PDPA Insights: Building Effective Privacy Governance
PDPA: AI Is Not Replacing Privacy Law—It Is Changing How We Apply It
Artificial intelligence has rapidly become part of everyday business operations. Recommendation engines personalize online shopping experiences, chatbots answer customer enquiries, fraud detection systems identify suspicious transactions, recruitment platforms screen job applicants, and generative AI assists with customer service, marketing and document preparation.
As AI adoption accelerates, organizations frequently ask whether the Personal Data Protection Act (PDPA) contains special rules governing AI.
The answer is both simple and nuanced.
Thailand’s PDPA does not establish a standalone regulatory framework for artificial intelligence. Unlike some jurisdictions that have introduced AI-specific legislation, the PDPA remains technology neutral. The same legal principles governing all personal data processing—including lawfulness, purpose limitation, transparency, data minimization, security, and accountability—continue to apply regardless of whether personal data is processed manually or through sophisticated AI systems.
Nevertheless, the Personal Data Protection Committee’s (PDPC) recent consultation on marketing and direct marketing demonstrates that the regulator increasingly recognizes AI-assisted personalization, profiling, and automated decision-making as ordinary components of modern business operations rather than exceptional technologies. This signals an important evolution in regulatory expectations. The question is no longer whether AI falls within the scope of the PDPA. Instead, organizations should consider how existing privacy principles should operate when personal data is processed at unprecedented speed and scale.
AI changes the scale—not the legal principles:
One misconception is that AI requires an entirely new compliance framework.
In reality, the core legal questions remain familiar.
Why is personal data being processed?
Is there an appropriate legal basis?
Have individuals been informed?
Is the processing proportionate?
Are appropriate safeguards in place?
These questions existed before AI and remain the foundation of PDPA compliance.
What AI changes is the scale and complexity of those questions.
A marketing employee might manually analyze one hundred customer records to recommend products.
An AI system may analyze ten million records every day, continuously refining customer profiles and generating individualized recommendations without direct human intervention.
The legal principles remain the same.
The governance challenge becomes significantly greater.
Organizations should focus on the processing—not the technology:
Discussions about AI frequently focus on algorithms.
Privacy law focuses on personal data.
Organizations should therefore avoid beginning compliance discussions with technical questions such as:
“Are we using AI?”
Instead, they should ask:
“How is personal data being collected, analyzed, combined, retained and disclosed?”
This shift in perspective has practical consequences.
An AI system recommending products based upon purchasing history raises different privacy considerations from an AI system screening job applicants or detecting fraudulent transactions.
The technology may be identical.
The processing purposes are not.
Organizations should therefore evaluate each AI use case separately rather than adopting a single enterprise-wide conclusion regarding AI compliance.
Profiling is becoming an ordinary business activity:
One of the most significant aspects of the PDPC’s recent consultation is the inclusion of profiling alongside AI-assisted marketing and automated decision-making.
This reflects commercial reality.
Retailers profile customers to recommend products.
Banks profile spending behaviour to identify suitable financial services.
Hotels profile travel patterns.
Streaming platforms profile viewing preferences.
Insurance companies profile claims histories.
Profiling has become routine.
The regulatory focus is therefore shifting away from asking whether profiling exists toward examining whether organizations understand, govern and explain how profiling operates.
Transparency becomes particularly important where profiling materially influences commercial decisions affecting individuals.
Explainability is becoming a governance issue:
Many AI systems are capable of generating sophisticated outputs while providing limited insight into how those outputs were produced.
This creates a practical challenge.
Organizations may be able to explain what an AI system does without fully understanding why it reached a particular recommendation.
The PDPA does not require organizations to explain complex algorithms.
However, organizations should be capable of explaining much more fundamental issues.
What personal data does the AI system use?
Why is that information necessary?
What business objective does the system support?
Who reviews significant outputs?
What safeguards exist to identify inappropriate outcomes?
These governance questions are likely to become increasingly important as AI adoption expands.
Vendor governance is becoming AI governance:
Few organizations develop AI systems internally.
Most rely on external providers.
Large language models.
Cloud AI services.
Marketing automation platforms.
Customer relationship management systems.
Fraud detection software.
Human resources platforms.
Consequently, AI governance increasingly depends upon vendor governance.
Organizations should understand:
- where personal data is processed;
- whether overseas transfers occur;
- whether providers use customer data to train models;
- whether subcontractors process personal data;
- how security is maintained;
- how long information is retained.
Vendor due diligence therefore becomes an essential component of AI governance under the PDPA.
Human oversight still matters:
AI enables organizations to automate decisions at unprecedented scale.
Automation, however, should not eliminate accountability.
Organizations should identify situations where meaningful human review remains appropriate.
Examples may include:
- rejecting employment applications;
- detecting suspected fraud;
- evaluating insurance claims;
- determining customer eligibility for significant commercial benefits.
The appropriate level of oversight will depend upon the context and the potential impact on individuals.
Organizations should therefore design governance frameworks that ensure AI supports decision-making without entirely replacing human judgement where significant interests are involved.
AI governance is ultimately privacy governance:
Perhaps the most important lesson is that organizations should resist creating isolated AI compliance programs.
Instead, AI should be incorporated into existing privacy governance.
Records of Processing Activities should identify AI-supported processing.
Privacy notices should accurately describe AI-related processing where appropriate.
Legal basis assessments should consider AI processing explicitly.
Vendor management should address AI providers.
Privacy impact assessments should evaluate AI risks.
Training programs should include AI governance.
In other words, organizations should integrate AI into their existing accountability framework rather than building a separate compliance structure.
Looking ahead:
Artificial intelligence will continue to reshape business operations.
The more significant challenge under the PDPA, however, is unlikely to be the technology itself.
It will be governance.
Organizations capable of explaining why AI is used, what personal data supports it, how risks are managed, and how decisions remain accountable are likely to be better prepared than organizations focusing exclusively on technical innovation.
The PDPC’s recent consultation suggests that this is the direction in which Thailand’s privacy regime is evolving. AI is becoming an ordinary business tool. As a result, organizations should treat AI governance as an ordinary component of privacy governance.
Key takeaways:
- The PDPA does not establish separate legal principles for AI; existing privacy obligations continue to apply regardless of the technology used.
- AI increases the scale and complexity of personal data processing but does not replace the need for lawful basis, transparency, purpose limitation, and accountability.
- Organizations should assess individual AI use cases rather than treating all AI deployments identically.
- Profiling and AI-assisted decision-making are becoming mainstream regulatory concerns and should be supported by appropriate governance and transparency.
- Vendor management is increasingly inseparable from AI governance because many AI capabilities are provided by third-party platforms.
The organizations best prepared for future regulation will be those that integrate AI into existing privacy governance rather than treating it as a separate compliance project.
Author: Panisa Suwanmatajarn, Managing Partner.
Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series
- PDPA: AI Is Not Replacing Privacy Law—It Is Changing How We Apply It
- PDPA: Data Breach Governance Is More Than a 72-Hour Deadline
- PDPA: PDPC Clarifies the Scope of “Health Data”
- PDPA: The PDPC Is Redefining Marketing Compliance
- PDPA: Legitimate Interest Is No Longer a Shortcut
- PDPA: ROPA Is Becoming the Organization’s Privacy Blueprint