Breaking Down Government Data Silos: New Rules on Inter-Agency Sharing of Personal Information
A new Royal Decree has established a legal framework requiring government agencies to share personal information under their control with other government agencies for specified electronic data-linkage purposes.
The Royal Decree on Disclosure of Personal Information Controlled by Government Agencies to Other Government Agencies B.E. 2569 (2026) (the “Royal Decree”) represents an important development in the government’s efforts to move away from fragmented, agency-specific databases toward greater interoperability of public-sector information.
The measure is intended to enable government agencies to use more complete and accurate information in policymaking, public services and targeted welfare programs, while reducing the burden on individuals of repeatedly submitting information already held by the government. The framework is also intended to contribute to greater transparency and more effective law enforcement.
Legal basis for inter-agency disclosure:
The Royal Decree is issued pursuant to Section 24(9) of the Official Information Act B.E. 2540 (1997).
Section 24 of the Official Information Act establishes, as a general rule, that a government agency may not disclose personal information under its control to another government agency or another person without the prior or contemporaneous written consent of the person concerned, subject to specified statutory exceptions.
Section 24(9) permits disclosure in other cases prescribed by Royal Decree.
The new Royal Decree uses this statutory mechanism to provide a specific legal basis for government-to-government disclosure of personal information falling within its scope. As a result, qualifying disclosure under the Royal Decree does not depend on obtaining the individual’s written consent on each occasion.
This is important because large-scale government data interoperability would be difficult to implement if each transfer of information between government agencies required separate consent from every affected individual.
From isolated databases to connected government:
The policy underlying the Royal Decree is broader than simply permitting one government agency to send information to another.
Government agencies hold significant amounts of information about individuals, but that information has traditionally been maintained within separate administrative systems. Where relevant information is distributed among different agencies, the government may not have ready access to the complete information required for policymaking, public services or welfare administration.
The Royal Decree is intended to address this fragmentation by enabling electronic linkage of personal information held across government agencies.
The stated objectives include allowing government policies and measures, government services and targeted welfare programs to be based on accurate and complete information. Greater data linkage is also intended to improve the efficiency of government services, reduce administrative burdens on the public, promote transparency and enhance the effectiveness of law enforcement.
In practical terms, the framework supports a move toward the principle that individuals should not continually be required to provide one government agency with information that is already held by another government agency where the conditions for lawful data linkage are satisfied.
Government agencies may be required to disclose information:
A significant feature of the Royal Decree is that it does not merely provide government agencies with a general permission to share personal information.
It establishes a framework under which a government agency controlling personal information must disclose that information to another government agency where the information is requested for purposes falling within the Royal Decree.
The relevant data linkage is intended to support the preparation and provision of government services and the provision of targeted welfare through electronic means.
This gives the Royal Decree practical significance beyond an ordinary exception to a confidentiality rule. It provides the legal infrastructure for systematic government data interoperability.
The receiving agency also assumes obligations:
Greater availability of government-held information is accompanied by safeguards.
A government agency requesting and receiving personal information must safeguard that information. Importantly, it may not further disclose the information to an outside person.
This restriction is an important limitation on the scope of the new regime. The Royal Decree should therefore not be understood as making personal information freely transferable simply because it has entered an interconnected government information system.
The legal authorization concerns disclosure within the framework established by the Royal Decree. Once information has been received, the recipient agency remains responsible for protecting it and complying with the restrictions applicable to its subsequent disclosure.
The required safeguards are also linked to criteria and conditions prescribed by the competent authority and cybersecurity requirements. Consequently, implementation of the Royal Decree is as much an information-governance issue as a data-access issue.
Targeted welfare and government services:
One of the clearest practical applications of government data linkage is the provision of targeted welfare.
Eligibility for government assistance may depend on information maintained by several different authorities. Without data linkage, individuals may have to obtain documents from one agency and submit them to another, while the agency administering the benefit may have difficulty independently establishing a complete picture of the applicant’s circumstances.
Electronic linkage can potentially change this process.
Where legally permitted, the administering agency may obtain relevant information directly from government data already available elsewhere. This can make eligibility assessment more accurate, reduce duplicate documentation and enable welfare programs to be directed more effectively toward intended recipients.
The same principle can apply more broadly to government services. Greater interoperability can reduce repeated requests for information and allow government agencies to make administrative decisions using more complete information.
Transparency and law enforcement:
The Royal Decree also has implications beyond welfare and administrative services.
The stated rationale includes increasing transparency within government and improving the effectiveness of law enforcement. Information that appears unremarkable when held in a single agency’s database may have greater significance when lawfully linked with information held by other agencies.
Inter-agency data linkage can therefore provide government authorities with a more complete information base for identifying inconsistencies, verifying information and carrying out their statutory functions.
This capability may be particularly relevant where investigations or enforcement activities require information held by several government bodies.
However, the Royal Decree should not be characterized as creating a general law-enforcement database or an unrestricted investigative power. Its significance lies in providing a statutory mechanism for disclosure and electronic data linkage within the scope established by the Royal Decree.
Data sharing does not mean unrestricted data use:
An important compliance point is the distinction between access to information and freedom to use or disclose that information.
The fact that one government agency is legally entitled to obtain information from another does not mean that information becomes unrestricted once transferred.
Government agencies implementing data-linkage arrangements should therefore consider controls covering at least:
- the authority and purpose for requesting information;
- identification of the information required;
- authentication of requesting agencies and authorized personnel;
- access controls within the receiving agency;
- secure electronic transmission;
- logging and traceability of access and transfers;
- cybersecurity safeguards;
- retention and management of linked information; and
- controls preventing unauthorized onward disclosure.
These controls are particularly important because increased interoperability can increase the consequences of inadequate security. A weakness in one interconnected system may potentially expose information originating from several agencies.
Relationship with personal data protection requirements:
The Royal Decree should also be understood within the broader legal framework governing personal information.
Its immediate statutory basis is the Official Information Act, and it establishes a specific mechanism permitting inter-agency disclosure that would otherwise be subject to the restrictions in Section 24 of that Act.
However, the existence of a statutory basis for disclosure should not automatically be equated with unlimited authority to process the information for any subsequent purpose.
Government agencies participating in data-linkage arrangements should therefore identify the legal authority supporting each stage of the information lifecycle—including collection, disclosure, receipt, use, retention, security and any subsequent disclosure—and consider other applicable personal data protection and cybersecurity requirements.
The distinction is particularly important as government systems become increasingly interconnected. Legal authority to receive information is only one component of lawful and responsible data governance.
A significant step toward data-driven government:
The Royal Decree represents a structural change in the management of government-held personal information.
The traditional model in which each government agency maintains its own information and individuals repeatedly provide substantially the same information to different authorities is increasingly being replaced by a model based on controlled interoperability.
If implemented effectively, the new framework should enable government agencies to make greater use of information already available within the public sector, improve the accuracy of public services and welfare programs, and reduce unnecessary administrative burdens on individuals.
The corresponding challenge is governance.
The more effectively government information systems are connected, the more important it becomes to ensure that access is authorized, purposes are properly defined, information is adequately protected and subsequent disclosure remains controlled.
The Royal Decree therefore represents not simply an expansion of government access to data, but a move toward a more integrated model of public-sector data governance.
Key Takeaways:
- The Royal Decree marks an important shift from government data held in separate institutional silos toward controlled, interoperable public-sector data infrastructure.
- The Royal Decree establishes a statutory mechanism for the disclosure of personal information between government agencies for qualifying electronic data-linkage purposes.
- Its legal basis is Section 24(9) of the Official Information Act, which allows exceptions to the general restriction on disclosure of government-controlled personal information without written consent.
- The framework goes beyond merely permitting voluntary data sharing and supports systematic interoperability between government information systems.
- A government agency receiving information under the framework must safeguard the information and is restricted from further disclosure to an outside person.
- The framework is intended to support more accurate policymaking, more efficient government services and targeted welfare, reduced administrative burdens on the public, greater transparency and more effective law enforcement.
- Government agencies should not treat authorization to receive information as unrestricted authority to use or further disclose it. Purpose limitation, access controls, cybersecurity and information governance remain central to implementation.
Author: Panisa Suwanmatajarn, Managing Partner.
Other Articles
- Class-Action Signal Raises the Stakes for Online Consumer Complaints
- Thailand-Australia Strategic Partnership 2026–2029: Advancing Cybersecurity, Economic Resilience, Cross-Border Crime Cooperation, and Support for SMEs and Startups
- OCPB Introduces FastTrack Complaint Handling for Online Purchases: Practical Implications for Digital Businesses
- Parliament Considers Carbon-Credit Sales from Community Forests
- United States Finalizes Section 301 Tariff Framework Based on Forced Labor Enforcement: Thailand Subject to a 12.5% Tariff
- Tomorrowland Thailand 2026: Business Opportunities and Operational Readiness for Local Investors