Thailand’s Personal Data Protection Act could soon undergo significant statutory changes under a draft amendment introduced in the House of Representatives, reshaping enforcement standards for both public and private sectors. According to legislative documents, the proposed overhaul aims to resolve ongoing implementation challenges by expanding government exemptions, establishing a concrete statutory definition for state agencies, and realigning data processing rules with international frameworks like the European Union’s General Data Protection Regulation.
Expanded Government Exemptions and Anticorruption Operations
The current regulatory framework exempts government bodies performing duties related to national security, public safety, anti-money laundering, forensic science, and cybersecurity. According to bill sponsors, the proposed amendment adds the prevention and suppression of corruption and misconduct to this exempt list. This change directly impacts agencies like the National Anti-Corruption Commission, allowing them to collect, use, and disclose personal data without standard restrictions while executing official duties. The public consultation phase for this draft amendment runs through August 15, accepting feedback before moving further through the legislative pipeline.
Defining Government Agencies Under Thai Law
Legal uncertainty has persisted regarding which entities qualify as government agencies under the existing statute. To resolve this ambiguity, the draft bill introduces a comprehensive statutory definition covering central, regional, and local government bodies, alongside state enterprises and public organizations. Parliament, courts, independent constitutional organizations, the Office of the Attorney General, public higher-education institutions, and independent state agencies are also explicitly included. This clarification ensures that compliance boundaries are clearly demarcated for a broader swath of the public sector.
Restructuring Lawful Bases for Data Processing
For private enterprises and data controllers, the most impactful modification involves the restructuring of Section 24. Currently, the law prohibits data collection without consent, relying on narrow carveouts. The draft amendment adopts a multiple-lawful-bases model comparable to GDPR standards. Under the revised framework, personal data processing becomes lawful when meeting at least one of seven coequal criteria: consent, legal obligation, contractual necessity, vital interests, public tasks or official authority, legitimate interests, and archival, research, or statistical purposes.
Did you know? Under the proposed amendment, consent is repositioned from the default requirement under Thai privacy law to one of seven coequal lawful bases for data processing.
Frequently Asked Questions
What is the status of the PDPA amendment bill?
The draft bill has been introduced in the House of Representatives and is currently undergoing a public consultation phase, with comments accepted through August 15.
According to the legislative proposal, the bill will take effect the day after its publication in the Government Gazette.
Stay Informed on Regulatory Changes
Subscribe to our regulatory updates or join the conversation below to share your perspective on the evolving compliance landscape in Asia.
Keep reading