Skip to main content
SUWANVARA LAWFIRM
Suwanvara Law Firm Co., Ltd.
SUWANVARA LAWFIRM
SUWANVARA LAWFIRM
Suwanvara Law Firm Co., Ltd.
Business Law

PDPA for HR in Thailand: Employee Data, CCTV, Job Applicants and Workplace Monitoring

An employer holds more personal data about its staff than about almost anyone else, including health and biometric data. How Thailand's Personal Data Protection Act applies to HR — lawful bases, sensitive data, CCTV, fingerprint time clocks, monitoring, applicants, sharing with a parent company and breaches.

Suwanvara Law FirmEmployment & Corporate TeamSeptember 18, 202610 min read

Why HR is where PDPA risk concentrates

A company's customer database gets most of the PDPA attention. The employee file is often riskier: it holds identity documents, bank details, family information, health records, performance reviews, disciplinary history — and increasingly biometric data from time clocks.

It is also the data most likely to be requested in a dispute. An employee in a termination claim may ask what the company holds about them, and how it was used.

Most HR processing rests on bases other than consent:

ProcessingUsual lawful basis
Payroll, contracts, leavePerforming the employment contract
Tax, social security, labour recordsLegal obligation
Security, CCTV, IT monitoringLegitimate interests, balanced against employees' rights
Optional programmes, photos for marketingConsent

Consent given by an employee to an employer is rarely treated as fully free, and can be withdrawn. Relying on it for processing the company actually needs creates a problem the day an employee withdraws.

2. Sensitive data

Some categories need explicit consent or a specific legal exception:

  • Health data — medical certificates, pre-employment health checks, sick leave details
  • Biometric data — fingerprint or face-scan time clocks, access control
  • Criminal records — background checks
  • Religion, ethnicity, disability

For each, identify the basis, limit who can see it, and set a retention period. Offer an alternative where consent is the basis — a card for employees who decline biometric attendance, for example.

3. The employee privacy notice

Employees need a notice explaining:

  • What data is collected and from where
  • Why, and on what lawful basis
  • Who it is shared with — payroll providers, insurers, the parent company
  • Whether it is transferred abroad
  • How long it is kept
  • How employees can exercise their rights

This is separate from the customer privacy notice on the website. See PDPA compliance checklist for the wider programme.

4. Job applicants

Applicants are data subjects before they are employees:

  • Tell them how their data is used in the application process
  • Collect only what the selection needs
  • Do not run background or health checks before they are relevant
  • Keep CVs of unsuccessful applicants only for a stated period, or with consent for a talent pool

5. CCTV and workplace monitoring

CCTV is generally acceptable for security and safety with:

  • Visible notices at entrances and monitored areas
  • A defined purpose and retention period
  • Restricted access to recordings
  • No cameras in private areas

Monitoring email, devices and internet use needs a written policy, a clear purpose, and proportionality. Monitoring everything, permanently, without telling employees, is the pattern that fails.

Using CCTV or monitoring data for purposes beyond those notified — performance management, for example — should be decided in advance and reflected in the notice.

6. Sharing with the parent company and vendors

  • Parent company access and HR systems hosted abroad are cross-border transfers and need a lawful basis and adequate safeguards
  • Payroll providers, HR software, insurers and recruiters are processors or separate controllers; put data processing terms in their contracts
  • Record who receives employee data and why

7. Employee requests and disputes

Employees can ask for access to their data, correction, and in some cases deletion. Requests often arrive during a dispute. Have a procedure: verify identity, locate data across systems, respond within the time the law allows, and take advice where the request overlaps with a claim.

8. Breaches

  • Assess risk immediately
  • Where the breach is likely to affect individuals' rights, notify the regulator without delay, within seventy-two hours of becoming aware where feasible
  • Where the risk is high, inform affected employees with the steps being taken
  • Keep a record of every breach, notified or not

9. Retention

Set retention periods for each category and apply them. Labour and tax law require some records to be kept; beyond that, data kept "just in case" is risk without a purpose.

HR checklist

  1. Map the employee data held, where it sits and who can access it
  2. Assign a lawful basis to each processing activity
  3. Identify sensitive data and its basis; offer alternatives where consent is used
  4. Issue an employee privacy notice and an applicant notice
  5. Review CCTV and monitoring against a written policy
  6. Put data processing terms in vendor and intra-group arrangements
  7. Set retention periods and a request-handling procedure
  8. Prepare a breach response plan

Frequently asked questions

Do we need employees' consent to process their data?+

Usually not, and relying on consent is often the weaker choice. Most HR processing rests on other lawful bases: performing the employment contract, complying with legal obligations such as tax, social security and labour records, and legitimate interests such as security. Consent given by an employee to an employer is rarely treated as fully free, and it can be withdrawn. Keep consent for processing that is genuinely optional.

Are fingerprint or face-scan time clocks allowed?+

Biometric data is sensitive data, which needs explicit consent or a specific legal exception. Many employers use biometric attendance systems with explicit consent and offer an alternative such as a card for employees who decline. Whatever the approach, the system, its purpose and the retention period should be set out in the employee privacy notice.

Can we install CCTV in the workplace?+

Generally yes, for security and safety, with visible notices, a defined purpose, limited access to recordings and a retention period. Cameras in private areas such as toilets or changing rooms are not acceptable. Using CCTV footage for purposes beyond those notified, such as performance management, needs to be considered carefully in advance.

Can our parent company overseas access employee data?+

It can, but cross-border transfer rules apply. The transfer needs a lawful basis and an adequate mechanism, such as intra-group binding rules or contractual safeguards, and employees should be told in the privacy notice. Shared HR systems hosted abroad count as transfers.

What must we do after a data breach involving employee data?+

Assess the risk immediately. Where the breach is likely to affect individuals' rights, the regulator must be notified without delay and within seventy-two hours of becoming aware where feasible, and where the risk is high, the affected employees must be informed with the remedial steps. Keep a record of every breach, including those not notified.