Delayed Implementation of Thailand’s Personal Data Protection Act
Time 2 Minute Read
Categories: International

The implementation of Thailand’s Personal Data Protection Act B.E. 2562 (A.D. 2019) (the “PDPA”) has been delayed until May 31, 2021.

Certain data controllers’ compliance with the main operative provisions concerning personal data protection (including those covering requests for data subjects’ consent; collection/use and disclosure of personal data; rights of data subjects; complaints; and civil liabilities and penalties), which were previously scheduled to come into force this year, has been deferred for another one-year period, i.e., until May 31, 2021.

Those data controllers for whom compliance has been deferred include agencies and operators of prescribed businesses specified in the Royal Decree on Agencies and Businesses Not Subject to the PDPA B.E. 2563 (2020) (the “Royal Decree”). The Royal Decree covers a broad range of agencies and businesses, including governmental authorities, industrial businesses, commercial businesses, transportation businesses, telecommunication/computer/digital businesses, banking and finance businesses, insurance businesses, real estate businesses and professional businesses. If any data controller is unsure as to whether it falls within the scope of those listed in the Royal Decree as being exempt from compliance with the PDPA until May 31, 2021, it may seek advice from the Personal Data Protection Committee.

Update: On July 17, 2020, the Thai government issued an interim Notification of Standards for Maintenance of Security of Personal Data (the “Notification”). The Notification is intended to act as a stop-gap to ensure that personal data is protected until the deferred provisions of the PDPA become effective in 2021 and compliance with the PDPA becomes mandatory. Under the Notification, certain data controllers must immediately implement basic security controls and measures, including, among others, administrative, technical and physical safeguards for personal data security and staff training and awareness.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 2 Minute Read

On February 18, 2026, Virginia Attorney General Jay Jones announced that his office intends to fully enforce new provisions of the Virginia Consumer Data Protection Act restricting minors’ use of social media.

Time 6 Minute Read

On February 9, 2026, trade association NetChoice filed a lawsuit challenging South Carolina’s newly passed Age-Appropriate Code Design (“SC AACD”) on First and Fourteenth Amendment grounds. The SC AACD was signed into law on February 5, 2026, making South Carolina the fifth U.S. state to enact such a law, following California, Maryland, Nebraska and Vermont.

Time 2 Minute Read

Congress has extended the Cybersecurity Information Sharing Act of 2015 through September 30, 2026 as part of the Consolidated Appropriations Act, a government funding package enacted in early February 2026.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page