PDPA: Applicability to a Facebook User’s Posting of Personal Data – Key Takeaways

women typing on the notebook

PDPA: Applicability to a Facebook User’s Posting of Personal Data – Key Takeaways

Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) regulates systematic personal data handling, with exemptions for personal or familial use. The Ad Hoc Subcommittee under the Personal Data Protection Committee has evaluated whether a Facebook user’s posting of an allegedly defamatory image and text qualifies them as a data controller under PDPA, as raised by Police Station F in a criminal investigation. This analysis outlines the facts, the subcommittee’s rulings, and the compliance implications.

Factual Background:

Police Station F received a complaint alleging that a Facebook user posted an image of the complainant with text causing insult or hatred, prompting a criminal case. The prosecutor’s office (C) requested the station to investigate: (1) whether the post’s visibility settings (public symbols like a globe or people) made it accessible to the general public or a specific group, and (2) whether the suspect qualifies as a data controller under PDPA Section 6 for posting the complainant’s image and text.

Subcommittee Decisions:

The subcommittee addressed the issues as follows:

  1. Post Visibility (Issue 1)
    • The question of whether the suspect’s Facebook post—with a globe or people symbol—was visible to the public or a limited group falls outside PDPA’s direct scope. PDPA defines “personal data” under Section 6 as information identifying a living individual, directly or indirectly (e.g., the complainant’s image). However, visibility settings pertain to evidence in a criminal investigation, not PDPA enforcement. The subcommittee deemed this a factual matter for the police to assess independently, unrelated to PDPA compliance.
  2. Data Controller Status (Issue 2)
    • Under PDPA Section 6, a “data controller” is a person or entity with authority to decide on the collection, use, or disclosure of personal data, subject to duties like lawful bases (Sections 24, 26), notification (Section 23), security (Section 37), and rights responses (Sections 30–36). The law targets systematic or regular data processing, not isolated acts, per its intent and Section 4(1) exemption for personal or family use. The suspect, a natural person posting on Facebook, isn’t a data controller if the act was for personal purposes (e.g., expression) without systematic intent. Absent evidence of regular, organized data handling, PDPA doesn’t apply, per Section 4(1). However, the act may violate other laws (e.g., Computer Crime Act B.E. 2550, Penal Code defamation, or Civil Code torts under Section 420), which the police should pursue separately.

Implications for Compliance:

The suspect’s posting likely falls outside PDPA’s ambit as a one-off personal act, not subjecting them to data controller obligations (e.g., consent, security measures). Police Station F must focus on criminal or tort laws for liability, using post visibility as evidence, not a PDPA issue. PDPA applies to entities with structured data practices, not casual social media use.

Key Takeaways:

  • PDPA Targets Systematic Use: The suspect isn’t a data controller under Section 6 unless their posting reflects regular, purposeful data management, per Section 4(1) exemption.
  • Personal Acts Are Exempt: One-time social media posts for personal ends fall outside PDPA, per Section 4(1), unlike organizational data handling.
  • Other Laws Apply: Privacy breaches or defamation may trigger liability under the Computer Crime Act, Penal Code, or Civil Code, not PDPA.
  • Visibility Is Investigative: Post accessibility (public vs. private) is a factual issue for criminal evidence, not a PDPA concern.

This ruling clarifies PDPA’s scope, excluding personal social media acts from its framework, directing Police Station F to pursue alternative legal avenues for the complainant’s grievance.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Posted in