+44 212 582 0192 [email protected]

This content is protected against AI scraping.

Thailand PDPA Local Representative:

Secure & On-the-Ground

Ensure full legal alignment with Section 37 of Thailand's Personal Data Protection Act.

Our Service Now Includes AI PDPA Compliance

PDPA AI Compliance FAQ

Q1:Does Thailand’s PDPA apply to AI providers?

A: Yes. Thailand’s PDPA already applies to many AI providers, and emerging Thai AI rules are adding further obligations for high‑risk AI systems and foreign AI companies.

Q2: Does Thailand’s PDPA apply to AI providers?

A: Yes Thailand’s PDPA applies whenever your AI system processes personal data relating to identifiable individuals in Thailand, whether you are based in the Kingdom or operating from overseas. If your AI platform offers services to Thai users or monitors their behaviour online, you are likely considered a data controller targeting Thai data subjects, which triggers PDPA obligations and, for non‑resident controllers, the Section 37 Local Representative requirement.

  • For AI providers, this typically includes recommendation engines, profiling tools, automated credit and risk‑scoring models, HR and recruitment screening systems, marketing automation, healthcare decision‑support, and any AI that influences individuals with legal or similarly significant effects. Under Section 34, where decisions are made solely by automated means, data subjects have specific rights, and your organisation must explain the logic, significance, and consequences of those automated decisions.
  • Foreign AI companies face an additional layer of regulation beyond the PDPA. High‑risk AI providers must appoint a local legal representative in Thailand under the draft AI framework, while PDPA Section 37 requires a Local Representative for non‑resident controllers that target Thai users or monitor their behaviour. This means an AI company without a Thai office can still be legally required to maintain a Thailand‑based point of contact for both PDPA and AI‑specific supervisory authorities.
  • As Thailand’s risk‑based AI regulation formalises, regulators are gaining broad enforcement powers, including the ability to issue stop orders, require platform takedowns, and coordinate investigations through the AI Governance Center and sectoral regulators. For AI providers, aligning PDPA compliance (lawful basis, transparency, DSAR handling, cross‑border transfers) with AI‑specific governance (risk classification, human oversight, incident reporting, record‑keeping) is becoming a single, integrated compliance task rather than two separate exercises.

Q3: We operate an AI platform with no Thai office – do we need a Local Representative?”

If your AI platform has Thai users or monitors the behaviour of people in Thailand, you are likely required to appoint a Local Representative. This usually applies where your AI uses profiling, behavioural tracking, or automated decision‑making involving Thai residents, even if all infrastructure and staff are outside Thailand. If you actively target the Thai market (for example through Thai‑language services, pricing, or campaigns), the Local Representative requirement is even more likely to apply.

Q4: How does a Local Representative help with AI‑related PDPA incidents?
A: A Local Representative acts as your on‑the‑ground point of contact for regulators and data subjects when AI‑related incidents occur. The Legal team can coordinate responses to regulatory inquiries and enforcement actions, the Privacy team can assess AI model breaches, training‑data issues, and automated decision complaints, and the Operations team can execute DSAR handling, evidence collection, and communication workflows through the platform. This ensures that investigation, containment, notification, and ongoing engagement with Thai authorities and affected individuals are managed in a structured, defensible way.

 
 
 

Calculate Your Thailand Local Representative Costs

Entering the Thai market offers immense growth, but Section 37 of the Personal Data Protection Act (PDPA) creates a mandatory "gatekeeper" requirement for non-resident businesses. If you collect data from Thai residents without a physical presence in the Kingdom, you face specific regulatory challenges that Formiti is built to solve..

Instant Thailand Local Representative Costs No Hidden Retainers

Stop guessing your  Thailand Local Representative compliance costs. unlike traditional law firms that bill by the hour, Formiti offers a transparent Fixed Annual Fee based on your data processing volume.

  • Instant Assessment

  • Transparent Tiered Pricing

  • Immediate Certificate Generation Instruction: Use the calculator to see your tailored rate 

Once submitted you will receive an instant email with your quote.  If the price meets your expectations we can provide a fully costed proposal and 24 hour onboarding. No hidden extras or restrictions.

Why Choose Formiti Over a Traditional Law Firm?

Most Section 37 appointments fail because they rely on a single Thai  lawyer or Consultant. We back your compliance with three dedicated teamsLegal, Privacy, and Operations—for less than the cost of a standard law firm retainer.

Feature
Formiti (Three-Team Support)
Traditional Law Firm
Team Structure

3 Specialized Teams

(Legal, Cyber & Admin Experts)

Single Point of Failure
Cost Structure

Fixed Annual Fee

(Includes all standard queries)

Hourly Billing

(Every email costs money)

Liability Coverage

24/7 Rapid Response

(Tech-led data breach triage)

Business Hours Only

(Slow manual response)

Incident Response

24/7 Rapid Response

(Tech-led data breach triage)

Business Hours Only

(Slow manual response)

Onboarding Speed

Instant Digital Appointment

(Certificate 24 Hours

Manual Paperwork

(Days or weeks to finalize

Thailand Official Office Formiti

The Formiti Difference

 Beyond Legal Advice

  1. (The Structure) Unlike law firms that strictly offer legal interpretation, our Three-Team Model provides comprehensive, full-spectrum coverage. We do not rely on a single point of contact; instead, we deploy three specialized units: a Legal Team to handle regulatory nuance and Authority correspondence, a Privacy Team to manage technical triage and breach reporting, and an Operations Team to facilitate Data Subject Access Requests (DSARs) through our secure platform.
  2. (The Operational Impact) This integrated structure fills the critical void left by traditional representation. While a law firm can interpret the regulation, they rarely possess the technical capability to assess a live data breach or the administrative capacity to process sudden spikes in consumer requests. By unifying legal counsel with cyber triage and administrative support, Formiti ensures that when an incident occurs, you have a complete, cohesive response mechanism in place—preventing small compliance gaps from escalating into costly regulatory fines.

The Formiti Difference for AI providers

Formiti’s Legal team assesses how your AI use cases fit under Thailand’s PDPA and emerging AI rules, validating lawful bases for training and inference, reviewing contracts, and ensuring your risk classification and governance approach will stand up to regulatory scrutiny. The Privacy team focuses on the full AI data lifecycle, evaluating training and inference data, minimising unnecessary personal data, and aligning transparency, retention, and cross‑border transfers with Thai requirements and your global privacy posture. The Operations team turns this governance into repeatable execution, using platform‑driven workflows to manage DSARs, incident response, and ongoing communications with Thai regulators and data subjects.

For AI providers, DSARs increasingly focus on automated decisions and profiling, not just raw data access. Formiti’s Operations team can manage requests for explanations of AI‑driven decisions, access to key data used in a model’s outputs, and objections to profiling or automated decision‑making affecting Thai residents, while the Legal and Privacy teams ensure that each response is consistent with PDPA, sectoral rules, and your documented AI governance controls.

Common Questions About Thailand Local Representation

Q1: Who needs a Local Representative under Thailand's PDPA?

Answer: Under Section 37(5) of the Personal Data Protection Act (PDPA), data controllers located outside of Thailand must appoint a Local Representative if they offer goods or services to data subjects in Thailand or monitor their behavior. This requirement specifically applies if you do not have a registered branch or subsidiary within Thai jurisdiction.

Q2: What is the main role of a Thai PDPA Representative?

Answer: Your Local Representative acts as your official point of contact in Thailand. They are legally authorized to receive orders, warrants, and inquiries from the PDPC (Personal Data Protection Committee) and complaints from Thai data subjects on your behalf. They ensure your business can respond to regulatory demands without needing a physical office in Bangkok

Q3: Is the Thailand PDPA Representative the same as a DPO?

Answer: No. A Data Protection Officer (DPO) advises on compliance strategy, whereas the Local Representative is a mandated communication channel. While the roles can sometimes overlap in small firms, the Representative must be physically resident in Thailand to accept legal notices. Formiti provides the Representative service to satisfy the physical presence requirement found in Section 37(5).

Q4: What are the penalties for not appointing a Representative in Thailand?

Answer: Failure to appoint a representative when required is a violation of the PDPA. Administrative fines can reach up to 5 million THB (approx. $145,000 USD), and the PDPC has the authority to issue orders stopping your data processing activities within Thailand, which effectively halts your business operations in the country.

Q5: Can we use our APAC regional office (e.g., in Singapore) as our Thai Representative?

Answer: No. The law requires the Representative to be established within the Kingdom of Thailand. An office in Singapore, Vietnam, or Hong Kong does not satisfy Section 37(5) of the PDPA. You must appoint a Thai national or a juristic person (company) registered in Thailand, like Formiti.

The 4-Step Process

Step 1: Calculate

Use the tool above to estimate your fee based on your data volume.

Step 2: Request

Submit your details in the form below to generate your Thailand Local Representative official proposal.

Step 3: Approve

Review and sign your  Section 37 mandate electronically.

Step 4: Rapid Activation

Our Formiti Rapid Onboarding™ activates your representation within 24 hours.

Thailand Local Representative Clients

Realme client logo