Thailand stopped being a paper regime
For a few years after Thailand's Personal Data Protection Act came into full force on 1 June 2022, it was reasonable to treat it as a law that existed mostly on paper. That is no longer a defensible read. The Personal Data Protection Committee, the regulator known as the PDPC, has been handing out administrative fines since 2024, and the reasons it gives are mundane: no data protection officer, weak security, a breach that went unreported.
That last point is the useful one for a small business. The companies being fined are not failing at some exotic technical standard. They are failing at housekeeping — the paperwork and the process, the things you can fix in an afternoon or two. This guide covers what the Act asks of a business with two to fifty people, what enforcement now looks like, and where to start if you have nothing in place.
Who this applies to
The Act applies to organisations that decide why and how personal data gets used (controllers) and to those that handle data on someone else's instructions (processors). If you run a shop, a booking system, a newsletter, or anything with a customer list, you are almost certainly a controller.
The part that catches people out is the reach beyond Thailand's borders. The Act applies to controllers and processors outside Thailand where they offer goods or services to people in Thailand, or monitor the behaviour of people in Thailand. You do not need a Thai entity or office. If you sell into Thailand, or run analytics and advertising tools that track Thai visitors on your site, you can be in scope. A small online shop in Singapore or Berlin with Thai customers is exactly the sort of business that assumes this is somebody else's problem.
What the Act actually asks of you
Have a lawful basis before you collect anything. Every use of personal data needs a legal ground. Consent is required where no other basis applies, but it is often the weakest option, because consent can be withdrawn. Contract performance, legal obligation and legitimate interest are all bases too, depending on what you are doing. Sensitive personal data — health, religion, race, political views, biometric and genetic data, criminal records, sexual orientation — sits under stricter rules and generally needs explicit consent. If you run a clinic, a gym with health intake forms, or a hiring process, this is your first stop.
Give people a privacy notice at or before collection. Not after. The notice has to explain what you collect, why, what your legal basis is, who you share it with, how long you keep it, and how someone exercises their rights. Write it in language your customers actually use. On cookies and trackers specifically: the PDPC has not issued a dedicated cookie guideline, so cookies are handled through the Act's general consent and notice provisions and the PDPC's general guidance. In practice, tell visitors what you are dropping on their device and get consent where the tracking is not strictly necessary to deliver the service.
Be ready to answer data subject requests. People in Thailand have rights of access, rectification, erasure, restriction of processing, data portability and objection. A right nobody can use is not a right, so the practical obligation is a route in — a monitored email address, a form, something — and a process behind it. Decide in advance who handles a request, how you verify the person is who they claim to be, and where you look.
Keep a record of your processing activities. This is the internal inventory: what categories of data you hold, why, who you share them with, retention periods, and what security you apply. It is unglamorous and it is the first thing a regulator asks for, because it shows whether you understand your own operation. Most small businesses discover, in the course of building one, that they are collecting fields nobody uses and holding data years past any purpose.
Work out whether you need a Data Protection Officer. A DPO is required where your core activities involve regular and systematic monitoring of personal data on a large scale, where you process sensitive data on a large scale, or where you are a public authority. Plenty of small businesses fall outside all three. But do not wave this away without checking — the PDPC has already fined a company for failing to appoint one, so it treats this as a live and enforceable obligation. Write down your reasoning either way, so that if the question is put to you, you have an answer.
Have a breach plan you can run inside 72 hours. If personal data is breached, you must notify the PDPC without delay and, where feasible, within 72 hours of becoming aware of it — unless the breach is unlikely to result in a risk to people's rights and freedoms. Where the risk to individuals is high, you notify the affected people too. Seventy-two hours is not long when the breach surfaces on a Friday night. Decide now who makes the call, who writes the notification, and what your hosting provider or payment processor will tell you.
Know your basis for sending data outside Thailand. If you use a CRM hosted in the US, an email platform in Europe, or a support desk anywhere else, you are transferring personal data out of Thailand and you need a lawful basis for doing so. In September 2025 the PDPC introduced a Binding Corporate Rules framework for transfers within corporate groups — a good sign that the regime is maturing, though it is built for multinationals. Most small businesses will rely on consent or another statutory transfer basis instead.
What enforcement actually looks like now
The first administrative fine under the Act was announced on 21 August 2024. On 1 August 2025 the PDPC announced a batch of administrative fines totalling roughly THB 14.5 million — eight fines across five cases. The cumulative total announced to date stands at around THB 21.5 million, which is a running tally rather than the size of any single batch.
The largest single fine in that batch, THB 7 million, went to a large IT product retailer. The grounds are worth reading closely, because they are not sophisticated: failure to appoint a Data Protection Officer, failure to implement appropriate security measures under section 37(1), and failure to report a data breach. Three procedural failures. None required an unusual business model or novel technology to trip over.
Administrative fines run up to THB 5 million for the most serious breaches, and the Act carries potential criminal and civil liability on top. But the relevant signal for a small business is not the ceiling — it is that the regulator is publishing outcomes, naming the grounds, and treating the basics as enforceable.
Common mistakes
The most common is assuming distance is protection. Businesses with no Thai presence read the extraterritorial provision, decide it is aimed at Google and Meta, and move on. It is not written that way.
The second is treating consent as the answer to everything. Bolting a checkbox onto a form does not create a lawful basis if the consent is bundled, pre-ticked, or impossible to withdraw. Often another basis is both more honest and more durable.
The third is publishing a privacy policy that describes a business you do not run. A template copied from a UK site, listing tools you have never used and omitting the three you rely on daily, is a written record of a claim you cannot support.
The fourth is having no breach plan. Nobody plans to have a breach, which is precisely why the 72-hour clock catches people out.
Where Dxtra fits
Dxtra builds a privacy program from a questionnaire about your business: a privacy policy, a cookie notice, consent records, records of processing, a public Transparency Center, and a way to handle data subject requests. It covers more than 500 obligations across 140+ countries, including Thailand, and starts at $10 a month. It is not a substitute for legal advice on a hard question, and it will not run your breach response for you — but it turns the paperwork layer into something you can finish.
If you want to see where you currently stand, Dxtra's free scan reads your site's public pages in about two minutes with no signup and returns a risk band along with findings mapped to named sources, so you can see what each one is based on.
Where to start
Start with the inventory, because everything else depends on it. Spend an hour listing every place customer data enters your business — checkout, contact form, newsletter, support inbox, analytics, ad pixels — and for each one write down what you collect, why, where it ends up, and who else can see it. That list is the raw material for your record of processing, your privacy notice and your transfer analysis all at once.
Then fix the notice so it describes what the list says. Then write down, on one page, what happens in the first 72 hours of a breach and who does it. Then check the DPO thresholds against your actual activities and record the conclusion.
None of this requires a legal team. It requires an afternoon, an honest look at what you collect, and the willingness to write it down.
This article is general information, not legal advice. Rules change; confirm anything that matters with Thailand's Personal Data Protection Committee (pdpc.or.th) or a qualified adviser before you rely on it.
