PDPA: When CCTV Becomes Biometric Processing
CCTV vs. Biometric Data:
The increasing use of facial recognition systems in office buildings, condominiums, hospitals, retail premises and other facilities raises an important question under the Personal Data Protection Act B.E. 2562 (2019) (PDPA): when does ordinary CCTV become processing of sensitive personal data? An identifiable image recorded by conventional CCTV will generally constitute personal data, but it should not automatically be regarded as sensitive biometric data merely because a person’s face is visible. The position changes where technology is applied to facial characteristics for the purpose of uniquely identifying or authenticating an individual. The PDPA treats biometric data resulting from such processing as sensitive personal data under section 26, with facial templates, iris templates and fingerprint templates being recognized examples.
Legal Basis for CCTV and Facial Recognition:
For ordinary CCTV, an organization must identify an appropriate legal basis and comply with requirements concerning transparency, purpose limitation, security, retention and data subject rights. For private organizations, CCTV installed for genuine security purposes may potentially rely on legitimate interests under section 24(5), subject to balancing those interests against the rights and freedoms of the individuals being recorded. Other grounds may apply depending on the circumstances, including compliance with a legal obligation under section 24(6), while public authorities may in appropriate cases rely on processing necessary for a task carried out in the public interest or exercise of official authority under section 24(4). Importantly, however, a legal basis that supports conventional CCTV does not automatically authorize facial recognition. Once facial images are processed as biometric data for unique identification, the organization must separately satisfy the requirements applicable to sensitive personal data under section 26.
Consent and Alternative Access:
This distinction is particularly important for facial recognition used to control access to condominiums, offices and other premises. A business may have a legitimate interest in protecting its premises, residents, employees and property, but the existence of a legitimate security objective does not necessarily establish that biometric identification is necessary to achieve it. Where no section 26 exception applies and explicit consent is relied upon, the organization should consider whether that consent is genuinely voluntary. If a resident, employee or tenant who refuses facial recognition cannot reasonably access the premises, the validity of that consent may be questionable. Providing a workable non-biometric alternative, such as an access card, physical key, PIN or mobile credential, can therefore be an important compliance measure. This should not be treated as an absolute rule requiring an alternative in every biometric deployment; the assessment depends on the applicable legal basis, necessity of the processing and circumstances in which consent is obtained.
Public Authorities and Large-Scale Processing:
Public authorities require a different analysis. They may have statutory functions or public-interest grounds supporting particular processing activities, but the existence of a public function does not itself provide unlimited authority to process biometric information. The authority should identify the specific statutory function and applicable section 26 exception and assess whether biometric processing is necessary and proportionate to that function. This is particularly important for large-scale identity verification systems involving transportation, border control, healthcare and public digital services. Similarly, organizations carrying out large-scale biometric identification or systematic monitoring should consider whether the nature, scale and risks of the processing require or justify a data protection impact assessment before implementation.
Transparency and Retention:
Transparency and retention also require particular attention. CCTV notices should be displayed appropriately before individuals enter monitored areas and should provide, or direct individuals to, information concerning the controller, purposes, legal basis, retention, disclosures, data subject rights and relevant contact channels. Where facial recognition is used, a generic notice stating merely that “CCTV is in operation” may not adequately describe the biometric processing taking place. Retention should likewise be determined by necessity and purpose rather than an assumed universal period such as 30 days. Particular footage may be preserved for longer where reasonably required for investigation, litigation or other legitimate purposes, while biometric templates warrant greater caution because biometric characteristics cannot readily be replaced if compromised.
What Businesses Should Review:
Businesses already using facial recognition should therefore reassess their systems rather than treating them merely as enhanced CCTV. The review should determine what information the technology actually generates, whether facial templates or other biometric identifiers are created, the section 26 basis relied upon, whether consent is genuinely voluntary where consent is used, and whether less intrusive technology could reasonably achieve the same purpose. Vendor arrangements should also be examined to determine where biometric data is stored and processed, who can access it, whether vendors retain or reuse the information, whether overseas transfers occur, and whether the data is used to develop or train the vendor’s technology. The critical compliance question is therefore no longer simply whether an organization may install CCTV, but what the system does with the images after they are captured.
Key Takeaways:
- Ordinary CCTV images are personal data but are not automatically sensitive biometric data.
- Facial recognition used for unique identification or authentication may constitute biometric processing under section 26.
- A legal basis for conventional CCTV does not automatically authorize facial recognition.
- Where biometric processing relies on consent, organizations should assess whether consent is genuinely voluntary and whether a practical non-biometric alternative should be available.
- Public authorities must still identify an applicable legal basis for sensitive biometric processing and consider necessity and proportionality.
- Retention periods should reflect necessity and purpose rather than an assumed fixed period.
- Introducing facial recognition or AI analytics into an existing CCTV system should trigger a fresh PDPA compliance assessment.
Author: Panisa Suwanmatajarn, Managing Partner.
Other Articles
- Thailand Revises Visa Exemption Scheme: 30-Day Stay and Revised List of Eligible Countries
- PDPA: When CCTV Becomes Biometric Processing
- PDPA: Cross-Border Data Transfer Compliance for Bank Z Under Thailand’s Data Protection Law – Key Takeaways
- PDPA: Does Removing a Name Make Data Anonymous?
- PDPA: Disclosure of Personal Data to Third Parties for Legal Proceedings
- PDPA: Applicability to a Facebook User’s Posting of Personal Data – Key Takeaways

