for high-risk processing. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing including large-scale + sensitive + systematic monitoring + new technologies + AI per PDPC guidance + (b) implement Privacy by Design and Default across systems + processes + products + procurement + (c) implement Personal Data of Minors protections per the PDPA + (d) maintain documented DPIA + safeguards + risk assessments + (e) integrate privacy considerations into change management + (f) maintain ongoing review of high-risk processing.

Artefacts an auditor will ask for
  • PDPA Thailand evidence for PDPATH-4
Where this commonly fails
  • DPO + DPIA + transfer assessment + breach notification partial

Individual Rights

PDPATH-3
Data Subject Rights, Automated Decisions, Accuracy

Per Thailand PDPA Chapter 3: data subject rights. Requirements include (a) implement Data Subject Rights Handling including Access + Rectification + Erasure + Restriction + Object to Processing + Data Portability + (b) implement Right to Object + Withdrawal of Consent + (c) implement Automated Decisions and Profiling protections including human review + explanation + objection rights where applicable + (d) implement Accuracy and Up-to-date Data principle ensuring personal data is accurate + complete + (e) maintain mechanism for receiving + verifying + responding to requests within statutory timelines + (f) maintain records of requests + responses + decisions.

Artefacts an auditor will ask for
  • PDPA Thailand evidence for PDPATH-3
Where this commonly fails
  • DPO + DPIA + transfer assessment + breach notification partial

Scope and Lawful Basis

PDPATH-1
Scope, Extra-Territorial Application, Lawful Basis, and Notice

Per Thailand PDPA B.E. 2562 (2019) Sections on scope + lawful basis + notice. Requirements include (a) determine scope including Extra-territorial Application - PDPA applies to processing of personal data of Thai data subjects even by controllers/processors outside Thailand + (b) establish Lawful Basis for Processing including consent + contract + legal obligation + vital interests + public interest + legitimate interests + (c) provide Privacy Notice to Data Subjects covering identity of controller + purposes + categories + recipients + retention + rights + transfer + (d) document applicability assessment + lawful basis + (e) maintain change management for notice and lawful basis updates + (f) align internal definitions and policies with PDPA Thailand and PDPC guidance.

Artefacts an auditor will ask for
  • PDPA Thailand evidence for PDPATH-1
Where this commonly fails
  • DPO + DPIA + transfer assessment + breach notification partial

Security

PDPATH-5
Security Measures and Data Protection

Per Thailand PDPA Section 37: implement appropriate security measures. Requirements include (a) implement Security Measures including organisational + technical + physical measures appropriate to risk + (b) implement Encryption of personal data at rest + in transit + appropriate to classification + (c) implement Pseudonymization Techniques where appropriate + (d) implement Access Control for personal data including authentication + authorisation + audit + (e) conduct Regular Security Testing and Assessment + (f) integrate with broader information security programme + (g) maintain documented security measures aligned to PDPC guidance + minimum standards.

Artefacts an auditor will ask for
  • PDPA Thailand evidence for PDPATH-5
Where this commonly fails
  • DPO + DPIA + transfer assessment + breach notification partial

Thailand PDPA Sections 19 to 26: Consent and Lawful Basis

Section 19
Lawful Basis and Consent Requirements

Collection, use, or disclosure of personal data requires consent unless another lawful basis applies. Consent must be explicit, freely given, specific, and clearly evidenced.

Artefacts an auditor will ask for
  • consent records
  • lawful basis register
  • consent UI screenshots
  • consent withdrawal logs
Where this commonly fails
  • bundled consent
  • pre-ticked boxes
  • no withdrawal mechanism
  • consent timestamp missing
Section 20
Consent for Minors

Consent from minors under 10 requires holder of parental responsibility. Minors 10-20 require parental consent unless transaction is appropriate for age.

Artefacts an auditor will ask for
  • age verification procedure
  • parental consent records
  • minor consent UX flow
Where this commonly fails
  • no age gate
  • parental consent not captured
  • age threshold misapplied
Section 21
Purpose Limitation

Personal data shall only be collected, used, or disclosed for purposes notified to the data subject prior to or at the time of collection.

Artefacts an auditor will ask for
  • purpose register
  • privacy notices
  • purpose change consent records
Where this commonly fails
  • secondary use without new consent
  • vague catch-all purposes
  • purpose drift undetected
Section 22
Data Minimisation

Collection of personal data shall be limited to that necessary for the lawful purposes of the data controller.

Artefacts an auditor will ask for
  • data minimisation review
  • field-level necessity justification
  • form design audits
Where this commonly fails
  • over-collection on intake forms
  • no periodic minimisation review
  • optional fields treated as mandatory
Section 23
Privacy Notice Requirements

Controllers must inform data subjects of purpose, categories collected, recipients, retention, rights, and contact details prior to or at collection.

Artefacts an auditor will ask for
  • privacy notice (Thai and English)
  • layered notice design
  • notice version control
  • just-in-time notices
Where this commonly fails
  • Thai language version missing
  • recipients not disclosed
  • retention period absent
  • DPO contact omitted
Section 24
Lawful Bases Other Than Consent

Processing without consent permitted for research with safeguards, vital interest, contract performance, legal obligation, public interest, or legitimate interest.

Artefacts an auditor will ask for
  • lawful basis assessment per processing activity
  • legitimate interest assessments (LIA)
  • contract necessity tests
Where this commonly fails
  • LIA missing balancing test
  • lawful basis switched mid-processing
  • no documented public interest rationale
Section 25
Historical and Pre-PDPA Data

Personal data collected prior to PDPA enforcement may continue to be processed for original purposes provided data subjects are notified of opt-out rights.

Artefacts an auditor will ask for
  • legacy data inventory
  • transition notice records
  • opt-out mechanism evidence
Where this commonly fails
  • legacy purposes drift
  • no opt-out for legacy data
  • transition notice never sent
Section 26
Sensitive Personal Data

Processing of sensitive data (race, religion, sexual orientation, criminal record, health, disability, union, biometric, genetic) requires explicit consent or specified exceptions.

Artefacts an auditor will ask for
  • sensitive data inventory
  • explicit consent records
  • exception applicability log
  • enhanced safeguards documentation
Where this commonly fails
  • biometric/genetic data unflagged
  • implicit consent for sensitive data
  • no enhanced controls

Thailand PDPA Sections 27 to 29: Disclosure and Cross-Border Transfer

Section 27
Disclosure to Third Parties

Disclosure of personal data to third parties requires consent or other lawful basis matching the original collection purpose.

Artefacts an auditor will ask for
  • third party disclosure register
  • consent records for disclosure
  • purpose-matching log
Where this commonly fails
  • bulk data sharing without consent
  • marketing partners undisclosed in notice
  • purpose mismatch
Section 28
Cross-Border Data Transfer

Transfers outside Thailand require destination country to have adequate protection, or one of the exceptions, including binding corporate rules or standard contractual clauses approved by PDPC.

Artefacts an auditor will ask for
  • transfer impact assessment
  • PDPC-approved SCCs
  • binding corporate rules
  • adequacy decisions register
  • transfer mapping
Where this commonly fails
  • transfers without legal basis
  • no TIA for cloud providers
  • SCCs not PDPC-approved format
  • onward transfers untracked
Section 29
Intra-Group Transfer Rules

Intra-group transfers within affiliated entities permitted where binding policies are approved and registered with the PDPC.

Artefacts an auditor will ask for
  • intra-group transfer policy
  • PDPC registration of BCRs
  • affiliate compliance attestations
Where this commonly fails
  • BCRs not registered
  • affiliates outside scope of policy
  • no enforcement mechanism within group

Thailand PDPA Sections 30 to 36: Data Subject Rights

Section 30
Right of Access

Data subjects have the right to access and obtain a copy of their personal data held by the controller and to request disclosure of acquisition source.

Artefacts an auditor will ask for
  • DSAR procedure
  • access request log
  • identity verification protocol
  • source disclosure register
Where this commonly fails
  • no Thai-language request channel
  • source of data not tracked
  • 30-day SLA breached
Section 31
Right to Data Portability

Data subjects may request personal data in a readable or commonly used machine-readable format and may request transfer to another controller.

Artefacts an auditor will ask for
  • data export procedure
  • machine-readable format spec
  • portability request log
Where this commonly fails
  • only PDF provided
  • transfer to third party unsupported
  • derived data excluded incorrectly
Section 32
Right to Object

Data subjects may object to processing including direct marketing, scientific or statistical research, or processing based on legitimate interest or public task.

Artefacts an auditor will ask for
  • objection handling procedure
  • marketing opt-out register
  • objection register
Where this commonly fails
  • no opt-out from analytics
  • objection not propagated to processors
  • marketing list not updated
Section 33
Right to Erasure

Data subjects may request deletion, destruction, or anonymisation of personal data where consent withdrawn, data no longer necessary, or unlawfully processed.

Artefacts an auditor will ask for
  • erasure procedure
  • anonymisation standard
  • backup deletion protocol
  • deletion certificates
Where this commonly fails
  • backups retain data indefinitely
  • anonymisation not irreversible
  • processors not instructed to delete
Section 34
Right to Restriction of Processing

Data subjects may request restriction of processing pending accuracy verification, unlawful processing claims, or pending objection decisions.

Artefacts an auditor will ask for
  • restriction flag in systems
  • restriction handling SOP
  • restriction request log
Where this commonly fails
  • no system-level restriction flag
  • restricted data still used in analytics
  • no expiry on restriction
Section 35
Right to Rectification

Controllers shall ensure personal data is accurate, current, complete, and not misleading. Data subjects may request correction.

Artefacts an auditor will ask for
  • data accuracy SOP
  • rectification log
  • periodic accuracy reviews
  • self-service update portal
Where this commonly fails
  • stale customer records
  • no proactive accuracy check
  • downstream systems not updated
Section 36
Retention and Deletion

Personal data shall be deleted, destroyed, or anonymised when retention period expires or processing purpose is fulfilled.

Artefacts an auditor will ask for
  • retention schedule
  • automated deletion workflows
  • anonymisation procedure
  • destruction certificates
Where this commonly fails
  • indefinite retention defaults
  • legal hold conflicts unresolved
  • no anonymisation standard

Thailand PDPA Sections 37 to 40: Security, Breach and Processor Duties

Section 37
Controller Security Obligations

Controllers shall implement appropriate security measures to prevent loss, unauthorised access, use, alteration, correction, or disclosure of personal data.

Artefacts an auditor will ask for
  • ISMS documentation
  • access control matrix
  • encryption standards
  • security policy
  • PDPC security standard compliance evidence
Where this commonly fails
  • no encryption at rest
  • shared admin credentials
  • no access reviews
  • PDPC minimum standard unmet
Section 37(4)
Breach Notification to Data Subjects

Where a breach is likely to result in high risk to rights and freedoms of data subjects, controllers must notify affected individuals with remedial measures.

Artefacts an auditor will ask for
  • data subject notification template (Thai)
  • risk assessment criteria
  • communication channel records
Where this commonly fails
  • notification only in English
  • remedial measures not communicated
  • delayed notification
Section 39
Record of Processing Activities (RoPA)

Controllers shall maintain a record of processing activities including categories of data, purposes, recipients, retention, security measures, and rights mechanisms.

Artefacts an auditor will ask for
  • RoPA register
  • processing activity inventory
  • annual RoPA review
  • RoPA-to-DPIA linkage
Where this commonly fails
  • RoPA outdated
  • processor activities omitted
  • no retention period documented
  • Thai operations missing
Section 40
Processor Obligations

Processors shall act only on documented instructions, implement security measures, maintain processing records, and notify controllers of breaches.

Artefacts an auditor will ask for
  • data processing agreements (DPA)
  • processor RoPA
  • processor audit reports
  • breach notification SLAs
Where this commonly fails
  • informal processor arrangements
  • no DPA in place
  • sub-processor flow-down missing
  • Thai counterparties unaware of obligations

Thailand PDPA Sections 41 to 43: Data Protection Officer and PDPC

Section 41
Appointment of Data Protection Officer

Controllers and processors must appoint a DPO where core activities involve large-scale sensitive data, systematic monitoring, or public authority processing.

Artefacts an auditor will ask for
  • DPO appointment letter
  • DPO job description
  • DPO independence statement
  • DPO contact in privacy notices
Where this commonly fails
  • DPO not registered with PDPC
  • DPO reports to processing function
  • no DPO for foreign entity
  • DPO contact not published
Section 42
DPO Duties

The DPO shall advise on PDPA compliance, monitor compliance, cooperate with PDPC, and serve as contact point. The DPO must not be dismissed for performing duties.

Artefacts an auditor will ask for
  • DPO activity reports
  • DPO training records
  • DPO independence protections
  • PDPC liaison logs
Where this commonly fails
  • DPO has conflicting role
  • no documented advisory output
  • DPO under-resourced
Section 43
PDPC Authority and Powers

The Personal Data Protection Committee has powers to investigate, issue orders, levy administrative fines, and publish guidelines and notifications.

Artefacts an auditor will ask for
  • PDPC engagement log
  • regulatory monitoring procedure
  • notification subscription
Where this commonly fails
  • new PDPC notifications missed
  • no regulatory horizon scan
  • PDPC enquiries unhandled

Thailand PDPA Sections 5 to 7: Scope and Representative

Section 5
Extraterritorial Application

PDPA applies to controllers and processors outside Thailand if they offer goods or services to, or monitor behaviour of, data subjects in Thailand.

Artefacts an auditor will ask for
  • jurisdictional applicability assessment
  • Thai data subject mapping
  • local representative appointment record
Where this commonly fails
  • foreign entities not assessed
  • no Thai representative
  • monitoring activities not mapped
Section 6
Definitions and Scope of Personal Data

Personal data means any information relating to a natural person enabling identification, directly or indirectly, excluding information of deceased persons.

Artefacts an auditor will ask for
  • personal data inventory
  • data classification policy
  • identifiability assessment
  • data element catalogue
Where this commonly fails
  • pseudonymised data not classified
  • indirect identifiers omitted
  • no living-person scoping check
Section 7
Local Representative Requirement

Foreign controllers and processors subject to PDPA must designate a representative in Thailand acting on their behalf without limitation.

Artefacts an auditor will ask for
  • representative appointment deed
  • representative contact in privacy notice
  • PDPC notification of representative
Where this commonly fails
  • no Thai representative appointed
  • representative authority limited
  • PDPC not notified

Thailand PDPA Sections 95: Transition and Complaints

Section 95
Effective Date and Enforcement

PDPA core provisions came into force 1 June 2022 following multiple postponements. All obligations are now actively enforced by the PDPC.

Artefacts an auditor will ask for
  • PDPA compliance roadmap
  • enforcement readiness assessment
  • board-level PDPA reporting
Where this commonly fails
  • still treating PDPA as future obligation
  • no executive sponsor
  • no maturity assessment
Section 95(2)
Complaint Handling

Data subjects may lodge complaints with the PDPC. Controllers must facilitate internal complaint mechanisms and respond within statutory timeframes.

Artefacts an auditor will ask for
  • complaint handling procedure
  • complaint register
  • PDPC complaint responses
  • 30-day SLA tracking
Where this commonly fails
  • no Thai-language complaint channel
  • SLA breached
  • no root cause analysis

Transfer and Processor Management

PDPATH-6
Cross-Border Transfer and Processor Engagement

Per Thailand PDPA cross-border transfer + processor provisions. Requirements include (a) implement Cross-Border Data Transfer restrictions - transfer personal data outside Thailand only where destination provides adequate protection (per PDPC determination) + binding corporate rules + standard contractual clauses + explicit consent + or other conditions per PDPA + (b) implement Cross-Border Transfer Safeguards documentation + transfer impact assessments + (c) implement Processor Engagement and Oversight via Data Processing Agreements ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (d) maintain inventory of cross-border flows + recipients + safeguards + (e) implement supplier + processor + sub-processor due diligence + (f) cooperate with PDPC on transfer matters.

Artefacts an auditor will ask for
  • PDPA Thailand evidence for PDPATH-6
Where this commonly fails
  • DPO + DPIA + transfer assessment + breach notification partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the PDPA Thailand framework page.