Legal service for foreign clients
Cybercrime, Data Breach, and Liability for AI Systems in Thailand
When data leaks the clock starts at once, and the law measures from when you knew — not from when the review is finished.
Quick answer
This work splits three ways. First, victims of hacking, identity spoofing, or AI-generated fake media, who must capture digital evidence correctly before it disappears. Second, organisations whose customer data has leaked and who owe a notification within the deadline set by data-protection law. Third, businesses deploying automated or AI systems that harm users — where liability sits mainly with the deployer, not automatically the developer. From THB 30,000.
From THB 30,000 — From THB 30,000 for handling one incident; litigation and deep forensics quoted separately. · Incident response 3–15 days; criminal case 8–20 months

Who this is for
- Individuals whose image or voice has been used to create fake media or defraud others
- Businesses whose systems were breached and customer data published or sold
- Data controllers facing notification duties and complaints
- Platforms asked to answer for content or automated outputs
- Victims of compromised bank or digital-asset accounts
What you receive
- Digital evidence capture with an admissible chain of custody
- Applications to take down offending computer data, plus criminal complaints
- Breach notifications to the regulator and to data subjects
- A post-incident programme that reduces repeat exposure to penalties
- A review of vendor contracts and which liability caps actually hold
Documents to prepare
- Screenshots showing the full URL and capture time
- Access logs, event logs, and the technical team's report
- Bank statements and transfer records where money was lost
- Privacy policy, records of processing, and processor agreements
- All contact with the perpetrator or extortionist, unedited
How it works
5-step process
- 1
Freeze the evidence in the first hours
Capture logs and screenshots before alerting anyone; evidence vanishes the moment the perpetrator knows.
- 2
Assess the notification duty
Not every incident is notifiable, but the assessment must be documented and completed within the deadline.
- 3
Run the criminal and takedown tracks together
A police report alone does not remove content; a suppression application must run alongside.
- 4
Chase the money immediately
Freezing the receiving account has a real chance in the first days and falls away quickly after.
- 5
Fix the system, not just the incident
Demonstrating concrete remediation materially affects how penalties are assessed.
In depth
Cybercrime, Data Breach, and Liability for AI Systems: what foreign clients need to know
Cyber incidents share a feature that sets them apart: the evidence disappears by itself within hours. Logs roll over, the account used is closed, posts are deleted, and transferred money is layered outward through several receiving accounts. What a victim does in the first hour therefore counts for more than what a lawyer can do the following month. Organisations that have leaked data face a second clock: the statutory notification window, which runs from when the incident became known, not from when the review is finished.
Capturing digital evidence a court will accept
A screenshot cropped to the message alone is worth less than most people assume. What makes it usable is a capture showing the full URL, the posting account, the time of capture, and how it was obtained. Third-party certification, or an unbroken video from opening the page to the content, is much harder to attack.
For organisations the system logs are central, yet most retain only a limited window. The first instruction on suspecting intrusion should be to stop the rollover and take a separate copy, before the technical team begins remediation — because restoring a system usually destroys the traces needed to identify the intruder.
One point bears repeating: do not delete contact with the perpetrator, however embarrassing, threatening, or awkward the exchange. Those messages are the strongest link to an identifiable person, and deleting part of a thread puts the whole set in doubt.
Duties when personal data leaks
Data-protection law requires a controller to notify the supervisory authority of a breach without delay within the prescribed window, and to notify data subjects where the risk to their rights and freedoms is high. The point often skipped is that while not every incident is notifiable, every incident must be assessed and the assessment recorded. An organisation that does not notify because it judged the risk low needs the paperwork behind that judgement.
A frequent misconception is that an incident caused by a vendor removes the organisation's liability. In fact the controller remains directly answerable to data subjects and then recovers from the processor under contract — and how far that recovery goes depends on how clearly the signed agreement set out security duties and indemnities.
What most affects the penalty is not the size of the incident but what the organisation did afterwards. Demonstrating that the gap was closed, access rights reviewed, staff trained, and the causal process changed carries far more weight than explaining that the attack was sophisticated.
Liability when an automated system causes harm
A question businesses increasingly ask is who answers when a deployed automated system gives a wrong output that harms a customer. The workable principle today is that the deployer is the one providing the service to the user and therefore answers first, just as with any tool or employee used in the business. Saying the system decided by itself does not remove liability.
The developer's or model provider's exposure is mainly contractual, and most contracts cap liability very low while stating that outputs may be inaccurate. A business deploying such systems in decisions that affect people — credit approval, candidate screening, health or financial guidance — needs a human review step before the output takes effect, or the whole risk sits with it.
A further area now producing real disputes is the use of a person's image, voice, or distinctive traits to generate synthetic media. Victims have several concurrent routes: computer-crime offences for importing false data, defamation where reputation is harmed, invasion of privacy, and a civil damages claim with an application to suppress publication.
Cost structure: government fees vs professional fees
| Item | Official fee | Professional fee | Note |
|---|---|---|---|
| Initial incident response and evidence capture | None | THB 30,000–60,000 | Includes same-day urgent guidance |
| Preparing a data-breach notification | None | THB 35,000–70,000 | Includes the risk assessment that supports the decision |
| Application to suppress offending computer data | Court fees at the prescribed rate | From THB 40,000 | The sooner it is filed, the more spread is contained |
| Vendor contract and liability-cap review | None | THB 25,000–50,000 | Best done before renewal, not after an incident |
An online shop whose customer database was sold on
Situation: A listing offering customer data appeared, with a sample matching the live database.
What we did: We copied the logs before restoration, completed the risk assessment and notification within the window, and applied to have the listing removed.
Outcome: The listing was taken down, and evidence of concrete remediation reduced the penalty exposure.
A victim of a synthetic clip using a real face
Situation: Images from a public account were used to build a misleading video that spread widely.
What we did: We captured continuous video evidence, filed a criminal complaint, and combined a suppression application with notices to the platforms.
Outcome: The material came down from the main channels within two weeks and the original poster was prosecuted.
When to act, and when waiting is fine
You discovered an intrusion hours ago
Copy the logs before the technical team begins restoring anything.
Money left your account without your action
Contact the bank to freeze the receiving account the same day, then file the report.
You are unsure whether the incident is notifiable
Document the assessment immediately; having no assessment is a bigger problem than deciding not to notify.
You are about to let an automated system decide
Insert human review wherever the output affects a user's rights.
FAQ
Frequently asked questions
My face was used in a fake clip — what actions are available?
Computer-crime offences, defamation, and a civil damages claim, together with an application to take the material down.
Customer data leaked — who must be told and when?
The regulator must be notified without delay within the statutory window, and data subjects when the risk to their rights is high.
Our vendor caused it — are we still liable?
You still answer to your customers, because the statutory duty rests on the controller; recovering from the vendor is a separate matter governed by whatever the agreement says.
An AI system made a wrong decision — who is liable?
The deployer answers to the injured party first; the developer's exposure turns on the contract and the warranties given.
Is paying a ransom unlawful?
Payment is not directly prohibited, but it carries money-laundering exposure, does not remove the notification duty, and guarantees nothing.
Is filing online different from filing at a station?
The online channel gives a reference number quickly, useful for freezing requests, but complex evidence still warrants attending in person with the documents.
Must a platform remove unlawful content immediately?
Once formally notified, leaving it up exposes the provider to shared liability, so notice should be in writing with proof kept.
Does leaked employee data trigger notification?
Employee data is personal data just as customer data is, so the same assessment applies.
If AI drafted a client document and it was wrong, who answers?
A professional remains bound by professional standards; using a tool does not lower them.
Will a court accept evidence I collected myself?
It is admissible; the weight depends on how complete the capture method is and how consistently its origin can be explained.
Related services
PDPA Compliance & Data Protection Counsel
Making every use of customer and staff data explainable — before someone complains.
Online Fraud: Account Freezing & Recovery
The first hours matter most: money still sitting in the account is money still recoverable.
Frozen Accounts, Mule-Account Allegations & Money Laundering
An account can be frozen within a minute. Unfreezing it turns on the quality of the very first bundle you file.
Written by: Thai Law & Accounting Services — attorneys and licensed accountants
Reviewed by: Reviewed by a Notarial Services Attorney registered with the Lawyers Council of Thailand.
Last updated: 2026-08
Information as of August 2026. Government fees and processing times change — verify with the relevant agency before acting, or let our team verify for you.