Site icon The Legal Co., Ltd.

PDPA: Cross-Border Data Transfer Compliance for Bank Z Under Thailand’s Data Protection Law – Key Takeaways

lights in darkness around thin lines

Photo by Suki Lee on Pexels.com

PDPA: Cross-Border Data Transfer Compliance for Bank Z Under Thailand’s Data Protection Law – Key Takeaways

Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) regulates the transfer of personal data abroad, imposing conditions to ensure adequate protection under Section 28. The Ad Hoc Subcommittee under the Personal Data Protection Committee has addressed Bank Z’s obligations when submitting directors’ personal data to comply with the Accounting and Corporate Regulatory Authority (ACRA) of Singapore and other foreign regulations. This analysis details the facts, the subcommittee’s rulings, and the resulting compliance framework.

Factual Background:

Bank Z must transmit directors’ personal data to meet ACRA requirements in Singapore and potentially other foreign laws. Under PDPA Section 28, cross-border data transfers require the recipient country or international organization to have adequate data protection standards, as determined by the Personal Data Protection Committee per Section 16(5), unless an exception applies. Bank Z faces uncertainty about whether “compliance with the law” under Section 28(1) includes foreign laws and, if not, how to proceed absent adequacy decisions for destination countries.

Subcommittee Decisions:

The subcommittee clarified Bank Z’s PDPA obligations as follows:

  1. Scope of “Compliance with the Law” Under Section 28(1)
    • Cross-border data transfers are permissible only if the destination has adequate protection standards, per Section 28 and criteria set under Section 16(5). Exceptions under Section 28(1)–(6) or Section 29 may apply. For Section 28(1)—compliance with the law—the law must be Thai and legally binding on the data controller. Foreign laws, such as ACRA regulations, do not qualify as a basis under this provision. Thus, Bank Z cannot rely on Section 28(1) to justify transfers based on Singaporean or other foreign legal obligations.
  2. Absence of Adequacy Decisions and Next Steps
    • No adequacy decisions exist under Section 16(5) and Section 28, as the committee has not yet designated any country or organization (e.g., Singapore) as having sufficient data protection standards. Without such designation, Bank Z must assess exceptions under Section 28(1)–(6). For instance, transferring directors’ data could fall under Section 28(3)—necessary to perform a contract where the director (data subject) is a party, such as employment or governance agreements—or pre-contractual steps requested by the director. If no exception applies (e.g., Sections 28(1), (3)–(6)), Bank Z must obtain explicit consent from directors per Section 28(2), informing them of the potentially inadequate protection standards in the destination country (e.g., Singapore) beforehand.

Implications for Compliance:

The subcommittee’s rulings restrict “compliance with the law” to Thai jurisdiction, excluding foreign mandates like ACRA’s as a direct basis. Absent adequacy decisions, Bank Z must either find a contractual or similar exception or secure directors’ informed consent, highlighting risks in destination countries. This dual approach balances legal obligations with data subject rights, pending future committee guidance on adequacy.

Key Takeaways:

Bank Z’s scenario underscores PDPA’s stringent cross-border framework, prioritizing Thai legal authority and data subject awareness until adequacy standards are clarified. Compliance demands the strategic use of exceptions or proactive consent processes to align with international obligations.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Exit mobile version