DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Asia-Pacific · In force · Opt-in

🇹🇭 Thailand Data Privacy Laws

Thailand's PDPA, fully enforced since June 2022, is a close GDPR cousin with a working regulator. The PDPC issued its first fine, THB 7M, in August 2024 against an online retailer over failures that included a missing DPO, weak security and an unreported breach, followed by five more fines in 2025, and it keeps building out sub-regulations on security, transfers and breach reporting.

Updated September 28, 2026 · digitalprivacyregs.com
Status
In force
Consent model
Opt-in
Primary law
Personal Data Protection Act (PDPA)
Year
2019
Authority
Personal Data Protection Committee (PDPC)
Marketing consent
GDPR-modeled bases including legitimate interests, but consent must be explicit where relied on, and direct marketing practice leans on consent; cookie consent expected for tracking.
Transfers
Adequacy, appropriate safeguards (SCC-style), BCRs or consent.
Penalties
Administrative fines to THB 5M, criminal penalties for sensitive-data violations, and statutory damages with punitive multipliers.

The framework

Thailand's framework rests on the Personal Data Protection Act (PDPA), adopted in 2019, with the Personal Data Protection Committee as the supervisory authority.

That puts Thailand in the global opt-in majority, where permission comes before processing and marketing waits for consent.

Key instruments

Personal Data Protection Act (PDPA)

2019 · In force

Thailand's PDPA, fully enforced since June 2022, is a close GDPR cousin with a working regulator. The PDPC issued its first fine, THB 7M, in August 2024 against an online retailer over failures that included a missing DPO, weak security and an unreported breach, followed by five more fines in 2025, and it keeps building out sub-regulations on security, transfers and breach reporting.

Marketing and advertising

GDPR-modeled bases including legitimate interests, but consent must be explicit where relied on, and direct marketing practice leans on consent; cookie consent expected for tracking. That single sentence decides most channel plans here.

Cross-border transfers

Adequacy, appropriate safeguards (SCC-style), BCRs or consent.

Enforcement and penalties

Administrative fines to THB 5M, criminal penalties for sensitive-data violations, and statutory damages with punitive multipliers.

Primary sources

Cite this page: "Thailand Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/thailand.html. Accessed [date].