PDPA Insights: Building Effective Privacy Governance
PDPA: The PDPC Is Redefining Marketing Compliance
Marketing has evolved dramatically over the past decade, yet many organizations continue to approach compliance under Thailand’s Personal Data Protection Act (PDPA) as though marketing still begins with an email campaign or a promotional text message. In practice, modern marketing starts much earlier. Businesses routinely collect, combine and analyze personal data to understand customer behavior, predict purchasing decisions and personalize customer experiences long before any advertisement reaches its intended audience.
This transformation has gradually blurred the distinction between marketing, customer analytics and data governance. Customer relationship management (CRM) platforms, loyalty programs, online tracking technologies, behavioral advertising, recommendation engines and artificial intelligence (AI) have become ordinary components of commercial operations. Personal data is no longer used simply to communicate with customers; it is increasingly used to decide what products customers see, when they see them and how organizations engage with them.
Against this backdrop, the Personal Data Protection Committee (PDPC) has released a consultation draft on marketing and direct marketing. Although the consultation is not yet legally binding, it provides an important indication of how the regulator interprets marketing under the PDPA. Significantly, the consultation extends beyond traditional direct marketing to include digital marketing, cookies and tracking technologies, targeted advertising, profiling, AI-assisted personalization and automated decision-making. In doing so, it reflects a broader regulatory understanding of marketing itself.
For businesses, this matters because it changes the focus of compliance. The central issue is no longer simply whether an organization has obtained consent before sending promotional communications. Increasingly, the question is whether the organization can justify and govern every significant use of personal data throughout the marketing lifecycle.
Marketing now begins with customer insight:
Traditional marketing compliance focused primarily on communications. Organizations assessed whether they could lawfully send promotional emails, SMS messages or telephone calls.
The consultation suggests that this perspective is becoming too narrow.
Marketing increasingly begins with customer insight rather than customer communication. Organizations analyze website activity, purchasing history, mobile application usage and online interactions to understand customer preferences before deciding which advertisements to display or which products to recommend. By the time a customer receives a promotional message, multiple processing activities may already have taken place.
Recognizing this distinction is essential. Compliance should not be confined to the final communication but should extend to the collection, analysis and use of personal data that supports marketing decisions.
The same customer data may support very different purposes:
One of the most significant practical consequences of this broader perspective is that organizations should avoid treating all customer information as though it were processed for a single purpose.
Consider an online retailer. Purchase history may initially be processed to complete an order and arrange delivery. The same information may later be used to administer a loyalty program, identify customer purchasing patterns, recommend complementary products, measure campaign effectiveness and improve future marketing strategies.
Although the dataset remains the same, the purposes differ.
This distinction is important because the PDPA regulates the processing of personal data according to purpose rather than according to the dataset itself. Organizations should therefore identify each processing activity separately and ensure that the legal basis relied upon corresponds to the actual business objective.
This represents a more sophisticated approach than simply obtaining a broad marketing consent covering every future use of customer information.
Profiling has become an ordinary commercial activity:
Customer profiling is no longer limited to technology companies.
Retailers recommend products based on purchasing history. Airlines personalize travel offers. Financial institutions categorize customers according to spending behavior. Hotels tailor promotions using previous booking information. Streaming services continuously refine recommendations according to viewing habits.
These activities have become standard business practice.
The more relevant compliance question is therefore no longer whether profiling occurs but whether profiling is appropriately governed.
Organizations should understand what information is analyzed, how customer profiles are created, whether those profiles influence commercial decisions and how customers are informed about these practices. Transparency becomes particularly important where profiling extends beyond simple customer segmentation and begins influencing individualized offers or recommendations.
AI magnifies existing compliance obligations:
Artificial intelligence has transformed the scale of modern marketing.
Tasks previously performed by marketing teams can now be undertaken automatically through recommendation engines, predictive analytics and generative AI. Systems can analyze millions of customer interactions, identify purchasing patterns and personalize marketing campaigns with minimal human intervention.
Despite these technological developments, AI does not alter the core legal principles established by the PDPA.
Organizations remain responsible for identifying an appropriate legal basis, limiting processing to specified purposes, maintaining transparency and respecting data subject rights.
What AI changes is the scale at which those obligations must be managed.
Organizations should therefore integrate AI into existing privacy governance rather than treating AI compliance as a separate exercise. Effective governance requires understanding what personal data is processed, how AI systems generate recommendations and what oversight exists to monitor automated outcomes.
Cookie compliance is only the beginning:
Cookies have traditionally been regarded as a website compliance issue.
In reality, they often represent only the first stage of a much larger processing ecosystem.
Information collected through tracking technologies may subsequently be combined with CRM data, disclosed to advertising technology providers, incorporated into customer profiles, analyzed using AI and ultimately used to deliver targeted advertising across multiple platforms.
Organizations should therefore move beyond focusing exclusively on cookie banners. Compliance should encompass the downstream use of tracking information throughout the digital advertising ecosystem.
Governance—not consent—will define future compliance:
Perhaps the most significant message emerging from the PDPC’s consultation is that marketing compliance is becoming a governance issue.
Historically, organizations invested considerable effort in drafting consent forms and updating privacy notices. Those measures remain important, but they no longer provide a complete compliance framework.
Organizations should instead ask broader governance questions.
Can we explain why customer information is collected?
Can we justify each processing activity?
Do we understand how profiling influences marketing decisions?
Can we identify every external platform receiving customer information?
Are customer objections implemented consistently across all marketing systems?
Can these decisions be demonstrated through appropriate documentation?
These questions reflect accountability rather than procedure.
As marketing technologies continue to evolve, organizations capable of answering them convincingly are likely to be better positioned than those relying primarily upon consent as evidence of compliance.
Looking ahead:
The PDPC’s consultation represents more than a discussion of direct marketing. It reflects an evolving regulatory understanding of how personal data underpins modern marketing.
Organizations should therefore resist the temptation to treat the consultation as another checklist of compliance requirements. Its broader significance lies in demonstrating that regulatory attention is shifting from individual communications toward governance of the entire marketing ecosystem.
Businesses that recognize this shift early—and embed privacy considerations into customer analytics, profiling, AI deployment and digital advertising—will be better prepared not only for future regulatory developments but also for an increasingly data-driven commercial environment.
Key takeaways:
- The PDPC’s consultation reflects an expanded understanding of marketing that extends beyond promotional communications to encompass customer analytics, digital advertising, profiling, AI-assisted personalization and automated decision-making.
- Organizations should identify individual processing activities and their purposes rather than treating all marketing-related processing as a single activity.
- Customer profiling has become an ordinary business practice and should be governed through transparency, accountability and appropriate internal controls.
- AI increases the scale of personal data processing but does not replace the fundamental principles of the PDPA.
- Marketing compliance is increasingly defined by governance of the entire marketing lifecycle rather than by obtaining consent alone.
Author: Panisa Suwanmatajarn, Managing Partner.
Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series
- PDPA: Data Breach Governance Is More Than a 72-Hour Deadline
- PDPA: PDPC Clarifies the Scope of “Health Data”
- PDPA: The PDPC Is Redefining Marketing Compliance
- PDPA: Legitimate Interest Is No Longer a Shortcut
- PDPA: ROPA Is Becoming the Organization’s Privacy Blueprint
- PDPA: The DPO Is Not Responsible for Compliance—Your Organization Is