PDPC Opens New Path for Intra-Group Cross-Border Data Transfers
The Personal Data Protection Committee (PDPC) has introduced a formal framework for the examination and certification of Binding Corporate Rules (BCRs), providing multinational corporate groups with a new mechanism to support cross-border transfers of personal data under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA).
The Regulation on the Examination and Certification of Binding Corporate Rules was published in the Government Gazette on 17 February 2026 and became effective immediately. The regulation establishes a certification process through which multinational organizations may seek PDPC approval of BCRs as an appropriate safeguard for intra-group international data transfers.
The development represents a significant milestone in the evolution of Thailand’s cross-border data transfer regime and offers multinational businesses greater flexibility in managing global data flows.
Existing Cross-Border Transfer Framework:
Cross-border transfers of personal data under the PDPA are principally governed by Sections 28 and 29.
Section 28 generally requires that personal data transferred to another country or international organization be sent only to destinations that maintain adequate data protection standards as prescribed by the PDPC.
Where the destination jurisdiction has not been recognized as providing adequate protection, Section 29 permits transfers based on certain safeguards or exemptions. In practice, organizations have often relied on contractual arrangements, consent, or other statutory exceptions to facilitate international transfers.
While these mechanisms remain available, they may be difficult to implement across large multinational groups involving numerous entities and complex data processing activities.
The introduction of a formal BCR framework provides an additional compliance option specifically designed for multinational organizations that routinely transfer personal data among affiliated companies located in different jurisdictions.
What Are Binding Corporate Rules?
Binding Corporate Rules are legally enforceable internal rules adopted by a corporate group to govern the processing and transfer of personal data among group entities.
The purpose of BCRs is to establish a consistent and comprehensive privacy framework across all participating companies within the group, regardless of where those companies are located.
Typically, BCRs address matters such as:
- Data protection principles and governance;
- Data subject rights;
- Security measures and incident management;
- Accountability and compliance monitoring;
- Internal complaint handling procedures;
- Employee training and awareness programs; and
- Mechanisms for enforcing compliance throughout the corporate group.
Once certified by the PDPC, BCRs may serve as a recognized safeguard for intra-group cross-border transfers of personal data, including transfers to jurisdictions that have not been designated as providing adequate protection under Thai law.
Key Features of the New Regulation:
The regulation establishes a formal process through which multinational corporate groups may apply for PDPC certification of their BCRs.
The framework contemplates separate certification mechanisms for:
- BCRs applicable to data controllers; and
- BCRs applicable to data processors.
Applicants must demonstrate that their BCRs contain adequate protections for personal data and create binding obligations that are enforceable throughout the corporate group.
The PDPC is authorized to review submitted documentation, request additional information, conduct assessments, and determine whether certification should be granted.
Certification is not merely a documentary exercise. Organizations will need to demonstrate that their privacy governance framework is operational, effective, and capable of ensuring compliance across all participating entities.
Why This Matters for Multinational Businesses:
The new framework is particularly relevant for organizations that centralize operations across multiple jurisdictions and routinely transfer personal data among affiliated entities.
Examples include:
- Regional shared-service centers managing human resources, finance, compliance, procurement, or customer support functions;
- Global cloud infrastructure and centralized IT operations;
- Technology companies operating multinational development and support teams;
- Organizations using centralized customer relationship management systems;
- Financial institutions operating regional processing hubs; and
- Businesses conducting cross-border analytics and artificial intelligence development activities.
For these organizations, maintaining individual contractual safeguards between every transferring and receiving entity can be administratively burdensome and difficult to scale.
A certified BCR framework may provide a more efficient and sustainable governance model by establishing a single set of group-wide privacy standards applicable across multiple jurisdictions and business functions.
Preparing for BCR Certification:
Organizations considering BCR certification should evaluate whether their existing privacy compliance framework is sufficiently mature to satisfy regulatory scrutiny.
Key areas likely to require attention include:
Governance Structure
Organizations should establish clear privacy governance arrangements, including defined responsibilities, reporting lines, and oversight mechanisms across the corporate group.
Data Subject Rights Management
Procedures should be implemented to ensure that individuals can effectively exercise their rights under the PDPA, regardless of which group entity is processing their personal data.
Cross-Border Transfer Controls
Companies should maintain accurate records of international data flows and implement controls governing transfers among participating entities.
Security and Incident Response
Appropriate technical and organizational security measures should be documented and consistently applied throughout the corporate group.
Monitoring and Auditing
Organizations should implement mechanisms to monitor compliance, conduct internal audits, and address identified deficiencies.
Training and Awareness
Regular employee training programs should be established to ensure that personnel understand and comply with the requirements of the BCR framework.
Alignment with Global Compliance Programs:
Many multinational organizations have already adopted BCRs or similar governance frameworks to comply with privacy laws in other jurisdictions.
For these organizations, the new regulation may provide an opportunity to leverage existing privacy governance structures while extending their applicability to Thailand-related data transfers.
However, organizations should not assume that existing frameworks will automatically satisfy the PDPC’s certification requirements. A careful review of the regulation and supporting documentation will be necessary to identify any jurisdiction-specific requirements.
Looking Ahead:
The introduction of the BCR certification regime demonstrates the continued development of Thailand’s data protection framework and reflects the increasing importance of international data flows in modern business operations.
As organizations continue to centralize functions, deploy cloud-based technologies, and expand artificial intelligence initiatives, the ability to move personal data across borders in a compliant and efficient manner will become increasingly important.
The availability of certified BCRs provides multinational groups with an additional tool for managing these transfers while maintaining consistent privacy standards across their global operations.
Key Takeaways:
- The PDPC’s Regulation on the Examination and Certification of Binding Corporate Rules became effective on 17 February 2026.
- The framework introduces a formal mechanism for certifying BCRs as a safeguard for intra-group cross-border transfers of personal data.
- Certified BCRs may provide multinational corporate groups with a more scalable alternative to maintaining multiple contractual transfer arrangements.
- The regime is particularly relevant for regional shared-service centers, cloud operations, multinational technology companies, and organizations conducting AI development activities.
- Businesses considering certification should assess whether their privacy governance, security, accountability, and compliance frameworks are sufficiently mature to meet the PDPC’s requirements.
Author: Panisa Suwanmatajarn, Managing Partner.
Other Articles
- PDPC Opens New Path for Intra-Group Cross-Border Data Transfers
- National Semiconductor Policy Committee Signals New Opportunities and Legal Considerations for High-Tech Investment
- Consumer Protection: Proposed Lemon Law Strengthens Remedies for Defective Goods
- Department of Intellectual Property Moves Toward AI-Enabled Examination and OECD-Aligned Governance Standards
- Consumer and Platform Accountability: Increasing Scrutiny of Digital Intermediaries in Scam-Related Advertising
- Thai Customs Department to Launch Reformed Tariff e-Service Platform to Enhance Transparency and Reduce Corruption Risks