What PDPA (Thailand) actually requires
Thailand's first comprehensive data protection law, closely modelled on the GDPR. It requires a lawful basis for processing personal data, with explicit consent the most common basis for non-essential cookies. The law is enforced by the Personal Data Protection Committee (PDPC Thailand).
Key requirements
- Obtain explicit consent before processing personal data, with very limited exceptions
- Provide a clear privacy notice in Thai and (typically) English
- Allow data subjects to access, correct, delete and port their data
- Appoint a Data Protection Officer for certain categories of processing
- Notify the PDPC and affected users of qualifying personal-data breaches within 72 hours
- Sign data processing agreements with vendors that handle personal data
At a glance
Full name
Personal Data Protection Act B.E. 2562 (2019)
Region
Thailand
Status
Fully enforceable since June 2022
Who it affects
Any data controller or processor that collects, uses or discloses personal data — including organisations based outside Thailand that offer goods or services to people in Thailand or monitor their behaviour.
Penalties
Administrative fines up to THB 5 million per violation, plus criminal penalties (including imprisonment) and civil damages including punitive damages up to twice the actual loss.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
