Thailand’s PDPA, fully enforced since June 2022, requires businesses to collect personal data only with valid consent, appoint a Data Protection Officer where applicable, and report breaches within 72 hours. The Electronic Transaction Act governs the legal validity of e-signatures and digital contracts. In August 2025, the PDPC issued fines totalling THB 21.5 million across five cases. Businesses operating in or targeting Thailand, regardless of where they are based, must treat both laws as active, enforceable obligations.
Running a digital business in Thailand, or even just selling to Thai customers from abroad, means two pieces of legislation are almost certainly relevant: the PDPA in Thailand, which governs how personal data is collected, stored, used, and transferred, and the Electronic Transaction Act, which determines whether digital contracts and e-signatures hold up legally. PD Legal, a regional law firm with a dedicated Thailand practice, regularly advises businesses navigating the intersection of both frameworks. Neither law is especially new. What has changed is how seriously regulators are now treating non-compliance.
What Are the Core Compliance Obligations Under Thailand’s PDPA for Digital Businesses?
Most businesses focus on consent banners and privacy policies, but those are only the baseline. Practically, compliance covers several interconnected requirements:
- Consent must be explicit and granular. A single checkbox does not satisfy the PDPA. Consent must be specific to each processing purpose and properly documented.
- Data subject rights must be actionable. Access, correction, deletion, and objection requests require a real handling process, not just a policy that mentions them.
- Breach notification is mandatory and time-bound. Failure to comply with the breach notification requirement may result in a fine of up to THB 3,000,000 (approximately USD 81,000).
- Data Processing Agreements are required. When engaging third-party vendors, the absence of these contracts has featured repeatedly in PDPC enforcement cases.
- Small businesses received partial relief in early 2025. Thailand’s PDPC published exemptions for small businesses from ROPA requirements under the PDPA, effective January and April 2025, though other obligations remain in force.
Documentation gaps and missing vendor contracts are consistently where businesses get caught.
How Does the Electronic Transaction Act Affect Digital Contracts in Thailand?
The Electronic Transaction Act B.E. 2544 (2001) gives e-signatures the same legal standing as traditional paper signatures, provided the ETA’s criteria are met. Finance and security documents add complexity, as sector-specific requirements from Thai financial regulators must be satisfied alongside the ETA. Thailand is also working on a proposed Electronic Transaction Bill that retains functional equivalence while introducing new notification and certification obligations. Businesses with established digital workflows should keep a close eye on its progress.
What Are the Rules for Cross-Border Transfer of Personal Data From Thailand?
On 25 December 2023, the PDPC published cross-border transfer notifications under Sections 28 and 29, enforceable from 24 March 2024. Data moving out of Thailand must go to countries with adequate protection standards or be covered by Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs). The problem is that the PDPC has yet to publish an adequacy list, so most transfers default to SCCs or BCRs, and those agreements need to be in place before data leaves, not after a breach surfaces.
What Penalties Has the PDPC Enforced and What Triggered Them?
On 1 August 2025, the PDPC announced eight administrative fines across five cases involving both public and private entities, totaling approximately THB 21.5 million, marking a clear shift from awareness-building to active compliance scrutiny. The cases revealed a consistent pattern of failures:
- A cosmetics company was fined THB 2.5 million for failing to notify the PDPC of a data breach and for inadequate technical safeguards.
- A government agency was penalized after engaging an unqualified service provider without a valid data processing agreement, exposing nearly 200,000 personal data records.
- A private hospital faced orders related to mishandling of medical record destruction.
These recurring failures emphasize a broader issue: a lack of strategic commitment to data protection.
How Does Thailand’s PDPA Compare to the GDPR for Businesses Operating Across Both Regions?
Thailand’s PDPA shares similarities with the GDPR on cross-border data transfers, consent standards, and DPO requirements, which gives businesses with existing GDPR programs a useful foundation. That said, GDPR compliance does not equal PDPA compliance. Consent mechanisms built for European users may not satisfy Thailand’s specific thresholds, and the local enforcement structure introduces its own procedural requirements. Businesses that assume cross-compliance without a proper gap analysis tend to find the gaps at the worst possible time.
Why Work with PD Legal?
PD Legal Thailand brings hands-on regional experience to the full spectrum of data protection and digital transaction compliance, advising businesses across Southeast Asia on PDPA obligations, cross-border transfer frameworks, and Electronic Transaction Act requirements. The firm’s Regulatory & Compliance practice operates from Bangkok with integrated support across Singapore, Malaysia, and Australia, giving clients a single point of contact for multi-jurisdictional matters. Recognized as one of ALB’s Firms to Watch: Thailand 2025, PD Legal combines local regulatory knowledge with the depth of a regional practice built for the pace of modern commerce.
Conclusion
Thailand’s regulatory environment for data and digital transactions has moved well past the awareness stage. Businesses operating in or targeting Thailand need to treat PDPA compliance and Electronic Transaction Act obligations as operational priorities, not legal formalities. The fines, enforcement cases, and cross-border transfer rules are all active and expanding.
PD Legal Thailand offers practical, regionally informed legal support for businesses working through these requirements. From consent framework reviews to cross-border data transfer documentation, the team understands what regulators are actually looking for. Get in touch with PD Legal now to discuss your compliance position and what steps make sense for your business!