Technology & Privacy Law in Thailand
Navigate technology and privacy law in Thailand, from personal data protection to cloud contracts, AI governance and digital platforms. ThaiAttorneys helps businesses identify relevant lawyers and other legal professionals for their technology and data needs.
Discuss Your Technology or Privacy Matter
Understanding Technology and Privacy Law in Thailand
A product launch, cloud migration or new use of customer data can involve several areas of law. Data protection, contracts, intellectual property, electronic transactions and sector-specific regulation need to be considered alongside how the technology will operate.
ThaiAttorneys is a legal information and professional connections platform. This page helps you identify the expertise relevant to your product, service or data activity, whether you are planning a deployment, reviewing a vendor agreement or responding to an incident.
The Personal Data Protection Act (PDPA) can apply to overseas controllers and processors where the relevant processing relates to offering goods or services to individuals in Thailand, or monitoring behaviour taking place in Thailand. Assess the activity and applicable exceptions; a Thai office is not always necessary for the Act to apply.
Technology & Privacy Expertise
Explore data governance, technology contracting and digital regulation. A single project may require expertise across more than one of these areas.
Privacy & Risk
- Data Privacy & PDPA Compliance
- Cybersecurity & Breach Response
- AI Governance & Contracting
Contracts & Deployment
- Software, SaaS & Cloud Agreements
- Technology Transactions & Licensing
- Electronic Transactions & Signatures
Regulation & Market Access
- Digital Platforms & E-Commerce
- Telecommunications & Infrastructure
- Digital Content & Platform Regulation
Data Protection and Privacy Law in Thailand
The PDPA Framework
PDPA compliance in Thailand begins with identifying the personal data involved, the purposes for processing it and the roles of the organisations handling it. Review the applicable lawful basis, privacy notices, security, retention and procedures for individual rights. Consent is one possible basis, rather than a universal requirement. Sensitive data, processor arrangements and data protection officer requirements need separate assessment.
Cross-Border Data Transfers
Map where personal data is sent, stored and accessed, including overseas affiliates and service providers. Assess the applicable transfer route, which may involve adequate protection, qualifying safeguards or a statutory exception. An ordinary commercial contract does not automatically satisfy the transfer requirements.
Review the transfer mechanism alongside processor terms, onward transfers, security and the purposes for which the recipient may use the data. The assessment depends on the parties, destination, data and current requirements.
Breach Response and Governance
Assess personal data breaches promptly. A controller must notify the Office of the PDPC without delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to risk individuals’ rights and freedoms. High-risk breaches also require notification to affected individuals without delay, with remedial measures. Internal escalation, evidence preservation and a documented risk assessment support timely decisions.
Technology and Digital Business in Thailand
Software, SaaS and Cloud
Software development, software-as-a-service (SaaS) and cloud agreements should reflect how the service will be delivered. Review scope, acceptance, service levels, data use, security, subcontractors, liability and exit support. Intellectual property ownership, licence scope and open-source components may also need attention. The appropriate terms depend on the product and the parties’ roles.
Digital Platforms, E-Commerce and Electronic Transactions
Online platforms may need to assess notification and ongoing obligations under Thailand’s digital platform framework, alongside consumer terms and personal data practices. Electronic signatures and records can receive legal recognition, subject to the applicable reliability requirements, exclusions and transaction formalities. For an official starting point, see ETDA’s digital platform resources (Thai).
Technology Transactions and Infrastructure
Outsourcing, systems implementation and infrastructure procurement can involve business continuity, integration, intellectual property, data migration and regulatory responsibilities. Agreements should address acceptance, change control and what happens when the relationship ends. Telecommunications and spectrum activities may require a separate licensing assessment involving the National Broadcasting and Telecommunications Commission (NBTC).
AI, Cybersecurity and Emerging Technology
Artificial Intelligence
For artificial intelligence (AI) projects, identify the intended use, data inputs, outputs, affected people and level of human oversight. Review personal data, intellectual property, confidentiality, vendor rights, security and responsibility for errors. The rules relevant to a deployment depend on its purpose, sector and operational context.
Distinguish binding requirements from policy proposals and voluntary guidance, and check the position when planning a deployment. ETDA’s AI Governance Practice Center (Thai) provides resources relevant to organisational AI governance.
Cybersecurity
The Cybersecurity Act provides a national framework, including specific requirements for designated critical information infrastructure. Assess designation, sector rules and the relevant authorities rather than assuming the same obligations apply to every business. Other organisations may still face applicable legal duties, regulatory measures and contractual security requirements. A cyber incident may also trigger a separate PDPA breach assessment.
When Technology & Privacy Issues Arise
Legal review can be particularly useful before a launch, procurement or change in data use, as well as during incident response. Governance and vendor oversight also continue after deployment.
Launching a Digital Platform
Entering the Thai market with a platform, app or digital service, and structuring compliance from the outset.
Collecting or Processing Data
Reviewing lawful bases, notices, retention and data-handling practices for customer or employee information.
Transferring Data Outside Thailand
Structuring cross-border data flows to affiliates, vendors or cloud providers using the appropriate safeguard.
Deploying or Procuring AI Systems
Reviewing data use, vendor terms, outputs, oversight and applicable requirements for an AI deployment.
Negotiating SaaS or Cloud Agreements
Reviewing or drafting technology contracts covering data, service levels, liability and IP ownership.
Responding to a Data Breach
Managing PDPC notification obligations, individual notification and internal governance after an incident.
Technology & Privacy Across Industries
Data sensitivity, customer relationships and sector rules can change the legal questions a business needs to address. These sectors illustrate the range of technology and privacy contexts.
Navigating Thailand’s Digital Regulatory Framework
Technology and privacy regulation in Thailand runs through several regulators rather than one, and a single business activity often falls under more than one at once.
- Personal Data Protection Committee
- The PDPC and its Office have regulatory and administrative roles under the PDPA. Applicable notifications and guidance help inform compliance, transfer and incident-response assessments.
- Electronic Transactions Development Agency
- ETDA supports electronic transactions and has responsibilities concerning digital platforms and related services. Its resources also address electronic signatures, standards and AI governance.
- Ministry of Digital Economy and Society
- MDES has digital-economy policy and legislative responsibilities. Specific duties and regulatory powers sit with the bodies identified under each applicable law.
- National Broadcasting and Telecommunications Commission
- The NBTC regulates telecommunications licensing, spectrum allocation and network infrastructure.
- Overlapping Frameworks
- An AI deployment or platform launch may involve data protection, intellectual property, contracts, consumer requirements and sector regulation. Map these obligations to the actual activity and the organisations responsible.
Related Practice Areas
Intellectual Property
Software copyright, AI-related IP, training data and technology licensing and ownership.
Commercial Contracts
Broader commercial agreements underpinning technology, platform and vendor relationships.
Foreign Investment
Market entry, foreign ownership and licensing considerations for international technology businesses.
Technology & Privacy FAQs
Does Thailand have a data privacy law?
Yes. The PDPA is a central part of privacy law in Thailand. It regulates personal data processing by organisations within its scope, subject to statutory exceptions. Duties vary with the activity and whether an organisation acts as a controller or processor.
Does the PDPA apply to foreign companies with no office in Thailand?
It can. Overseas processing may fall within scope where it relates to offering goods or services to individuals in Thailand, or monitoring behaviour that takes place in Thailand. The particular processing and any applicable exceptions need to be assessed.
Can personal data be transferred outside Thailand?
Yes, where the applicable legal conditions are met. Available routes may include adequate protection, qualifying safeguards or a statutory exception. Review the destination, recipient, onward transfers and relevant PDPC requirements rather than assuming a vendor contract is sufficient.
When must a data breach be reported under the PDPA?
A controller must notify the Office of the PDPC without delay and, where feasible, within 72 hours of awareness, unless the breach is unlikely to risk individuals’ rights and freedoms. High-risk breaches also require affected individuals to be notified without delay, with remedial measures. Assess the facts promptly.
Does Thailand regulate artificial intelligence?
AI use can engage data protection, intellectual property, consumer, contractual and sector-specific requirements. Check the binding rules applicable to the proposed use and distinguish them from draft legislation or voluntary guidance. The answer depends on the activity, not simply whether the system is described as AI.
Are electronic signatures legally recognised in Thailand?
Yes, generally, subject to the Electronic Transactions Act and applicable transaction requirements. Review how the method identifies the signatory, demonstrates approval and supports reliable records. Certain transactions may involve exclusions or additional formalities.
Do online platforms or digital services require a licence in Thailand?
Not every digital service follows the same route. Some platforms have notification and ongoing obligations under ETDA’s framework. Activities such as regulated telecommunications or financial services may require separate licences or approvals. Assess the business model and services offered.
What law governs cybersecurity obligations in Thailand?
The Cybersecurity Act is one relevant framework, with specific provisions for critical information infrastructure. Data protection law, sector rules and contracts may impose additional requirements. Security incidents should be assessed for each applicable reporting and response duty.
Need Advice on Technology or Privacy Law in Thailand?
Describe your product, service or data activity, the organisations involved and any important dates. ThaiAttorneys helps identify relevant expertise in technology and privacy law in Thailand.