PDPA Insights: Building Effective Privacy Governance
PDPA: The DPO Is Not Responsible for Compliance—Your Organization Is
One of the most persistent misconceptions surrounding Thailand’s Personal Data Protection Act (PDPA) is that appointing a Data Protection Officer (DPO) satisfies an organization’s compliance obligations.
In practice, many organizations regard the DPO as the person responsible for “doing PDPA.” Privacy notices, data subject requests, breach notifications, contract reviews, training, audits and even cybersecurity issues are routinely directed to the DPO, often regardless of whether the DPO has the authority, resources or operational involvement to manage those activities effectively.
This perception is understandable. The PDPA requires certain organizations to appoint a DPO, and the role naturally becomes the focal point for privacy-related matters. However, the PDPC’s recent consultation on DPOs suggests that this understanding is incomplete. Rather than placing responsibility for compliance on the DPO, the consultation reinforces a governance model in which responsibility remains with the organization itself. The DPO’s role is to advise, monitor and facilitate compliance—not to replace management’s accountability.
This distinction may appear technical, but it has significant practical consequences for how organizations should structure their privacy governance.
Compliance belongs to the organization:
Privacy compliance is often described as a legal function, yet effective compliance depends upon decisions made throughout the organization.
Marketing teams determine how customer data is used.
Human resources departments manage employee information.
Information technology teams implement technical safeguards.
Procurement negotiates contracts with service providers.
Business units decide what personal data should be collected and why.
These operational decisions cannot realistically be delegated to a single individual.
The DPO may advise on each of these activities, but the responsibility for making business decisions—and ensuring those decisions comply with the PDPA—remains with the organization.
This governance model is consistent with the broader direction of the PDPC’s recent consultations, which increasingly emphasize accountability across the organization rather than concentrating responsibility within a single compliance function.
Independence does not mean isolation:
The PDPA requires that the DPO perform their duties independently.
This requirement is sometimes misunderstood to mean that the DPO should operate separately from the business.
In practice, independence means something quite different.
A DPO should be able to provide objective advice without inappropriate influence from commercial considerations. Management should not pressure the DPO to approve questionable processing activities or discourage the DPO from identifying compliance risks.
At the same time, independence should not prevent close collaboration with business units.
An effective DPO understands the organization’s operations, participates in project planning, and provides practical advice before privacy issues become compliance problems.
The most successful DPOs are therefore integrated into decision-making while remaining sufficiently independent to challenge proposals where necessary.
The DPO should be involved early:
Privacy risks are easiest to manage before systems are implemented.
Once a customer platform has been launched, an AI tool deployed, or a vendor contract executed, addressing privacy concerns often becomes significantly more expensive.
Organizations should therefore involve the DPO during the planning stage of new initiatives.
Examples include:
- launching new digital products;
- introducing AI-powered customer service;
- implementing HR technologies;
- engaging cloud providers;
- deploying CCTV systems;
- expanding overseas operations.
Early involvement allows privacy considerations to be incorporated into business decisions rather than added after implementation.
Expertise matters more than job title:
The PDPA does not prescribe a single professional background for DPOs.
In practice, effective DPOs come from diverse disciplines, including law, information security, compliance, risk management and information technology.
What matters is not professional qualification alone but the ability to understand both legal requirements and operational realities.
An effective DPO should be capable of translating legal principles into practical business guidance while communicating effectively with senior management, technical specialists and operational teams.
Organizations should therefore focus on competence rather than formal titles when appointing a DPO.
Conflicts of interest deserve careful consideration:
One of the most challenging aspects of DPO governance is avoiding conflicts of interest.
Individuals responsible for determining why and how personal data is processed may struggle to provide independent oversight of those same decisions.
For example, appointing the head of marketing as DPO may create tension where marketing initiatives require objective privacy review.
Similarly, information technology leaders responsible for designing systems may find it difficult to independently assess privacy risks arising from those systems.
Organizations should therefore consider whether reporting structures, operational responsibilities and decision-making authority could compromise the DPO’s independence.
The objective is not to prohibit dual roles entirely but to ensure that privacy oversight remains objective and credible.
A successful DPO builds a privacy culture:
Perhaps the greatest misconception is that privacy compliance can be centralized.
No DPO—regardless of experience—can personally oversee every processing activity across a large organization.
Long-term success depends upon building privacy awareness throughout the business.
Training, internal guidance, standardized procedures, governance committees and clearly allocated responsibilities often contribute more to sustainable compliance than expanding the DPO’s workload.
The DPO’s most valuable contribution may therefore be enabling others to make better privacy decisions rather than making every decision personally.
Looking ahead:
The PDPC’s consultation reflects an increasingly mature understanding of the DPO function.
Rather than acting as the organization’s privacy manager, the DPO is emerging as an independent adviser who supports, challenges and guides the organization while management retains responsibility for compliance.
Organizations that recognize this distinction will be better positioned to establish sustainable governance frameworks rather than relying excessively on a single individual to solve increasingly complex privacy issues.
Key takeaways:
- Appointing a DPO does not transfer PDPA compliance responsibilities from the organization to the DPO.
- The DPO’s role is to advise, monitor and facilitate compliance while management remains accountable for processing decisions.
- Independence enables objective advice but should not prevent close collaboration with business units.
- Early involvement of the DPO in new projects helps identify and address privacy risks before implementation.
- Organizations should carefully assess potential conflicts of interest and ensure that the DPO has sufficient authority, resources and access to senior management.
- A mature privacy program depends on organization-wide governance and a culture of compliance, not on the DPO alone.
Author: Panisa Suwanmatajarn, Managing Partner.
Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series
- PDPA: Data Breach Governance Is More Than a 72-Hour Deadline
- PDPA: PDPC Clarifies the Scope of “Health Data”
- PDPA: The PDPC Is Redefining Marketing Compliance
- PDPA: Legitimate Interest Is No Longer a Shortcut
- PDPA: ROPA Is Becoming the Organization’s Privacy Blueprint
- PDPA: The DPO Is Not Responsible for Compliance—Your Organization Is

