PDPA Compliance in Thailand — Assessment, Documents and Training
The gap is between the policy on your website and what the company actually does

The gap is between the policy on your website and what the company actually does
Nearly every organisation operating in Thailand now has a privacy policy published somewhere. Far fewer can answer the questions that follow it: which systems hold personal data, which staff can open them, which vendors receive exports of it, and what happens in the first hour after a breach is noticed. That gap is invisible until a data subject complains or data leaks, and then it becomes the whole case. We work in the order that produces a defensible position rather than a thicker folder — establish the facts first, measure them against what the law requires, then build only the documents the findings call for, and train the people who will have to use them under pressure.
What we cover
A policy is not compliance, and regulators know the difference
The most common finding in a first assessment is not a missing document — it is a working practice that contradicts one the company already published. Marketing exports a customer list to a tool nobody recorded. HR keeps applicant CVs indefinitely because no one set a retention period. A support team shares screenshots containing customer identifiers in a group chat. None of these appear in a policy review, because they are not in the policy. They surface only when someone traces where data actually travels, which is why the assessment starts with systems and people rather than with paperwork.
Vendors are where most organisations are exposed
Personal data rarely stays inside one company. It moves to payroll providers, cloud platforms, marketing tools, logistics partners and overseas parent companies. Each transfer needs a basis, and each processor needs an agreement setting out what it may and may not do with the data. Organisations that have never mapped this typically discover more third parties than they expected, several of them onboarded by a department rather than by procurement. Getting the list right matters more than getting each contract perfect: an unknown processor cannot be governed at all.
Groups with a foreign parent have a second problem
Where a Thai entity sits inside a foreign group, personal data usually flows to the parent for reporting, HR administration or shared systems. Two questions then have to be answered together: whether the transfer out of Thailand is properly grounded, and whether the group's existing framework — often written for another jurisdiction — actually covers what Thai law asks for. Reusing a group template without that check is common and rarely survives scrutiny. Mapping the group's flows and adapting the framework is usually less work than it sounds, but it is not a translation exercise.
The plan that matters is the one for the day it goes wrong
When a breach is discovered, the decisions that shape the outcome happen in the first hours: who is told internally, what is preserved, who speaks to the affected people, and how the assessment of severity is documented. Organisations without a written plan spend that window deciding who decides. A workable plan names the individuals, not the departments, sets out what must be recorded as it happens, and has been walked through at least once by the people named in it.
Talk to us about this
Free initial consultation. Tell us what your business needs and we'll map the steps and a quote.
Frequently asked questions about PDPA Compliance & Data Protection
7 questions answered
Further reading
A step-by-step PDPA implementation checklist with timelines, cost estimates, and pitfalls. Built from 50+ PDPA audit engagements since 2022.
18 min readForeign Investment GuideCash gets trapped in Thai subsidiaries for structural reasons decided at incorporation, not banking ones. The debt-versus-equity choice you cannot cheaply reverse, where IP should be owned before the brand has value, the substance behind any charge to the Thai entity, and how these structures fail.
10 min read