Skip to main content

Legal service for foreign clients

Cybercrime, Data Breach, and Liability for AI Systems in Thailand

When data leaks the clock starts at once, and the law measures from when you knew — not from when the review is finished.

Quick answer

This work splits three ways. First, victims of hacking, identity spoofing, or AI-generated fake media, who must capture digital evidence correctly before it disappears. Second, organisations whose customer data has leaked and who owe a notification within the deadline set by data-protection law. Third, businesses deploying automated or AI systems that harm users — where liability sits mainly with the deployer, not automatically the developer. From THB 30,000.

From THB 30,000 From THB 30,000 for handling one incident; litigation and deep forensics quoted separately. · Incident response 3–15 days; criminal case 8–20 months

Cybercrime, Data Breach, and Liability for AI Systems handled by Thai Law & Accounting lawyers in Thailand
Our bilingual team handles cybercrime, data breach, and liability for ai systems end to end across Thailand.

Who this is for

  • Individuals whose image or voice has been used to create fake media or defraud others
  • Businesses whose systems were breached and customer data published or sold
  • Data controllers facing notification duties and complaints
  • Platforms asked to answer for content or automated outputs
  • Victims of compromised bank or digital-asset accounts

What you receive

  • Digital evidence capture with an admissible chain of custody
  • Applications to take down offending computer data, plus criminal complaints
  • Breach notifications to the regulator and to data subjects
  • A post-incident programme that reduces repeat exposure to penalties
  • A review of vendor contracts and which liability caps actually hold

Documents to prepare

  • Screenshots showing the full URL and capture time
  • Access logs, event logs, and the technical team's report
  • Bank statements and transfer records where money was lost
  • Privacy policy, records of processing, and processor agreements
  • All contact with the perpetrator or extortionist, unedited

How it works

5-step process

  1. 1

    Freeze the evidence in the first hours

    Capture logs and screenshots before alerting anyone; evidence vanishes the moment the perpetrator knows.

  2. 2

    Assess the notification duty

    Not every incident is notifiable, but the assessment must be documented and completed within the deadline.

  3. 3

    Run the criminal and takedown tracks together

    A police report alone does not remove content; a suppression application must run alongside.

  4. 4

    Chase the money immediately

    Freezing the receiving account has a real chance in the first days and falls away quickly after.

  5. 5

    Fix the system, not just the incident

    Demonstrating concrete remediation materially affects how penalties are assessed.

In depth

Cybercrime, Data Breach, and Liability for AI Systems: what foreign clients need to know

Cyber incidents share a feature that sets them apart: the evidence disappears by itself within hours. Logs roll over, the account used is closed, posts are deleted, and transferred money is layered outward through several receiving accounts. What a victim does in the first hour therefore counts for more than what a lawyer can do the following month. Organisations that have leaked data face a second clock: the statutory notification window, which runs from when the incident became known, not from when the review is finished.

Capturing digital evidence a court will accept

A screenshot cropped to the message alone is worth less than most people assume. What makes it usable is a capture showing the full URL, the posting account, the time of capture, and how it was obtained. Third-party certification, or an unbroken video from opening the page to the content, is much harder to attack.

For organisations the system logs are central, yet most retain only a limited window. The first instruction on suspecting intrusion should be to stop the rollover and take a separate copy, before the technical team begins remediation — because restoring a system usually destroys the traces needed to identify the intruder.

One point bears repeating: do not delete contact with the perpetrator, however embarrassing, threatening, or awkward the exchange. Those messages are the strongest link to an identifiable person, and deleting part of a thread puts the whole set in doubt.

Duties when personal data leaks

Data-protection law requires a controller to notify the supervisory authority of a breach without delay within the prescribed window, and to notify data subjects where the risk to their rights and freedoms is high. The point often skipped is that while not every incident is notifiable, every incident must be assessed and the assessment recorded. An organisation that does not notify because it judged the risk low needs the paperwork behind that judgement.

A frequent misconception is that an incident caused by a vendor removes the organisation's liability. In fact the controller remains directly answerable to data subjects and then recovers from the processor under contract — and how far that recovery goes depends on how clearly the signed agreement set out security duties and indemnities.

What most affects the penalty is not the size of the incident but what the organisation did afterwards. Demonstrating that the gap was closed, access rights reviewed, staff trained, and the causal process changed carries far more weight than explaining that the attack was sophisticated.

Liability when an automated system causes harm

A question businesses increasingly ask is who answers when a deployed automated system gives a wrong output that harms a customer. The workable principle today is that the deployer is the one providing the service to the user and therefore answers first, just as with any tool or employee used in the business. Saying the system decided by itself does not remove liability.

The developer's or model provider's exposure is mainly contractual, and most contracts cap liability very low while stating that outputs may be inaccurate. A business deploying such systems in decisions that affect people — credit approval, candidate screening, health or financial guidance — needs a human review step before the output takes effect, or the whole risk sits with it.

A further area now producing real disputes is the use of a person's image, voice, or distinctive traits to generate synthetic media. Victims have several concurrent routes: computer-crime offences for importing false data, defamation where reputation is harmed, invasion of privacy, and a civil damages claim with an application to suppress publication.

Cost structure: government fees vs professional fees

ItemOfficial feeProfessional feeNote
Initial incident response and evidence captureNoneTHB 30,000–60,000Includes same-day urgent guidance
Preparing a data-breach notificationNoneTHB 35,000–70,000Includes the risk assessment that supports the decision
Application to suppress offending computer dataCourt fees at the prescribed rateFrom THB 40,000The sooner it is filed, the more spread is contained
Vendor contract and liability-cap reviewNoneTHB 25,000–50,000Best done before renewal, not after an incident

An online shop whose customer database was sold on

Situation: A listing offering customer data appeared, with a sample matching the live database.

What we did: We copied the logs before restoration, completed the risk assessment and notification within the window, and applied to have the listing removed.

Outcome: The listing was taken down, and evidence of concrete remediation reduced the penalty exposure.

A victim of a synthetic clip using a real face

Situation: Images from a public account were used to build a misleading video that spread widely.

What we did: We captured continuous video evidence, filed a criminal complaint, and combined a suppression application with notices to the platforms.

Outcome: The material came down from the main channels within two weeks and the original poster was prosecuted.

When to act, and when waiting is fine

  • You discovered an intrusion hours ago

    Copy the logs before the technical team begins restoring anything.

  • Money left your account without your action

    Contact the bank to freeze the receiving account the same day, then file the report.

  • You are unsure whether the incident is notifiable

    Document the assessment immediately; having no assessment is a bigger problem than deciding not to notify.

  • You are about to let an automated system decide

    Insert human review wherever the output affects a user's rights.

FAQ

Frequently asked questions

My face was used in a fake clip — what actions are available?

Computer-crime offences, defamation, and a civil damages claim, together with an application to take the material down.

Customer data leaked — who must be told and when?

The regulator must be notified without delay within the statutory window, and data subjects when the risk to their rights is high.

Our vendor caused it — are we still liable?

You still answer to your customers, because the statutory duty rests on the controller; recovering from the vendor is a separate matter governed by whatever the agreement says.

An AI system made a wrong decision — who is liable?

The deployer answers to the injured party first; the developer's exposure turns on the contract and the warranties given.

Is paying a ransom unlawful?

Payment is not directly prohibited, but it carries money-laundering exposure, does not remove the notification duty, and guarantees nothing.

Is filing online different from filing at a station?

The online channel gives a reference number quickly, useful for freezing requests, but complex evidence still warrants attending in person with the documents.

Must a platform remove unlawful content immediately?

Once formally notified, leaving it up exposes the provider to shared liability, so notice should be in writing with proof kept.

Does leaked employee data trigger notification?

Employee data is personal data just as customer data is, so the same assessment applies.

If AI drafted a client document and it was wrong, who answers?

A professional remains bound by professional standards; using a tool does not lower them.

Will a court accept evidence I collected myself?

It is admissible; the weight depends on how complete the capture method is and how consistently its origin can be explained.

Browse the full legal FAQ wiki

Written by: Thai Law & Accounting Services — attorneys and licensed accountants

Reviewed by: Reviewed by a Notarial Services Attorney registered with the Lawyers Council of Thailand.

Last updated: 2026-08

Information as of August 2026. Government fees and processing times change — verify with the relevant agency before acting, or let our team verify for you.

contact@tla.co.thจ.–ส. 9–18น.15 นาที