PDPA enforcement is real: recent fines
Many businesses still treat the PDPA as a paper law. The numbers say otherwise. Thailand's Personal Data Protection Committee (PDPC) has started striking: the country's first fine hit a major IT retailer for ฿7 million over a customer data leak; the Election Commission was fined ฿335,000 after data on more than 23,000 senate candidates leaked; and 2025 orders against public and private organisations totalled over ฿21.5 million. In 2026 the PDPC is also aggressively investigating a 200,000-record breach at a health platform.
Your core duties under the PDPA
- Obtain consent or another legal basis before collecting/using/disclosing personal data, with clearly stated purposes.
- Collect only what you need (data minimisation) and delete data when no longer necessary.
- Implement appropriate security — encryption, access control, activity logging.
- Sign clear agreements with data processors — including your hosting/cloud provider — defining who is responsible for what.
- Report breaches to the PDPC within 72 hours, and to affected individuals when their rights are significantly impacted.
- Honour data-subject rights — access, correction, deletion and consent withdrawal.
Why server location matters
- Cross-border transfers are conditional under Section 28 — the destination must offer adequate protection or fit an exception. Keeping data in Thailand removes that entire question.
- Sector regulators (finance, health, insurance) impose stricter storage and audit expectations, which are easier to satisfy with in-country servers.
- When incidents require evidence or forensics, physical access to a Thai data center is immediate — no cross-border process.
- Thai providers sit directly under the PDPA as data processors, making DPAs and security verification straightforward.
A PDPA-friendly hosting checklist
- 1Data center in Thailand, Tier III or better, with physical access control (biometric, CCTV).
- 2Security certifications such as ISO/IEC 27001 and documented PDPA-aligned practices.
- 3Willingness to sign a Data Processing Agreement (DPA) with clear responsibility boundaries.
- 4Logging and access-control features you can audit.
- 5Network-level DDoS protection and firewalls — network gaps are a common leak origin.
- 6Fast 24/7 support — the PDPA's 72-hour clock counts every minute.
Your breach response plan
- 1Stop the leak — isolate affected systems, rotate credentials, close the exploited path.
- 2Scope it within the first 24 hours: what data, how many people, what impact on their rights.
- 3Notify the PDPC within 72 hours with incident details and measures already taken.
- 4Notify data subjects if their rights face high risk, with practical advice such as changing passwords.
- 5Preserve evidence throughout, write the incident report, and fix the root cause so it cannot recur.
Sources
- Isra News — First PDPA fine: PDPC orders ฿7M penalty over customer data leak: isranews.org/article/isranews-news/131111-invessdsddssd.html
- Matichon — Election Commission fined ฿335,000 over senate candidate data leak: matichon.co.th/politics/news_5499733
- Bangkok Biz News — PDPC fines public and private organisations over data leaks: bangkokbiznews.com/tech/gadget/1192423
- Thairath — PDPC investigates 2026 health-platform data leak: thairath.co.th/money/economics/thai_economics/2949404




