PDPA: Data Breach Governance Is More Than a 72-Hour Deadline

cardboard box full of file folders

PDPA Insights: Building Effective Privacy Governance

PDPA: Data Breach Governance Is More Than a 72-Hour Deadline

One of the best-known requirements under Thailand’s Personal Data Protection Act (PDPA) is the obligation to notify the Personal Data Protection Committee (PDPC) of certain personal data breaches without undue delay and, where required, within 72 hours.

As a result, many organizations approach breach preparedness primarily as a reporting exercise. Internal discussions often focus on when the 72-hour period begins, what information should be included in the notification, and whether affected individuals must also be informed.

These are important questions.

They are also the wrong place to begin.

The Personal Data Protection Committee’s recent consultation on security measures and personal data breach management suggests a broader regulatory perspective. Rather than treating breach notification as the central compliance obligation, the consultation emphasizes governance before, during and after a security incident. It discusses risk management, organizational measures, technical safeguards, incident response planning, documentation, and continuous improvement as integral components of compliance. The message is clear: a well-governed organization should be managing breach risk long before it considers whether a notification must be submitted.

A breach rarely begins with the breach:

Organizations often describe a breach as a discrete event.

An employee clicks a malicious link.

A laptop is stolen.

A cloud storage bucket is misconfigured.

A ransomware attack encrypts corporate systems.

Yet these events rarely occur in isolation.

Most data breaches reflect weaknesses that existed long before the incident itself. Poor access management, inadequate vendor oversight, outdated systems, excessive user privileges, insufficient employee training, and incomplete asset inventories frequently contribute to the eventual breach.

Consequently, organizations should regard breach management as an ongoing governance process rather than an emergency response exercise.

The most effective incident response plans are developed before they are needed.

Security is an organizational responsibility:

Information security is often viewed primarily as an IT issue.

The PDPA takes a broader approach.

Protecting personal data requires coordinated action across multiple business functions.

Senior management establishes governance.

Human resources develops training.

Procurement evaluates vendors.

Legal reviews contractual protections.

Business units determine what personal data is collected and why.

Information technology implements technical controls.

Each function contributes to reducing breach risk.

Organizations that treat cybersecurity as the sole responsibility of technical teams may overlook governance failures that contribute equally to privacy incidents.

Incident response plans should answer practical questions:

Many organizations maintain incident response policies that satisfy regulatory requirements but provide limited operational guidance.

An effective incident response plan should answer practical questions before an incident occurs.

Who investigates the incident?

Who determines whether personal data has been compromised?

Who decides whether notification is required?

Who communicates with regulators?

Who informs affected individuals?

Who preserves evidence?

Who approves public statements?

Who manages communications with vendors?

These decisions should not be made for the first time during a cybersecurity incident.

Clear governance significantly improves response quality while reducing confusion during high-pressure situations.

Vendors increasingly determine organizational resilience:

Modern organizations rarely process personal data entirely within their own infrastructure.

Cloud providers.

Payroll processors.

CRM vendors.

Marketing platforms.

AI providers.

Managed security services.

Software developers.

Each may process significant volumes of personal data on the organization’s behalf.

Consequently, incident preparedness increasingly depends upon vendor governance.

Organizations should understand how vendors detect incidents, when they notify customers, what contractual obligations apply, how investigations are coordinated, and whether subcontractors introduce additional risk.

Vendor due diligence should therefore extend beyond procurement and continue throughout the contractual relationship.

Documentation matters before regulators ask for it:

Organizations often focus on documenting the breach itself.

Increasingly, regulators may also expect organizations to demonstrate what preventive measures existed before the incident.

Could the organization explain:

  • why specific security measures were selected?
  • why particular risks were considered acceptable?
  • when systems were last reviewed?
  • whether employees received appropriate training?
  • whether incident response plans had been tested?
  • whether previous incidents had resulted in corrective action?

These questions reflect organizational accountability rather than incident reporting.

Good documentation demonstrates that the organization actively managed risk rather than merely reacting after an incident occurred.

Every breach should improve the organization:

The conclusion of an investigation should not mark the end of breach management.

Every incident provides an opportunity to improve governance.

Organizations should conduct post-incident reviews addressing not only technical causes but also organizational lessons.

Were responsibilities clearly allocated?

Did communication function effectively?

Were vendors responsive?

Did documentation prove sufficient?

Were customers informed appropriately?

Could similar incidents occur elsewhere within the organization?

Continuous improvement is one of the strongest indicators of a mature privacy governance program.

The future of breach management:

Cyber threats will continue to evolve.

Artificial intelligence will introduce new attack vectors.

Cloud ecosystems will become increasingly complex.

Third-party dependencies will continue expanding.

Against this background, organizations should avoid viewing the PDPA primarily as imposing notification obligations.

The broader challenge is establishing governance capable of identifying, managing and learning from security incidents before they become regulatory problems.

The organizations that respond most effectively to future breaches are unlikely to be those that simply notify within 72 hours.

They will be those that can demonstrate that security, governance and accountability existed long before the incident occurred.

Key takeaways:

  • Personal data breach management begins before a breach occurs through governance, risk management and organizational preparedness.
  • Effective breach response requires coordination among legal, IT, information security, procurement, human resources and senior management.
  • Incident response plans should allocate responsibilities and decision-making authority before an incident arises.
  • Vendor governance has become an essential component of breach preparedness because third-party providers increasingly process personal data on behalf of organizations.
  • Documentation of preventive measures and continuous improvement may become as important as the breach notification itself.
  • Organizations should view breach management as an ongoing governance process rather than a regulatory reporting obligation.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

Posted in