PDPA Insights: Building Effective Privacy Governance

PDPA: Legitimate Interest Is No Longer a Shortcut

For many organizations implementing Thailand’s Personal Data Protection Act (PDPA), legitimate interest has become the preferred legal basis whenever obtaining consent appears impractical. Marketing activities, CCTV surveillance, fraud prevention, internal investigations, customer analytics, vendor due diligence, and employee monitoring are frequently justified on the basis that the organization has a legitimate business interest in processing personal data.

Yet legitimate interest is often misunderstood.

Some organizations treat it as a convenient alternative to consent, while others avoid relying on it altogether for fear that regulators may later disagree with their assessment. Both approaches overlook the purpose of legitimate interest within the PDPA.

The Personal Data Protection Committee’s recent consultation on legal bases provides an important indication of how the regulator expects organizations to approach legitimate interest. Rather than treating it as a residual category available whenever consent cannot be obtained, the consultation emphasizes a structured decision-making process requiring organizations to identify the processing purpose, assess necessity, balance competing interests, and document their reasoning. Although the consultation remains subject to revision, it reflects a broader movement toward accountability-based compliance rather than checklist compliance.

Legitimate interest is a legal analysis—not a business preference:

One of the most common misconceptions is that organizations may choose whichever legal basis they prefer.

The PDPA does not permit such flexibility.

Instead, the legal basis should reflect the actual purpose of the processing activity. Organizations should therefore begin by asking why the processing is taking place before considering whether legitimate interest is available.

For example, processing customer contact details to deliver purchased goods differs fundamentally from processing the same information to analyze purchasing behavior for future marketing campaigns. Likewise, operating CCTV to protect premises serves a different purpose from monitoring employee productivity.

Each processing activity should therefore be assessed independently.

Legitimate interest becomes relevant only after organizations have clearly identified the processing purpose and determined that no more appropriate legal basis applies.

Legitimate interest requires necessity:

The consultation suggests that organizations should demonstrate that the processing is genuinely necessary to achieve the identified purpose rather than merely convenient.

Necessity does not require the organization to prove that no alternative exists. However, it should be able to explain why the processing contributes meaningfully to the legitimate objective and why less intrusive alternatives would not achieve substantially the same result.

For example, a shopping mall operating CCTV in public areas for security purposes may reasonably conclude that surveillance is necessary to deter crime and investigate incidents. By contrast, continuous monitoring of employees in low-risk office environments may require a much more persuasive justification.

Organizations should therefore avoid assuming that every commercially useful processing activity automatically satisfies the necessity requirement.

Balancing interests requires more than common sense:

Perhaps the most significant aspect of legitimate interest is the balancing exercise.

Organizations should evaluate not only their own commercial interests but also the likely impact on individuals.

Relevant considerations may include:

  • the nature of the personal data;
  • the reasonable expectations of the individuals concerned;
  • the relationship between the organization and the individual;
  • the potential consequences of the processing;
  • whether adequate safeguards have been implemented; and
  • whether individuals can reasonably object to the processing.

This balancing exercise is particularly important where organizations undertake customer profiling, behavioral analytics, fraud detection, or other activities involving continuous monitoring.

Importantly, the outcome is not predetermined. Two organizations undertaking similar processing activities may legitimately reach different conclusions depending upon their operational context and safeguards.

Documentation is becoming as important as the decision itself:

One of the clearest messages emerging from the PDPC’s recent consultation is that organizations should be able to explain how they reached their legal conclusions.

Historically, many organizations simply recorded “Legitimate Interest” in their Records of Processing Activities or privacy notices without documenting the underlying reasoning.

That approach is becoming increasingly difficult to justify.

Organizations should instead maintain contemporaneous records explaining:

  1. the legitimate interest pursued;
  2. why the processing is necessary;
  3. how competing interests were balanced;
  4. what safeguards were implemented; and
  5. when the assessment will be reviewed.

These records not only support regulatory accountability but also improve internal governance by ensuring that legal basis assessments remain consistent across different business units.

Legitimate interest should evolve with the processing:

A legal basis assessment should not be regarded as a one-time exercise.

Business practices evolve. New technologies are introduced. AI systems become more sophisticated. Customer expectations change.

Processing that was originally assessed as proportionate may become significantly more intrusive over time.

Organizations should therefore periodically review Legitimate Interest Assessments, particularly where processing activities involve profiling, AI-assisted decision-making, large-scale analytics, or new categories of personal data.

Periodic review is consistent with the broader accountability framework underpinning the PDPA and helps ensure that legal basis assessments remain aligned with actual business practices.

Legitimate interest is ultimately about governance:

Perhaps the most important lesson emerging from the PDPC’s consultation is that legitimate interest should not be viewed primarily as a legal exception to consent.

Instead, it should be understood as a governance framework requiring organizations to demonstrate thoughtful decision-making.

Organizations that simply declare legitimate interest without documented analysis are unlikely to satisfy increasing regulatory expectations.

By contrast, organizations capable of demonstrating why processing is necessary, how competing interests were balanced, and what safeguards were implemented will be better positioned to justify their decisions if questioned by regulators or affected individuals.

The emphasis is therefore shifting from selecting a legal basis to demonstrating why that legal basis remains appropriate throughout the lifecycle of the processing activity.

Looking ahead:

As organizations increasingly deploy AI, customer analytics, fraud detection systems, behavioral advertising, and other data-driven technologies, reliance on legitimate interest is likely to become more common rather than less.

This makes governance increasingly important.

The PDPC’s consultation suggests that future enforcement may focus less on whether organizations selected legitimate interest and more on whether they can demonstrate the quality of the assessment supporting that decision.

Organizations that treat Legitimate Interest Assessments as living governance documents rather than compliance paperwork will be better prepared as Thailand’s privacy regime continues to mature.

Key takeaways:

  • Legitimate interest is not an alternative chosen for convenience but a legal basis that should reflect the actual purpose of processing.
  • Organizations should identify each processing activity separately before determining whether legitimate interest is appropriate.
  • Necessity and balancing are substantive assessments that should be documented rather than assumed.
  • Legitimate Interest Assessments should evolve alongside changes in technology, business practices, and customer expectations.
  • Increasingly, regulatory scrutiny is likely to focus on the quality of governance and documentation supporting legitimate interest rather than the mere assertion that it applies.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

PDPA Insights: Building Effective Privacy Governance

PDPA: ROPA Is Becoming the Organization’s Privacy Blueprint

For many organizations, preparing a Record of Processing Activities (ROPA) has been one of the least engaging aspects of complying with Thailand’s Personal Data Protection Act (PDPA). Frequently viewed as a statutory obligation rather than a practical management tool, ROPAs are often prepared once, filed away, and revisited only when requested during internal audits or regulatory inquiries.

This perception is beginning to change.

The Personal Data Protection Committee’s (PDPC) recent consultation on Records of Processing Activities suggests that the regulator increasingly views the ROPA as more than a compliance checklist. Instead, it appears to regard the ROPA as the central document connecting an organization’s privacy governance framework. Although the guidance remains subject to public consultation, it illustrates how the regulator expects organizations to understand, document, and govern personal data processing across the enterprise. Rather than serving as a static inventory of personal data, the ROPA is evolving into a living record of how an organization manages privacy risks and demonstrates accountability under the PDPA.

This shift is significant because it mirrors the growing complexity of modern business operations. Organizations increasingly process personal data through cloud services, software-as-a-service platforms, artificial intelligence (AI), customer relationship management systems, outsourced service providers, and cross-border digital ecosystems. A ROPA that merely lists departments and categories of personal data is unlikely to provide meaningful insight into how those activities actually operate.

A good ROPA should explain how the business works:

Many organizations approach a ROPA as a spreadsheet of processing activities.

That is an understandable starting point, but it is no longer sufficient.

A well-developed ROPA should allow someone unfamiliar with the organization to understand how personal data flows through the business. It should explain why personal data is collected, who uses it, where it is stored, whether it is shared with third parties, whether it leaves Thailand, how long it is retained, and what safeguards protect it.

Viewed in this way, a ROPA resembles a process map rather than an inventory.

This broader perspective benefits the organization as much as the regulator. It enables legal, compliance, information security, procurement, and business teams to work from a common understanding of data processing activities rather than maintaining separate records that quickly become inconsistent.

Processing activities—not departments—should become the focus:

One recurring challenge is that organizations frequently prepare ROPAs according to organizational structure rather than business activities.

Typical entries include “Human Resources,” “Finance,” or “Marketing.”

While administratively convenient, these categories often obscure the underlying processing activities that matter under the PDPA.

For example, a marketing department may collect personal data to administer loyalty programmes, analyze customer behavior, operate targeted advertising campaigns, manage promotional events, and respond to customer inquiries. Each activity may involve different categories of personal data, different legal bases, different retention periods, and different third-party service providers.

Documenting each activity separately provides a more accurate picture of privacy risk and facilitates more meaningful governance.

A ROPA should reveal dependencies:

One of the most valuable functions of a ROPA is identifying operational dependencies.

Many organizations discover during ROPA preparation that multiple business units rely on the same customer database, share vendors, or process identical information for different purposes.

These dependencies often remain invisible until the organization attempts to document its processing activities comprehensively.

Recognizing them can improve not only privacy compliance but also cybersecurity, procurement, contract management, and incident response planning.

The ROPA therefore becomes a tool for organizational learning rather than regulatory compliance alone.

AI and cloud services are changing what a ROPA should capture:

When many organizations first prepared ROPAs, processing activities were comparatively straightforward.

Today, organizations increasingly rely on cloud platforms, AI-powered customer service tools, outsourced analytics providers, and software supplied by multiple vendors.

This evolution raises new governance questions.

A modern ROPA should help organizations understand:

  • which AI tools process personal data;
  • what information is transferred to cloud providers;
  • whether overseas processing occurs;
  • what vendors act as processors or sub-processors;
  • how long AI systems retain information;
  • what contractual safeguards exist.

These questions are increasingly relevant regardless of whether AI is used internally or through third-party services.

ROPAs should support decision-making:

The most effective ROPAs are not prepared for regulators.

They are used internally.

Before launching a new customer loyalty programme, introducing AI-powered customer service, engaging a new cloud provider, or expanding into another jurisdiction, organizations should review existing processing activities through the ROPA.

Doing so helps identify whether new processing purposes arise, whether additional legal bases are required, whether privacy notices should be updated, and whether vendors require additional contractual protections.

Used effectively, the ROPA becomes an operational governance tool rather than a historical record.

Keeping the ROPA alive:

One of the greatest risks is allowing the ROPA to become outdated.

Business models evolve continuously. New technologies are introduced. Vendors change. Retention periods are revised. AI capabilities expand.

A ROPA that accurately reflected the organization two years ago may no longer describe current processing activities.

Organizations should therefore integrate ROPA maintenance into existing governance processes.

Updates should occur whenever significant changes are introduced, including new products, major technology implementations, acquisitions, outsourcing arrangements, or cross-border processing activities.

Periodic review should become part of normal business governance rather than a special compliance exercise.

Looking ahead:

The PDPC’s consultation suggests that the ROPA is evolving from a statutory record into a central governance document. This reflects a broader movement under the PDPA toward accountability and demonstrable compliance rather than documentation for its own sake.

Organizations that treat the ROPA as a living blueprint of their data processing environment will be better equipped to respond to regulatory inquiries, support privacy impact assessments, evaluate AI deployments, manage vendors, and demonstrate compliance with the PDPA.

Key takeaways:

  • A ROPA should describe how personal data flows through the organization rather than merely listing departments.
  • Processing activities—not organizational units—should form the foundation of the ROPA.
  • A well-maintained ROPA helps identify operational dependencies, shared datasets, and vendor relationships that may otherwise remain unnoticed.
  • Modern ROPAs should capture AI systems, cloud services, cross-border processing, and processor/sub-processor relationships where relevant.
  • Organizations should treat the ROPA as a living governance document that supports operational decision-making rather than as a static compliance record.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

PDPA Insights: Building Effective Privacy Governance

PDPA: The DPO Is Not Responsible for Compliance—Your Organization Is

One of the most persistent misconceptions surrounding Thailand’s Personal Data Protection Act (PDPA) is that appointing a Data Protection Officer (DPO) satisfies an organization’s compliance obligations.

In practice, many organizations regard the DPO as the person responsible for “doing PDPA.” Privacy notices, data subject requests, breach notifications, contract reviews, training, audits and even cybersecurity issues are routinely directed to the DPO, often regardless of whether the DPO has the authority, resources or operational involvement to manage those activities effectively.

This perception is understandable. The PDPA requires certain organizations to appoint a DPO, and the role naturally becomes the focal point for privacy-related matters. However, the PDPC’s recent consultation on DPOs suggests that this understanding is incomplete. Rather than placing responsibility for compliance on the DPO, the consultation reinforces a governance model in which responsibility remains with the organization itself. The DPO’s role is to advise, monitor and facilitate compliance—not to replace management’s accountability.

This distinction may appear technical, but it has significant practical consequences for how organizations should structure their privacy governance.

Compliance belongs to the organization:

Privacy compliance is often described as a legal function, yet effective compliance depends upon decisions made throughout the organization.

Marketing teams determine how customer data is used.

Human resources departments manage employee information.

Information technology teams implement technical safeguards.

Procurement negotiates contracts with service providers.

Business units decide what personal data should be collected and why.

These operational decisions cannot realistically be delegated to a single individual.

The DPO may advise on each of these activities, but the responsibility for making business decisions—and ensuring those decisions comply with the PDPA—remains with the organization.

This governance model is consistent with the broader direction of the PDPC’s recent consultations, which increasingly emphasize accountability across the organization rather than concentrating responsibility within a single compliance function.

Independence does not mean isolation:

The PDPA requires that the DPO perform their duties independently.

This requirement is sometimes misunderstood to mean that the DPO should operate separately from the business.

In practice, independence means something quite different.

A DPO should be able to provide objective advice without inappropriate influence from commercial considerations. Management should not pressure the DPO to approve questionable processing activities or discourage the DPO from identifying compliance risks.

At the same time, independence should not prevent close collaboration with business units.

An effective DPO understands the organization’s operations, participates in project planning, and provides practical advice before privacy issues become compliance problems.

The most successful DPOs are therefore integrated into decision-making while remaining sufficiently independent to challenge proposals where necessary.

The DPO should be involved early:

Privacy risks are easiest to manage before systems are implemented.

Once a customer platform has been launched, an AI tool deployed, or a vendor contract executed, addressing privacy concerns often becomes significantly more expensive.

Organizations should therefore involve the DPO during the planning stage of new initiatives.

Examples include:

  • launching new digital products;
  • introducing AI-powered customer service;
  • implementing HR technologies;
  • engaging cloud providers;
  • deploying CCTV systems;
  • expanding overseas operations.

Early involvement allows privacy considerations to be incorporated into business decisions rather than added after implementation.

Expertise matters more than job title:

The PDPA does not prescribe a single professional background for DPOs.

In practice, effective DPOs come from diverse disciplines, including law, information security, compliance, risk management and information technology.

What matters is not professional qualification alone but the ability to understand both legal requirements and operational realities.

An effective DPO should be capable of translating legal principles into practical business guidance while communicating effectively with senior management, technical specialists and operational teams.

Organizations should therefore focus on competence rather than formal titles when appointing a DPO.

Conflicts of interest deserve careful consideration:

One of the most challenging aspects of DPO governance is avoiding conflicts of interest.

Individuals responsible for determining why and how personal data is processed may struggle to provide independent oversight of those same decisions.

For example, appointing the head of marketing as DPO may create tension where marketing initiatives require objective privacy review.

Similarly, information technology leaders responsible for designing systems may find it difficult to independently assess privacy risks arising from those systems.

Organizations should therefore consider whether reporting structures, operational responsibilities and decision-making authority could compromise the DPO’s independence.

The objective is not to prohibit dual roles entirely but to ensure that privacy oversight remains objective and credible.

A successful DPO builds a privacy culture:

Perhaps the greatest misconception is that privacy compliance can be centralized.

No DPO—regardless of experience—can personally oversee every processing activity across a large organization.

Long-term success depends upon building privacy awareness throughout the business.

Training, internal guidance, standardized procedures, governance committees and clearly allocated responsibilities often contribute more to sustainable compliance than expanding the DPO’s workload.

The DPO’s most valuable contribution may therefore be enabling others to make better privacy decisions rather than making every decision personally.

Looking ahead:

The PDPC’s consultation reflects an increasingly mature understanding of the DPO function.

Rather than acting as the organization’s privacy manager, the DPO is emerging as an independent adviser who supports, challenges and guides the organization while management retains responsibility for compliance.

Organizations that recognize this distinction will be better positioned to establish sustainable governance frameworks rather than relying excessively on a single individual to solve increasingly complex privacy issues.

Key takeaways:

  • Appointing a DPO does not transfer PDPA compliance responsibilities from the organization to the DPO.
  • The DPO’s role is to advise, monitor and facilitate compliance while management remains accountable for processing decisions.
  • Independence enables objective advice but should not prevent close collaboration with business units.
  • Early involvement of the DPO in new projects helps identify and address privacy risks before implementation.
  • Organizations should carefully assess potential conflicts of interest and ensure that the DPO has sufficient authority, resources and access to senior management.
  • A mature privacy program depends on organization-wide governance and a culture of compliance, not on the DPO alone.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

PDPA Insights: Building Effective Privacy Governance

PDPA: Why Many Compliance Programs Fail Before They Begin

For many organizations, implementing Thailand’s Personal Data Protection Act (PDPA) begins with a familiar request.

“Can you send us a privacy notice?”

“Do you have a consent form we can use?”

“Can we copy the privacy policy from another company?”

These questions are understandable. Privacy notices, consent forms and cookie banners are visible. Customers can see them, business partners frequently request them during due diligence, and regulators often ask for them during investigations. Producing these documents therefore creates the impression that an organization is making tangible progress towards compliance.

Yet, in practice, this approach often starts the compliance journey in the wrong place.

The Personal Data Protection Committee’s (PDPC) recent series of draft guidelines consistently points towards a broader principle. Whether discussing legal bases, direct marketing, Records of Processing Activities (ROPAs), Data Protection Officers (DPOs), or security measures, the common theme is not documentation—it is governance. The regulator’s emerging expectation is that organizations first understand how personal data is processed before attempting to document those activities.

The consequence is significant. Many compliance programs fail not because organizations lack policies or templates, but because they build documentation before understanding the business processes those documents are intended to describe.

Compliance should begin with understanding the business—not drafting documents:

Perhaps the most common mistake is assuming that PDPA compliance starts with drafting a privacy notice.

In reality, a privacy notice should be one of the last documents prepared.

Before an organization can explain how personal data is processed, it must first understand its own processing activities. That requires data mapping and gap analysis.

Organizations should begin by asking practical questions.

  • What categories of personal data are collected?
  • Why is each category collected?
  • Which departments use the information?
  • Which vendors receive it?
  • Does the information leave Thailand?
  • How long is it retained?
  • Which legal basis supports each processing activity?

Only after these questions have been answered can an organization prepare a privacy notice that accurately reflects its operations.

A privacy notice should describe reality—not define it.

Unfortunately, many organizations reverse this process. They prepare documentation first and attempt to fit their operations into those documents afterwards. The result is often a privacy notice describing processing activities that do not exist while overlooking activities that are central to the business.

Compliance therefore begins with understanding data flows rather than drafting legal documents.

Visible documents should not be mistaken for compliance:

Another widespread misconception is that having a privacy notice, consent form and cookie banner demonstrates compliance.

These documents are important.

They are not, however, evidence that personal data is being processed lawfully.

An organization may publish an excellent privacy notice while having no documented legal basis assessments, no ROPA, no retention schedule, no vendor management procedures, no incident response plan and no understanding of how AI systems process personal data.

In other words, documentation can describe compliance without demonstrating it.

A useful distinction is this:

A privacy notice tells customers what an organization says it does. Governance demonstrates what the organization actually does.

The latter is what increasingly matters.

Every organization has different data flows:

Organizations frequently ask whether they may use another company’s privacy notice as a starting point.

While templates may provide useful drafting ideas, no two organizations process personal data in exactly the same way.

Even businesses operating within the same industry often differ significantly.

One retailer may outsource customer relationship management while another performs those functions internally.

One financial institution may process customer information entirely within Thailand while another relies extensively on overseas cloud providers.

One hospital may deploy AI-assisted diagnostic tools while another does not.

These operational differences inevitably influence legal basis assessments, retention periods, vendor management, international transfers and privacy notices.

Consequently, copying another organization’s documentation without first understanding one’s own processing activities risks producing documentation that is inaccurate from the outset.

Privacy documentation should therefore be tailored to the organization’s actual business model rather than borrowed from comparable organizations.

Consent is not the answer to every question:

Another persistent misconception is that obtaining consent automatically resolves privacy compliance.

Consent certainly plays an important role under the PDPA, but it should not become the default legal basis simply because it appears straightforward.

The more appropriate starting point is to identify the processing activity and understand why personal data is being processed.

Different activities frequently require different legal analyses.

Customer information collected to deliver purchased goods serves a different purpose from analyzing purchasing behavior to personalize future recommendations. Human resources information collected to administer payroll differs from information processed for employee engagement surveys.

Treating all processing activities as though they rely upon a single consent often oversimplifies legal requirements while creating unnecessary operational complexity.

Privacy is not the DPO’s responsibility alone:

Appointing a Data Protection Officer is another milestone that organizations sometimes mistake for compliance.

The DPO performs an important governance role, but the DPO does not “own” privacy.

Marketing determines how customer information is used.

Human resources processes employee information.

Information technology implements security measures.

Procurement appoints vendors.

Management determines business objectives.

Privacy compliance therefore depends upon decisions made throughout the organization rather than by one individual.

Organizations that rely exclusively upon the DPO often discover that privacy issues continue arising because governance has not been embedded into operational decision-making.

A ROPA is more than regulatory paperwork:

Many organizations prepare a Record of Processing Activities only because they believe the law requires one.

This perception overlooks the ROPA’s greatest value.

A well-maintained ROPA explains how personal data moves through the organization.

It identifies processing activities, legal bases, recipients, retention periods, international transfers and relationships with processors.

Perhaps more importantly, it often reveals inconsistencies that organizations had not previously recognized.

Different departments may retain identical information for different periods.

Separate business units may rely upon the same vendor.

Customer information may be transferred internationally without centralized oversight.

Viewed this way, the ROPA becomes a governance tool rather than merely a compliance document.

Cybersecurity does not equal privacy compliance:

Investment in cybersecurity has increased significantly in recent years.

Organizations deploy multi-factor authentication, endpoint detection systems, encryption technologies and internationally recognized security standards.

These investments are essential.

However, privacy compliance extends beyond technical security.

Organizations must still determine whether they collect more personal data than necessary, retain information for appropriate periods, rely upon suitable legal bases, manage processors appropriately and provide individuals with meaningful transparency.

Strong cybersecurity reduces certain risks.

It does not replace governance under the PDPA.

AI has not replaced traditional privacy principles:

Artificial intelligence has prompted many organizations to assume that entirely new privacy obligations now apply.

In reality, AI changes the scale of processing rather than the legal principles themselves.

Organizations should still ask familiar questions.

Why is personal data being processed?

What legal basis applies?

What information is being used?

Who receives it?

How are decisions documented?

AI governance therefore begins with ordinary privacy governance rather than replacing it.

Organizations that already understand their data flows will usually be better positioned to manage AI than those attempting to develop AI policies without first understanding their existing processing activities.

Compliance is not a project with an end date:

Perhaps the most damaging misconception is that PDPA compliance can be completed once and then forgotten.

Many organizations implemented privacy notices and consent forms when the PDPA first became fully enforceable.

Since then, business operations have changed considerably.

Organizations have adopted cloud platforms, AI tools, digital marketing technologies, remote working arrangements and increasingly sophisticated customer analytics.

Privacy governance should evolve alongside those changes.

Compliance should therefore be viewed as an ongoing governance function rather than a one-time legal project.

Looking ahead:

The common thread running through the PDPC’s recent draft guidance is that privacy compliance is becoming increasingly operational.

Organizations are expected not merely to produce documentation but to understand their processing activities, justify their decisions, manage risk and demonstrate accountability throughout the lifecycle of personal data.

That begins with understanding the business itself.

Organizations that start with data mapping, gap analysis and governance are likely to produce privacy notices, consent forms and internal policies that accurately reflect their operations.

Organizations that begin with templates may produce attractive documentation but still struggle to explain how personal data actually moves through the business.

Ultimately, effective PDPA compliance is not built by copying documents. It is built by understanding the organization those documents are intended to describe.

Key takeaways:

  • Effective PDPA compliance should begin with data mapping and gap analysis rather than drafting privacy notices or consent forms.
  • Privacy notices should reflect an organization’s actual processing activities and should be developed after those activities have been identified and documented.
  • Copying another organization’s privacy documentation without understanding one’s own data flows often results in inaccurate and ineffective compliance.
  • Consent is only one of several legal bases and should not be treated as the default solution for every processing activity.
  • Privacy governance is an organization-wide responsibility involving management, business units, IT, HR, procurement and legal—not only the DPO.
  • A well-maintained ROPA is a governance tool that helps organizations understand data flows, vendors and operational risks.
  • Strong cybersecurity supports privacy compliance but does not replace broader governance obligations under the PDPA.

Privacy compliance should be treated as a continuous governance function that evolves alongside changes in technology and business operations.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

PDPC Certification: Turning Privacy Compliance into a Competitive Advantage

The Office of the Personal Data Protection Committee (PDPC) has recently introduced a formal certification framework for personal data protection under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The framework establishes a mechanism through which organizations may obtain certification and display certification marks demonstrating adherence to recognized data protection standards.

While many organizations may initially view certification as another compliance exercise, the broader significance of the new framework lies in its potential to transform privacy compliance from a legal obligation into a strategic business asset. As customers, business partners, investors, and regulators place increasing emphasis on data governance, certification offers organizations an opportunity to distinguish themselves in an increasingly competitive marketplace.

Privacy as a Business Differentiator:

Over the past several years, data privacy has evolved from a niche compliance issue into a boardroom-level concern. High-profile data breaches, growing public awareness of privacy rights, and increasingly stringent regulatory requirements have elevated privacy protection into a key component of corporate governance.

As a result, organizations are increasingly expected not only to comply with legal requirements but also to demonstrate that compliance in a credible and transparent manner.

The new certification framework addresses this need by providing a mechanism through which organizations can obtain independent recognition of their privacy management practices. Rather than merely asserting compliance, certified organizations can point to a formal assessment conducted under a framework recognized by the PDPC.

In many industries, this distinction may prove valuable. Consumers are becoming more selective about how their personal information is collected, used, and protected. Organizations that can demonstrate a higher level of commitment to privacy may gain a competitive advantage over those that rely solely on contractual assurances or privacy notices.

Strengthening Customer Trust:

Trust is often one of the most valuable intangible assets an organization possesses. In the digital economy, that trust is closely linked to how personal data is managed.

Organizations routinely collect personal information from customers, employees, suppliers, and business partners. Any perceived weakness in data protection practices can quickly damage brand reputation and customer confidence.

Certification can help bridge the trust gap by providing independent verification that an organization has implemented appropriate data protection controls. Customers may view certification as evidence that an organization takes privacy obligations seriously and has invested in developing robust governance measures.

For businesses operating in sectors involving extensive personal data processing—such as financial services, healthcare, technology, telecommunications, hospitality, retail, and e-commerce—the ability to demonstrate recognized privacy standards may become an increasingly important competitive differentiator.

Facilitating Business-to-Business Relationships:

The benefits of certification may extend well beyond customer-facing activities.

Organizations increasingly conduct privacy and cybersecurity due diligence before engaging vendors, service providers, and business partners. Privacy questionnaires, vendor assessments, and contractual compliance reviews have become standard features of commercial transactions.

A recognized certification may help organizations streamline these processes by providing objective evidence of their privacy governance capabilities. Business partners may gain greater confidence in certified organizations, reducing the need for extensive verification exercises and accelerating commercial negotiations.

This may be particularly beneficial for service providers that process personal data on behalf of clients, including cloud service providers, software companies, outsourcing providers, human resources service providers, and professional service firms.

As privacy-related contractual obligations become more sophisticated, certification may increasingly serve as a practical tool for demonstrating compliance readiness.

Enhancing Corporate Governance:

One of the most significant benefits of certification may be the strengthening of internal governance structures.

Organizations pursuing certification are likely to establish clearer accountability mechanisms, more structured policies, improved risk management processes, and stronger oversight of personal data processing activities.

These governance improvements often extend beyond privacy compliance itself. Well-designed privacy programs frequently contribute to broader organizational objectives, including operational efficiency, information security, risk management, and regulatory compliance.

In this respect, certification should not be viewed merely as a badge or marketing tool. The process of achieving and maintaining certification may encourage organizations to embed privacy considerations more deeply into their governance culture and decision-making processes.

Supporting Regulatory Engagement:

Certification does not eliminate an organization’s legal obligations under the PDPA, nor does it provide immunity from regulatory enforcement.

Nevertheless, certification may serve as evidence that an organization has implemented structured and recognized measures to protect personal data.

Should a regulatory inquiry, investigation, or enforcement action arise, certification may help demonstrate that the organization has adopted a proactive and accountable approach to compliance. While each case will depend on its specific facts and circumstances, organizations that can demonstrate established governance frameworks may be better positioned when engaging with regulators.

This reflects a broader shift in privacy regulation globally, where regulators increasingly focus on accountability and governance rather than merely technical compliance.

Alignment with International Privacy Developments:

The introduction of a certification framework also aligns with broader international developments in privacy regulation.

The European Union’s General Data Protection Regulation (GDPR) recognizes data protection certification mechanisms under Articles 42 and 43 as tools for demonstrating compliance with data protection requirements. Although GDPR certification schemes are still developing across Europe, the underlying principle is clear: independent certification can strengthen trust, transparency, and accountability in personal data processing.

The PDPC’s certification framework follows a similar philosophy. Rather than relying exclusively on enforcement mechanisms, the framework encourages organizations to demonstrate compliance proactively through recognized standards and independent assessment.

For multinational organizations, this development may be particularly significant. Many businesses already operate under global privacy frameworks and seek consistency across jurisdictions. The availability of a domestic certification mechanism may help organizations align local compliance initiatives with broader international privacy governance strategies.

Supporting Cross-Border Business Opportunities:

As businesses increasingly participate in regional and global digital ecosystems, privacy credentials can become an important factor in commercial decision-making.

Foreign customers, investors, and business partners often assess privacy governance capabilities before entering into business relationships involving personal data processing. Organizations that can demonstrate recognized privacy standards may enjoy greater credibility during these assessments.

Certification may therefore provide advantages when competing for international business opportunities, participating in global supply chains, or providing services to overseas customers.

While certification alone will not satisfy all cross-border compliance requirements, it may serve as a valuable indicator of organizational maturity and commitment to responsible data management.

Looking Ahead:

The introduction of the PDPC’s certification framework represents more than a new compliance mechanism. It signals the continuing evolution of privacy regulation toward a model centered on accountability, governance, and demonstrable trustworthiness.

Organizations that view certification solely as a regulatory requirement may overlook its broader strategic value. In an environment where privacy expectations continue to rise, certification has the potential to strengthen customer confidence, facilitate commercial relationships, enhance corporate governance, and support long-term business growth.

For many organizations, the most significant benefit of certification may ultimately be its ability to transform privacy compliance from a cost center into a source of competitive advantage.

Key Takeaways:

  • The PDPC has introduced a formal certification framework for personal data protection under the PDPA.
  • Certification enables organizations to demonstrate privacy compliance through independent assessment and recognition.
  • Certified organizations may strengthen customer trust and enhance their market reputation.
  • Certification can facilitate vendor due diligence and improve business-to-business relationships.
  • The framework encourages stronger governance, accountability, and risk management practices.
  • Certification may help organizations demonstrate proactive compliance efforts when engaging with regulators.
  • The framework aligns with international developments, including certification mechanisms recognized under the GDPR.
  • Organizations engaged in cross-border business activities may benefit from the increased credibility and trust that certification can provide.
  • Privacy certification should be viewed not merely as a compliance tool, but as a strategic asset capable of creating competitive advantage.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPC Opens New Path for Intra-Group Cross-Border Data Transfers

The Personal Data Protection Committee (PDPC) has introduced a formal framework for the examination and certification of Binding Corporate Rules (BCRs), providing multinational corporate groups with a new mechanism to support cross-border transfers of personal data under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA).

The Regulation on the Examination and Certification of Binding Corporate Rules was published in the Government Gazette on 17 February 2026 and became effective immediately. The regulation establishes a certification process through which multinational organizations may seek PDPC approval of BCRs as an appropriate safeguard for intra-group international data transfers.

The development represents a significant milestone in the evolution of Thailand’s cross-border data transfer regime and offers multinational businesses greater flexibility in managing global data flows.

Existing Cross-Border Transfer Framework:

Cross-border transfers of personal data under the PDPA are principally governed by Sections 28 and 29.

Section 28 generally requires that personal data transferred to another country or international organization be sent only to destinations that maintain adequate data protection standards as prescribed by the PDPC.

Where the destination jurisdiction has not been recognized as providing adequate protection, Section 29 permits transfers based on certain safeguards or exemptions. In practice, organizations have often relied on contractual arrangements, consent, or other statutory exceptions to facilitate international transfers.

While these mechanisms remain available, they may be difficult to implement across large multinational groups involving numerous entities and complex data processing activities.

The introduction of a formal BCR framework provides an additional compliance option specifically designed for multinational organizations that routinely transfer personal data among affiliated companies located in different jurisdictions.

What Are Binding Corporate Rules?

Binding Corporate Rules are legally enforceable internal rules adopted by a corporate group to govern the processing and transfer of personal data among group entities.

The purpose of BCRs is to establish a consistent and comprehensive privacy framework across all participating companies within the group, regardless of where those companies are located.

Typically, BCRs address matters such as:

  • Data protection principles and governance;
  • Data subject rights;
  • Security measures and incident management;
  • Accountability and compliance monitoring;
  • Internal complaint handling procedures;
  • Employee training and awareness programs; and
  • Mechanisms for enforcing compliance throughout the corporate group.

Once certified by the PDPC, BCRs may serve as a recognized safeguard for intra-group cross-border transfers of personal data, including transfers to jurisdictions that have not been designated as providing adequate protection under Thai law.

Key Features of the New Regulation:

The regulation establishes a formal process through which multinational corporate groups may apply for PDPC certification of their BCRs.

The framework contemplates separate certification mechanisms for:

  • BCRs applicable to data controllers; and
  • BCRs applicable to data processors.

Applicants must demonstrate that their BCRs contain adequate protections for personal data and create binding obligations that are enforceable throughout the corporate group.

The PDPC is authorized to review submitted documentation, request additional information, conduct assessments, and determine whether certification should be granted.

Certification is not merely a documentary exercise. Organizations will need to demonstrate that their privacy governance framework is operational, effective, and capable of ensuring compliance across all participating entities.

Why This Matters for Multinational Businesses:

The new framework is particularly relevant for organizations that centralize operations across multiple jurisdictions and routinely transfer personal data among affiliated entities.

Examples include:

  • Regional shared-service centers managing human resources, finance, compliance, procurement, or customer support functions;
  • Global cloud infrastructure and centralized IT operations;
  • Technology companies operating multinational development and support teams;
  • Organizations using centralized customer relationship management systems;
  • Financial institutions operating regional processing hubs; and
  • Businesses conducting cross-border analytics and artificial intelligence development activities.

For these organizations, maintaining individual contractual safeguards between every transferring and receiving entity can be administratively burdensome and difficult to scale.

A certified BCR framework may provide a more efficient and sustainable governance model by establishing a single set of group-wide privacy standards applicable across multiple jurisdictions and business functions.

Preparing for BCR Certification:

Organizations considering BCR certification should evaluate whether their existing privacy compliance framework is sufficiently mature to satisfy regulatory scrutiny.

Key areas likely to require attention include:

Governance Structure

Organizations should establish clear privacy governance arrangements, including defined responsibilities, reporting lines, and oversight mechanisms across the corporate group.

Data Subject Rights Management

Procedures should be implemented to ensure that individuals can effectively exercise their rights under the PDPA, regardless of which group entity is processing their personal data.

Cross-Border Transfer Controls

Companies should maintain accurate records of international data flows and implement controls governing transfers among participating entities.

Security and Incident Response

Appropriate technical and organizational security measures should be documented and consistently applied throughout the corporate group.

Monitoring and Auditing

Organizations should implement mechanisms to monitor compliance, conduct internal audits, and address identified deficiencies.

Training and Awareness

Regular employee training programs should be established to ensure that personnel understand and comply with the requirements of the BCR framework.

Alignment with Global Compliance Programs:

Many multinational organizations have already adopted BCRs or similar governance frameworks to comply with privacy laws in other jurisdictions.

For these organizations, the new regulation may provide an opportunity to leverage existing privacy governance structures while extending their applicability to Thailand-related data transfers.

However, organizations should not assume that existing frameworks will automatically satisfy the PDPC’s certification requirements. A careful review of the regulation and supporting documentation will be necessary to identify any jurisdiction-specific requirements.

Looking Ahead:

The introduction of the BCR certification regime demonstrates the continued development of Thailand’s data protection framework and reflects the increasing importance of international data flows in modern business operations.

As organizations continue to centralize functions, deploy cloud-based technologies, and expand artificial intelligence initiatives, the ability to move personal data across borders in a compliant and efficient manner will become increasingly important.

The availability of certified BCRs provides multinational groups with an additional tool for managing these transfers while maintaining consistent privacy standards across their global operations.

Key Takeaways:

  • The PDPC’s Regulation on the Examination and Certification of Binding Corporate Rules became effective on 17 February 2026.
  • The framework introduces a formal mechanism for certifying BCRs as a safeguard for intra-group cross-border transfers of personal data.
  • Certified BCRs may provide multinational corporate groups with a more scalable alternative to maintaining multiple contractual transfer arrangements.
  • The regime is particularly relevant for regional shared-service centers, cloud operations, multinational technology companies, and organizations conducting AI development activities.
  • Businesses considering certification should assess whether their privacy governance, security, accountability, and compliance frameworks are sufficiently mature to meet the PDPC’s requirements.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Approves Draft Royal Decree on Inter-Agency Personal Data Sharing

On 5 May 2026, the Thai Cabinet approved in principle the Draft Royal Decree on the Disclosure of Personal Data under the Control of State Agencies to Other State Agencies (B.E. .…) (the “Draft Royal Decree”), as proposed by the Office of the Council of State.

The Draft Royal Decree represents a significant development in Thailand’s digital government agenda and is expected to substantially expand the capacity of state agencies to exchange and process personal data across the public sector.

The measure seeks to establish a centralized legal framework for inter-agency data sharing in support of more integrated and efficient public administration. It also forms part of Thailand’s broader transition toward a digital and data-driven government, with the stated aims of strengthening welfare systems, improving regulatory coordination, and streamlining public services.

Background and Policy Objectives

Historically, personal data held by Thai government agencies has remained fragmented across separate authorities and databases. This fragmentation has frequently resulted in duplicated procedures, inconsistent records, delays in public service delivery, and constraints on data-driven policymaking.

The Draft Royal Decree seeks to address these challenges by requiring state agencies to disclose relevant personal data to other government agencies upon request, where such disclosure serves public administration purposes. The stated objective is to facilitate more effective governance while reducing administrative burdens on citizens and businesses.

The Draft Royal Decree also seeks to balance greater data accessibility with robust safeguards relating to confidentiality, cybersecurity, and data protection compliance.

Key Provisions of the Draft Royal Decree

1. Mandatory Disclosure Between State Agencies

Under the Draft Royal Decree, state agencies would be required to disclose personal data under their control to other state agencies upon request. The proposed framework is intended to facilitate:

  • inter-agency data linkage;
  • integrated digital government services;
  • more efficient welfare administration; and
  • evidence-based policymaking.

This would represent a material departure from the current framework, under which data sharing between agencies is often limited, fragmented, or governed by sector-specific regulations.

2. Restrictions on Further Disclosure

The Draft Royal Decree imposes obligations on receiving agencies to safeguard any personal data disclosed to them. In particular, receiving agencies must:

  • maintain the confidentiality of the disclosed data; and
  • refrain from disclosing such data to external parties, whether public or private.

These requirements are designed to establish a controlled framework governing the circulation of personal data within the public sector.

3. Security and Cybersecurity Compliance

The handling and protection of shared data must comply with:

  • criteria prescribed by the Official Information Commission (“OIC”); and
  • applicable cybersecurity standards.

The inclusion of cybersecurity obligations reflects growing regulatory concern regarding unauthorized access, data breaches, and the risks associated with large-scale government data integration.

Interaction with Thailand’s PDPA

One of the most significant legal implications of the Draft Royal Decree lies in its interaction with the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”). The Draft Royal Decree appears intended to qualify as “other law” within the meaning of Section 21(2) of the PDPA. If enacted, this would permit state agencies to process personal data for purposes beyond those originally notified to data subjects, provided that such processing is authorized under the Royal Decree.

In practice, this may operate as a statutory exception to the PDPA’s purpose limitation principle in the context of inter-agency data sharing within the public sector, thereby granting state agencies broader authority to reuse, exchange, and integrate personal data where necessary for public administration and service delivery.

Expected Impact

The Draft Royal Decree is expected to advance Thailand’s transition toward a more integrated digital government by:

  • reducing duplication across government databases;
  • streamlining administrative procedures;
  • improving access to public services;
  • enhancing transparency and regulatory oversight;
  • supporting anti-corruption initiatives; and
  • enabling more effective monitoring of informal economic activity.

For businesses and individual citizens, the proposed framework may reduce the need for repetitive document submissions and administrative formalities when dealing with government authorities.

At the same time, the expanded ability of state agencies to access and process personal data is likely to attract increased scrutiny with respect to proportionality, data governance standards, inter-agency oversight mechanisms, and the adequacy of cybersecurity safeguards.

The Draft Royal Decree may accordingly prove to be a defining development in Thailand’s evolving public-sector data governance landscape, particularly as government agencies continue to expand their digital infrastructure and interconnected service delivery capabilities.

Key Takeaways

  • Thailand is advancing toward a mandatory inter-agency data sharing framework within the public sector.
  • State agencies may be legally required to disclose personal data to other government authorities upon request.
  • Receiving agencies must maintain confidentiality and comply with applicable cybersecurity and data protection standards.
  • The Draft Royal Decree may operate as an “other law” exception under the PDPA, permitting broader processing of personal data by state agencies.
  • The proposed framework forms part of Thailand’s broader digital government strategy, aimed at improving administrative efficiency, regulatory coordination, and public service delivery.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Medical Data: Balancing Privacy and Legal Needs in Inheritance and Liability Cases

In Thailand, the disclosure of medical records involves a delicate balance between protecting patient privacy and enabling access for legitimate purposes, such as legal proceedings. A landmark 2025 ruling by the Official Information Board’s Appeal Committee (Social Affairs, Public Administration, and Law Enforcement Branch) illustrates this principle: a public hospital initially refused to release a deceased patient’s treatment history, but the board overturned the decision, ordering disclosure to support a civil lawsuit.

Case Summary: Authorized Representative Seeking Records for Tort Claim

The appellant sought the medical treatment records of “Ms. K.” (a pseudonym), their full sibling who had passed away. The hospital denied the request, citing privacy concerns.

On appeal, the Committee found that:

  • The appellant was acting under a power of attorney granted by “Mrs. B” (the mother of the deceased and a legal heir).
  • The records were needed to support a tort lawsuit alleging medical negligence that contributed to Ms. K.’s death.
  • Since the patient was deceased and unable to request the records herself, the authorized representative was exercising rights on her behalf.
  • This was pursuant to the Ministerial Regulation No. 2 (B.E. 2541 (1998)) issued under the Official Information Act, B.E. 2540 (1997), which allows designated representatives to access information when the data subject is incapacitated or deceased.

The Committee explicitly ruled that this did not constitute a request for “another person’s health information” under Section 7 of the National Health Act, B.E. 2550 (2007). After weighing the agency’s legal duties, public interest, and private benefits, the board concluded that disclosure was justified, with appropriate redactions for unrelated personal data.

This decision reinforces that authorized heirs or representatives can access deceased patients’ records for legitimate legal purposes without violating core privacy protections.

Key Legislation Governing Medical Record Disclosure:

  1. Official Information Act, B.E. 2540 (1997) Public agencies, including state hospitals, must disclose official information upon request (Section 11). Exceptions include personal data where disclosure would unreasonably invade privacy (Sections 14-15). Appeals against refusals are handled by the Official Information Board, whose rulings are binding. Ministerial Regulation No. 2 (B.E. 2541) specifically permits representatives to act for deceased or incapacitated individuals.
  2. National Health Act, B.E. 2550 (2007) Section 7 protects health information privacy and restricts disclosure of “another person’s” data without consent. However, as clarified in this ruling, requests by authorized representatives of deceased patients fall outside this prohibition when tied to legal rights.
  3. Personal Data Protection Act, B.E. 2562 (2019) (PDPA). Health data is sensitive personal data requiring strict protection. Exemptions apply for legal claims, compliance with law, or court processes. Disclosures mandated by the OIB under the OIA are generally permissible.
  4. Medical Profession Act, B.E. 2525 (1982), and Hospital Regulations. These impose confidentiality on healthcare providers but allow exceptions for legal obligations or authorized requests.

How These Laws Interact:

The system operates through complementary layers:

  • Patient/Representative Rights vs. Third-Party Requests: Direct access (by patients or proxies) is facilitated under the National Health Actม B.E. 2550 (2007)  and OIA regulations, while unrelated third-party requests face higher barriers.
  • Privacy vs. Justice: Hospitals often invoke Section 7 of the National Health Act, B.E. 2550 (2007) or PDPA to refuse, but the OIB can override when disclosure serves legal accountability (e.g., malpractice suits) without undue harm.
  • Deceased Persons’ Data: Post-mortem privacy persists, but heirs’ inheritance or liability claims create legitimate interests, resolved via representative powers under OIA regulations.
  • Enforcement Mechanism: OIA appeals provide an administrative remedy, binding on public agencies. Parallel court subpoenas or PDPA complaints may arise in complex cases.

This ruling sets valuable precedent for families pursuing medical negligence claims after a relative’s death. Individuals facing similar denials should document authorization (e.g., power of attorney from heirs) and appeal through the Official Information Commission (oic.go.th). Consulting legal experts or the Ministry of Public Health can further clarify rights in such sensitive matters.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPA: Administrative Fine

The Personal Data Protection Act B.E. 2562 (2019) (PDPA) of Thailand, enforced from June 1, 2022, has reshaped the data protection landscape by mandating strict compliance standards for organizations. One of the key enforcement tools available under the PDPA is the imposition of administrative fines for non-compliance.

Following the issuance of the Royal Gazette Notification in April 2025, the procedures for administrative fines are now clearly outlined. Below is a comprehensive overview of the administrative fine system and process.

Scope of Administrative Fines:

Administrative fines apply to:

  • Data Controllers who fail to comply with lawful processing, security standards, or respect for data subject rights.
  • Data Processors who act beyond instructions or fail to maintain required security standards.
  • Representatives acting on behalf of overseas controllers or processors carrying out activities in Thailand.

Violations triggering fines include:

  • Unlawful data processing without valid consent or legal basis.
  • Inadequate responses to data subject rights.
  • Failure to report data breaches promptly.
  • Unauthorized data sharing or cross-border data transfers.
  • Absence of proper organizational security measures.

Authorities Empowered to Act:

The Personal Data Protection Committee (PDPC) and its designated investigating officers have the authority to:

  • Conduct investigations.
  • Summon witnesses and request evidence.
  • Recommend fines for PDPC approval.
  • Issue administrative orders enforceable under administrative law.
close up shot of a typewriter

PDPA Administrative Fine Process:

The administrative fine process is clearly structured into the following key stages:

1. Preliminary Investigation

An investigating officer gathers evidence, interviews involved parties, and assesses whether there are grounds for a violation. If sufficient evidence exists, the officer proceeds with the next step.

2. Notice of Allegations

The alleged violator receives a formal notification, detailing:

  • The alleged facts.
  • Applicable legal provisions breached.
  • The right to submit a defense or clarifications within a stipulated period.

3. Consideration and Decision

The competent authority reviews all evidence, defenses, and mitigating factors. The seriousness of the violation, damages, prior conduct, and cooperation are taken into account when determining the fine amount.

4. Issuance of Administrative Order

An administrative order is issued specifying:

  • The nature of the violation.
  • The amount of the fine imposed.
  • Payment instructions and deadlines.

Failure to comply may result in further legal enforcement actions.

5. Right to Appeal

The fined party may appeal the administrative order in accordance with the Administrative Procedure Act B.E. 2539 (1996).

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPA: Handling Personal Data of Third-Party Representatives in Contractual Communications

Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) regulates how companies, say Company K, which provides building management and outsourcing services, manage personal data. The Subcommittee under the Personal Data Protection Committee has clarified Company K’s obligations regarding consent and lawful bases for data processing in two scenarios: business transactions with representatives and property management services. This analysis details the facts, the subcommittee’s rulings, and the compliance implications.

Factual Background:

Company K operates in building administration and outsourcing, requiring the collection, use, and disclosure of personal data. It raised two issues: (1) When dealing with natural persons or entities, it coordinates with employees or agents, collecting their names, phone numbers, and other personal data – does it need their consent? Given Section 24(3)’s contractual exemption applies only to direct parties? (2) When managing condominiums/villages, either as the legal manager or an outsourced administrator, it handles residents’ data for billing, security, parking stickers, registries, and services—must it obtain consent, or does an exemption apply?

Subcommittee Decisions:

The subcommittee provided rulings on both issues:

  1. Data of Representatives in Business Transactions
    • Case 1: Natural Person as Counterparty: When Company K contracts with an individual (e.g., for goods and services), it can collect their data under PDPA Section 24(3)—necessary for contract performance or pre-contractual steps—without consent. This includes names and contact details for coordination, as the individual is a direct party.
    • Case 2: Representatives of Entities: When coordinating with employees/agents of a legal entity counterparty, these individuals are not parties to the contract, so Section 24(3) does not apply. Instead, Company K can use Section 24(5)—legitimate interests—if the data collection (e.g., names, phone numbers for quotes and documents) is necessary, outweighs data subject rights, and respects reasonable expectations in business contexts. Caution is required to minimize impact and avoid excessive use. For sensitive data under Section 26 (e.g., health and criminal records), additional lawful bases from Section 26 are needed. Consent is not mandatory if these conditions are met.
  2. Data of Residents in Property Management
    • Whether Company K manages a condominium/village as the legal entity (registered under condominium or land allocation laws) or as an outsourced administrator, it processes residents’ data (e.g., for billing, security and parking) under instructions from the condominium/village legal entity. Here, Company K is not a “data controller” (Section 6)—an entity deciding data use—but a “data processor” (Section 40), acting on behalf of the controller (the legal entity). The controller must secure a lawful basis under Sections 24 or 26 (e.g., contract and legal duty), not Company K. As a processor, Company K does not need residents’ consent or a direct lawful basis; it follows the controller’s lawful instructions (Section 40(1)). The controller must establish a data processing agreement per Section 40, paragraph 3, ensuring compliance.
close up of a smart phone with a lock

Implications for Compliance:

Company K can avoid consent in business dealings by leveraging contractual (Section 24(3)) or legitimate interest (Section 24(5)) bases, tailoring its approach to the counterparty’s status, with extra care for sensitive data. In property management, its processor role shifts responsibility to the legal entity, requiring clear agreements to define duties and ensure lawful data handling. This dual framework simplifies Company K’s compliance while upholding PDPA standards.

Key Takeaways:

  • Contractual Base for Direct Parties: Section 24(3) exempts consent for natural person counterparties, covering pre and post-contract data.
  • Legitimate Interest for Agents: Section 24(5) supports collecting representatives’ data without consent, if necessary and balanced, with Section 26 for sensitive data.
  • Processor Role in Management: As a processor, Company K does not need consent or a direct basis; the controller (legal entity) bears that duty.
  • Agreements Are Key: Section 40 mandates controller and processor agreement to align outsourced data handling with PDPA.

This ruling enables Company K to streamline operations under PDPA, distinguishing its roles and leveraging exemptions effectively.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles