Skip to main content
SUWANVARA LAWFIRM
Suwanvara Law Firm Co., Ltd.
SUWANVARA LAWFIRM
SUWANVARA LAWFIRM
Suwanvara Law Firm Co., Ltd.
Business Services

PDPA Compliance in Thailand — Assessment, Documents and Training

The gap is between the policy on your website and what the company actually does

PDPA Compliance in Thailand — Assessment, Documents and Training
Business Services

The gap is between the policy on your website and what the company actually does

Nearly every organisation operating in Thailand now has a privacy policy published somewhere. Far fewer can answer the questions that follow it: which systems hold personal data, which staff can open them, which vendors receive exports of it, and what happens in the first hour after a breach is noticed. That gap is invisible until a data subject complains or data leaks, and then it becomes the whole case. We work in the order that produces a defensible position rather than a thicker folder — establish the facts first, measure them against what the law requires, then build only the documents the findings call for, and train the people who will have to use them under pressure.

What we cover

Data mapping — what personal data is held, where, who can access it, and who it is shared with
Gap assessment against Thai PDPA requirements, with findings ranked by exposure
Privacy notices, consent wording, and records of processing activities
Data processing agreements with vendors, and cross-border transfer arrangements
Data-subject request procedure and a breach response plan that names roles
Staff training for the teams that actually handle personal data

A policy is not compliance, and regulators know the difference

The most common finding in a first assessment is not a missing document — it is a working practice that contradicts one the company already published. Marketing exports a customer list to a tool nobody recorded. HR keeps applicant CVs indefinitely because no one set a retention period. A support team shares screenshots containing customer identifiers in a group chat. None of these appear in a policy review, because they are not in the policy. They surface only when someone traces where data actually travels, which is why the assessment starts with systems and people rather than with paperwork.

Vendors are where most organisations are exposed

Personal data rarely stays inside one company. It moves to payroll providers, cloud platforms, marketing tools, logistics partners and overseas parent companies. Each transfer needs a basis, and each processor needs an agreement setting out what it may and may not do with the data. Organisations that have never mapped this typically discover more third parties than they expected, several of them onboarded by a department rather than by procurement. Getting the list right matters more than getting each contract perfect: an unknown processor cannot be governed at all.

Groups with a foreign parent have a second problem

Where a Thai entity sits inside a foreign group, personal data usually flows to the parent for reporting, HR administration or shared systems. Two questions then have to be answered together: whether the transfer out of Thailand is properly grounded, and whether the group's existing framework — often written for another jurisdiction — actually covers what Thai law asks for. Reusing a group template without that check is common and rarely survives scrutiny. Mapping the group's flows and adapting the framework is usually less work than it sounds, but it is not a translation exercise.

The plan that matters is the one for the day it goes wrong

When a breach is discovered, the decisions that shape the outcome happen in the first hours: who is told internally, what is preserved, who speaks to the affected people, and how the assessment of severity is documented. Organisations without a written plan spend that window deciding who decides. A workable plan names the individuals, not the departments, sets out what must be recorded as it happens, and has been walked through at least once by the people named in it.

Talk to us about this

Free initial consultation. Tell us what your business needs and we'll map the steps and a quote.

Frequently asked questions about PDPA Compliance & Data Protection

7 questions answered

The law does not exempt by size — if you hold customer or staff data, you are in scope. What differs is how much work is required, which follows the nature and volume of the data.
By finding out what data you hold and where. Documents drafted without knowing the reality tend to be useless on the day something happens.
It depends on the nature and volume of the data you process — and the role need not be filled by an employee. An outsourced officer is permitted, and is what many organisations choose.
The assessment answers a different question. A policy states what the organisation intends to do; an assessment establishes what it actually does and where the two diverge. In practice the divergences — an unrecorded vendor, data kept long past its purpose, access nobody revoked — are what create exposure, and none of them are visible from reading the policy.
It depends far more on how many systems and departments hold personal data than on headcount. A single-site operation with a small number of systems moves quickly; a group with several entities, a shared HR platform and overseas reporting takes longer because the flows have to be traced rather than described. We scope it after a short conversation about what systems exist, so the timeline is set against your actual estate rather than a standard package.
It depends on what the organisation does with personal data rather than on its size — the nature and scale of processing is what drives the requirement. This is one of the first things the assessment resolves, because the answer changes who has to own the work internally afterwards. Where an appointment is required, we help define the role so it has genuine authority rather than being a title added to an existing job.
Yes, and that is usually the efficient route. What it needs is a mapping exercise: the group framework is checked against Thai requirements, the points where it falls short are identified, and a Thai-specific layer is added on top rather than the whole framework being rebuilt. Where the group framework is stricter, we say so rather than adding work.

Other business services

Company & Corporate Registration
Company formation, changes to directors/capital/address/objectives, dissolution, and full DBD paperwork — handled end-to-end by a team that sees it through.
Accounting & Monthly Tax
Monthly bookkeeping, tax filing (withholding & VAT), annual financial statements, payroll, and social security — all in one place, right after we register your company.
Business License Applications
Industry-specific licenses — restaurants, food sale/storage, hotels, import-export, FDA, and e-commerce — with documents prepared and agencies coordinated for you.
Contract Drafting & Document Review
Draft and review business contracts of every kind — employment, NDAs, services, sale, lease — plus website T&Cs/privacy policies and demand letters, to prevent disputes before they start.
Notarial Services & Certified Translation
Notarial Services Attorney certification of signatures and documents, certified translation, and embassy/consular liaison — for use at home and abroad.
Employer Labour-Law Compliance & HR Advisory
Employment contracts and work rules that hold up, a documented discipline-and-termination process, and a standing labour adviser your HR team can call before they act — not after.
Work Permit & Visa Processing Service
Work permits and business visas filed and renewed end to end — company eligibility checked first, employer paperwork prepared, 90-day reporting handled, and clean cancellation when staff leave.
Retained Corporate Legal Counsel
A named lawyer on monthly retainer — reviewing the contracts you use, answering day-to-day questions, issuing demand letters, and settling disputes before they reach court.
Customs & Cross-Border Trade Compliance
Tariff classification and customs valuation, responding to post-clearance audits, challenging retrospective duty assessments, and claiming the privileges you are entitled to.
Demand Letters for Unpaid Debts
A lawyer-issued demand letter setting a deadline to pay — putting the debtor formally in default, building the evidence you will need in court, and staying inside what the law on debt collection allows.
Legal Notices & Cease-and-Desist Letters
Lawyer-issued notices that terminate a contract, require a property to be vacated, demand an infringement stop, or set a deadline to cure a breach — plus replies to notices you have received.
Factory Setup in Thailand
The legal sequence for a new plant — investment route and site, land and lease diligence, building and factory licensing, machinery import, and work permits for the team that installs and runs it.
Family Business & Succession
Family constitutions, holding-company structures, shareholders' agreements between family members, and a plan for passing shares and management to the next generation — with what the family agrees written into documents Thai law will actually enforce.
Business Plans & Feasibility Studies
Business plans and financial projections for bank loans, BOI promotion applications, Foreign Business Licence applications, investors and partners, and project feasibility studies — written by the same team that prepares the legal documents.