Skip to content
ทีมทนาย Notary Public บริษัท Thai Notary Law & Service — ทนายผู้ได้รับใบอนุญาตทำคำรับรองลายมือชื่อและเอกสารจากสภาทนายความในพระบรมราชูปถัมภ์

ทีมทนายผู้ได้รับใบอนุญาต Notarial Services Attorney

ใบอนุญาตจากสภาทนายความในพระบรมราชูปถัมภ์

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายอนุตรีย์ Miss Anutaree

    ทนายอนุตรีย์Miss Anutaree

    Notarial Services Attorney • Sworn Translator

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายจิรพันธ์ Mr. Jirapan

    ทนายจิรพันธ์Mr. Jirapan

    Notarial Services Attorney • Corporate Counsel

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายจิรศักดิ์ Mr. Jirasak

    ทนายจิรศักดิ์Mr. Jirasak

    Notarial Services Attorney • Litigation

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายปฏิภาณ Mr. Patipan

    ทนายปฏิภาณMr. Patipan

    Notarial Services Attorney • Immigration

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายวราวุธ Mr. Warawut

    ทนายวราวุธMr. Warawut

    Notarial Services Attorney • Real Estate

  • ใบอนุญาตทนายทำคำรับรองลายมือชื่อและเอกสาร (Notary Public) ของ ทนายวิวัฒน์ Mr. Wiwat

    ทนายวิวัฒน์Mr. Wiwat

    Notarial Services Attorney • Family & Marriage

เลื่อนดูใบอนุญาตทั้งหมด →

Data Protection & PDPA

Privacy policies, consent, data-subject requests and incident response

A lawyer reviewing a data-processing map and privacy documentation on a laptop and printed sheets

This practice covers bringing an organisation's personal-data handling in line with Thailand's PDPA: mapping what data is collected and why, drafting privacy notices and consent language, putting data-processing agreements in place with vendors, handling data-subject requests, and responding to incidents. The firm starts from what the business actually does with data, not from a template.

Who this page is for

  • Businesses collecting customer data online or in store
  • Companies with HR and recruitment data to handle properly
  • Organisations using overseas cloud or marketing vendors
  • Teams that received a data-subject access or deletion request
  • Organisations dealing with a suspected data breach

What the firm actually handles

  • Data mapping and lawful-basis analysis for each processing activity
  • Privacy notices, consent forms and cookie notices
  • Records of processing and internal policies
  • Data-processing agreements with vendors and cross-border transfer terms
  • Procedures for data-subject requests
  • Incident response, assessment and notification obligations

Matters clients bring us

  • A website needs a privacy notice and cookie handling that match reality
  • Recruitment data is retained indefinitely with no policy
  • A marketing vendor abroad processes customer lists without an agreement
  • A customer asks for deletion of their data
  • CCTV and access-control data are collected without notice
  • A suspected breach requires assessment against notification duties

Documents to bring to the first meeting

  • A list of the systems and vendors that hold personal data
  • Existing privacy notice, consent forms and internal policies
  • Vendor contracts, especially cloud and marketing providers
  • HR forms and recruitment materials
  • Records of any data-subject requests already received
  • Incident logs or vendor reports, where an incident is involved

If some documents are missing, send what you have. The lawyer will tell you which office issues the remaining ones and which documents need certified translation before they can be used.

How the work proceeds

  1. 1Walk us through what data the business collects and where it goes
  2. 2We map the processing activities and identify the lawful basis for each
  3. 3We draft the notices, consent wording and internal policies
  4. 4We put the vendor and transfer terms in place
  5. 5We set up the process for data-subject requests and incidents
  6. 6We review again when systems, vendors or activities change

Pitfalls and common misunderstandings

Consent is not the answer to everything

Relying on consent where another lawful basis fits better creates a fragile position, because consent can be withdrawn. Each activity should be matched to the basis that actually supports it.

A published policy that nobody follows is worse than none

If the notice promises retention limits or controls the organisation does not implement, the document itself becomes evidence of the gap. Policies and practice are aligned rather than drafted separately.

Vendor arrangements are part of your compliance

Using a processor without appropriate terms, or transferring data overseas without addressing the transfer conditions, leaves the organisation exposed even where the vendor is at fault.

Consent, contractual necessity and legitimate interest

Choosing the right lawful basis determines what you must document and what a data subject can require of you.

PointConsentContractual necessityLegitimate interest
Best suited toMarketing and optional activitiesProcessing needed to deliver the serviceSecurity, fraud prevention and comparable purposes
What to documentClear, specific consent records and withdrawalThe contract and why the data is necessaryA balancing assessment and mitigations
Data subject's positionMay withdraw consent at any timeCannot withdraw while the contract requires itMay object; the balance is reconsidered
Main riskBundled or unclear consent is ineffectiveCollecting more than the contract needsNo assessment on file to show the balance
Common pitfallUsing consent for everythingTreating optional extras as necessaryAsserting it without any documented analysis

The right basis depends on the specific activity. A single organisation normally relies on several across different activities.

Hand the whole matter to the firm

The firm can take the whole programme: the data mapping, the notices and policies, the vendor terms, the request and incident procedures, and training for the team that handles requests day to day.

Data Protection & PDPA: frequently asked questions

Which organisations must comply with the PDPA?
In broad terms, organisations that collect, use or disclose personal data in Thailand, and in defined circumstances those outside Thailand that handle data of people here. Size is not the deciding factor, so small businesses handling customer or employee data are within scope.
Is a privacy notice on the website enough?
No. The notice is the visible part, but compliance rests on knowing what data you hold, having a lawful basis for each use, controlling vendor access, and being able to handle requests and incidents. A notice that does not match practice creates risk of its own.
How should a data-subject request be handled?
Verify who is asking, identify what data you hold and where, decide what the request covers under the applicable exceptions, and respond within the required timeframe with a record of what you did. Having the procedure written before the first request is what makes this manageable.
What should happen after a suspected breach?
Contain it, then assess what data and how many people are affected and what the risk is, because that assessment drives whether notification is required and in what timeframe. Keep the log from the first hour; it is what the assessment is later built on.
Can personal data be sent to overseas vendors?
Cross-border transfers are permitted where the conditions in the law are met, which usually means addressing them in the vendor contract and documenting the basis. Using an overseas cloud provider without those terms is one of the most common gaps we see.
Do employees' and applicants' data need the same treatment?
Yes. HR and recruitment data is personal data, and retention of unsuccessful applicants' files without a policy is a frequent issue. Sensitive categories such as health information require additional care.
Is CCTV covered?
Images of identifiable people are personal data, so notice, purpose limitation, retention and access controls all apply. Cameras installed without any notice or retention rule are a common finding in reviews.
Does the organisation need a data protection officer?
That depends on the nature and scale of the processing and on the criteria in the law. Where one is not required, someone still needs clear responsibility for requests and incidents, otherwise deadlines are missed by default.

Speak with the lawyer responsible for Data Protection & PDPA

เล่าเรื่องหรือส่งภาพเอกสารมาให้ทีมงานตรวจเบื้องต้น ทนายจะแจ้งแนวทาง เอกสารที่ต้องใช้ กำหนดเวลาที่ต้องระวัง และค่าบริการเป็นลายลักษณ์อักษรก่อนเริ่มงาน