Data Protection Atlas

Thailand

Tier 3 Comprehensive law Asia-Pacific

Principal framework: PDPA (in force 2022) (2019). Regulator: PDPC. The PDPA has been fully in force since June 2022; the PDPC issued its first major administrative fine in 2024 over a large data-leak case.

At a glance

Principal law
PDPA (in force 2022)
Regulator
PDPC
Breach notification
72 hours to the PDPC where risk; affected persons where high risk
Maximum penalty
Administrative fines to THB 5m; criminal penalties and punitive damages possible
DPO required
Required for core large-scale monitoring or sensitive processing
Digital consent age
Parental consent for minors under 10 (capacity rules to 20)
Extraterritorial reach
Yes — offering goods or services to people in Thailand

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
TH

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

No source recorded yet. This record cannot rise above Tier 3 until it has one — see depth tiers.

Never independently verified — seeded from the prototype.