Thailand’s Personal Data Protection Act 2019 (PDPA) comes fully into force today, after its main provisions were postponed twice to give organisations more time to prepare.
Key points
- Security measures to minimum standards are required.
- Breaches must be notified to the PDPC within 72 hours.
- A DPO is needed for large-scale or sensitive processing.
- Foreign controllers need a local representative.
The PDPA applies extraterritorially, so UK organisations offering goods or services to, or monitoring, individuals in Thailand should review their compliance and appoint a local representative where needed.
Source: Personal Data Protection Act B.E. 2562 (2019) (Thai Ministry of Digital Economy and Society)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.