Legal service for foreign clients
PDPA Compliance & Data Protection Counsel in Thailand
Making every use of customer and staff data explainable — before someone complains.
Quick answer
A PDPA build starts with a survey of what the organisation collects, from whom, where it sits, and who receives it. Each dataset is then given a lawful basis, followed by the processing record, the privacy notice, purpose-separated consent forms, processor agreements, and a route for handling data-subject requests. It closes with a breach playbook geared to the statutory notification window. Programme work from THB 45,000.
From THB 45,000 — Programme from 45k · retained advice from 12k monthly · breach response from 30k per incident · Survey 2–3 weeks · full document set 4–8 weeks · breach work starts the hour you call

Who this is for
- Businesses holding large individual customer bases: clinics, schools, online sellers
- HR teams keeping applicant histories and employee health records
- Companies sending data to a parent company or overseas cloud provider
- Organisations that just received a complaint letter or a data-subject query
- Executives asked to certify compliance to a partner or auditor
What you receive
- A data-flow map across systems, naming the owner of each process
- A processing record with the lawful basis stated dataset by dataset
- Privacy notices for the website, for staff, and for job applicants
- Contract set: processor agreement and joint-controller agreement
- A rights-request procedure with an identity-verification form
- A breach plan with the risk assessment sheet and draft notification letters
- One staff training round with a comprehension test
Documents to prepare
- A list of internal systems and vendors that touch personal data
- The forms currently used to collect data, on paper and online
- Employment contracts and internal rules touching data
- Contracts with cloud, accounting-system, and marketing agency providers
- Any past complaint or breach incident, if one occurred
How it works
6-step process
- 1
Survey the whole estate
Interview each department to surface the data nobody admits to keeping.
- 2
Assign a lawful basis per dataset
Separate what rests on contract, on legal duty, and on genuine consent.
- 3
Draft the core documents
Privacy notices, consent forms, and the processor agreements.
- 4
Install the rights and breach routes
Fix who receives, who decides, and the day count for closing.
- 5
Train and rehearse
Rehearse a live customer-data leak with the IT and communications teams.
- 6
Review annually and on change
New vendors or sales channels always send the record back for revision.
In depth
PDPA Compliance & Data Protection Counsel: what foreign clients need to know
The Personal Data Protection Act has changed how Thai organisations must treat customer and staff data entirely. What used to be collected on instinct now needs a lawful basis for every channel, a privacy notice that a reader can actually understand, and a record of processing activities ready to be shown to the Personal Data Protection Committee office at any time.
Data mapping and the record of processing activities (ROPA)
The most essential opening step is walking through what data the organisation actually holds, where each item comes from, how long it is kept, and who it is passed to, from a website sign-up form and office CCTV to the payroll system HR touches daily. Many organisations discover data sitting in places no one had thought to check, such as attachments in old emails or a spreadsheet a staff member kept for personal convenience.
The findings feed into the record of processing activities the law requires every data controller to maintain. That record must state the purpose of each collection, the legal basis relied on, the retention period, and the security measures applied to each data set. It is not a document written once and filed away; it needs updating whenever a new system or new collection channel appears.
In practice we give each department a short questionnaire paired with an interview of the process owner, because existing policy documents rarely match what happens on the ground. The result is an organisation-wide data map that underpins every later task, from drafting the privacy notice to assessing risk when a breach occurs.
Lawful basis and a privacy notice a reader can actually understand
Each data set needs a lawful basis for its collection and use, whether consent, contractual necessity, legal obligation, legitimate interest, or another basis appropriate to the data. The most common mistake is defaulting to consent for every case, when in some situations consent is not a suitable basis at all because the customer has no genuine choice to refuse while still receiving the service.
A good privacy notice genuinely informs the data subject what is collected, why, who it is shared with, and what rights they hold, written in language an ordinary reader understands without needing a law degree. We avoid lifting a translated foreign template, because the collection context differs by business: a retail shop and a hospital hold entirely different sensitive touchpoints.
Sensitive data such as health, religious or criminal record information carries stricter conditions than ordinary data, requiring explicit consent or a specific statutory exception. We therefore isolate this category for special review from the mapping stage onward, rather than letting it blend into a general form alongside ordinary fields.
Data processing agreements (DPA) and appointing a data protection officer (DPO)
When an organisation sends data to an outside vendor for processing, whether a cloud provider, an email marketing platform, or an outsourced call centre, the law requires a data processing agreement specifying the scope of processing, security measures, and the duty to report incidents back to the controller. We review every existing contract, because standard service agreements rarely cover these terms in full.
Appointing a data protection officer is mandatory for certain types of businesses, particularly those processing sensitive data at scale or routinely monitoring individuals' behaviour. Even for businesses outside the mandatory threshold, having someone clearly responsible makes handling data-subject requests and liaising with the regulator far more orderly. We help define the role's scope so it does not simply overlap with existing legal or IT duties.
For corporate groups with several affiliated entities, a common question is whether one officer can cover the whole group and how an intra-group data-sharing agreement should be worded. We design the document structure to match how the group actually operates, rather than forcing everything into a single template that does not reflect real practice.
Consent management and handling data-subject rights
A consent request must sit separately from other terms of service; the data subject needs to understand exactly what they are agreeing to, and withdrawal must be as easy as giving consent in the first place. A checkbox buried at the end of a long document, or a default set to opt-in, are both high-risk practices under scrutiny.
Data subjects hold several rights: to access their data, to have it corrected, to have it erased or destroyed, and to object to processing in certain cases. The organisation needs a clear intake channel and an internal process assigning responsibility and a response timeframe. We design the request form and internal workflow so that frontline staff know exactly who to escalate a request to and within what number of days it must be answered.
Cross-border transfer to overseas service providers
Many Thai businesses use software and cloud services hosted overseas, which legally counts as a cross-border transfer. The destination country must offer an adequate standard of data protection, or, failing that, the transfer must rely on an alternative safeguard such as a contract with data-protection clauses recognised by the regulator or an approved set of intra-group binding rules.
Our work is to check which category the overseas provider a business already uses falls into, and to prepare the necessary substitute documentation where the destination country has not been declared adequate. Many cases involve negotiating with large providers to accept added clauses within their own standard contracts, which requires understanding both Thai law and the frameworks those providers are already used to working with.
Organisations with an overseas parent or branch often face the same recurring question of whether to centralise employee and customer data at the foreign head office. We help structure the transfer correctly from the outset, rather than allowing the transfer to happen first and fixing it retroactively, which carries far higher cost and risk.
Responding to a data breach within the 72-hour window
When a breach occurs that risks the rights and freedoms of data subjects, the law requires the controller to notify the PDPC office without delay and, where feasible, within 72 hours of becoming aware. That window is extremely short against how complex it can be to establish what actually happened, so an organisation needs a written response plan in place beforehand, not one improvised as the incident unfolds.
A workable plan names who holds decision authority, sets out the initial technical containment steps, provides a fact-logging form to be completed immediately, and gives criteria for deciding whether affected data subjects must also be notified directly. We help run a simulated exercise with the IT and management teams before a real incident, because even a single rehearsal usually exposes gaps in the process that the written plan alone never revealed.
After the incident, the step most often overlooked is recording lessons learned and updating safeguards to prevent recurrence. The regulator typically weighs whether reasonable safeguards were already in place alongside how promptly the incident was reported. An organisation with a documented history of post-incident improvement stands in a far better position than one that never reviewed anything at all.
Internal audits and preparing to face a PDPC complaint
A data subject dissatisfied with how an organisation has treated their data may file a complaint directly with the PDPC office. When a request for information arrives from the office, an organisation with a maintained record of processing activities, written policies and complete consent evidence can respond quickly and credibly, unlike one scrambling to reconstruct documentation under time pressure.
We recommend a periodic internal audit, at least annually or whenever a major system changes, to confirm that actual practice still matches written policy. This covers both the documentary side, such as whether the privacy notice is still current, and the technical side, such as whether database access rights are genuinely limited to those who need them.
When facing a complaint or an inquiry from the office, a cooperative and directly responsive stance tends to produce a better outcome than denial or delay. We help organisations prepare responses grounded in genuine internal documents, showing an ongoing system of data governance rather than paperwork assembled only after the complaint arrived.
Cost structure: government fees vs professional fees
| Item | Official fee | Professional fee | Note |
|---|---|---|---|
| Organisation-wide data mapping and building the ROPA | No government fee | THB 40,000–120,000 depending on the number of departments and systems | Should come first before any other document, since it underlies the whole plan |
| Drafting privacy notices and consent forms | No government fee | THB 25,000–70,000 per document set by channel used | Sets are separated by data-subject group, such as customers, staff and vendors |
| Preparing data processing agreements (DPA) with vendors | No government fee | THB 20,000–60,000 per key counterparty | Includes negotiating amended terms with large overseas providers |
| Appointing and scoping the data protection officer (DPO) | No government fee for the appointment itself | THB 30,000–90,000 to structure the role and produce the operating manual | The role holder's ongoing remuneration is a separate line item |
| Building the breach-response plan and running a simulation | No government fee; notifying the PDPC office itself carries no charge | THB 50,000–150,000 including the exercise with IT and management teams | Must be finished before a real incident, since there is no time to design a plan within the 72-hour window |
| Annual internal audit and complaint-readiness review | No government fee | THB 30,000–80,000 per cycle, by organisation size | Run at least annually or whenever a core system changes |
A retailer with customer data scattered across several systems
Situation: The marketing team held customer emails in several personal spreadsheets, and no one in the organisation could say how many places the data actually sat in.
What we did: We surveyed every department and consolidated the findings into a single record of processing activities, assigning a named owner to each data category.
Outcome: The organisation reduced the number of storage points and shut down the duplicate spreadsheets that lacked adequate safeguards.
A tech company using an overseas cloud vendor without a data processing agreement
Situation: The company had used an overseas cloud storage service for years under a standard service agreement that never addressed personal data protection at all.
What we did: We assessed the destination country and negotiated with the provider to add data-protection clauses meeting Thai legal requirements into the existing agreement.
Outcome: The cross-border transfer gained proper supporting documentation without switching providers or migrating systems.
A private hospital facing a leak of patient records
Situation: The server holding treatment records was accessed without authorisation over a weekend, and the IT team detected the anomaly later than it should have.
What we did: We helped assess the scope of the damage on an urgent basis, prepared the notification to the PDPC office within the statutory window, and drafted the notice to affected patients.
Outcome: The hospital reported within the deadline and subsequently upgraded its monitoring system to reduce the chance of a similar incident recurring.
When to act, and when waiting is fine
Start immediately if the organisation has never built a record of processing activities
This is the foundation every later task references; the longer it waits, the more new collection points accumulate that later need chasing down.
Prioritise sensitive data ahead of ordinary data
Health data and other sensitive categories carry stricter legal conditions and are typically the first point a data subject complains about.
No need for a full-time data protection officer yet if the business is small and outside the mandatory threshold
Assigning a clear internal owner is enough for the early stage; reassess once the business grows or begins processing more sensitive data.
Once an anomaly is spotted in a system, follow the response plan immediately without waiting for a complete investigation
The 72-hour clock, where feasible, runs from becoming aware of the incident, not from the day the full investigation concludes.
FAQ
Frequently asked questions
Does a small company need a data protection officer?
Not every organisation must appoint one; it turns on the nature and scale of processing. We assess whether you fall inside, and where you do not, we set an internal owner instead.
Does one consent cover everything later?
No. Consent is tied to the purpose disclosed. New marketing uses or sharing with a partner require a fresh, purpose-specific request.
Who is told first after a leak?
Assess risk at once, notify the supervisory office within the statutory window, and tell affected individuals where risk is high. We pre-draft both letters.
Can data go to servers abroad?
Yes, with appropriate safeguards such as contract terms binding the recipient to equivalent protection. We review your cloud contracts and add what is missing.
Do shop CCTV cameras count?
They do. Facial images are personal data, so you need signage, a defined retention period, and a named short list of people who may view footage.
Can a complaint still arrive after the build?
It can, but with a complete record and a reasoned explanation for every use, the response closes faster and penalty exposure drops sharply.
Does a small business with only a few hundred customers need to comply with PDPA in full?
The law applies to controllers of every size in principle, but the scope of work scales with risk and data volume; a small business typically starts with a privacy notice and a lean record of processing activities.
Does using office CCTV require consent from everyone who walks past?
Security CCTV can generally rely on the legitimate interest basis without individual consent, but a clear notice sign is required and the use of the footage must stay limited to that stated purpose.
If a customer asks for erasure but another law requires the records be kept, what should happen?
The right to erasure is not absolute; where another law such as accounting or tax legislation requires the record be retained, the request can be declined for that necessary portion, with the reason explained back to the customer.
Can a former employee demand all their personal data be erased from company systems right after resigning?
The company still has statutory duties to retain certain records under labour and tax law for a defined period; only data outside that retention duty can be erased immediately, with the rest erased once the required period lapses.
After notifying the PDPC office of a breach, must every customer also be notified?
Direct notification to data subjects is additionally required only where the incident poses a high risk to individuals' rights and freedoms; not every breach automatically requires notifying every customer individually.
If a business runs entirely on a foreign e-commerce platform, does Thai PDPA still apply?
The law applies to the collection and use of data belonging to individuals in Thailand regardless of where the controller is based; running on a foreign platform does not remove the obligations under Thai law.
Related services
Draft & Review Business Contracts — NDA, JV, Shareholder
Enforceable contracts — bilingual, with dispute-resolution and arbitration clauses.
Labor Lawyer — Termination, Severance, Labor Court
Both employer- and employee-side, at all Labor Courts nationwide.
Online Fraud: Account Freezing & Recovery
The first hours matter most: money still sitting in the account is money still recoverable.
Corporate & M&A Lawyer — Due Diligence, Joint Venture
Mid- to large-cap deals under FBA, BOI, JV — structuring and protection.
Written by: Thai Law & Accounting Services — attorneys and licensed accountants
Reviewed by: Reviewed by a Notarial Services Attorney registered with the Lawyers Council of Thailand.
Last updated: 2026-08
Information as of August 2026. Government fees and processing times change — verify with the relevant agency before acting, or let our team verify for you.