Technology & Privacy Law in Thailand
Practical legal guidance on data protection, cybersecurity, AI governance and digital regulation for technology companies, platforms and businesses operating in Thailand.
Discuss Your Technology or Privacy Matter
Technology, Data and Digital Regulation in Thailand
Thailand regulates its digital economy through several distinct legal frameworks rather than a single unified technology code. Data privacy, cybersecurity, electronic transactions, digital platforms and telecommunications each sit under their own legislation and regulator, and increasingly overlap — a single product launch, data flow or AI deployment can touch several of these frameworks at once.
One significant feature of Thailand’s data protection framework is its potential extraterritorial application. A company with no office or staff in Thailand can still fall within scope by offering goods or services to people in Thailand or monitoring their behaviour — a starting point that shapes compliance obligations for platforms, SaaS providers and digital businesses well before any local presence is established.
Thailand’s Personal Data Protection Act applies to organisations outside Thailand that offer goods or services to individuals in Thailand or monitor their behaviour, regardless of whether the organisation has a physical presence in the country.
Technology & Privacy Capabilities
Technology and privacy work in Thailand spans data governance, technology contracting and platform regulation — often within the same engagement.
Privacy & Risk
- Data Privacy & PDPA Compliance
- Cybersecurity & Breach Response
- AI Governance & Contracting
Contracts & Deployment
- Software, SaaS & Cloud Agreements
- Technology Transactions & Licensing
- Electronic Transactions & Signatures
Regulation & Market Access
- Digital Platforms & E-Commerce
- Telecommunications & Infrastructure
- Digital Content & Platform Regulation
Data Protection and Privacy in Thailand
The PDPA Framework
Thailand’s Personal Data Protection Act (PDPA) governs the collection, use and disclosure of personal data by data controllers and processors. Processing generally requires a lawful basis — most often consent, contractual necessity, legal obligation or legitimate interest — and controllers must provide clear privacy notices, honour data subject rights such as access, correction, deletion and objection, and maintain appropriate technical and organisational security measures. Processing sensitive personal data, including health, biometric or similar categories, is subject to stricter conditions. Certain controllers and processors are also required to designate a data protection officer where their core activities involve large-scale monitoring or processing of sensitive personal data.
Cross-Border Data Transfers
Transferring personal data outside Thailand is restricted unless the destination country offers an adequate level of protection or the transfer is supported by appropriate safeguards. The Personal Data Protection Committee (PDPC) has not yet published a list of jurisdictions recognised as adequate, so in practice most cross-border transfers currently rely on standard contractual clauses — commonly based on ASEAN or EU models — or binding corporate rules, for which the PDPC introduced a formal certification process. Businesses transferring data to group affiliates, cloud providers or vendors outside Thailand should confirm which safeguard mechanism applies well before the transfer takes place.
Breach Response and Governance
Where a personal data breach poses a risk to individuals’ rights and freedoms, the PDPA requires notification to the PDPC without undue delay, and notification to affected individuals may also be required in certain circumstances. Effective governance — clear internal escalation procedures, vendor data processing agreements, and a documented lawful basis for each category of processing — reduces both regulatory exposure and the practical difficulty of responding to a breach under time pressure.
Technology and Digital Business in Thailand
Software, SaaS and Cloud
Software development, licensing, SaaS subscriptions and cloud hosting arrangements each raise Thailand-specific contracting issues — data location and processing terms, service levels, liability caps, source code and escrow arrangements, and the interaction between contractual IP ownership and Thailand’s Copyright Act. Open-source components introduce further licence-compliance considerations that are frequently addressed inconsistently in vendor contracts.
Digital Platforms, E-Commerce and Electronic Transactions
Online platforms, marketplaces and e-commerce businesses operating in Thailand must account for electronic transaction law, consumer-facing terms and policies, and, depending on the nature of the platform, obligations under Thailand’s digital platform regulatory framework. The Electronic Transactions Act gives legal recognition to electronic signatures, records and contracts — administered with the support of the Electronic Transactions Development Agency (ETDA) — allowing many electronic commercial arrangements to be validly concluded without a handwritten signature, subject to the reliability and formality requirements the Act and specific transaction types may require.
Technology Transactions and Infrastructure
Larger technology arrangements — outsourcing, systems implementation, technology-driven joint ventures and infrastructure procurement — combine standard commercial contracting with technology-specific risk allocation around data, uptime, intellectual property and regulatory compliance. Telecommunications and connectivity infrastructure sit under separate licensing requirements administered by the National Broadcasting and Telecommunications Commission (NBTC), relevant where a business’s technology operations extend into network services or spectrum use rather than software or platform services alone.
AI, Cybersecurity and Emerging Technology
Artificial Intelligence
Thailand does not yet have comprehensive AI-specific legislation in force. A draft Thailand AI Act, developed by the Electronic Transactions Development Agency, proposes a risk-based framework broadly comparable to international models, including obligations for high-risk AI systems and human oversight requirements. Until such legislation is enacted, AI-related activity in Thailand continues to be governed by existing law — including the PDPA where personal data trains or operates an AI system, the Copyright Act for AI-related works and training data, and general civil liability principles. Businesses deploying or procuring AI should treat this as a fast-moving area and build contracts and governance that can adapt as the regulatory position develops.
Cybersecurity
The Cybersecurity Act establishes a national cybersecurity framework and imposes specific obligations on operators of critical information infrastructure across designated sectors, including incident reporting and cooperation with the National Cybersecurity Committee. Businesses outside these designated sectors are not directly subject to the Act’s critical-infrastructure obligations, but cybersecurity failures frequently intersect with PDPA breach-notification duties and contractual security obligations owed to customers and partners.
When Technology & Privacy Issues Arise
Technology and privacy questions tend to surface at specific moments in a business’s operations in Thailand, rather than as a standing concern.
Launching a Digital Platform
Entering the Thai market with a platform, app or digital service, and structuring compliance from the outset.
Collecting or Processing Data
Building PDPA-compliant data collection, consent and processing practices for customers or employees.
Transferring Data Outside Thailand
Structuring cross-border data flows to affiliates, vendors or cloud providers using the appropriate safeguard.
Deploying or Procuring AI Systems
Assessing legal exposure and contracting for AI tools while Thailand’s AI-specific regulation develops.
Negotiating SaaS or Cloud Agreements
Reviewing or drafting technology contracts covering data, service levels, liability and IP ownership.
Responding to a Data Breach
Managing PDPC notification obligations, individual notification and internal governance after an incident.
Industries We Support
Technology and privacy considerations vary by sector. These are the industries where this practice area is most consistently central to the legal work.
Navigating Thailand’s Digital Regulatory Framework
Technology and privacy regulation in Thailand runs through several regulators rather than one, and a single business activity often falls under more than one at once.
- Personal Data Protection Committee
- The PDPC oversees the PDPA, investigates complaints and issues notifications and guidance, including the current rules on cross-border data transfers.
- Electronic Transactions Development Agency
- ETDA supports the Electronic Transactions Act and digital platform regulation, and is leading the development of Thailand’s draft AI legislation.
- Ministry of Digital Economy and Society
- MDES is the ministry overseeing Thailand’s principal digital-economy legislation, including the PDPA and the Cybersecurity Act.
- National Broadcasting and Telecommunications Commission
- The NBTC regulates telecommunications licensing, spectrum allocation and network infrastructure.
- Overlapping Frameworks
- A single activity — deploying an AI system, for example — can simultaneously engage the PDPA, the Copyright Act and, once enacted, AI-specific legislation, making coordinated legal review more useful than a single-law compliance check.
Related Practice Areas
Intellectual Property
Software copyright, AI-related IP, training data and technology licensing and ownership.
Commercial Contracts
Broader commercial agreements underpinning technology, platform and vendor relationships.
Foreign Investment
Market entry, foreign ownership and licensing considerations for international technology businesses.
Technology & Privacy FAQs
Does Thailand have a data privacy law?
Yes. Thailand’s Personal Data Protection Act (PDPA) governs the collection, use and disclosure of personal data and applies to both private and public sector organisations.
Does the PDPA apply to foreign companies with no office in Thailand?
It can. The PDPA applies extraterritorially to organisations outside Thailand that offer goods or services to individuals in Thailand or monitor their behaviour, regardless of whether the organisation has a physical presence in the country.
Can personal data be transferred outside Thailand?
Yes, subject to restrictions. Transfers require either an adequate level of protection in the destination country — for which the PDPC has not yet published a formal list — or appropriate safeguards such as standard contractual clauses or PDPC-certified binding corporate rules.
When must a data breach be reported under the PDPA?
Where a breach poses a risk to individuals’ rights and freedoms, notification to the Personal Data Protection Committee is required without undue delay, and notification to affected individuals may also be required in certain circumstances.
Does Thailand regulate artificial intelligence?
Not yet through comprehensive AI-specific legislation. A draft Thailand AI Act is under development and was released for public consultation, but existing laws — including the PDPA, the Copyright Act and general civil liability principles — currently apply to AI-related activity.
Are electronic signatures legally recognised in Thailand?
Yes, in general. The Electronic Transactions Act gives legal recognition to electronic signatures, records and contracts, though specific reliability and formality requirements can vary by transaction type.
Do online platforms or digital services require a licence in Thailand?
It depends on the nature of the service. General e-commerce and digital platforms are subject to electronic transaction and consumer-facing regulation, while telecommunications, network and connectivity services generally require licensing from the National Broadcasting and Telecommunications Commission (NBTC).
What law governs cybersecurity obligations in Thailand?
The Cybersecurity Act establishes Thailand’s national cybersecurity framework and imposes specific obligations on operators of critical information infrastructure, while cybersecurity failures more broadly can also trigger PDPA breach-notification duties and contractual security obligations.
Need Advice on Technology or Privacy Law in Thailand?
Speak with the right legal expertise for your situation — from PDPA compliance to technology contracts and digital regulation.