The framework
Thailand's framework rests on the Personal Data Protection Act (PDPA), adopted in 2019, with the Personal Data Protection Committee as the supervisory authority.
That puts Thailand in the global opt-in majority, where permission comes before processing and marketing waits for consent.
Key instruments
Personal Data Protection Act (PDPA)
Thailand's PDPA, fully enforced since June 2022, is a close GDPR cousin with a working regulator. The PDPC issued its first fine, THB 7M, in August 2024 against an online retailer over failures that included a missing DPO, weak security and an unreported breach, followed by five more fines in 2025, and it keeps building out sub-regulations on security, transfers and breach reporting.
Marketing and advertising
GDPR-modeled bases including legitimate interests, but consent must be explicit where relied on, and direct marketing practice leans on consent; cookie consent expected for tracking. That single sentence decides most channel plans here.
Cross-border transfers
Adequacy, appropriate safeguards (SCC-style), BCRs or consent.
Enforcement and penalties
Administrative fines to THB 5M, criminal penalties for sensitive-data violations, and statutory damages with punitive multipliers.