PDPA Thailand
What is PDPA Thailand?
Personal Data Protection Act of Thailand. It comprises 8 controls organised across 8 domains, and applies in Thailand.
How PDPA Thailand maps to other frameworks
All 8 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains PDPA Thailand groups its controls into
Where PDPA Thailand overlaps with the standards you already hold
What PDPA Thailand means in your sector
What PDPA Thailand means for your job
Questions people ask about PDPA Thailand
What is PDPA Thailand?
How many controls does PDPA Thailand have?
Where does PDPA Thailand apply?
What frameworks does PDPA Thailand map to?
How do I get started with PDPA Thailand compliance?
Query PDPA Thailand programmatically
PDPA Thailand, its 8 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
PDPA Thailand API reference and MCP config →What PDPA Thailand requires, control by control
Each page carries the requirement text for one PDPA Thailand control and what an assessor expects to see as evidence.
- PDPATH-3 Data Subject Rights, Automated Decisions, Accuracy
- PDPATH-4 DPIA, Privacy by Design, Children's Data
- PDPATH-5 Security Measures and Data Protection
- PDPATH-6 Cross-Border Transfer and Processor Engagement
- PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training
- PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement
How ready are you for PDPA Thailand?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.