What Is Personal Data Protection Act B.E. 2562 (2019)?
The Personal Data Protection Act B.E. 2562 (2019) was published in the Royal Gazette on 27 May 2019. Section 2 made most provisions effective the next day but delayed the core operative chapters (II, III, V, VI, VII and Sections 95-96) for one year — a delay that was then postponed twice by Royal Decree before those provisions finally took effect 1 June 2022. Full enforcement does not mean no remaining exemptions. The Act's permanent Section 4 exclusions remain in force: purely personal/household activity; specified national-security, public-safety, fiscal-security, anti-money-laundering, forensic-science, and cybersecurity duties; media/artistic/literary activity under professional ethics or public interest; Parliament/Senate/committee duties; courts and criminal-justice processes; and credit-data businesses governed by separate credit-business legislation. A 2023 Royal Decree, effective 14 January 2024, separately and partially exempts specified state functions — mainly from Chapters II and III only, not the whole Act, and exempt controllers must still maintain prescribed security standards. No amending Act to B.E. 2562 itself has been located in the current MDES index.
At a glance
- Full name
- Personal Data Protection Act B.E. 2562 (2019)
- Short code
- Thai PDPA
- Jurisdiction
- Thailand
- Enacted
- 2019
- Last major update
- Fully in force for the general business sector since 1 June 2022, after two staged postponements; a 2023 Royal Decree (effective 14 January 2024) added a partial exemption for specified state functions
- Regulator
- Personal Data Protection Committee (PDPC), Office of the PDPC
- Private right of action
- Yes
- Statutory citation
- Personal Data Protection Act B.E. 2562 (2019)
Scope, who Thai PDPA covers
Protected data
Data subject rights
Informed: notice of collection, purpose, and processing details
Withdraw consent, as easily as giving it
Access to personal data
Rectification, keeping data accurate, current, complete, and non-misleading
Erasure, destruction, or anonymization
Restriction of use
Data portability, for automatically-readable, common-format data on consent or specified contractual/legal bases
Object to processing, including an unconditional stop for direct marketing
Notable features
Thailand's staged-enforcement history — an initial one-year statutory delay, then two further postponement decrees before the core chapters finally took effect — means pre-2022 descriptions of the Act as "not yet enforced" are stale, while the 2023/2024 state-sector partial exemption means "fully enforced" descriptions must still account for the Section 4 permanent exclusions and the narrower state-function carve-out. The access-request deadline is a firm 30 days, but the rectification right has no separate numerical response deadline stated in the Act.
Enforcement & penalties
Regulator: Personal Data Protection Committee (PDPC), Office of the PDPC
Penalties: Civil liability: actual damages including reasonable prevention/mitigation expenses, plus punitive damages up to 2x actual damages, generally limited to 3 years from knowledge of the damage and responsible party (10-year absolute limit). Criminal penalties: unlawful sensitive-data collection/use/disclosure — up to 6 months imprisonment or a fine up to 500,000 baht, or both (up to 1 year or 1,000,000 baht if for unlawful benefit); unauthorized disclosure by someone who learned data through official duties — up to 6 months or 500,000 baht, or both. Administrative fines: up to 1,000,000-5,000,000 baht depending on the violation category for controllers, with corresponding processor maximums, and 500,000 baht for non-compliance with expert-committee orders.
Private right of action: Section 73 gives a data subject the right to complain about a controller, processor, employee, or contractor violation, adjudicated by the relevant expert committee via the Office of the PDPC, alongside separate civil-damages rights. No statutory filing limitation period or complaint-submission deadline was located in the reviewed Act and complaint regulation; the expert committee's own decision is generally due within 90 days from its first meeting, extendable up to twice by 60 days each.
Relevance to data brokers
No Thailand-specific data-broker, people-search-service, or public-record-aggregator complaint or deletion route has been located in accessible official MDES and PDPC materials. A general erasure provision does apply to publicly made-available data: if a controller made data public and receives a valid erasure request, it must take appropriate technical or cost-related steps regarding other controllers, with a complaint route to the expert committee if the controller fails to act — a general mechanism, not a broker-specific one.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is the Thai PDPA fully enforced?+
Yes, for the general business sector, since 1 June 2022. But full enforcement does not mean no exemptions remain: the Act's permanent Section 4 exclusions (household activity, specified security/media/judicial functions, credit-data businesses) still apply, and a 2023 decree partially exempts specified state functions from Chapters II and III, effective 14 January 2024.
How long does a company have to respond to an access request under the PDPA?+
Access requests must generally be answered without delay and within 30 days, subject to limited refusal grounds (law/court order or likely damage to others). The rectification right, by contrast, has no separate numerical response deadline stated in the Act.
Can I get my public data removed under the Thai PDPA?+
If a controller made your data public and you make a valid erasure request, it must take appropriate technical or cost-related steps to address other controllers holding that data, with a complaint route to the PDPC's expert committee if it fails to act. This is a general provision, not a dedicated data-broker or public-record deletion route.
Official sources & citations
Other international privacy regimes
Thai PDPA sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
