PDPA Insights: Building Effective Privacy Governance

PDPA: Data Breach Governance Is More Than a 72-Hour Deadline

One of the best-known requirements under Thailand’s Personal Data Protection Act (PDPA) is the obligation to notify the Personal Data Protection Committee (PDPC) of certain personal data breaches without undue delay and, where required, within 72 hours.

As a result, many organizations approach breach preparedness primarily as a reporting exercise. Internal discussions often focus on when the 72-hour period begins, what information should be included in the notification, and whether affected individuals must also be informed.

These are important questions.

They are also the wrong place to begin.

The Personal Data Protection Committee’s recent consultation on security measures and personal data breach management suggests a broader regulatory perspective. Rather than treating breach notification as the central compliance obligation, the consultation emphasizes governance before, during and after a security incident. It discusses risk management, organizational measures, technical safeguards, incident response planning, documentation, and continuous improvement as integral components of compliance. The message is clear: a well-governed organization should be managing breach risk long before it considers whether a notification must be submitted.

A breach rarely begins with the breach:

Organizations often describe a breach as a discrete event.

An employee clicks a malicious link.

A laptop is stolen.

A cloud storage bucket is misconfigured.

A ransomware attack encrypts corporate systems.

Yet these events rarely occur in isolation.

Most data breaches reflect weaknesses that existed long before the incident itself. Poor access management, inadequate vendor oversight, outdated systems, excessive user privileges, insufficient employee training, and incomplete asset inventories frequently contribute to the eventual breach.

Consequently, organizations should regard breach management as an ongoing governance process rather than an emergency response exercise.

The most effective incident response plans are developed before they are needed.

Security is an organizational responsibility:

Information security is often viewed primarily as an IT issue.

The PDPA takes a broader approach.

Protecting personal data requires coordinated action across multiple business functions.

Senior management establishes governance.

Human resources develops training.

Procurement evaluates vendors.

Legal reviews contractual protections.

Business units determine what personal data is collected and why.

Information technology implements technical controls.

Each function contributes to reducing breach risk.

Organizations that treat cybersecurity as the sole responsibility of technical teams may overlook governance failures that contribute equally to privacy incidents.

Incident response plans should answer practical questions:

Many organizations maintain incident response policies that satisfy regulatory requirements but provide limited operational guidance.

An effective incident response plan should answer practical questions before an incident occurs.

Who investigates the incident?

Who determines whether personal data has been compromised?

Who decides whether notification is required?

Who communicates with regulators?

Who informs affected individuals?

Who preserves evidence?

Who approves public statements?

Who manages communications with vendors?

These decisions should not be made for the first time during a cybersecurity incident.

Clear governance significantly improves response quality while reducing confusion during high-pressure situations.

Vendors increasingly determine organizational resilience:

Modern organizations rarely process personal data entirely within their own infrastructure.

Cloud providers.

Payroll processors.

CRM vendors.

Marketing platforms.

AI providers.

Managed security services.

Software developers.

Each may process significant volumes of personal data on the organization’s behalf.

Consequently, incident preparedness increasingly depends upon vendor governance.

Organizations should understand how vendors detect incidents, when they notify customers, what contractual obligations apply, how investigations are coordinated, and whether subcontractors introduce additional risk.

Vendor due diligence should therefore extend beyond procurement and continue throughout the contractual relationship.

Documentation matters before regulators ask for it:

Organizations often focus on documenting the breach itself.

Increasingly, regulators may also expect organizations to demonstrate what preventive measures existed before the incident.

Could the organization explain:

  • why specific security measures were selected?
  • why particular risks were considered acceptable?
  • when systems were last reviewed?
  • whether employees received appropriate training?
  • whether incident response plans had been tested?
  • whether previous incidents had resulted in corrective action?

These questions reflect organizational accountability rather than incident reporting.

Good documentation demonstrates that the organization actively managed risk rather than merely reacting after an incident occurred.

Every breach should improve the organization:

The conclusion of an investigation should not mark the end of breach management.

Every incident provides an opportunity to improve governance.

Organizations should conduct post-incident reviews addressing not only technical causes but also organizational lessons.

Were responsibilities clearly allocated?

Did communication function effectively?

Were vendors responsive?

Did documentation prove sufficient?

Were customers informed appropriately?

Could similar incidents occur elsewhere within the organization?

Continuous improvement is one of the strongest indicators of a mature privacy governance program.

The future of breach management:

Cyber threats will continue to evolve.

Artificial intelligence will introduce new attack vectors.

Cloud ecosystems will become increasingly complex.

Third-party dependencies will continue expanding.

Against this background, organizations should avoid viewing the PDPA primarily as imposing notification obligations.

The broader challenge is establishing governance capable of identifying, managing and learning from security incidents before they become regulatory problems.

The organizations that respond most effectively to future breaches are unlikely to be those that simply notify within 72 hours.

They will be those that can demonstrate that security, governance and accountability existed long before the incident occurred.

Key takeaways:

  • Personal data breach management begins before a breach occurs through governance, risk management and organizational preparedness.
  • Effective breach response requires coordination among legal, IT, information security, procurement, human resources and senior management.
  • Incident response plans should allocate responsibilities and decision-making authority before an incident arises.
  • Vendor governance has become an essential component of breach preparedness because third-party providers increasingly process personal data on behalf of organizations.
  • Documentation of preventive measures and continuous improvement may become as important as the breach notification itself.
  • Organizations should view breach management as an ongoing governance process rather than a regulatory reporting obligation.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

Anti-Bribery: Digital Government Data Integration Raises Compliance Expectations

Thailand’s Cabinet has acknowledged progress on a series of anti-bribery initiatives designed to strengthen transparency and improve the government’s ability to detect corruption. While the measures remain at the policy and implementation stage, they indicate a clear direction toward greater use of digital government systems, cross-agency data integration, and risk-based monitoring.

For businesses that interact with government agencies, participate in public procurement, or operate in regulated industries, these developments are likely to increase compliance expectations even before new legal requirements are formally introduced.

Key Policy Developments:

The government’s anti-bribery initiatives contemplate a more integrated approach to corruption prevention through digital technologies and inter-agency cooperation. Key initiatives include:

  • Integration of financial, tax, and public procurement data across government agencies.
  • Greater public disclosure of government information through centralized digital platforms.
  • Expansion of end-to-end digital government services to reduce discretionary human interaction.
  • Use of data analytics and risk assessment tools to identify suspicious transactions and detect corruption proactively.
  • Consideration of incentive mechanisms to encourage greater private-sector participation in anti-corruption efforts.

Although these initiatives primarily reflect policy direction, they are consistent with Thailand’s broader digital government strategy and increasing reliance on technology to strengthen regulatory oversight.

Practical Implications for Businesses:

Businesses should anticipate that government agencies will increasingly be able to cross-reference information obtained from different regulatory systems. As digital integration expands, inconsistencies or unusual transaction patterns may become more visible.

Particular attention should be paid to:

Increased Cross-Database Verification:

Payments, tax filings, procurement records, licensing information, and other regulatory submissions may increasingly be compared across multiple government databases. Information that previously existed in separate systems may become easier for authorities to analyze collectively.

Higher Scrutiny of Third-Party Relationships:

Transactions involving consultants, agents, brokers, intermediaries, subcontractors, and other third parties are likely to attract greater regulatory attention. Authorities may increasingly examine whether such arrangements serve legitimate business purposes or could conceal improper payments or undisclosed benefits.

Enhanced Documentation of Business Hospitality and Related Expenditures:

Corporate hospitality, gifts, sponsorships, charitable contributions, travel expenses, and any facilitation-type payments should be supported by clear business justifications, documented approval processes, and appropriate accounting records. Well-documented decision-making will become increasingly important if government agencies rely on integrated digital records during investigations.

Greater Focus on Third-Party Due Diligence:

Businesses should expect growing emphasis on robust third-party risk management, including:

  • Appropriate due diligence before engaging intermediaries;
  • Verification of beneficial ownership where appropriate;
  • Ongoing monitoring of higher-risk business partners; and
  • Documentation demonstrating that compensation arrangements are commercially reasonable.

Recommended Compliance Actions:

Even in the absence of new mandatory legal obligations, organizations should consider reviewing whether their anti-corruption compliance framework remains appropriate for an increasingly data-driven enforcement environment.

Areas for review include:

  • Anti-bribery and anti-corruption policies;
  • Approval matrices for gifts, entertainment, sponsorships, donations, and government-related expenditures;
  • Conflict-of-interest declaration procedures;
  • Gift and hospitality registers;
  • Third-party due diligence procedures;
  • Beneficial ownership verification processes;
  • Record-keeping and supporting documentation standards; and
  • Whistleblowing channels and internal investigation procedures.

Particular attention should be given to employees who regularly interact with government officials, including sales personnel, business development teams, procurement staff, regulatory affairs personnel, and employees responsible for obtaining government approvals or participating in public procurement.

Looking Ahead:

The government’s continued investment in digital infrastructure suggests that anti-corruption enforcement may increasingly rely on data integration and analytical tools rather than solely on traditional investigations or complaints. As government agencies gain greater ability to connect information across multiple regulatory systems, businesses should expect higher standards of transparency, documentation, and governance.

Organizations that strengthen their compliance controls now will be better positioned to respond to increased regulatory scrutiny and demonstrate effective anti-bribery compliance as Thailand’s digital government initiatives continue to evolve.

Key Takeaways:

Businesses should review their anti-bribery policies, third-party due diligence procedures, conflict-of-interest controls, gift registers, and whistleblowing mechanisms to ensure they remain effective in an increasingly digital regulatory environment.

Government agencies are moving toward greater integration of financial, tax, procurement, and regulatory data.

Cross-agency data sharing is likely to increase the detection of inconsistent or high-risk transactions.

Third-party relationships, including consultants, agents, brokers, and subcontractors, are expected to receive greater scrutiny.

Gifts, hospitality, sponsorships, charitable contributions, and other government-related expenditures should be supported by clear documentation and approval records.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand and China Strengthen Cooperation on IP Enforcement

The Thai Cabinet has approved a draft Memorandum of Understanding (MOU) between the Ministry of Commerce of Thailand and China’s market regulatory authority to strengthen cooperation on intellectual property enforcement.

The proposed cooperation framework includes information sharing, coordination on IP enforcement, and cooperation in training and capacity building for enforcement officials. The MOU is intended to facilitate closer administrative cooperation between the two authorities and enhance enforcement effectiveness against IP infringement.

Practical implications for businesses:

The MOU does not create a mechanism allowing rights holders to file cross-border enforcement requests directly or alter existing enforcement procedures in either jurisdiction. Nevertheless, it reflects a policy direction toward closer administrative cooperation between Thailand and China.

Businesses that manufacture, distribute, or sell products in China, particularly through e-commerce platforms, should consider strengthening their cross-border IP enforcement strategy by:

  • ensuring that trademarks, patents, and other IP rights are separately registered in China, as protection in Thailand does not extend automatically to China;
  • maintaining evidence of ownership and use of IP rights, distribution channels, and suspected counterfeit products;
  • reviewing agreements with manufacturers, distributors, and online platform operators to ensure adequate IP protection and enforcement provisions; and
  • considering customs recordation and online takedown procedures as part of an integrated enforcement strategy, alongside civil or administrative actions where appropriate.

The development is particularly relevant for brand owners in consumer goods, fashion, cosmetics, food and beverage, and businesses that rely heavily on cross-border e-commerce.

Key takeaways:

Although the proposed MOU does not introduce new legal remedies for rights holders, it signals stronger institutional cooperation between Thai and Chinese enforcement authorities. Businesses with commercial activities in China should ensure that their IP portfolios and enforcement strategies are prepared to take advantage of enhanced cross-border administrative coordination as it develops

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Supreme Court Confirms Internal Estate Rules Cannot Override the Land Allocation Act

A recent Supreme Court judgment provides important guidance on the limits of a housing estate juristic person’s authority under the Land Allocation Act. In Supreme Court Judgment, the Court held that internal regulations and resolutions adopted by members cannot override mandatory statutory provisions or expand the powers granted to a housing estate juristic person under the Act.

Although the dispute concerned the retention of a construction security deposit, the decision has broader implications for developers, housing estate juristic persons, property managers, and homeowners. It reinforces the principle that private governance documents cannot be used to circumvent statutory protections established under the Land Allocation Act.

Background:

The dispute arose after a homeowner obtained permission from a housing estate juristic person to renovate a house within the estate. As required under the estate’s procedures, the homeowner paid construction security deposits before commencing the renovation works.

The renovation was completed without causing any damage to the estate’s common property or infrastructure. The homeowner subsequently requested the return of the deposits.

The housing estate juristic person refused to refund the full amount, arguing that, under its internal regulations and resolutions adopted at members’ meetings, it was entitled to retain part of the deposits as contributions toward the maintenance of common property.

The Court of First Instance dismissed the homeowner’s claim. However, the Court of Appeal reversed that decision and ordered the housing estate juristic person to refund the retained amount together with statutory interest. The housing estate juristic person appealed to the Supreme Court.

Supreme Court’s Decision:

The Supreme Court upheld the appellate judgment.

The Court first examined the legal purpose of a construction security deposit. It held that such a deposit is intended solely to secure compensation for potential damage to common property or common facilities arising from construction or renovation works.

Because the renovation had been completed without any damage to the common property, the purpose of the security deposit had been fulfilled. Consequently, the housing estate juristic person had no legal basis to continue holding the deposit.

The Court rejected the argument that the retained amount could instead be treated as common area maintenance fees.

Internal Regulations Cannot Override the Act:

The central issue before the Supreme Court was whether the housing estate juristic person could rely on its internal regulations and resolutions adopted by members to justify retaining part of the construction security deposit.

The Court answered this question in the negative.

The Supreme Court observed that the collection and administration of maintenance fees for common property are comprehensively governed by the Land Allocation Act and the subordinate regulations issued under that legislation. The statutory framework prescribes how maintenance fees are to be imposed, collected, and administered.

Accordingly, a housing estate juristic person cannot create an alternative collection mechanism simply because it has been approved by members or incorporated into the estate’s internal regulations.

The Court emphasized that internal regulations may facilitate the administration of the estate but cannot enlarge the statutory powers granted by the Land Allocation Act or create rights that are inconsistent with the legislation.

The Land Allocation Act Is Mandatory Legislation:

Perhaps the most significant aspect of the judgment is the Court’s characterization of the Land Allocation Act itself.

The Supreme Court expressly stated that the Act is legislation enacted to protect purchasers of land allocation projects and concerns matters of public order. As a result, private arrangements that are inconsistent with the statutory framework cannot prevail.

This means that even unanimous resolutions adopted by members of a housing estate juristic person cannot authorize practices that conflict with the Act.

The Court further reasoned that allowing construction security deposits to be retained as maintenance fees would effectively establish an alternative method of collecting maintenance fees that is not contemplated by the legislation. Such an arrangement would undermine the statutory scheme governing the management of housing estates.

Practical Implications:

The judgment has implications extending well beyond construction security deposits.

Housing estate juristic persons should review their bylaws, regulations, and resolutions to ensure that they remain consistent with the Land Allocation Act. Provisions that seek to create additional collection rights or modify statutory obligations may be vulnerable to legal challenge.

Developers and property managers should likewise review renovation procedures and security deposit arrangements to ensure that deposits are used solely for their intended purpose and are refunded promptly once the statutory conditions for their retention no longer exist.

The decision also serves as a reminder that internal governance documents—including estate regulations, bylaws, and members’ resolutions—cannot enlarge statutory powers or circumvent mandatory provisions enacted to protect purchasers.

Key Takeaways:

Housing estate juristic persons should review their internal regulations and operational practices to ensure they do not purport to exercise powers beyond those conferred by the Land Allocation Act.

Supreme Court Judgmentconfirms that internal regulations and members’ resolutions of a housing estate juristic person cannot override the Land Allocation Act.

The Land Allocation Act provides the exclusive statutory framework governing the collection and administration of maintenance fees.

Construction security deposits may only be used for their statutory purpose of securing compensation for damage arising from construction or renovation works.

Once renovation is completed without damage, the legal basis for retaining the security deposit ceases to exist.

The Supreme Court reaffirmed that the Land Allocation Act is mandatory legislation enacted to protect purchasers and concerns matters of public order, meaning inconsistent private arrangements are unenforceable.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand signals a shift toward expenditure-based management of universal healthcare

Thailand’s universal healthcare system has long been regarded as one of the country’s most successful public policy achievements. However, increasing healthcare utilization, an aging population, rising treatment costs, and fiscal constraints are prompting policymakers to reconsider how the system should be financed over the long term.

Recent policy discussions within the Ministry of Public Health indicate that the focus is no longer solely on expanding healthcare benefits. Instead, the government appears to be moving toward a framework that emphasizes expenditure management, efficiency, and value-based healthcare while maintaining universal access to essential medical services.

Shift from expanding benefits to managing sustainability:

Thailand’s public healthcare system is primarily delivered through three government-funded schemes:

  • the Universal Coverage Scheme (UCS);
  • the Social Security Scheme (SSS); and
  • the Civil Servant Medical Benefit Scheme (CSMBS).

Although annual government appropriations for these schemes have continued to increase, healthcare expenditure has grown at an even faster pace due to demographic changes, increasing prevalence of chronic diseases, advances in medical technology, and greater public expectations regarding access to treatment. Policymakers have therefore expressed concern that healthcare expenditure may outpace long-term fiscal capacity unless structural reforms are implemented.

Proposed expenditure management measures:

Current policy discussions suggest that future reforms may include greater reliance on expenditure controls rather than across-the-board budget increases.

Measures under consideration reportedly include:

  • expenditure ceilings for public hospitals;
  • tighter monitoring of hospital operating costs, pharmaceuticals, and medical supplies;
  • wider use of digital technologies and data analytics to improve financial oversight;
  • periodic review of healthcare benefit packages to prioritize clinically effective and cost-effective services; and
  • broader adoption of value-based healthcare models that reward providers based on patient outcomes rather than service volume.

These initiatives reflect an effort to improve efficiency without fundamentally changing the principle of universal healthcare coverage.

Potential implications for healthcare providers:

Public hospitals may face increasing pressure to operate within fixed budgetary allocations while maintaining service quality. More sophisticated financial management, procurement practices, and clinical governance are therefore likely to become increasingly important.

Healthcare providers may also experience:

  • greater scrutiny of prescribing practices;
  • stronger emphasis on evidence-based treatment pathways;
  • expanded use of health technology assessment in reimbursement decisions; and
  • increased reporting and compliance obligations relating to cost management.

Private healthcare providers participating in government reimbursement programs may likewise experience closer oversight of reimbursement methodologies and service delivery standards.

Regulatory considerations:

While no legislative amendments have fundamentally altered Thailand’s universal healthcare framework, any future implementation of expenditure caps or revised reimbursement mechanisms will require careful alignment with existing legislation governing public health financing and healthcare entitlements.

Future regulatory developments may include:

  • revised payment methodologies;
  • updated reimbursement criteria;
  • enhanced procurement controls;
  • expanded digital monitoring of healthcare expenditure; and
  • revised administrative guidelines governing public healthcare providers.

Businesses operating in the healthcare, pharmaceutical, medical device, and digital health sectors should therefore continue to monitor policy developments, as changes in reimbursement and procurement practices may influence market access and commercial strategies.

Key takeaways:

  • Thailand is shifting its healthcare policy emphasis from expanding benefits toward improving financial sustainability.
  • Expenditure management and value-based healthcare are emerging as central policy themes.
  • Public hospitals are likely to face tighter budgetary controls and enhanced financial oversight.
  • Healthcare suppliers should anticipate increasing scrutiny of reimbursement, procurement, and cost-effectiveness.
  • Although universal healthcare remains intact, future reforms are expected to focus on preserving the system through more disciplined allocation of healthcare resources rather than unlimited expenditure growth.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Ride-Sharing Platforms Face New Digital Governance Requirements

Thailand has completed another important step in regulating ride-sharing services by introducing additional obligations for digital platform operators under the Digital Platform Services (DPS) regime.

While the Department of Land Transport (DLT) regulates the transport aspects of ride-sharing—including the licensing of drivers, vehicles, and transport operators—the Electronic Transactions Commission (ETC), with the Electronic Transactions Development Agency (ETDA) serving as the regulator, has introduced additional operational requirements applicable specifically to ride-sharing platforms. These requirements are issued under the Royal Decree on Digital Platform Services Businesses Required to be Notified and are intended to strengthen platform governance, consumer protection, and regulatory oversight.

The new notification reflects the growing recognition that digital platforms are no longer merely technology providers but have become key participants in the delivery of transportation services.

Regulatory Background:

Until recently, Thailand’s regulation of ride-sharing focused primarily on transport law. Existing legislation governed the licensing of public vehicles and drivers, while digital platforms facilitating ride-sharing services were subject mainly to general laws relating to electronic transactions, consumer protection, and personal data protection.

As app-based transportation became increasingly popular, regulators recognized that platforms exercise substantial control over the passenger experience. Platforms determine which drivers are permitted to provide services, process payments, establish pricing mechanisms, collect user data, manage customer complaints, and may suspend or remove drivers from the platform.

Accordingly, Thailand has adopted a dual regulatory model.

The Department of Land Transport is responsible for transport regulation, including driver qualifications, vehicle registration, licensing requirements, and operational safety. Separately, the ETC and ETDA regulate the operation of ride-sharing platforms as digital platform services under the DPS Royal Decree. Rather than regulating the transportation service itself, the ETC notification focuses on the responsibilities of platform operators in operating their digital services responsibly and protecting users.

Why Ride-Sharing Platforms Are Subject to Additional Regulation:

The ETC considers ride-sharing platforms to present unique risks compared with many other digital platforms because they facilitate real-world services that directly affect users’ safety and involve continuous interaction between passengers and drivers.

Unlike a conventional online marketplace, ride-sharing platforms influence who may provide transportation services, verify drivers’ qualifications, allocate trips, process payments, and maintain records relating to every journey.

For these reasons, the notification establishes additional operational requirements specifically for ride-sharing platforms.

Enhanced Driver and Vehicle Verification:

One of the principal obligations is the requirement for platform operators to verify that drivers and vehicles satisfy applicable transport law requirements before allowing them to accept bookings.

Platforms are expected to establish systems capable of verifying that:

  • drivers possess the required public driving licences;
  • vehicles have been properly registered for public transport;
  • supporting documentation remains valid; and
  • drivers who no longer satisfy regulatory requirements are prevented from providing services through the platform.

This complements, rather than replaces, the DLT’s licensing framework by requiring platforms to actively support regulatory compliance.

Greater Transparency:

The notification also promotes greater transparency between platform operators and users.

Platforms are expected to provide users with clear and accessible information regarding matters such as:

  • applicable service terms and conditions;
  • pricing information and fees;
  • cancellation policies;
  • complaint procedures;
  • user rights and responsibilities; and
  • other information necessary for users to make informed decisions when using the service.

Greater transparency is intended to strengthen user confidence while reducing disputes arising from misunderstandings concerning platform operations.

Complaint Handling and User Protection:

Consumer protection is another central feature of the notification.

Platform operators are expected to establish accessible procedures allowing users to report complaints, safety incidents, inappropriate conduct, or other service-related concerns.

Operators should maintain procedures for:

  • receiving complaints;
  • investigating reported incidents;
  • communicating investigation outcomes;
  • providing appropriate remedies where justified; and
  • maintaining records of complaint resolution.

These requirements reinforce the principle that platform operators should actively manage user protection rather than relying solely on government enforcement.

Internal Governance and Regulatory Cooperation:

The notification also requires operators to implement appropriate internal governance measures.

Depending on the nature of the platform’s operations, these measures may include maintaining operational records, documenting compliance activities, monitoring platform risks, and cooperating with competent authorities when information is requested.

Such obligations support more effective regulatory supervision while encouraging platforms to adopt robust compliance management systems.

Relationship with Other Laws:

Compliance with the ETC notification does not eliminate obligations arising under other legal regimes.

Ride-sharing platform operators must continue to comply with:

  • transport regulations administered by the Department of Land Transport;
  • the Digital Platform Services Royal Decree and related notifications;
  • the Personal Data Protection Act;
  • consumer protection legislation; and
  • other applicable laws governing electronic transactions.

Businesses should therefore adopt an integrated compliance framework that addresses both transport regulation and digital platform governance.

Practical Implications:

The notification requires ride-sharing platforms to move beyond a purely commercial focus and adopt governance structures comparable to those expected of regulated digital intermediaries.

Operators should review whether their existing compliance programmes adequately address:

  • driver and vehicle verification;
  • platform transparency;
  • complaint handling procedures;
  • user protection measures;
  • internal governance policies;
  • document retention; and
  • coordination between transport compliance and digital platform compliance.

For international platform operators, many of these requirements may resemble governance obligations already implemented in other jurisdictions. Nevertheless, local compliance should be reviewed carefully because the Thai notification imposes specific obligations linked to Thailand’s transport regulatory framework.

Key Takeaways:

  • Thailand now regulates ride-sharing through complementary transport and digital platform regulatory regimes.
  • The Department of Land Transport oversees drivers, vehicles, and transport licensing, while the ETC/ETDA regulates the operation of ride-sharing platforms under the Digital Platform Services framework.
  • The new notification requires platforms to implement enhanced driver and vehicle verification, improve transparency, strengthen complaint handling, and maintain appropriate governance systems.
  • Platform operators should integrate transport compliance with digital platform compliance to satisfy Thailand’s evolving regulatory expectations.
  • The notification demonstrates Thailand’s broader policy of holding digital platforms directly accountable for the services they facilitate, rather than regulating only the underlying transport providers.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPA Insights: Building Effective Privacy Governance

PDPA: PDPC Clarifies the Scope of “Health Data”

The Personal Data Protection Committee (PDPC) has recently issued an advisory opinion addressing whether the appearance of the Thai Red Cross symbol and the wording indicating organ donor status on Thailand’s new driver’s license constitutes sensitive personal data under Section 26 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). While the factual question concerned organ donor status, the more significant legal development lies in the PDPC’s interpretation of what constitutes “health data” under the PDPA.

The issue arose following the Department of Land Transport’s introduction of a new driver’s license format that allows license holders who have registered their intention to donate organs with the Thai Red Cross Society to display the Thai Red Cross symbol together with a statement indicating organ donor status on the face of the license. A private-sector organization sought clarification from the PDPC regarding whether such information should be treated as sensitive personal data under Section 26 of the PDPA.

The PDPC’s Interpretation of Health Data:

Section 26 of the PDPA imposes enhanced protection requirements on certain categories of sensitive personal data, including data concerning health. However, the PDPA does not provide a specific definition of “health data”.

In considering the issue, the PDPC examined various legislative and regulatory sources relating to healthcare information. The Committee observed that information concerning healthcare services, healthcare-related intentions and the expression of wishes regarding organ donation have traditionally been regarded as information connected with an individual’s health and healthcare status.

The PDPC emphasized that the information displayed on the driver’s license is not merely a symbol or administrative notation. Rather, it reflects an individual’s expressed intention relating to organ donation and is intended to be used by medical personnel and relevant authorities in circumstances where healthcare services and organ transplantation procedures may become relevant. As a result, the information is intrinsically connected to healthcare services and medical treatment.

On that basis, the PDPC concluded that the status of being a registered organ donor, as displayed on a driver’s license, constitutes health-related personal data and therefore falls within the scope of Section 26 of the PDPA.

A Broader Understanding of Health Data:

The opinion provides an important indication of how the PDPC is likely to interpret health data in future cases.

Traditionally, organizations often associate health data with medical records, diagnoses, treatment histories, laboratory results or information concerning physical and mental conditions. The PDPC’s reasoning suggests that the concept is broader.

The Committee’s analysis indicates that information may qualify as health data even where it does not reveal a specific illness or medical condition. Information that reflects an individual’s healthcare-related intentions, healthcare choices or participation in healthcare-related activities may also fall within the scope of health data where such information is sufficiently connected to healthcare services or medical treatment.

This interpretation reinforces the need for organizations to assess the nature and purpose of information being processed rather than relying solely on traditional assumptions about what constitutes medical information.

Practical Implications:

Although the PDPC classified organ donor status as health data, the opinion also contains practical guidance for organizations that routinely collect copies of driver’s licenses.

The Committee recognized that where a data controller collects a copy of a driver’s license solely for identification or verification purposes and does not collect, use or disclose the organ donor information for the purpose of identifying an individual’s donor status or obtaining health-related information, such processing should not automatically be regarded as the collection of health data under Section 26 merely because the information incidentally appears on the document.

This aspect of the opinion will be particularly relevant to banks, financial institutions, insurers, employers, telecommunications providers and other organizations that regularly collect copies of official identification documents as part of their business operations.

At the same time, organisations that specifically collect, use or disclose information concerning donor status or other healthcare-related declarations should carefully assess whether Section 26 applies and whether an appropriate legal basis exists for the processing of such sensitive personal data.

Key Takeaways:

  • The PDPC has confirmed that organ donor status displayed on a driver’s license constitutes health-related personal data under Section 26 of the PDPA.
  • The opinion suggests that health data is not limited to medical records or information concerning diseases and medical conditions.
  • Information reflecting healthcare-related intentions, wishes or decisions may also constitute health data where it is closely connected to healthcare services or medical treatment.
  • Organizations should review whether information they process could reveal healthcare-related intentions or decisions, even where it does not contain traditional medical information.
  • The incidental collection of such information as part of a driver’s license copy does not necessarily mean that the organization is processing health data, provided the information is not used for health-related purposes.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

PDPA Insights: Building Effective Privacy Governance

PDPA: The PDPC Is Redefining Marketing Compliance

Marketing has evolved dramatically over the past decade, yet many organizations continue to approach compliance under Thailand’s Personal Data Protection Act (PDPA) as though marketing still begins with an email campaign or a promotional text message. In practice, modern marketing starts much earlier. Businesses routinely collect, combine and analyze personal data to understand customer behavior, predict purchasing decisions and personalize customer experiences long before any advertisement reaches its intended audience.

This transformation has gradually blurred the distinction between marketing, customer analytics and data governance. Customer relationship management (CRM) platforms, loyalty programs, online tracking technologies, behavioral advertising, recommendation engines and artificial intelligence (AI) have become ordinary components of commercial operations. Personal data is no longer used simply to communicate with customers; it is increasingly used to decide what products customers see, when they see them and how organizations engage with them.

Against this backdrop, the Personal Data Protection Committee (PDPC) has released a consultation draft on marketing and direct marketing. Although the consultation is not yet legally binding, it provides an important indication of how the regulator interprets marketing under the PDPA. Significantly, the consultation extends beyond traditional direct marketing to include digital marketing, cookies and tracking technologies, targeted advertising, profiling, AI-assisted personalization and automated decision-making. In doing so, it reflects a broader regulatory understanding of marketing itself. 

For businesses, this matters because it changes the focus of compliance. The central issue is no longer simply whether an organization has obtained consent before sending promotional communications. Increasingly, the question is whether the organization can justify and govern every significant use of personal data throughout the marketing lifecycle.

Marketing now begins with customer insight:

Traditional marketing compliance focused primarily on communications. Organizations assessed whether they could lawfully send promotional emails, SMS messages or telephone calls.

The consultation suggests that this perspective is becoming too narrow.

Marketing increasingly begins with customer insight rather than customer communication. Organizations analyze website activity, purchasing history, mobile application usage and online interactions to understand customer preferences before deciding which advertisements to display or which products to recommend. By the time a customer receives a promotional message, multiple processing activities may already have taken place.

Recognizing this distinction is essential. Compliance should not be confined to the final communication but should extend to the collection, analysis and use of personal data that supports marketing decisions.

The same customer data may support very different purposes:

One of the most significant practical consequences of this broader perspective is that organizations should avoid treating all customer information as though it were processed for a single purpose.

Consider an online retailer. Purchase history may initially be processed to complete an order and arrange delivery. The same information may later be used to administer a loyalty program, identify customer purchasing patterns, recommend complementary products, measure campaign effectiveness and improve future marketing strategies.

Although the dataset remains the same, the purposes differ.

This distinction is important because the PDPA regulates the processing of personal data according to purpose rather than according to the dataset itself. Organizations should therefore identify each processing activity separately and ensure that the legal basis relied upon corresponds to the actual business objective.

This represents a more sophisticated approach than simply obtaining a broad marketing consent covering every future use of customer information.

Profiling has become an ordinary commercial activity:

Customer profiling is no longer limited to technology companies.

Retailers recommend products based on purchasing history. Airlines personalize travel offers. Financial institutions categorize customers according to spending behavior. Hotels tailor promotions using previous booking information. Streaming services continuously refine recommendations according to viewing habits.

These activities have become standard business practice.

The more relevant compliance question is therefore no longer whether profiling occurs but whether profiling is appropriately governed.

Organizations should understand what information is analyzed, how customer profiles are created, whether those profiles influence commercial decisions and how customers are informed about these practices. Transparency becomes particularly important where profiling extends beyond simple customer segmentation and begins influencing individualized offers or recommendations.

AI magnifies existing compliance obligations:

Artificial intelligence has transformed the scale of modern marketing.

Tasks previously performed by marketing teams can now be undertaken automatically through recommendation engines, predictive analytics and generative AI. Systems can analyze millions of customer interactions, identify purchasing patterns and personalize marketing campaigns with minimal human intervention.

Despite these technological developments, AI does not alter the core legal principles established by the PDPA.

Organizations remain responsible for identifying an appropriate legal basis, limiting processing to specified purposes, maintaining transparency and respecting data subject rights.

What AI changes is the scale at which those obligations must be managed.

Organizations should therefore integrate AI into existing privacy governance rather than treating AI compliance as a separate exercise. Effective governance requires understanding what personal data is processed, how AI systems generate recommendations and what oversight exists to monitor automated outcomes.

Cookie compliance is only the beginning:

Cookies have traditionally been regarded as a website compliance issue.

In reality, they often represent only the first stage of a much larger processing ecosystem.

Information collected through tracking technologies may subsequently be combined with CRM data, disclosed to advertising technology providers, incorporated into customer profiles, analyzed using AI and ultimately used to deliver targeted advertising across multiple platforms.

Organizations should therefore move beyond focusing exclusively on cookie banners. Compliance should encompass the downstream use of tracking information throughout the digital advertising ecosystem.

Governance—not consent—will define future compliance:

Perhaps the most significant message emerging from the PDPC’s consultation is that marketing compliance is becoming a governance issue.

Historically, organizations invested considerable effort in drafting consent forms and updating privacy notices. Those measures remain important, but they no longer provide a complete compliance framework.

Organizations should instead ask broader governance questions.

Can we explain why customer information is collected?

Can we justify each processing activity?

Do we understand how profiling influences marketing decisions?

Can we identify every external platform receiving customer information?

Are customer objections implemented consistently across all marketing systems?

Can these decisions be demonstrated through appropriate documentation?

These questions reflect accountability rather than procedure.

As marketing technologies continue to evolve, organizations capable of answering them convincingly are likely to be better positioned than those relying primarily upon consent as evidence of compliance.

Looking ahead:

The PDPC’s consultation represents more than a discussion of direct marketing. It reflects an evolving regulatory understanding of how personal data underpins modern marketing.

Organizations should therefore resist the temptation to treat the consultation as another checklist of compliance requirements. Its broader significance lies in demonstrating that regulatory attention is shifting from individual communications toward governance of the entire marketing ecosystem.

Businesses that recognize this shift early—and embed privacy considerations into customer analytics, profiling, AI deployment and digital advertising—will be better prepared not only for future regulatory developments but also for an increasingly data-driven commercial environment.

Key takeaways:

  • The PDPC’s consultation reflects an expanded understanding of marketing that extends beyond promotional communications to encompass customer analytics, digital advertising, profiling, AI-assisted personalization and automated decision-making.
  • Organizations should identify individual processing activities and their purposes rather than treating all marketing-related processing as a single activity.
  • Customer profiling has become an ordinary business practice and should be governed through transparency, accountability and appropriate internal controls.
  • AI increases the scale of personal data processing but does not replace the fundamental principles of the PDPA.
  • Marketing compliance is increasingly defined by governance of the entire marketing lifecycle rather than by obtaining consent alone.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

PDPA Insights: Building Effective Privacy Governance

PDPA: Legitimate Interest Is No Longer a Shortcut

For many organizations implementing Thailand’s Personal Data Protection Act (PDPA), legitimate interest has become the preferred legal basis whenever obtaining consent appears impractical. Marketing activities, CCTV surveillance, fraud prevention, internal investigations, customer analytics, vendor due diligence, and employee monitoring are frequently justified on the basis that the organization has a legitimate business interest in processing personal data.

Yet legitimate interest is often misunderstood.

Some organizations treat it as a convenient alternative to consent, while others avoid relying on it altogether for fear that regulators may later disagree with their assessment. Both approaches overlook the purpose of legitimate interest within the PDPA.

The Personal Data Protection Committee’s recent consultation on legal bases provides an important indication of how the regulator expects organizations to approach legitimate interest. Rather than treating it as a residual category available whenever consent cannot be obtained, the consultation emphasizes a structured decision-making process requiring organizations to identify the processing purpose, assess necessity, balance competing interests, and document their reasoning. Although the consultation remains subject to revision, it reflects a broader movement toward accountability-based compliance rather than checklist compliance.

Legitimate interest is a legal analysis—not a business preference:

One of the most common misconceptions is that organizations may choose whichever legal basis they prefer.

The PDPA does not permit such flexibility.

Instead, the legal basis should reflect the actual purpose of the processing activity. Organizations should therefore begin by asking why the processing is taking place before considering whether legitimate interest is available.

For example, processing customer contact details to deliver purchased goods differs fundamentally from processing the same information to analyze purchasing behavior for future marketing campaigns. Likewise, operating CCTV to protect premises serves a different purpose from monitoring employee productivity.

Each processing activity should therefore be assessed independently.

Legitimate interest becomes relevant only after organizations have clearly identified the processing purpose and determined that no more appropriate legal basis applies.

Legitimate interest requires necessity:

The consultation suggests that organizations should demonstrate that the processing is genuinely necessary to achieve the identified purpose rather than merely convenient.

Necessity does not require the organization to prove that no alternative exists. However, it should be able to explain why the processing contributes meaningfully to the legitimate objective and why less intrusive alternatives would not achieve substantially the same result.

For example, a shopping mall operating CCTV in public areas for security purposes may reasonably conclude that surveillance is necessary to deter crime and investigate incidents. By contrast, continuous monitoring of employees in low-risk office environments may require a much more persuasive justification.

Organizations should therefore avoid assuming that every commercially useful processing activity automatically satisfies the necessity requirement.

Balancing interests requires more than common sense:

Perhaps the most significant aspect of legitimate interest is the balancing exercise.

Organizations should evaluate not only their own commercial interests but also the likely impact on individuals.

Relevant considerations may include:

  • the nature of the personal data;
  • the reasonable expectations of the individuals concerned;
  • the relationship between the organization and the individual;
  • the potential consequences of the processing;
  • whether adequate safeguards have been implemented; and
  • whether individuals can reasonably object to the processing.

This balancing exercise is particularly important where organizations undertake customer profiling, behavioral analytics, fraud detection, or other activities involving continuous monitoring.

Importantly, the outcome is not predetermined. Two organizations undertaking similar processing activities may legitimately reach different conclusions depending upon their operational context and safeguards.

Documentation is becoming as important as the decision itself:

One of the clearest messages emerging from the PDPC’s recent consultation is that organizations should be able to explain how they reached their legal conclusions.

Historically, many organizations simply recorded “Legitimate Interest” in their Records of Processing Activities or privacy notices without documenting the underlying reasoning.

That approach is becoming increasingly difficult to justify.

Organizations should instead maintain contemporaneous records explaining:

  1. the legitimate interest pursued;
  2. why the processing is necessary;
  3. how competing interests were balanced;
  4. what safeguards were implemented; and
  5. when the assessment will be reviewed.

These records not only support regulatory accountability but also improve internal governance by ensuring that legal basis assessments remain consistent across different business units.

Legitimate interest should evolve with the processing:

A legal basis assessment should not be regarded as a one-time exercise.

Business practices evolve. New technologies are introduced. AI systems become more sophisticated. Customer expectations change.

Processing that was originally assessed as proportionate may become significantly more intrusive over time.

Organizations should therefore periodically review Legitimate Interest Assessments, particularly where processing activities involve profiling, AI-assisted decision-making, large-scale analytics, or new categories of personal data.

Periodic review is consistent with the broader accountability framework underpinning the PDPA and helps ensure that legal basis assessments remain aligned with actual business practices.

Legitimate interest is ultimately about governance:

Perhaps the most important lesson emerging from the PDPC’s consultation is that legitimate interest should not be viewed primarily as a legal exception to consent.

Instead, it should be understood as a governance framework requiring organizations to demonstrate thoughtful decision-making.

Organizations that simply declare legitimate interest without documented analysis are unlikely to satisfy increasing regulatory expectations.

By contrast, organizations capable of demonstrating why processing is necessary, how competing interests were balanced, and what safeguards were implemented will be better positioned to justify their decisions if questioned by regulators or affected individuals.

The emphasis is therefore shifting from selecting a legal basis to demonstrating why that legal basis remains appropriate throughout the lifecycle of the processing activity.

Looking ahead:

As organizations increasingly deploy AI, customer analytics, fraud detection systems, behavioral advertising, and other data-driven technologies, reliance on legitimate interest is likely to become more common rather than less.

This makes governance increasingly important.

The PDPC’s consultation suggests that future enforcement may focus less on whether organizations selected legitimate interest and more on whether they can demonstrate the quality of the assessment supporting that decision.

Organizations that treat Legitimate Interest Assessments as living governance documents rather than compliance paperwork will be better prepared as Thailand’s privacy regime continues to mature.

Key takeaways:

  • Legitimate interest is not an alternative chosen for convenience but a legal basis that should reflect the actual purpose of processing.
  • Organizations should identify each processing activity separately before determining whether legitimate interest is appropriate.
  • Necessity and balancing are substantive assessments that should be documented rather than assumed.
  • Legitimate Interest Assessments should evolve alongside changes in technology, business practices, and customer expectations.
  • Increasingly, regulatory scrutiny is likely to focus on the quality of governance and documentation supporting legitimate interest rather than the mere assertion that it applies.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

PDPA Insights: Building Effective Privacy Governance

PDPA: ROPA Is Becoming the Organization’s Privacy Blueprint

For many organizations, preparing a Record of Processing Activities (ROPA) has been one of the least engaging aspects of complying with Thailand’s Personal Data Protection Act (PDPA). Frequently viewed as a statutory obligation rather than a practical management tool, ROPAs are often prepared once, filed away, and revisited only when requested during internal audits or regulatory inquiries.

This perception is beginning to change.

The Personal Data Protection Committee’s (PDPC) recent consultation on Records of Processing Activities suggests that the regulator increasingly views the ROPA as more than a compliance checklist. Instead, it appears to regard the ROPA as the central document connecting an organization’s privacy governance framework. Although the guidance remains subject to public consultation, it illustrates how the regulator expects organizations to understand, document, and govern personal data processing across the enterprise. Rather than serving as a static inventory of personal data, the ROPA is evolving into a living record of how an organization manages privacy risks and demonstrates accountability under the PDPA.

This shift is significant because it mirrors the growing complexity of modern business operations. Organizations increasingly process personal data through cloud services, software-as-a-service platforms, artificial intelligence (AI), customer relationship management systems, outsourced service providers, and cross-border digital ecosystems. A ROPA that merely lists departments and categories of personal data is unlikely to provide meaningful insight into how those activities actually operate.

A good ROPA should explain how the business works:

Many organizations approach a ROPA as a spreadsheet of processing activities.

That is an understandable starting point, but it is no longer sufficient.

A well-developed ROPA should allow someone unfamiliar with the organization to understand how personal data flows through the business. It should explain why personal data is collected, who uses it, where it is stored, whether it is shared with third parties, whether it leaves Thailand, how long it is retained, and what safeguards protect it.

Viewed in this way, a ROPA resembles a process map rather than an inventory.

This broader perspective benefits the organization as much as the regulator. It enables legal, compliance, information security, procurement, and business teams to work from a common understanding of data processing activities rather than maintaining separate records that quickly become inconsistent.

Processing activities—not departments—should become the focus:

One recurring challenge is that organizations frequently prepare ROPAs according to organizational structure rather than business activities.

Typical entries include “Human Resources,” “Finance,” or “Marketing.”

While administratively convenient, these categories often obscure the underlying processing activities that matter under the PDPA.

For example, a marketing department may collect personal data to administer loyalty programmes, analyze customer behavior, operate targeted advertising campaigns, manage promotional events, and respond to customer inquiries. Each activity may involve different categories of personal data, different legal bases, different retention periods, and different third-party service providers.

Documenting each activity separately provides a more accurate picture of privacy risk and facilitates more meaningful governance.

A ROPA should reveal dependencies:

One of the most valuable functions of a ROPA is identifying operational dependencies.

Many organizations discover during ROPA preparation that multiple business units rely on the same customer database, share vendors, or process identical information for different purposes.

These dependencies often remain invisible until the organization attempts to document its processing activities comprehensively.

Recognizing them can improve not only privacy compliance but also cybersecurity, procurement, contract management, and incident response planning.

The ROPA therefore becomes a tool for organizational learning rather than regulatory compliance alone.

AI and cloud services are changing what a ROPA should capture:

When many organizations first prepared ROPAs, processing activities were comparatively straightforward.

Today, organizations increasingly rely on cloud platforms, AI-powered customer service tools, outsourced analytics providers, and software supplied by multiple vendors.

This evolution raises new governance questions.

A modern ROPA should help organizations understand:

  • which AI tools process personal data;
  • what information is transferred to cloud providers;
  • whether overseas processing occurs;
  • what vendors act as processors or sub-processors;
  • how long AI systems retain information;
  • what contractual safeguards exist.

These questions are increasingly relevant regardless of whether AI is used internally or through third-party services.

ROPAs should support decision-making:

The most effective ROPAs are not prepared for regulators.

They are used internally.

Before launching a new customer loyalty programme, introducing AI-powered customer service, engaging a new cloud provider, or expanding into another jurisdiction, organizations should review existing processing activities through the ROPA.

Doing so helps identify whether new processing purposes arise, whether additional legal bases are required, whether privacy notices should be updated, and whether vendors require additional contractual protections.

Used effectively, the ROPA becomes an operational governance tool rather than a historical record.

Keeping the ROPA alive:

One of the greatest risks is allowing the ROPA to become outdated.

Business models evolve continuously. New technologies are introduced. Vendors change. Retention periods are revised. AI capabilities expand.

A ROPA that accurately reflected the organization two years ago may no longer describe current processing activities.

Organizations should therefore integrate ROPA maintenance into existing governance processes.

Updates should occur whenever significant changes are introduced, including new products, major technology implementations, acquisitions, outsourcing arrangements, or cross-border processing activities.

Periodic review should become part of normal business governance rather than a special compliance exercise.

Looking ahead:

The PDPC’s consultation suggests that the ROPA is evolving from a statutory record into a central governance document. This reflects a broader movement under the PDPA toward accountability and demonstrable compliance rather than documentation for its own sake.

Organizations that treat the ROPA as a living blueprint of their data processing environment will be better equipped to respond to regulatory inquiries, support privacy impact assessments, evaluate AI deployments, manage vendors, and demonstrate compliance with the PDPA.

Key takeaways:

  • A ROPA should describe how personal data flows through the organization rather than merely listing departments.
  • Processing activities—not organizational units—should form the foundation of the ROPA.
  • A well-maintained ROPA helps identify operational dependencies, shared datasets, and vendor relationships that may otherwise remain unnoticed.
  • Modern ROPAs should capture AI systems, cloud services, cross-border processing, and processor/sub-processor relationships where relevant.
  • Organizations should treat the ROPA as a living governance document that supports operational decision-making rather than as a static compliance record.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series