
Step 1: Determine Your Extraterritorial Obligations Under PDPA
Thailand's PDPA binds organisations that have never incorporated in the country, never leased an office there, and never billed a customer in baht. Before you design any controls, establish whether Section 5 captures your entity as a controller or processor located outside Thailand.
Work through the scope test in this order:
- Confirm whether you offer goods or services to data subjects in Thailand, irrespective of whether payment is required from those individuals.
- Identify any monitoring of the behaviour of data subjects while they are within Thailand — analytics, ad tracking, device fingerprinting and app telemetry all qualify.
- Assess your processing volume against the "large amount" threshold used to determine whether small-enterprise relief from the data protection officer requirement applies to you.
- Map which group entities actually make the purpose-and-means decisions, because extraterritorial liability follows the controller, not the local sales channel.
A Thai-language website, a local payment rail or a regional CDN node is enough to trigger scope. Absence of a legal entity in Thailand is not a defence.
This is where Formiti Consulting closes the gap between legal theory and operational reality, combining expert advisory with a proprietary SaaS platform, Privacy360, so scope decisions are evidenced rather than assumed.
Step 2: Appoint a Thailand Local Representative
Need a Thailand representative? Formiti acts as your PDPA local representative with full authority to deal with the PDPC and data subjects. Explore our Thailand PDPA representative and compliance service →
Offshore controllers and processors within scope must appoint a representative in Thailand. Treat this as a statutory empowerment exercise, not a procurement task — the Thailand local representative PDPA obligation fails the moment the appointee lacks authority to answer for you.
- Select a representative who is resident in Thailand or a juristic person established under Thai law, with the standing to receive regulatory correspondence locally.
- Draft a written appointment instrument that names the controller, identifies the processing activities covered, and expressly authorises the representative to act on the controller's behalf.
- Empower the representative to communicate directly with the PDPC and with data subjects, and to produce records on demand without needing head-office sign-off for each response.
- Publish the representative's identity and contact details in your Thai-facing privacy notice so data subjects can reach them without routing through an overseas helpdesk.
Technical callout — limitation of liability. The appointment must operate without limitation of liability on the controller's part. Any clause capping the representative's authority, or framing them as a commercial agent or reseller contact, undermines the appointment and leaves the offshore entity exposed.
Step 3: Operationalise Data Subject Rights and Consent
Appointing a representative achieves nothing if the systems behind them cannot produce a response. This is the engineering half of pdpa compliance step by step.
- Rewrite your Thai privacy notice against the PDPC Practice Guidelines on privacy notices and consent, stating purposes, legal bases, retention periods and the representative's contact point in Thai as well as English.
- Rebuild consent capture so consent is explicit, unbundled from terms of service, and recorded with a timestamp and version — and so withdrawal is as straightforward as the original opt-in.
- Route Thai rights requests — access, rectification, erasure, objection, portability — through a local channel operated by or reachable via the representative, with defined internal escalation owners.
- Extend your records of processing to log each cross-border transfer out of Thailand, the receiving jurisdiction, and the transfer mechanism relied upon.
Verify the build by submitting a test request in Thai through the published channel. If it cannot be resolved without an exception process, the control is not live.
Step 4: Mitigate Criminal Liability for Directors
Thailand departs sharply from administrative-only regimes. The PDPA's penalty provisions attach criminal exposure — including custodial sentences — to certain unlawful disclosures and misuse of sensitive personal data, and that exposure can reach directors and managers of the offending entity personally. For foreign leadership, Thailand data privacy for offshore entities is therefore a board-level risk, not a functional one.
| Violation type | Potential penalty | Responsible party |
|---|---|---|
| Unlawful use or disclosure of general personal data | Administrative fine | Controller entity |
| Unlawful use or disclosure of sensitive personal data | Criminal penalty, including imprisonment, plus fine | Entity and responsible directors |
| Disclosure of personal data obtained in the course of duties | Criminal penalty | Individual discloser |
| Failure to appoint a representative or DPO where required | Administrative fine | Controller entity |
Confirm current penalty thresholds with Thai counsel before briefing the board. Then give the DPO or representative a direct reporting line to the board, minute the escalations, and retain the assessments, training logs and vendor reviews that evidence reasonable steps.
How to Maintain Long-Term PDPA Compliance: Key Takeaways
Thailand PDPA compliance for foreign companies rests on a single mechanism: a legally empowered local presence that can answer to the regulator. Everything else — notices, consent, records, transfer justifications — hangs off that appointment.
- Scope is activity-based. Offering goods or services to, or monitoring, data subjects in Thailand brings foreign companies into the PDPA regardless of local incorporation.
- Appointing a local representative in Thailand is a statutory mandate for in-scope offshore entities, and the appointment must carry real authority without limitation of liability.
- Consent must be explicit, granular and as easy to withdraw as to give, aligned to PDPC Practice Guidelines.
- Criminal liability can extend to directors, so document oversight and retain evidence of reasonable steps.
- Reassess scope whenever you launch a Thai-language product, add a processor, or change a cross-border transfer route.
Formiti Consulting closes the gap between legal theory and operational reality by combining expert advisory with a proprietary SaaS platform. Privacy360, alongside outsourced DPO and cross-border representation services, keeps Thailand evidence audit-ready across a 120+ jurisdiction programme. Speak to Formiti Consulting about appointing your Thai representative →