This article examines the evolving data protection landscape in the Asia–Pacific region, with a specific focus on Thailand’s Personal Data Protection Act BE 2562 (PDPA), effective from June 2021. It outlines the PDPA’s requirements for privacy and data protection, highlighting the potential for civil penalties and criminal liability for violations. The article also addresses the legal basis for data processing, the handling of sensitive data, and provisions for processing data for research purposes under the PDPA. Unlike the GDPR, the PDPA does not provide specific rules for the collection, use, or disclosure of pseudonymized data, and its definitions of Data Controller and Data Processor differ slightly.
Emergence of Data Protection Regimes
Data protection regimes have seen significant global growth, particularly in the Asia-Pacific region, where the regulatory landscape has transformed dramatically over the past decade. This trend is expected to continue as data protection laws evolve rapidly. Thailand is among the first five countries in the region to implement comprehensive data protection regulations.
Thailand’s Personal Data Protection Act BE 2562 (PDPA)
The PDPA, effective since June 2021, introduces substantial changes to Thailand’s data protection framework. Businesses operating in the region must understand and comply with its privacy and data protection requirements. Non-compliance with the PDPA may result in both civil penalties and criminal liability.
Scope of the PDPA
The PDPA applies to the processing of personal data by Data Controllers and Data Processors located in Thailand, regardless of whether the collection, use, or disclosure of personal data occurs within the country (Establishment Criteria).
For Data Controllers or Data Processors established outside Thailand, the PDPA applies if they:
- Offer goods or services to data subjects in Thailand, regardless of whether payment is required (Targeting Criteria); or
- Monitor the behavior of data subjects in Thailand, where such behavior occurs within the country.
Unlike the GDPR, the PDPA does not define terms such as pseudonymized data, and its definitions of Data Controller and Data Processor diverge slightly. The PDPA defines a Data Controller as a person or legal entity with the authority and responsibility to make decisions regarding the collection, use, or disclosure of personal data. A Data Processor, in contrast, is a person who processes personal data under the instructions of, or on behalf of, a Data Controller and must not act as the Data Controller.
Legal Basis for Data Processing
The PDPA’s legal basis for data processing aligns closely with the GDPR.
A Data Controller may not collect, use, or disclose personal data without the data subject’s prior consent, unless permitted by the PDPA or other applicable laws.
Consent requests must be explicit, in writing, or via electronic means, unless impractical due to the nature of the data processing. Data subjects may withdraw consent at any time. For minors under 10 years of age, consent must be obtained from a person with parental responsibility.
In line with the transparency principle, Data Controllers must inform data subjects of the data collection details, as outlined in Article 23 of the PDPA, before or at the time of collection. Personal data may be collected without consent in specific cases, including:
- For the preparation of historical documents, public interest archives, or research and statistical purposes, provided appropriate safeguards for the data subject’s rights and freedoms are in place, as prescribed by the Personal Data Protection Committee (the “Committee”);
- To prevent or address dangers to a person’s life, body, or health;
- For the performance of a contract to which the data subject is a party or to take steps at the data subject’s request prior to entering a contract;
- For tasks carried out in the public interest or the exercise of official authority vested in the Data Controller;
- For the legitimate interests of the Data Controller or other persons, unless overridden by the data subject’s fundamental rights; or
- For compliance with applicable laws.
Sensitive Data
Article 26 of the PDPA lists special categories of data, including racial or ethnic origins, political opinions, religious or philosophical beliefs, sexual behavior, criminal records, health data, disabilities, trade union information, genetic data, biometric data, or other data that may similarly affect the data subject, as determined by the Committee.
Processing Data for Research Purposes
Processing special categories of data is prohibited without explicit consent from the data subject, except where necessary for compliance with laws to achieve purposes such as public health, ensuring the quality of medicines or medical devices, or for scientific, historical, or statistical research. Such processing must be limited to what is necessary and include suitable measures to safeguard the data subject’s rights and interests, as prescribed by the Committee. Unlike the GDPR, the PDPA does not provide specific rules for processing personal data for research purposes, requiring only “suitable measures” without defining scientific research.
Data Transfers Outside Thailand
Personal data transfers to foreign countries or international organizations must meet adequate data protection standards, as outlined in Article 28 and prescribed by the Committee. Exceptions to this requirement include:
- Compliance with legal obligations;
- Consent from the data subject, provided they are informed of the destination’s inadequate data protection standards;
- Performance of a contract to which the data subject is a party or at their request prior to entering a contract;
- Compliance with a contract between the Data Controller and another party for the data subject’s benefit;
- Preventing or addressing dangers to the life, body, or health of the data subject or others when consent cannot be obtained; or
- Carrying out activities related to substantial public interest.
Issues regarding the adequacy of data protection in the destination country must be submitted to the Committee for review. The Committee’s decisions may be revisited if new evidence demonstrates improved data protection standards. Multinational companies in Thailand may transfer data to affiliated entities abroad if they have a Personal Data Protection Policy certified by the Office of the Personal Data Protection Committee. In the absence of a Committee decision or certified policy, Data Controllers or Processors may transfer data abroad under exemptions to Article 28, provided they implement suitable protection measures to enforce the data subject’s rights, including effective legal remedies, as prescribed by the Committee.
Data Subjects’ Rights
Data subjects have the right to:
- Access and obtain copies of their personal data or request disclosure of data obtained without their consent;
- Receive their personal data in a machine–readable format using commonly available tools;
- Restrict the use of their personal data, object to its collection, use, or disclosure, or request its erasure or anonymization under specific circumstances.
Data Controllers must ensure personal data remains accurate, up-to-date, complete, and not misleading. If a Data Controller does not act on a data subject’s request, they must record the request and the reasons for non-compliance.
Main Duties of Data Controllers
Data Controllers’ obligations under the PDPA are similar to those under the GDPR, including:
- Implementing appropriate security measures to prevent unauthorized or unlawful loss, access, use, alteration, correction, or disclosure of personal data, with regular reviews, particularly when technology changes;
- Complying with specific rules for data processing (Article 40) and the duties of Competent Officers (Chapter IV);
- Establishing procedures for preventing data destruction and addressing data breaches;
- Appointing a Data Protection Officer (DPO) and maintaining records as required.
Civil Liability
Data Controllers or Processors who violate the PDPA or cause damage to data subjects through their operations must compensate the affected data subject, regardless of intent or negligence, unless the violation results from:
- A force majeure or the data subject’s own actions or omissions; or
- Compliance with a government official’s lawful orders.
Courts may also impose punitive damages in addition to actual compensation.
Criminal Liability
Violations of Article 27 (use or disclosure of personal data without consent) or Article 28 (data transfer rules) involving sensitive data under Article 26, which cause damage, reputational harm, or humiliation to a data subject, are punishable by imprisonment of up to six months, a fine of up to 500,000 Thai Baht (approximately $14,000), or both.
Violations intended to unlawfully benefit the Data Controller or another person may result in imprisonment of up to one year, a fine of up to 1,000,000 Thai Baht (approximately $28,000), or both.
Additionally, any person who discloses personal data obtained while performing duties under the PDPA faces imprisonment of up to six months, a fine of up to 500,000 Thai Baht, or both.
It remains unclear whether intent or actual harm to the data subject is required for this provision. Companies, their directors, managers, or responsible persons may also face criminal liability if their actions or omissions lead to a violation.
Learn More
For further information on data protection in the context of clinical trials or other the data protection legislation in other Asian countries, contact MyData-TRUST, specialists in data protection for life sciences.