PDPA enforcement is real: recent fines

Many businesses still treat the PDPA as a paper law. The numbers say otherwise. Thailand's Personal Data Protection Committee (PDPC) has started striking: the country's first fine hit a major IT retailer for ฿7 million over a customer data leak; the Election Commission was fined ฿335,000 after data on more than 23,000 senate candidates leaked; and 2025 orders against public and private organisations totalled over ฿21.5 million. In 2026 the PDPC is also aggressively investigating a 200,000-record breach at a health platform.

Your core duties under the PDPA

  • Obtain consent or another legal basis before collecting/using/disclosing personal data, with clearly stated purposes.
  • Collect only what you need (data minimisation) and delete data when no longer necessary.
  • Implement appropriate security — encryption, access control, activity logging.
  • Sign clear agreements with data processors — including your hosting/cloud provider — defining who is responsible for what.
  • Report breaches to the PDPC within 72 hours, and to affected individuals when their rights are significantly impacted.
  • Honour data-subject rights — access, correction, deletion and consent withdrawal.

Why server location matters

  • Cross-border transfers are conditional under Section 28 — the destination must offer adequate protection or fit an exception. Keeping data in Thailand removes that entire question.
  • Sector regulators (finance, health, insurance) impose stricter storage and audit expectations, which are easier to satisfy with in-country servers.
  • When incidents require evidence or forensics, physical access to a Thai data center is immediate — no cross-border process.
  • Thai providers sit directly under the PDPA as data processors, making DPAs and security verification straightforward.

A PDPA-friendly hosting checklist

  1. 1Data center in Thailand, Tier III or better, with physical access control (biometric, CCTV).
  2. 2Security certifications such as ISO/IEC 27001 and documented PDPA-aligned practices.
  3. 3Willingness to sign a Data Processing Agreement (DPA) with clear responsibility boundaries.
  4. 4Logging and access-control features you can audit.
  5. 5Network-level DDoS protection and firewalls — network gaps are a common leak origin.
  6. 6Fast 24/7 support — the PDPA's 72-hour clock counts every minute.

Your breach response plan

  1. 1Stop the leak — isolate affected systems, rotate credentials, close the exploited path.
  2. 2Scope it within the first 24 hours: what data, how many people, what impact on their rights.
  3. 3Notify the PDPC within 72 hours with incident details and measures already taken.
  4. 4Notify data subjects if their rights face high risk, with practical advice such as changing passwords.
  5. 5Preserve evidence throughout, write the incident report, and fix the root cause so it cannot recur.

Sources