DBD Opens Consultation on Exempting Five Business Categories from Foreign Business Licensing

Introduction

The Department of Business Development (the “DBD”) has published an announcement inviting public comments on the principles of a draft Ministerial Regulation Prescribing Businesses Not Requiring a License for the Operation of Business by Foreigners, B.E. …. (the Draft Regulation”).

The Draft Regulation would allow foreign nationals to operate five categories of business without obtaining a license under the Foreign Business Act B.E. 2542 (1999) (the “FBA”). All five categories are already supervised by a sector regulator under specific legislation, reflecting the removal of duplicate licensing rather than the liberalization of previously unregulated activity.

Background

Section 9 of the FBA requires the Foreign Business Committee (the “Committee”) to review the restricted business categories under the lists annexed to the FBA at least once a year. Following its reviews for 2024 (B.E. 2567) and 2025 (B.E. 2568), the Committee resolved to propose removing five business activities from the restricted categories. The Committee reasoned that the businesses concerned are already supervised by specific agencies under specific laws, so removing them would reduce duplication in state oversight. It also considered that the exemptions are consistent with economic development and with the readiness of Thai operators to compete; further, because certain of the activities are provided only to affiliated companies, exempting them would reduce costs and facilitate business operations without exposing Thai operators to new competition.

Consultation

The consultation itself reflects a recent procedural change. Section 5 of the Act on Legislative Drafting and Evaluation of Law B.E. 2562 (2019) requires state agencies to conduct consultation and impact analysis before enacting any law, to disclose the results, and to take them into account at every stage of the process; this requirement applies to ministerial regulations by analogy.

On 10 March 2026 (B.E. 2569), the Cabinet approved recommendations of the Law Development Commission extending the minimum consultation period from not less than 15 days to not less than 30 days, and requiring agencies to consult on the principles of a law before it is drafted, in addition to consulting on the drafted text.

The present exercise is therefore a first-stage consultation on principles. The text of the Draft Regulation has not yet been produced, and a further consultation on the drafted provisions is expected to follow.

The consultation period runs from 10 August 2026 to 30 September 2026 (B.E. 2569). Comments may be submitted through the Central Legal System website and the DBD website.

The Five Proposed Categories

1. Businesses related to, supporting, or necessary for securities or derivatives business

A foreign national conducting any of these activities must already be licensed by the Office of the Securities and Exchange Commission (the “SEC Office”) to operate a securities business under the securities and exchange law, or a derivatives business under the derivatives law, and must obtain the SEC Office’s approval before commencing the additional activity.

2. Aircraft maintenance services

This covers the maintenance of aircraft, aircraft major components, appliances, and aircraft parts under the air navigation law. The Air Navigation Act B.E. 2497 (1954) (the “ANA”) requires a repair station certificate, issued in three types corresponding respectively to aircraft, aircraft major components, and appliances and parts. The ANA prohibits operating a repair station without such a certificate and requires applicants to meet prescribed qualifications. The certificate is issued by the Director of the Civil Aviation Authority of Thailand (“CAAT”), which would become the single licensing authority for the activity.

3. Procuring customers to offer financial products of companies within a financial business group

Please see details of explanation in Item 4.

4. Debt collection services provided to companies within a financial business group

For categories 3 and 4, the foreign operator must itself be a company within a financial business group and may provide the relevant services only to other companies within that group. The term “financial business group” follows the Bank of Thailand (“BOT”) notification, which covers a commercial bank together with its parent company, subsidiaries at every tier, and joint ventures, whether domestic or foreign. Both activities constitute a supporting business, and where the group company is itself a commercial bank, they fall within the “other services” framework.

One qualification applies to debt collection: where collection is made from a debtor who is a natural person, the activity constitutes a debt collection business under the Debt Collection Act B.E. 2558 (2015) and must be registered in accordance with the criteria, methods, and conditions prescribed under that Act and its associated Ministerial Regulation.

5. Service business where a state enterprise is the counterparty

This category differs in nature from the others: it is not a new exemption but a correction to an existing one.

The business already appears in the Ministerial Regulation Prescribing Service Businesses Not Requiring a License for Foreigners (No. 3), B.E. 2560 (2017), which was issued when the applicable budget legislation was the Budget Procedure Act B.E. 2502 (1959) (the “2502 BPA”). The Budget Procedure Act B.E. 2561 (2018) (the “2561 BPA”) subsequently narrowed the definition of “state enterprise” by excluding limited companies and public limited companies in which state enterprises hold more than 50 percent of the capital. The transitional provision of the 2561 BPA, however, provides that references to “state enterprise” in pre-existing legislation continue to carry the meaning under the 2502 BPA.

As a result, the term used in the 2017 Ministerial Regulation still bears the older, wider meaning, which is inconsistent with the definition now in force. The DBD proposes to align the reference with the 2561 BPA, together with a transitional provision preserving the rights of foreign nationals already providing services to state enterprises under the former definition before the Draft Regulation takes effect.

Legal Significance

The exemption removes the requirement to obtain the FBL. However, a foreign national or entity relying on it must still obtain the licenses and approvals from the other agencies regulating such activities as follows:

  • SEC Office licensing and approval for the securities-related activities;
  • A CAAT repair station certificate for aircraft maintenance;
  • The BOT financial business group framework for the two financial support services; and
  • Registration under the Debt Collection Act where collection is made from natural persons.

The scope conditions are also narrow and should be read closely. Categories 3 and 4 are available only to a company within a financial business group serving other companies within the same group — a limitation expressly intended to confine the commercial reach of the exemption so that Thai operators are not affected. Category 1 is confined to management, marketing, human resources, and information technology services, and to a defined class of recipients.

For category 5, the practical question runs the other way. Because the definition of “state enterprise” has narrowed, some foreign operators currently serving state-enterprise subsidiaries may fall outside the exemption once the reference is updated. The proposed transitional provision is intended to address this, and its drafting will matter to those affected.

Key Takeaways

  • The DBD is consulting on the principles of a Draft Regulation that would exempt five business categories from FBA licensing. The proposal remains subject to the legislative process and does not yet have legal effect.
  • The proposal aims to reduce regulatory duplication in areas where specific sectoral laws and regulators already apply.
  • Comments are open until 30 September 2026. This is a principles-stage consultation, and a second consultation on the drafted text is expected before the Draft Regulation is finalized.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPA: Cross-Border Data Transfer Compliance for Bank Z Under Thailand’s Data Protection Law – Key Takeaways

Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) regulates the transfer of personal data abroad, imposing conditions to ensure adequate protection under Section 28. The Ad Hoc Subcommittee under the Personal Data Protection Committee has addressed Bank Z’s obligations when submitting directors’ personal data to comply with the Accounting and Corporate Regulatory Authority (ACRA) of Singapore and other foreign regulations. This analysis details the facts, the subcommittee’s rulings, and the resulting compliance framework.

Factual Background:

Bank Z must transmit directors’ personal data to meet ACRA requirements in Singapore and potentially other foreign laws. Under PDPA Section 28, cross-border data transfers require the recipient country or international organization to have adequate data protection standards, as determined by the Personal Data Protection Committee per Section 16(5), unless an exception applies. Bank Z faces uncertainty about whether “compliance with the law” under Section 28(1) includes foreign laws and, if not, how to proceed absent adequacy decisions for destination countries.

Subcommittee Decisions:

The subcommittee clarified Bank Z’s PDPA obligations as follows:

  1. Scope of “Compliance with the Law” Under Section 28(1)
    • Cross-border data transfers are permissible only if the destination has adequate protection standards, per Section 28 and criteria set under Section 16(5). Exceptions under Section 28(1)–(6) or Section 29 may apply. For Section 28(1)—compliance with the law—the law must be Thai and legally binding on the data controller. Foreign laws, such as ACRA regulations, do not qualify as a basis under this provision. Thus, Bank Z cannot rely on Section 28(1) to justify transfers based on Singaporean or other foreign legal obligations.
  2. Absence of Adequacy Decisions and Next Steps
    • No adequacy decisions exist under Section 16(5) and Section 28, as the committee has not yet designated any country or organization (e.g., Singapore) as having sufficient data protection standards. Without such designation, Bank Z must assess exceptions under Section 28(1)–(6). For instance, transferring directors’ data could fall under Section 28(3)—necessary to perform a contract where the director (data subject) is a party, such as employment or governance agreements—or pre-contractual steps requested by the director. If no exception applies (e.g., Sections 28(1), (3)–(6)), Bank Z must obtain explicit consent from directors per Section 28(2), informing them of the potentially inadequate protection standards in the destination country (e.g., Singapore) beforehand.

Implications for Compliance:

The subcommittee’s rulings restrict “compliance with the law” to Thai jurisdiction, excluding foreign mandates like ACRA’s as a direct basis. Absent adequacy decisions, Bank Z must either find a contractual or similar exception or secure directors’ informed consent, highlighting risks in destination countries. This dual approach balances legal obligations with data subject rights, pending future committee guidance on adequacy.

Key Takeaways:

  • Section 28(1) Is Thai-Law Specific: “Compliance with the law” applies only to Thai statutes, not foreign regulations like ACRA’s.
  • No Adequacy, No Free Pass: Without designated adequate destinations, transfers hinge on exceptions (e.g., Section 28(3)) or consent under Section 28(2).
  • Consent Requires Transparency: If consent is the basis, directors must be notified of inadequate protections in recipient jurisdictions.
  • Contractual Basis Offers Flexibility: Section 28(3) may cover director data transfers tied to governance duties, bypassing consent if applicable.

Bank Z’s scenario underscores PDPA’s stringent cross-border framework, prioritizing Thai legal authority and data subject awareness until adequacy standards are clarified. Compliance demands the strategic use of exceptions or proactive consent processes to align with international obligations.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPA: Does Removing a Name Make Data Anonymous?

Organizations increasingly remove names and other obvious identifiers from datasets before using the data for analytics, research, artificial intelligence development, or sharing it with third parties. A common assumption is that once names and identification numbers have been removed, the information is no longer personal data and therefore falls outside the Personal Data Protection Act B.E. 2562 (2019) (PDPA).

That assumption can be dangerous. Recent guidance from the Personal Data Protection Committee (PDPC) provides an important reminder: removing a person’s name does not, by itself, make data anonymous.

When does data become anonymous?

The key question is not simply whether direct identifiers have been deleted, but whether an individual can still be identified from the remaining information.

The PDPC’s approach indicates that data may be treated as anonymized where the data subject cannot be identified without additional information and appropriate technical and organizational measures have been implemented to ensure that identification is not reasonably possible in practice.

This distinction is particularly important where a dataset contains multiple indirect identifiers. Removing a person’s name while retaining information such as age, date of birth, location, gender, occupation, accident location, medical information, or other characteristics may still allow that person to be identified when those data points are considered together or combined with information from other sources.

Accordingly, de-identification is a question of substance, not merely the removal of specified fields.

Pseudonymization is not anonymization:

Organizations should also distinguish anonymization from pseudonymization.

If a person’s name is replaced with a code but the organization retains a separate table linking that code to the individual’s identity, the information remains capable of being attributed to that person. The dataset is therefore pseudonymized rather than truly anonymized.

Pseudonymization can be an important security and privacy measure, but it does not automatically take the data outside the PDPA. By contrast, properly anonymized information that can no longer reasonably be linked to an identifiable individual is no longer personal data for PDPA purposes.

This distinction has significant practical consequences. An organization cannot simply label a dataset “anonymous” or remove names and assume that the PDPA no longer applies.

Research provides a useful illustration:

The issue arose in the context of research into the causes of motorcycle accidents. Such research may involve ordinary personal data as well as sensitive personal data, particularly health information concerning injured persons.

The PDPA expressly recognizes research and statistical purposes as circumstances in which personal data may be processed without relying exclusively on consent. Section 24(1) provides a basis relating to research or statistical purposes, subject to appropriate safeguards protecting the rights and freedoms of data subjects. For sensitive personal data, Section 26(5)(d) similarly permits processing where necessary for scientific, historical or statistical research, or other public-interest purposes, subject to necessity and appropriate safeguards.

The PDPC has also prescribed specific safeguards for processing personal data for research and statistical purposes.

The practical significance is that organizations should not assume that anonymization is the only way to conduct research lawfully. Personal data may remain subject to the PDPA and nevertheless be processed for legitimate research purposes where the applicable statutory requirements and safeguards are satisfied.

What should organizations do in practice?

For organizations seeking to take datasets outside the scope of the PDPA, anonymization should be treated as a risk-based technical and governance process, rather than a simple data-cleaning exercise.

Direct identifiers should be removed, but organizations should also assess combinations of indirect identifiers and consider whether information could be matched against other reasonably available datasets. Where coded identifiers have been used, organizations should consider whether any linkage mechanism remains available. If a mapping table between codes and identities continues to exist, the resulting dataset is likely to remain pseudonymized rather than anonymous.

Depending on the nature of the dataset, additional techniques may be necessary, including aggregation, generalization, suppression, masking, reducing geographic or temporal precision, and other techniques designed to reduce re-identification risk.

Organizations should also document the anonymization process, the methodology used, the potential sources of re-identification, and the conclusion reached regarding residual risk. Technical measures should be accompanied by organizational controls restricting access and preventing attempts to re-identify individuals.

Why this matters for AI, analytics and data sharing:

The distinction has implications well beyond academic research.

Businesses increasingly want to use existing customer, employee, patient, transaction, location, behavioral, and operational datasets for AI development and training, statistical analysis, product improvement, or collaboration with external service providers and research institutions.

Where the information remains identifiable, the organization must continue to consider the PDPA requirements applicable to its collection, use, disclosure, retention, security, and other processing activities.

Where information has been effectively and irreversibly anonymized so that individuals are no longer reasonably identifiable in practice, however, the resulting dataset may fall outside the scope of the PDPA.

This makes anonymization potentially valuable for data-driven businesses, but it also means that organizations should be cautious about treating anonymization as a shortcut around data protection obligations. A dataset that can realistically be reconstructed, linked, or matched back to individuals remains exposed to PDPA risk regardless of what the organization calls it.

Key Takeaways:

  • Deleting names does not automatically anonymize personal data.
  • Organizations must consider whether individuals remain identifiable from other information or combinations of information in the dataset.
  • Pseudonymized data remains personal data where a person can be re-identified using additional information.
  • Proper anonymization requires technical and organizational measures designed to make re-identification impracticable.
  • Research and statistical processing may have specific legal bases under Sections 24(1) and 26(5)(d), subject to appropriate safeguards.
  • Organizations using data for AI, analytics, research or external data sharing should conduct and document a re-identification risk assessment before treating a dataset as outside the PDPA.
  • Anonymization should be viewed as an ongoing risk-management and governance exercise, not simply the deletion of names or identification numbers.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPA: Disclosure of Personal Data to Third Parties for Legal Proceedings

A recurring practical question under the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) is whether an organization may disclose personal data to a third party who needs the information to pursue a legal claim. Organizations often take a conservative position that personal data cannot be disclosed without the data subject’s consent. However, consent is only one of the legal bases under the PDPA, and the fact that information constitutes personal data does not, by itself, prohibit its disclosure. A recent opinion issued in response to a consultation by the Department of Land Transport (“DLT Opinion”) provides useful guidance on this issue and is particularly relevant to requests for personal data made for the purpose of exercising legal rights or pursuing legal proceedings.

Disclosure Does Not Necessarily Require Consent:

The DLT Opinion illustrates an important distinction between two questions: whether the information constitutes personal data and, if so, whether there is a lawful basis for its disclosure. Once information falls within the definition of personal data, its collection, use, or disclosure must comply with the PDPA, but this does not mean that disclosure is prohibited unless the data subject has given consent. Section 24 recognizes several legal bases for processing personal data without consent. Depending on the circumstances, disclosure to a third party may therefore be permissible where an appropriate legal basis exists. This is particularly important where the requesting party requires information to establish or exercise a legal right, claim damages, identify a responsible party, or commence legal proceedings. For example, a person who suffers damage involving a vehicle may know the vehicle registration number but may not know the identity of the person against whom a claim should be made. Similarly, a person injured in an incident recorded by CCTV may need the footage to establish the circumstances of the incident and pursue a claim. Treating the PDPA as an absolute prohibition against disclosure in such circumstances could prevent a person from effectively exercising legitimate legal rights.

Legitimate Interests and Legal Claims:

One potentially relevant legal basis is legitimate interests under Section 24(5) of the PDPA. This provision permits processing where it is necessary for the legitimate interests of the controller or another person, except where those interests are overridden by the fundamental rights of the data subject. A genuine need to obtain information for the establishment, exercise, or defense of a legal claim may constitute a significant legitimate interest. However, merely stating that information will be used in litigation should not automatically entitle a requester to obtain another person’s personal data. The controller should consider whether the claimed legal interest is genuine, whether disclosure of the requested information is necessary to pursue that interest, and whether the interests of the requester outweigh the privacy interests and fundamental rights of the data subject. In practical terms, this can be approached through a purpose–necessity–balancing analysis. The controller should first identify the legal purpose for which the information is requested; determine whether disclosure is reasonably necessary to achieve that purpose; and then balance that interest against the potential impact on the data subject. Supporting documents, such as a police report, evidence of damage, a demand letter, court documents, or other evidence demonstrating an actual or reasonably contemplated legal claim, may assist the controller in making and documenting this assessment.

The same reasoning has broader significance beyond vehicle-registration information. Government guidance discussing requests for CCTV footage has referred to the DLT Opinion by analogy when considering whether personal data may be disclosed to enable an injured person to exercise legal rights. This suggests that the Opinion may become an important reference point for third-party disclosure requests generally. Comparable issues arise frequently in the private sector: condominium juristic persons receive requests for CCTV footage following accidents or disputes; employers receive requests concerning former employees; insurers may hold information concerning parties to an accident; property owners may receive requests concerning tenants; and online service providers may receive requests for information identifying persons alleged to have committed a civil wrong. In each case, the correct question should not simply be whether the requested information is personal data, but whether the proposed disclosure has an appropriate legal basis and satisfies the requirements of necessity and proportionality.

Disclosure Should Be Limited to What Is Necessary:

Even where a lawful basis exists, the controller should not assume that all information in its possession may be disclosed. The scope of disclosure should be limited to information reasonably necessary for the stated legal purpose. If a requester needs information to identify a person against whom proceedings may be commenced, disclosure of the person’s name and information necessary for the relevant legal process may potentially be justified, while disclosure of unrelated information—such as identification numbers, telephone numbers, dates of birth, historical records, or other data not required for the claim—may not be. Redaction, partial disclosure, controlled access, or other safeguards should therefore be considered where appropriate. This distinction can be expressed simply as two separate questions: “Can the information lawfully be disclosed?” and “How much information is necessary to disclose?” Establishing a legal basis answers only the first question; the principles of necessity, proportionality, purpose limitation, and data minimization remain relevant to the second.

Organizations should also distinguish ordinary personal data under Section 24 from sensitive personal data under Section 26. Section 26 contains specific exceptions relating to processing necessary for the establishment, compliance, exercise, or defense of legal claims. Where sensitive personal data is involved, the requirements of Section 26 should therefore be considered separately rather than assuming that the legal basis applicable to ordinary personal data automatically applies. In all cases, organizations should consider implementing a documented Third-Party Personal Data Disclosure Request Procedure requiring verification of the requester’s identity, the purpose of the request, evidence supporting the claimed legal interest, the categories of information genuinely required, possible effects on the data subject, appropriate redaction or other safeguards, and a record of the reasons for approving or rejecting the request. Such documentation can be particularly important where the controller relies on legitimate interests and must subsequently demonstrate how the competing interests were assessed.

Key Takeaways:

The DLT Opinion is significant because it reinforces that the PDPA should not be treated as an automatic barrier to disclosure whenever personal data is involved. Consent is not the only legal basis for disclosure, and a genuine need to obtain information for the establishment, exercise, or defense of legal rights may support disclosure where the applicable requirements of the PDPA are satisfied. At the same time, an assertion that information is required for litigation does not create an unrestricted right of access to another person’s personal data. Controllers should assess the purpose, necessity, and balancing of interests, require appropriate evidence where necessary, limit disclosure to the minimum information reasonably required, and document the decision-making process. The broader lesson is that the PDPA is not intended to make personal data permanently inaccessible; rather, it establishes a framework for determining when disclosure is lawful, why it is necessary, and how much information may appropriately be disclosed.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPA: Applicability to a Facebook User’s Posting of Personal Data – Key Takeaways

Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) regulates systematic personal data handling, with exemptions for personal or familial use. The Ad Hoc Subcommittee under the Personal Data Protection Committee has evaluated whether a Facebook user’s posting of an allegedly defamatory image and text qualifies them as a data controller under PDPA, as raised by Police Station F in a criminal investigation. This analysis outlines the facts, the subcommittee’s rulings, and the compliance implications.

Factual Background:

Police Station F received a complaint alleging that a Facebook user posted an image of the complainant with text causing insult or hatred, prompting a criminal case. The prosecutor’s office (C) requested the station to investigate: (1) whether the post’s visibility settings (public symbols like a globe or people) made it accessible to the general public or a specific group, and (2) whether the suspect qualifies as a data controller under PDPA Section 6 for posting the complainant’s image and text.

Subcommittee Decisions:

The subcommittee addressed the issues as follows:

  1. Post Visibility (Issue 1)
    • The question of whether the suspect’s Facebook post—with a globe or people symbol—was visible to the public or a limited group falls outside PDPA’s direct scope. PDPA defines “personal data” under Section 6 as information identifying a living individual, directly or indirectly (e.g., the complainant’s image). However, visibility settings pertain to evidence in a criminal investigation, not PDPA enforcement. The subcommittee deemed this a factual matter for the police to assess independently, unrelated to PDPA compliance.
  2. Data Controller Status (Issue 2)
    • Under PDPA Section 6, a “data controller” is a person or entity with authority to decide on the collection, use, or disclosure of personal data, subject to duties like lawful bases (Sections 24, 26), notification (Section 23), security (Section 37), and rights responses (Sections 30–36). The law targets systematic or regular data processing, not isolated acts, per its intent and Section 4(1) exemption for personal or family use. The suspect, a natural person posting on Facebook, isn’t a data controller if the act was for personal purposes (e.g., expression) without systematic intent. Absent evidence of regular, organized data handling, PDPA doesn’t apply, per Section 4(1). However, the act may violate other laws (e.g., Computer Crime Act B.E. 2550, Penal Code defamation, or Civil Code torts under Section 420), which the police should pursue separately.

Implications for Compliance:

The suspect’s posting likely falls outside PDPA’s ambit as a one-off personal act, not subjecting them to data controller obligations (e.g., consent, security measures). Police Station F must focus on criminal or tort laws for liability, using post visibility as evidence, not a PDPA issue. PDPA applies to entities with structured data practices, not casual social media use.

Key Takeaways:

  • PDPA Targets Systematic Use: The suspect isn’t a data controller under Section 6 unless their posting reflects regular, purposeful data management, per Section 4(1) exemption.
  • Personal Acts Are Exempt: One-time social media posts for personal ends fall outside PDPA, per Section 4(1), unlike organizational data handling.
  • Other Laws Apply: Privacy breaches or defamation may trigger liability under the Computer Crime Act, Penal Code, or Civil Code, not PDPA.
  • Visibility Is Investigative: Post accessibility (public vs. private) is a factual issue for criminal evidence, not a PDPA concern.

This ruling clarifies PDPA’s scope, excluding personal social media acts from its framework, directing Police Station F to pursue alternative legal avenues for the complainant’s grievance.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Telemedicine Practices and Data Protection Compliance in Thailand: Legal Brief

I. Introduction to Telemedicine in Thailand:

Telemedicine has emerged as one of the most transformative innovations in healthcare. By leveraging modern communication technologies, telemedicine enables the delivery of medical services regardless of geographic barriers. As the global demand for accessible, efficient, and cost-effective healthcare increases, many countries have embraced telemedicine to overcome traditional challenges such as distance, cost, and limited access to medical expertise.

Thailand, with its rapidly developing digital infrastructure and progressive approach to healthcare, is becoming a prominent destination for telemedicine providers. However, alongside its tremendous growth potential, Thailand presents unique challenges, particularly in the realm of data protection and privacy. For both local and international telemedicine platforms, understanding and complying with the local legal environment is critical. The country’s evolving legal landscape, especially concerning data protection, patient privacy, and healthcare standards, requires providers to implement robust compliance measures. Doing so not only safeguards sensitive patient information but also builds trust with users, ensuring sustainable business growth in a competitive market.

In this guide, we delve into the key considerations for data compliance, discuss the relevant regulatory frameworks under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), and outline practical steps for telemedicine platforms to navigate these regulations. By doing so, telemedicine providers can effectively mitigate risks, secure patient data, and maintain a competitive edge in the Thai market.


II. Health Information Protection Before the Enforcement of the Personal Data Protection Law:

  1. The National Health Act and Ministerial Regulation:

Thailand’s regulatory framework for data protection has undergone significant evolution over recent years. Prior to the enactment of the PDPA in 2019, Thailand relied on a combination of the Thai Constitution, the Thai Civil and Commercial Code, and sector-specific regulations like the National Health Act B.E. 2550 (2007) (“National Health Act”). The National Health Act mandated that personal health information be kept confidential. Specifically, Section 7 of the National Health Act required that such information not be disclosed in a manner that could harm the data subject, except when authorized by the individual or required by law.

The Ministerial Regulation on the Protection and Management of Personal Health Information B.E. 2561 (2018) (“MR”) provided further details on the scope and nature of personal health information. Clause 4 of the MR defined personal health information as encompassing a variety of documents, case files, reports, and other materials capable of identifying an individual’s health status. Clause 11 offered an exhaustive list of items considered personal health information, such as:

  1. Health History: Such as height, weight, blood type, and body shape.
    1. Medical Records: Such as nursing records, laboratory examinations, and x-ray films.
    1. Related Documents: Any documents or objects that relate to the above data.
    1. Photographic Evidence: Images of medical personnel or actions during treatment.
    1. Additional Information: Any further information as specified by the Personal Health Data Protection and Management Committee.
  2. Penalties for Non-Compliance:

Before the PDPA’s enactment, violations regarding the unlawful or unauthorized disclosure of personal health information were met with penalties prescribed under the NHA. Under Section 49 of the National Health Act, such violations could result in imprisonment of up to six months, fines of up to 10,000 THB, or both. Moreover, wrongful use of personal data was addressed under Section 420 of the Civil and Commercial Code, which provided for civil liability in cases where data misuse resulted in harm to the data subject.

  • Transition to the PDPA:

In 2019, the PDPA was published in the Royal Gazette, marking a significant shift in Thailand’s data protection landscape. With its comprehensive framework, the PDPA rendered the earlier MR obsolete. The Medical Council of Thailand subsequently issued a new Ministerial Regulation on the Revocation of the MR B.E. 2565 (2022). This evolution represents Thailand’s commitment to aligning its data protection standards with international best practices.


III. What Is Health Information?

As a result of the MR revocation, Thailand no longer has a statutory definition of health information, which is crucial in terms of personal data protection and compliance with obligations under the PDPA. Telemedicine platforms need to understand the personal data in their possession and handle such data according to the PDPA.

In the absence of subordinate regulations, directives, or guidelines to clarify the extent and scope of health information under the PDPA, it is worth exploring the definition given under the European Union General Data Protection Regulations (2016/679) (“EU GDPR”), which was a core foundation of the Thai PDPA, containing many similar provisions tailored to Thailand’s contexts.

Article 4 (15) of the EU GDPR defines ‘data concerning health’ as personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status. Additionally, the European Parliament and the Council of the European Union opined that ‘personal data concerning health’ should include all data pertaining to the health status of a data subject, including information collected during registration or provision of health care services, testing results, disease history, clinical treatments, or physiological states.

By this principle, personal data that may not obviously qualify as health information could still be considered health information depending on the context of personal data processing activities.


IV. Overview of PDPA Compliance for Telemedicine Platforms:

The PDPA extends its reach not only to local businesses but also to international data controllers who process the personal data of Thai residents. This extraterritorial effect means that even telemedicine platforms headquartered outside Thailand must comply with the PDPA if they process the personal data of individuals located in the country.

  1. Extraterritorial Applicability:

According to Section 5, Paragraph 2 of the PDPA, foreign data controllers are subject to the PDPA if any of the following criteria are met:

  1. The offering of goods or services to the data subjects who are in the Kingdom of Thailand, irrespective of whether the payment is made by the data subject, or
    1. The monitoring of the data subject’s behavior, where the behavior takes place in the Kingdom of Thailand.
  • Obligations for Telemedicine Providers:

Once the PDPA applies, telemedicine providers (whether local or international) must adhere to various obligations under the PDPA, some of which include:

  1. Data Collection and Processing: Ensure that personal data is collected, used, and disclosed with legal bases supporting each processing activity.
    1. Privacy Notices: Clearly communicate to data subjects how their personal data will be used.
    1. Security Measures: Implement appropriate technical and organizational measures to safeguard personal data.
    1. Data Subject Rights: Provide mechanisms for data subjects to exercise their rights (e.g., access, correction, deletion).
    1. Breach Notification: Establish procedures to notify both the regulatory authority and affected data subjects in the event of a data breach.
    1. Record-Keeping: Maintain a Record of Processing Activities (ROPA) to document data processing practices.

V. Privacy Notice / Privacy Policy Under the PDPA:

One of the foundational requirements under the PDPA is the preparation and dissemination of a comprehensive privacy notice or privacy policy. This document serves to inform data subjects about how their personal data is collected, processed, stored, and shared.

  1. Content of Privacy Policy:

Under Section 23 of the PDPA, data controllers must notify data subjects of the purposes of data collection prior to or at the time of collection. Common practices include written notices, electronic pop-ups on websites or applications, or verbal communications as applicable.

  • Best Practices for Drafting a Privacy Policy:

For telemedicine platforms, drafting a privacy policy involves a deep understanding of the personal data flows within the organization. Understanding the customer journey is vital for telemedicine platforms in preparing the privacy policy, as each touchpoint involves the collection and processing of personal data.

  1. Sign-Up / Registration:

During the initial sign-up process, users are generally required to provide basic personal data such as their name, age, contact details, and, in some cases, initial health information, such as their height, weight, medical history, passport or national identification card, contact information, and information relating to personal allergies. This stage sets the foundation for subsequent interactions and must be handled with the highest level of security and clarity regarding data usage.

  • Know Your Customer (KYC) and Confirming the Identity of the Data Subject: To ensure compliance with Thailand’s PDPA and safeguard sensitive personal data, telemedicine platforms must implement robust KYC procedures during the sign-up phase. These procedures are designed to verify the identity of the data subject and establish trust between the platform and its users.
  • Verification of Identity: Platforms should require users to provide a valid
    • identification documents, such as a national ID card, passport, or other government-issued IDs, to confirm their identity.
    • The verification process may involve uploading scanned copies of these documents or using digital identity verification tools that comply with Thai legal standards.
  • Biometric Verification (Optional):

For enhanced security, telemedicine platforms may opt to incorporate biometric verification methods, such as facial recognition or fingerprint scanning, where applicable and permitted by law.

  • Data Matching:

Once the user submits their identification details, the platform should cross-check this information against official databases (e.g., government records) to ensure accuracy and prevent fraud.

  • Explicit Consent:

During the registration process, explicit consent must be obtained from the user for the collection, use, and disclosure of both general personal data and sensitive personal data. This includes clear explanations of how their data will be processed, stored, and shared.

If the user is under 20 years of age, additional consent from their legal representative, guardian, or curator may be required under Section 20 of the PDPA.

  • Booking / Appointment Scheduling:

Once registered, users schedule appointments with healthcare providers. The booking process may involve selecting a healthcare professional based on specialty, availability, or patient reviews. Additional forms might be used to capture medical history or current health conditions.

  • Consultation:

Consultations are the core of telemedicine services. Whether conducted via video calls, chat sessions, or telephone, these interactions involve real-time exchange of sensitive health information. Data from these sessions may include verbal communications, visual data, and records of diagnosis and treatment.

  1. Post-Consultation Services:

After the consultation, several processes may occur:

  • Payments: Patients make payments through integrated or third-party payment gateways. This process generally involves third-party service providers.
  • Insurance Claims: In some cases, patients may file insurance claims. Telemedicine platforms might assist in this process by forwarding relevant health information to insurers.
  • Medicine Delivery: If medication is prescribed, delivery logistics come into play. This may involve sharing personal data (such as address and contact information) with third-party courier services.
  • Follow-up Appointments: Follow-up consultations or treatment plans may be scheduled, requiring further data collection.
  • Feedback and Reviews: Post-consultation feedback is often solicited to improve service quality. While this may involve general data, any health-related feedback is treated with heightened sensitivity

n)


VI. Legal Bases for Each Activity:

Different stages of the customer journey require distinct legal bases under the PDPA. For example:

ActivityGeneral Personal DataSensitive Personal Data
Sign-up / RegistrationNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Booking / AppointmentNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
ConsultationNecessary to enter into / Performance of a contract
(Section 24 (3))
Necessary for compliance with a law with respect to the provision of health or social care / Explicit Consent (Section 26 (5)(a) / Section 26)
Payment and BillingNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Insurance ClaimsLegitimate interest
(Section 24 (5))
Explicit Consent
(Section 26)
Medicine DeliveryNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Feedback / ReviewsLegitimate interest
(Section 24 (5))
Explicit Consent
(Section 26)

Important Remark: Please note that the table above shall only be used as a reference. The actual legal basis for each activity may differ based on the specific facts and circumstances.


VII. Processing Personal Data of Minors, Quasi-Incompetent Persons, or Incompetent Persons:

Where a patient is under 20 years of age or is a quasi-incompetent person or incompetent person, Section 20 of the PDPA requires their consent to be accompanied by consent from their respective legal representatives, guardians, or curators. However, if the patient is under 10 years of age, sole consent from the legal representative is sufficient.

Section 24 of the Thai Civil and Commercial Code provides an exemption for acts deemed suitable for a minor’s reasonable needs. Therefore, a minor (between 10 and 20 years of age) may give sole consent for telemedicine consultation purposes, as it deems suitable and actually required for their reasonable needs.


VIII. Data Subject Rights and Request Compliance Under the PDPA:

The PDPA enshrines several rights for data subjects. Telemedicine platforms must have robust processes to facilitate these rights.

A. Overview of Data Subject Rights:

The PDPA grants data subjects the following rights:

  1. Right to Access: Data subjects may request copies of their personal data.
  2. Right to Data Portability: Individuals can obtain their personal data in a structured, commonly used format.
  3. Right to Object: Data subjects may object to certain personal data processing activities.
  4. Right to Delete: Also known as the “right to be forgotten,” this allows data subjects to request deletion or anonymization of their personal data.
  5. Right to Restrict Processing: In certain circumstances, processing may be limited or suspended.
  6. Right to Rectification: Data subjects can have inaccurate or incomplete personal data corrected.
  7. Right to Lodge a Complaint: Data subjects can lodge complaints with regulatory authorities.
  8. Right to Withdraw Consent: Where processing is based on consent, data subjects may withdraw that consent at any time.

B. Procedures for Data Subject Rights Requests (DSRR):

Upon receiving a data subject request, telemedicine platforms should follow a set of protocols:

  1. Verification: Confirm the identity of the data subject or their representative.
  • Clarification: Request additional information if the request is ambiguous.
  • Documentation: Record all details of the request.
  • Data Retrieval: Locate and compile the relevant data.
  • Review for Exemptions: Determine if any exemptions apply.
  • Response: Communicate a clear response—either fulfilling the request, rejecting it, or outlining why an exception applies.
  • Record-Keeping: Maintain records of the requests and responses for regulatory audits.

IX. Record of Processing Activities (ROPA):

Maintaining a detailed ROPA is a regulatory requirement under Section 39 of the PDPA.

A comprehensive ROPA should include,

  1. the collected personal data;
    1. the purpose of the collection of personal data in each category;
    1. details of the data controller;
    1. the retention period of personal data;
    1. rights and methods for accessing personal data, including conditions for exercising these rights;
    1. the use or disclosure of personal data;
    1. rejection or objection to the data subject’s rights request; and
    1. explanation of the appropriate security measures.

However, SMEs may be exempt from maintaining a full ROPA if they employ fewer than 100 people and have an annual revenue of no more than 300,000,000 THB. Nevertheless, telemedicine platforms handling sensitive personal data must maintain a full ROPA due to the risks involved.


X. Appropriate Security Measures for Telemedicine Platforms:

Prescribed under Section 37 (1) of the PDPA, where a data controller is required to provide appropriate security measures to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data. In this regard, the appropriate security measures for the telemedicine platforms shall focus on the maintenance of personal data’s confidentiality, integrity, and availability.

According to the PDPC’s Announcement on Security Measures for Personal Data,  the security measures should contain at least the following mechanism: (1) access controls, allowing access to personal data only on a need-to-know basis provided that there shall also be an identity proofing, authentication, and authorization procedure; (2) user access management including registration and de-registration of access provision; (3) user responsibilities shall be prescribed; (4) implement an audit trail to enable the reviewing of access, change, alteration, or deletion of personal data.

The duty to implement appropriate security measures shall be extended to the imposition of obligations on the data processor of the telemedicine platforms (such as medicine delivery service providers), to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data.


XI. Personal Data Breach and Breach Notification Procedures:

Despite security measures, data breaches can occur. The PDPA requires prompt action in response to breaches.

A. Definition:

A personal data breach is defined as a breach of security measures resulting in the loss, access, use, alteration, modification, or disclosure of personal data without authorization or unlawfully.

B. Procedures:

Assess the reliability of the breach report and investigate the facts.

Notify the PDPC within 72 hours if the breach affects the rights and freedoms of data subjects.

Notify affected data subjects without delay if the breach poses a high risk.

Mitigate the situation and review security measures to prevent future breaches.


XII. Processing of Sensitive Personal Data by Data Processors:

Throughout the customer journey, a data processor may be involved in processes such as medicine delivery. A data controller must prepare a Data Processing Agreement (DPA) to control the activities of the data processor. Key provisions of a DPA include:

Restriction on use or disclosure of personal data.

Implementation of appropriate security measures.

Recording of personal data processing activities.

Notification of personal data breaches.


XIII. Designating a Representative and a Data Protection Officer (DPO) in Thailand:

A. Designating a Representative for Foreign Providers:

Foreign telemedicine providers offering services to Thai residents must designate a representative in Thailand under Section 5, Paragraph 2 of the PDPA.

B. Appointment of a Data Protection Officer (DPO):

Telemedicine platforms are obligated to designate a DPO if their core activities involve processing sensitive personal data. External or outsourced DPOs may be appointed for SMEs.


XIV. Use of Sensitive Personal Data (Health Information) for Telemarketing Purposes:

Sensitive personal data cannot be used for marketing purposes without explicit consent. Instead, telemedicine platforms may rely on general personal data (e.g., email addresses) for mass communications, provided an opt-out mechanism is available.


XV. Frequently Asked Questions (FAQs)

Q1: Does Weight and Height Qualify as Health Information?

Weight and height information may qualify as either general personal data or sensitive personal data, depending on the context. For example, in telemedicine services, weight and height may play a vital role in medical analysis and thus could be considered sensitive personal data.

Q2: Can a Patient Request Deletion of Their Health Information?

Patients have the right to request deletion of their personal data under certain conditions. However, telemedicine platforms are required to retain medical records for at least 5 years in accordance with the National Health Act.


XVI. Conclusion

As telemedicine continues to revolutionize the healthcare industry, ensuring robust compliance with data protection laws like the PDPA is critical. Health information, being sensitive personal data, demands the highest level of security and compliance to protect patient privacy and maintain trust in digital healthcare services.

For telemedicine platforms operating in Thailand, navigating the interplay between local regulations and international frameworks necessitates a meticulous approach to data processing. Failure to comply can lead to reputational damage, regulatory penalties, and legal liabilities. By adopting best practices such as transparent privacy policies, strong security measures, and compliance with data subject rights, telemedicine providers can create a safe and legally compliant environment.

In conclusion, the landscape of health information regulation is complex and continuously evolving. Telemedicine platform providers must proactively update their policies and compliance strategies to align with changing regulations, ensuring that patient rights remain protected while fostering innovation in digital healthcare solutions. By doing so, they can contribute to a more secure, efficient, and globally compliant telemedicine ecosystem.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Government Support for Small and Medium Enterprises (SMEs): Four New Economic Working Groups

Introduction

On 10 August 2026, Ms. Suphajee Suthumpun, Deputy Prime Minister and Minister of Commerce (“MOC”), chaired the first 2026 meeting of the Sub-Committee on the Development of Trade, Tourism and the Community Economy (the “Sub-Committee”). The Sub-Committee resolved to establish four specialized working groups tasked with restructuring the Thai economy across four dimensions:

  • the creative and visitor economy;
  • high-value agriculture and food security;
  • the community economy and SMEs; and
  • international trade.

The initiative is built on a two-tier delivery model:

  • Quick Big Win (short-term): targets measurable results within 6 to 12 months, principally by reviewing and removing regulatory requirements that obstruct business. This tier is deliberately confined to measures achievable without amending primary legislation and without requiring substantial budget allocation.
  • Big Win (long-term): targets structural reform over a two-to-four-year horizon to strengthen Thailand’s international competitiveness.

For businesses — particularly SMEs — the initiative carries particular significance. The MOC has identified small operators as accounting for approximately 35 percent of total national income, and the working group dedicated to the community economy and SMEs has been given an express mandate covering the entire entrepreneurial lifecycle, from business formation through to scale-up.

The initiative also places strong emphasis on regulatory and administrative reform. In particular, the Quick Big Win framework is intended to deliver practical improvements through measures that can generally be implemented without amendments to primary legislation.

The Four Working Groups

  1. Creative Economy and Visitor Economy
    This group aims to extend the policy frame beyond conventional tourism to a broader visitor economy that includes those travelling to Thailand for education, business, and wellness purposes. Its work draws on Thailand’s cultural capital, identity, and visitor experience, and seeks to connect secondary cities and local communities to visitor spending.
  2. Agricultural Products, Food Security, and High-Value Agriculture
    This group addresses the agricultural sector across the full value chain — upstream production, midstream processing, and downstream marketing — with the goal of moving Thai agriculture toward higher-value output, linking the sector more closely to industry and investment, and reinforcing food security.
  3. Community Economy and Small and Medium Enterprises (SMEs)
    This group covers the entrepreneurial ecosystem as a whole: reducing licensing burdens, streamlining permit processes, building operator knowledge, upgrading goods and services, and promoting both scale-up and fair competition. Wholesale and retail trade is treated as a connected dimension of the same mandate. The group’s focus reflects the Government’s broader objective of improving the business environment for SMEs through practical regulatory and administrative reform.
  4. International Trade
    This group focuses on promoting a more balanced import-export position, opening new markets, increasing utilization of existing free trade agreements, and responding to geopolitical pressure and non-tariff measures. It also carries the specific objectives of increasing SMEs’ share of the export structure and reducing dependency on any single market, thereby strengthening the resilience and international competitiveness of Thai businesses.

Legal and Regulatory Context

The Quick Big Win initiative is expected to be implemented through existing legal and administrative mechanisms, including:

  • Facilitation of Licensing and Public Services Consideration Act B.E. 2569 (2026): streamlines licensing procedures and public service delivery through new administrative mechanisms, replacing and expanding the earlier framework under the Facilitation of Official Licensing Consideration Act B.E. 2558 (2015).
  • Act on Legislative Drafting and Evaluation of Law B.E. 2562 (2019): facilitates stakeholder participation in the law-making and regulatory reform process.
  • SME Promotion Act B.E. 2543 (2000): provides the institutional framework for SME development and policy coordination.

These instruments provide the legal and administrative foundation for implementing the Quick Big Win agenda, particularly in relation to licensing simplification, regulatory reform, public service efficiency, and SME development.

Key Takeaways

  • The initiative underscores the strategic importance of SMEs in driving inclusive and sustainable economic growth.
  • The Quick Big Win framework aims to deliver measurable regulatory and administrative improvements within 6 to 12 months, primarily through reforms that do not require legislative amendment.
  • The Community Economy and SMEs Working Group has been tasked with supporting businesses throughout the entrepreneurial lifecycle — from establishment and compliance to expansion and competitiveness.
  • Businesses should closely monitor developments over the next 6 to 12 months and take advantage of opportunities to raise regulatory concerns as reforms are implemented.
  • Although the initiative does not create binding legal obligations, it offers an early indication of the Government’s priorities for future economic and regulatory reform.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Cabinet Approves Draft Ministerial Regulation Introducing Per-Item Fees for DBD Data Linkage Services

On August 7, 2026, The Deputy Government Spokesperson announced that the Cabinet of Thailand (“Cabinet”) has approved in principle a draft Ministerial Regulation Prescribing Fee Rates and Fee Exemptions for Registration, Requests for Document Inspection, Requests for Certified Copies, and Other Fees Relating to Partnerships and Limited Companies B.E. …. (“Draft Regulation”), as proposed by the Ministry of Commerce (“MOC”). The Draft Regulation has been referred to and is currently under the Office of the Council of State’s review. The Cabinet also instructed the MOC to take into account comments from the Office of the National Economic and Social Development Council regarding this Draft Regulation.

Background

Members of the public and businesses can currently verify juristic person information through a data linkage between the Department of Business Development (“DBD”) computer network and the user’s own system. Under the Ministerial Regulation Prescribing Fee Rates, Fee Reductions and Fee Exemptions Relating to Partnerships and Limited Companies B.E. 2563 (2020) (the “2563 Regulation”), a fee of THB 30 is charged per data set, with each set comprising six items:

  • name of the partnership or limited company
  • director information
  • number and names of authorized directors
  • registered capital
  • head office and branch locations
  • corporate objectives

The current system does not permit partial data requests: a user seeking only a single item — for example, registered capital — must nevertheless pay THB 30 for the full data set. The MOC considers this structure an unnecessary cost burden on both the public and private sectors, an obstacle to digital government development, and inconsistent with modern business practices that call for selective data access.

The Draft Regulation therefore aims to lower data-linkage service costs for juristic person verification by the public and private sectors. It also seeks to encourage corporate transactions through reliable electronic platforms, accelerate digital transformation in government, facilitate inter-agency data integration, and enable the DBD to expand its service coverage.

Key Changes

  • Introduction of a per-item fee. A new fee of THB 5 per individual item will apply to company certificate data. Users may still request the complete data set at the existing rate of THB 30, while the installation fee for the data linkage program remains THB 3,000 per instance. This allows users to select and pay only for the items they require.
  • Removal of the expired e-Registration discount. Clause 4 of the 2563 Regulation — which granted a 50 percent reduction on certain registration fees for partnerships and limited companies filing through the electronic juristic person registration system between 1 January 2021 and 31 December 2023 — will be deleted, as the discount period has already lapsed.

Key Takeaways

  • Users of the DBD data linkage service will be able to obtain individual certificate items at THB 5 each, rather than paying THB 30 for the full six-item data set.
  • For a typical two-item request, cost will fall from THB 30 to THB 10.
  • The THB 3,000 installation fee and the THB 30 full-set option are retained; all other registration and document fees are unaffected.
  • The Draft Regulation remains subject to review by the Office of the Council of State and is not yet in force. Businesses relying on the data linkage service should monitor the Royal Gazette for the effective date.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Employee Benefits and the Personal Data of Family Members

Employee benefit programs frequently require employers to process personal data not only of their employees, but also of their employees’ spouses, children, parents, or other family members. Typical examples include medical benefits, insurance coverage, educational allowances, travel benefits, and other welfare programs. While such processing is routine from an HR perspective, it raises an important question under the Personal Data Protection Act B.E. 2562 (2019) (PDPA): can an employer rely on the same lawful basis for the employee and the employee’s family members?

This issue was addressed by the Office of the Personal Data Protection Committee (PDPC Office) in Consultation No. 10/2568 concerning a bank’s processing of personal data of employees and their family members for employee benefits. The consultation is particularly useful because it illustrates a point that is sometimes overlooked in HR privacy compliance: identifying a legitimate business purpose is not enough. The data controller must identify the appropriate lawful basis in relation to each data subject whose personal data is being processed. The consultation also refers to the PDPA provisions concerning minors and purpose limitation, making the issue especially relevant where employee benefits extend to children.

The Employee and the Family Member Are Different Data Subjects:

For the employee, the analysis is relatively straightforward. Where benefits form part of the employee’s employment package, the employer may need to process the employee’s personal data to administer those benefits. Section 24 of the PDPA permits processing without consent in several circumstances, including where processing is necessary for the performance of a contract to which the data subject is a party, compliance with a legal obligation, or legitimate interests, subject to the applicable conditions.

Accordingly, where a benefit arises from the employment relationship, the contractual basis may potentially support processing of the employee’s personal data if that processing is objectively necessary to perform the employer’s obligations under the employment arrangement. Other benefits may instead be supported by a legal obligation or legitimate interests, depending on their nature and purpose.

The position becomes more complicated when the same benefit requires information about the employee’s spouse, child, parent, or other family member. Those individuals are separate data subjects. More importantly, they will ordinarily not be parties to the employment contract between the employer and the employee. The fact that processing their data enables the employer to provide a contractual benefit to the employee does not automatically make the family member a party to that contract.

This distinction matters because the contractual basis under the PDPA focuses on a contract to which the data subject is a party. Employers should therefore be cautious about treating the employment contract as a blanket lawful basis covering everyone whose information happens to be required for HR administration.

What Lawful Basis Can Apply to Family Members?

The appropriate basis must instead be considered according to the particular processing activity. Depending on the circumstances, an employer may be able to rely on legitimate interests, provided that the processing is necessary for a legitimate purpose and the employer has appropriately considered the rights and interests of the affected family members. Consent may be relevant where no other lawful basis is available, although it should not automatically be treated as the default solution merely because the individual is not an employee.

This distinction becomes even more important where benefits involve sensitive personal data under Section 26, particularly health information. Medical reimbursement and health insurance schemes, for example, may require medical certificates, diagnoses, treatment information, disability information, or other health data concerning an employee or family member. A lawful basis for ordinary personal data under Section 24 does not by itself resolve the processing of sensitive personal data. The employer must separately determine whether one of the conditions under Section 26 applies or whether explicit consent is required.

Children introduce an additional layer of compliance. If an employee submits personal data concerning a child for educational, medical, insurance, or other benefits, the employer must consider the PDPA requirements applicable to minors, including the rules governing consent where consent is the basis relied upon. Consultation No. 10/2568 expressly refers to Section 20 of the PDPA, which contains the statutory framework governing consent involving minors.

Do Not Forget the Privacy Notice:

Another practical issue is transparency. Section 21 requires personal data to be collected, used, and disclosed consistently with the purposes communicated to the data subject, subject to the statutory exceptions. Employers therefore need to consider not only whether they have a lawful basis, but also whether the relevant family members have been properly informed about the processing of their data.

An employee privacy notice that describes how the employer processes employee information does not necessarily solve this problem. The spouse, child, or parent remains a separate data subject. In many organizations, however, the employer obtains the family member’s information indirectly through the employee rather than directly from that family member.

HR teams should therefore review how their privacy notices deal with this situation. Depending on the circumstances, organizations may consider a separate notice for family members and beneficiaries, or incorporate appropriately drafted provisions into the HR privacy framework together with a mechanism for ensuring that the relevant information reaches those individuals. The notice should explain, among other matters, the purposes of processing, categories of information involved, applicable lawful bases, disclosures to insurers or other benefit providers, retention arrangements, and data subject rights.

Practical Implications for Employers:

Consultation No. 10/2568 is a useful reminder that an HR database should not be analyzed simply as a database containing “employee information.” A single employee record may contain personal data belonging to several legally distinct data subjects, and the lawful basis may differ among them.

Employers should therefore map benefit-related processing at the data-subject level. For each benefit, HR and privacy teams should identify whose information is collected, why it is required, whether ordinary or sensitive personal data is involved, the lawful basis applicable to each category of data subject, how the required privacy information is provided, and whether information is transferred to insurers, hospitals, benefit administrators, payroll providers, or other third parties.

This approach is particularly important because many HR processes were designed long before privacy compliance became a formal legal requirement. Forms asking employees to provide the names, identification numbers, dates of birth, relationship information, bank details, or medical information of family members may have existed for years. Their operational familiarity does not remove the need to identify a lawful basis and comply with the PDPA’s transparency, data minimization, security, and retention requirements.

Key Takeaways:

  • Do not automatically extend the employee’s lawful basis to family members. The employee and each family member are separate data subjects.
  • Contractual necessity requires particular attention. A spouse, child, or parent will ordinarily not be a party to the employment contract merely because the employee receives a benefit relating to that person.
  • Consider legitimate interests or another appropriate lawful basis for family-member data rather than treating consent as the automatic solution.
  • Analyze sensitive personal data separately. Health and similar information requires a basis permitted under Section 26 in addition to the analysis applicable to ordinary personal data.
  • Children require additional consideration, particularly where processing relies on consent.
  • Review privacy notices and indirect collection procedures. An employee privacy notice should not automatically be assumed to satisfy transparency obligations toward family members.
  • Audit existing benefit forms and HR systems. Employers should identify exactly what family-member information they collect and whether each data field remains necessary for administering the relevant benefit.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

Consumer Protection: Proposed Labeling Rules for Solar Panels, Inverters and Energy-Storage Batteries

The Office of the Consumer Protection Board (OCPB) has opened a public consultation on three draft notifications of the Committee on Labels covering solar panels, inverters used with solar panels, and batteries for storing energy generated from solar panels. The consultation runs from 13–27 August 2026. Although, the notifications remain in draft form, they are an important development for manufacturers, importers, distributors, dealers, installers, and businesses supplying rooftop-solar and energy-storage systems.

The Proposed Labeling Rules:

The three draft notifications would regulate labeling requirements for the principal components of a solar-energy system: solar panels, inverters, and energy-storage batteries. The initiative follows increased regulatory attention to consumer protection in the solar sector, including concerns regarding the quality and safety of solar equipment and installations.

Designation of these products as label-controlled products is significant because labeling under the Consumer Protection Act is more than a product-branding requirement. The regulatory framework is intended to ensure that consumers receive sufficient and accurate information about the products they purchase, including information prescribed by the Committee on Labels. The precise disclosures, language requirements, and presentation requirements will ultimately depend on the final wording of each notification.

For solar products, compliance can be particularly complex because consumers frequently purchase an entire rooftop-solar or solar-plus-storage system rather than individual components. The panels, inverter, and battery may be manufactured by different companies, imported by different entities, and supplied to the consumer through a distributor or installer. As a result, businesses should consider labeling compliance across the entire supply chain rather than treating it solely as a manufacturer’s responsibility.

Key Compliance Issues for Businesses:

Manufacturers and importers should be particularly attentive to the proposals because they generally control product specifications, labels, packaging, and accompanying documentation. Imported equipment may present additional challenges where the original labels and manuals are prepared for international markets. Importers should therefore assess whether Thai-language supplementary labels will be required and whether information on those labels is consistent with the manufacturer’s original product information.

This review should extend beyond literal translation. Product names, model numbers, technical specifications, manufacturer and importer details, instructions, warnings, and other required disclosures should be consistent across the product label, packaging, manuals, technical specifications, warranties, and other customer-facing materials. Inconsistencies between these materials can create both regulatory and consumer-dispute risks.

Distributors, dealers, and installers should also monitor the proposals closely. A rooftop-solar provider may purchase panels, an inverter, and a battery from different suppliers and then offer them to the consumer as a single installed system. Businesses operating this model should consider incorporating label verification into their procurement and installation procedures, including checking that required labels are present, correspond to the correct product model, and are not removed or obscured during installation.

The proposals may therefore have consequences beyond the physical product label. Depending on the final requirements, businesses may need to review packaging, Thai-language disclosures, product specification sheets, user instructions, warranties, quotations, sales proposals, online product descriptions, and information provided by dealers and installers. Not all of these materials will necessarily constitute regulated labels, but consistency between mandatory product information and commercial representations should form part of the compliance review.

Supply-Chain Contracts and Existing Inventory:

Businesses should also review how responsibility for labeling compliance is allocated contractually. Supply, import, distribution, dealer, and installation agreements often contain general obligations to comply with applicable law but may not specifically address responsibility for preparing Thai-language labels, verifying technical information, implementing regulatory changes, or bearing the cost of relabeling noncompliant products.

For importers dealing with overseas manufacturers, this can be commercially important. Changes to factory-applied labels or packaging may require manufacturing lead times and additional costs. Agreements should therefore be reviewed to determine who must implement regulatory changes, who bears the associated costs, and what remedies apply where products supplied into the market do not satisfy mandatory labeling requirements.

Existing inventory will be another important issue when the final notifications are issued. Businesses may already hold substantial stocks of solar panels, inverters, and batteries bearing existing labels, while additional products may be in transit or subject to outstanding purchase orders. Companies should monitor the final rules for their effective dates and any transitional provisions, including whether existing inventory can continue to be sold or whether supplementary labeling will be permitted. Businesses should not assume that existing products will automatically be grandfathered.

Labeling, Product Safety, and Enforcement:

The proposed rules should also be considered alongside broader product-safety regulation. The OCPB has previously highlighted consumer concerns relating to allegedly substandard solar installations and has emphasized the importance of consumers being able to identify relevant product, manufacturer, importer, origin, and standards information.

Labeling compliance and technical compliance should therefore be managed as related but distinct requirements. A product’s compliance with an applicable industrial or technical standard does not necessarily establish compliance with consumer-labeling requirements, while a correctly labeled product may still fail to satisfy separate product-safety requirements.

Noncompliance with labeling requirements can carry criminal consequences under the Consumer Protection Act. The OCPB has stated that a seller of a label-controlled product without the required label, or with an incorrect label where the seller knows or ought to know of the noncompliance, may face imprisonment for up to six months, a fine of up to THB 100,000, or both. For manufacturers producing goods for sale and persons ordering or importing goods for sale, the potential penalty may increase to imprisonment for up to one year, a fine of up to THB 200,000, or both.

What Businesses Should Do Now:

As the notifications remain in draft form, immediate changes to product labels may be premature. However, businesses can begin preparing by identifying affected product models and collecting their current labels, packaging, manuals, and Thai-language product information. Importers should determine which labeling changes can be made locally and which would require cooperation from overseas manufacturers.

Businesses should also map responsibility throughout their distribution networks, review supply and dealer agreements, and identify existing inventory that could be affected by the new requirements. Once the final notifications are issued, particular attention should be given to the exact product scope, mandatory disclosures, Thai-language requirements, effective dates, and transitional arrangements.

Key Takeaways:

  • The OCPB is consulting on three draft labeling notifications covering solar panels, solar inverters, and batteries used for solar-energy storage.
  • The proposals are relevant to manufacturers, importers, distributors, dealers, installers, and integrated rooftop-solar and energy-storage providers.
  • Businesses should review not only physical labels but also packaging, Thai-language product information, technical documentation, sales materials, and downstream dealer practices.
  • Importers should assess whether existing global labels and packaging can satisfy the proposed requirements or whether local supplementary labeling or factory changes may be necessary.
  • Supply-chain agreements should clearly allocate responsibility and costs for labeling compliance and regulatory changes.
  • Businesses holding substantial inventory should monitor effective dates and transitional provisions carefully.
  • Companies can use the consultation period to conduct a preliminary product and labeling audit so they are prepared to implement the final requirements efficiently.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles