Thailandregulation

Thailand Personal Data Protection Act

Punitive damages up to twice actual losses and criminal penalties make Thailand PDPA non-compliance a direct personal and commercial liability for management.

Mapped to Microsoft controls
Effective Date1 June 2022 (full enforcement)
Enforcement BodyPersonal Data Protection Committee (PDPC) / Office of the PDPC
Penalty FrameworkAdministrative fines of up to THB 5 million (approximately USD 140,000). Criminal penalties including imprisonment of up to 1 year and/or fines of up to THB 1 million for certain offences. Punitive damages of up to twice the actual damages in civil cases. The PDPC can issue corrective orders and impose administrative fines.

The Thailand Personal Data Protection Act B.E. 2562 (2019) is Thailand's comprehensive data protection legislation, establishing a GDPR-aligned framework for the collection, use, and disclosure of personal data. Full enforcement commenced on 1 June 2022 after several deferrals.

The PDPA establishes the Personal Data Protection Committee (PDPC) as the supervisory authority and requires organisations to obtain consent, appoint DPOs where applicable, implement security safeguards, and notify breaches within 72 hours. Cross-border transfers require adequate safeguards.

For Microsoft 365 environments, PDPA compliance requires Purview sensitivity labels for data classification, DLP policies for data protection controls, Defender XDR incident detection and response for breach notification, and Conditional Access for access management. StremarControl engineers and operates the Microsoft-native controls required for Thailand PDPA mandates, translating obligations into enforceable Microsoft-native controls, structured evidence, and ongoing assurance discipline for PDPC compliance reporting.

Why This Matters Now

Thailand's PDPA is the country's first comprehensive data protection law, establishing GDPR-aligned principles for Southeast Asia's second-largest economy. It mandates DPO appointment, consent-based processing, cross-border transfer safeguards, and 72-hour breach notification. For M365 environments, compliance requires Purview data classification, DLP policies for data protection, and Defender XDR incident workflows for breach notification. Thailand's growing role as an ASEAN data hub makes PDPA compliance essential.

Scope & Applicability

Applies to data controllers and processors collecting, using, or disclosing personal data in Thailand, or offering goods/services to individuals in Thailand, or monitoring behaviour of individuals in Thailand. The PDPA has extraterritorial reach. Exemptions for personal/household activities, public interest activities, and media. M365 tenants processing Thai personal data must comply.

Core Obligations

01
Sections 19–24

Consent and Lawful Basis

Collect, use, or disclose personal data only with explicit consent or another lawful basis. Consent must be freely given, specific, and informed.

02
Section 41

Data Protection Officer

Appoint a DPO where the organisation regularly processes large volumes of personal data or sensitive data.

03
Section 37(4)

Breach Notification

Notify the PDPC of a personal data breach within 72 hours. Notify affected individuals if the breach is likely to pose a high risk to their rights.

04
Section 28

Cross-Border Transfers

Transfer personal data to foreign countries only where adequate protection standards exist or with appropriate safeguards.

05
Section 37(1)

Security Measures

Implement appropriate security measures to prevent unauthorised access, use, disclosure, alteration, or destruction of personal data.

Microsoft 365 Control Mapping

How each obligation maps to enforceable Microsoft 365 controls and the evidence they produce.

Obligation

Security Measures

M365 Control

Conditional Access with MFA and device compliance. Intune endpoint security. Defender XDR for threat protection. Purview sensitivity labels.

Evidence

Conditional Access logs, Intune compliance reports, Defender analytics, label usage reports.

Obligation

72-Hour Breach Notification

M365 Control

Defender XDR incident detection with Sentinel playbooks for PDPC notification workflows. Automated breach severity classification.

Evidence

Incident timeline reports, playbook execution logs, PDPC notification records.

Obligation

Cross-Border Transfers

M365 Control

Purview DLP with geo-fencing rules. Conditional Access named locations for geographical restrictions. Data residency controls.

Evidence

DLP cross-border logs, Conditional Access geo-reports, data residency configuration exports.

Implementation Timeline

May 2019
Personal Data Protection Act B.E. 2562 enacted
June 2022
Full enforcement begins after multiple deferrals
2023
Subordinate regulations and royal decrees issued for cross-border transfers
2024
PDPC begins active enforcement with compliance inspections

Related Frameworks

Ready to get Thailand PDPA-ready?

Start with a fixed-scope sprint. We assess your Microsoft 365 controls against Thailand PDPA requirements, close gaps, and produce audit-ready evidence.