Technology & Privacy

Technology & Privacy Law in Thailand

Practical legal guidance on data protection, cybersecurity, AI governance and digital regulation for technology companies, platforms and businesses operating in Thailand.

Discuss Your Technology or Privacy Matter
Abstract network server architecture illustrating technology and privacy law in Thailand
Overview

Technology, Data and Digital Regulation in Thailand

Thailand regulates its digital economy through several distinct legal frameworks rather than a single unified technology code. Data privacy, cybersecurity, electronic transactions, digital platforms and telecommunications each sit under their own legislation and regulator, and increasingly overlap — a single product launch, data flow or AI deployment can touch several of these frameworks at once.

One significant feature of Thailand’s data protection framework is its potential extraterritorial application. A company with no office or staff in Thailand can still fall within scope by offering goods or services to people in Thailand or monitoring their behaviour — a starting point that shapes compliance obligations for platforms, SaaS providers and digital businesses well before any local presence is established.

Legal Intelligence

Thailand’s Personal Data Protection Act applies to organisations outside Thailand that offer goods or services to individuals in Thailand or monitor their behaviour, regardless of whether the organisation has a physical presence in the country.

How We Help

Technology & Privacy Capabilities

Technology and privacy work in Thailand spans data governance, technology contracting and platform regulation — often within the same engagement.

Data & Digital Governance

Privacy & Risk

  • Data Privacy & PDPA Compliance
  • Cybersecurity & Breach Response
  • AI Governance & Contracting
Technology & Transactions

Contracts & Deployment

  • Software, SaaS & Cloud Agreements
  • Technology Transactions & Licensing
  • Electronic Transactions & Signatures
Platforms & Connectivity

Regulation & Market Access

  • Digital Platforms & E-Commerce
  • Telecommunications & Infrastructure
  • Digital Content & Platform Regulation
Data Protection

Data Protection and Privacy in Thailand

The PDPA Framework

Thailand’s Personal Data Protection Act (PDPA) governs the collection, use and disclosure of personal data by data controllers and processors. Processing generally requires a lawful basis — most often consent, contractual necessity, legal obligation or legitimate interest — and controllers must provide clear privacy notices, honour data subject rights such as access, correction, deletion and objection, and maintain appropriate technical and organisational security measures. Processing sensitive personal data, including health, biometric or similar categories, is subject to stricter conditions. Certain controllers and processors are also required to designate a data protection officer where their core activities involve large-scale monitoring or processing of sensitive personal data.

Cross-Border Data Transfers

Transferring personal data outside Thailand is restricted unless the destination country offers an adequate level of protection or the transfer is supported by appropriate safeguards. The Personal Data Protection Committee (PDPC) has not yet published a list of jurisdictions recognised as adequate, so in practice most cross-border transfers currently rely on standard contractual clauses — commonly based on ASEAN or EU models — or binding corporate rules, for which the PDPC introduced a formal certification process. Businesses transferring data to group affiliates, cloud providers or vendors outside Thailand should confirm which safeguard mechanism applies well before the transfer takes place.

Breach Response and Governance

Where a personal data breach poses a risk to individuals’ rights and freedoms, the PDPA requires notification to the PDPC without undue delay, and notification to affected individuals may also be required in certain circumstances. Effective governance — clear internal escalation procedures, vendor data processing agreements, and a documented lawful basis for each category of processing — reduces both regulatory exposure and the practical difficulty of responding to a breach under time pressure.

Technology & Digital Business

Technology and Digital Business in Thailand

Software, SaaS and Cloud

Software development, licensing, SaaS subscriptions and cloud hosting arrangements each raise Thailand-specific contracting issues — data location and processing terms, service levels, liability caps, source code and escrow arrangements, and the interaction between contractual IP ownership and Thailand’s Copyright Act. Open-source components introduce further licence-compliance considerations that are frequently addressed inconsistently in vendor contracts.

Digital Platforms, E-Commerce and Electronic Transactions

Online platforms, marketplaces and e-commerce businesses operating in Thailand must account for electronic transaction law, consumer-facing terms and policies, and, depending on the nature of the platform, obligations under Thailand’s digital platform regulatory framework. The Electronic Transactions Act gives legal recognition to electronic signatures, records and contracts — administered with the support of the Electronic Transactions Development Agency (ETDA) — allowing many electronic commercial arrangements to be validly concluded without a handwritten signature, subject to the reliability and formality requirements the Act and specific transaction types may require.

Technology Transactions and Infrastructure

Larger technology arrangements — outsourcing, systems implementation, technology-driven joint ventures and infrastructure procurement — combine standard commercial contracting with technology-specific risk allocation around data, uptime, intellectual property and regulatory compliance. Telecommunications and connectivity infrastructure sit under separate licensing requirements administered by the National Broadcasting and Telecommunications Commission (NBTC), relevant where a business’s technology operations extend into network services or spectrum use rather than software or platform services alone.

Emerging Risk

AI, Cybersecurity and Emerging Technology

Artificial Intelligence

Thailand does not yet have comprehensive AI-specific legislation in force. A draft Thailand AI Act, developed by the Electronic Transactions Development Agency, proposes a risk-based framework broadly comparable to international models, including obligations for high-risk AI systems and human oversight requirements. Until such legislation is enacted, AI-related activity in Thailand continues to be governed by existing law — including the PDPA where personal data trains or operates an AI system, the Copyright Act for AI-related works and training data, and general civil liability principles. Businesses deploying or procuring AI should treat this as a fast-moving area and build contracts and governance that can adapt as the regulatory position develops.

Cybersecurity

The Cybersecurity Act establishes a national cybersecurity framework and imposes specific obligations on operators of critical information infrastructure across designated sectors, including incident reporting and cooperation with the National Cybersecurity Committee. Businesses outside these designated sectors are not directly subject to the Act’s critical-infrastructure obligations, but cybersecurity failures frequently intersect with PDPA breach-notification duties and contractual security obligations owed to customers and partners.

When It Matters

When Technology & Privacy Issues Arise

Technology and privacy questions tend to surface at specific moments in a business’s operations in Thailand, rather than as a standing concern.

Launching a Digital Platform

Entering the Thai market with a platform, app or digital service, and structuring compliance from the outset.

Collecting or Processing Data

Building PDPA-compliant data collection, consent and processing practices for customers or employees.

Transferring Data Outside Thailand

Structuring cross-border data flows to affiliates, vendors or cloud providers using the appropriate safeguard.

Deploying or Procuring AI Systems

Assessing legal exposure and contracting for AI tools while Thailand’s AI-specific regulation develops.

Negotiating SaaS or Cloud Agreements

Reviewing or drafting technology contracts covering data, service levels, liability and IP ownership.

Responding to a Data Breach

Managing PDPC notification obligations, individual notification and internal governance after an incident.

Industries

Industries We Support

Technology and privacy considerations vary by sector. These are the industries where this practice area is most consistently central to the legal work.

Technology Software & SaaS AI & Machine Learning Telecommunications Financial Services Fintech & Digital Assets E-Commerce & Digital Platforms Healthcare & Life Sciences Media & Entertainment
Thailand Legal Intelligence

Navigating Thailand’s Digital Regulatory Framework

Technology and privacy regulation in Thailand runs through several regulators rather than one, and a single business activity often falls under more than one at once.

Personal Data Protection Committee
The PDPC oversees the PDPA, investigates complaints and issues notifications and guidance, including the current rules on cross-border data transfers.
Electronic Transactions Development Agency
ETDA supports the Electronic Transactions Act and digital platform regulation, and is leading the development of Thailand’s draft AI legislation.
Ministry of Digital Economy and Society
MDES is the ministry overseeing Thailand’s principal digital-economy legislation, including the PDPA and the Cybersecurity Act.
National Broadcasting and Telecommunications Commission
The NBTC regulates telecommunications licensing, spectrum allocation and network infrastructure.
Overlapping Frameworks
A single activity — deploying an AI system, for example — can simultaneously engage the PDPA, the Copyright Act and, once enacted, AI-specific legislation, making coordinated legal review more useful than a single-law compliance check.
Related Expertise

Related Practice Areas

Intellectual Property

Software copyright, AI-related IP, training data and technology licensing and ownership.

Commercial Contracts

Broader commercial agreements underpinning technology, platform and vendor relationships.

Foreign Investment

Market entry, foreign ownership and licensing considerations for international technology businesses.

FAQ

Technology & Privacy FAQs

Does Thailand have a data privacy law?

Yes. Thailand’s Personal Data Protection Act (PDPA) governs the collection, use and disclosure of personal data and applies to both private and public sector organisations.

Does the PDPA apply to foreign companies with no office in Thailand?

It can. The PDPA applies extraterritorially to organisations outside Thailand that offer goods or services to individuals in Thailand or monitor their behaviour, regardless of whether the organisation has a physical presence in the country.

Can personal data be transferred outside Thailand?

Yes, subject to restrictions. Transfers require either an adequate level of protection in the destination country — for which the PDPC has not yet published a formal list — or appropriate safeguards such as standard contractual clauses or PDPC-certified binding corporate rules.

When must a data breach be reported under the PDPA?

Where a breach poses a risk to individuals’ rights and freedoms, notification to the Personal Data Protection Committee is required without undue delay, and notification to affected individuals may also be required in certain circumstances.

Does Thailand regulate artificial intelligence?

Not yet through comprehensive AI-specific legislation. A draft Thailand AI Act is under development and was released for public consultation, but existing laws — including the PDPA, the Copyright Act and general civil liability principles — currently apply to AI-related activity.

Are electronic signatures legally recognised in Thailand?

Yes, in general. The Electronic Transactions Act gives legal recognition to electronic signatures, records and contracts, though specific reliability and formality requirements can vary by transaction type.

Do online platforms or digital services require a licence in Thailand?

It depends on the nature of the service. General e-commerce and digital platforms are subject to electronic transaction and consumer-facing regulation, while telecommunications, network and connectivity services generally require licensing from the National Broadcasting and Telecommunications Commission (NBTC).

What law governs cybersecurity obligations in Thailand?

The Cybersecurity Act establishes Thailand’s national cybersecurity framework and imposes specific obligations on operators of critical information infrastructure, while cybersecurity failures more broadly can also trigger PDPA breach-notification duties and contractual security obligations.

Need Advice on Technology or Privacy Law in Thailand?

Speak with the right legal expertise for your situation — from PDPA compliance to technology contracts and digital regulation.