Data Protection & PDPA
Privacy policies, consent, data-subject requests and incident response

This practice covers bringing an organisation's personal-data handling in line with Thailand's PDPA: mapping what data is collected and why, drafting privacy notices and consent language, putting data-processing agreements in place with vendors, handling data-subject requests, and responding to incidents. The firm starts from what the business actually does with data, not from a template.
Who this page is for
- Businesses collecting customer data online or in store
- Companies with HR and recruitment data to handle properly
- Organisations using overseas cloud or marketing vendors
- Teams that received a data-subject access or deletion request
- Organisations dealing with a suspected data breach
What the firm actually handles
- Data mapping and lawful-basis analysis for each processing activity
- Privacy notices, consent forms and cookie notices
- Records of processing and internal policies
- Data-processing agreements with vendors and cross-border transfer terms
- Procedures for data-subject requests
- Incident response, assessment and notification obligations
Matters clients bring us
- A website needs a privacy notice and cookie handling that match reality
- Recruitment data is retained indefinitely with no policy
- A marketing vendor abroad processes customer lists without an agreement
- A customer asks for deletion of their data
- CCTV and access-control data are collected without notice
- A suspected breach requires assessment against notification duties
Documents to bring to the first meeting
- A list of the systems and vendors that hold personal data
- Existing privacy notice, consent forms and internal policies
- Vendor contracts, especially cloud and marketing providers
- HR forms and recruitment materials
- Records of any data-subject requests already received
- Incident logs or vendor reports, where an incident is involved
If some documents are missing, send what you have. The lawyer will tell you which office issues the remaining ones and which documents need certified translation before they can be used.
How the work proceeds
- 1Walk us through what data the business collects and where it goes
- 2We map the processing activities and identify the lawful basis for each
- 3We draft the notices, consent wording and internal policies
- 4We put the vendor and transfer terms in place
- 5We set up the process for data-subject requests and incidents
- 6We review again when systems, vendors or activities change
Pitfalls and common misunderstandings
Consent is not the answer to everything
Relying on consent where another lawful basis fits better creates a fragile position, because consent can be withdrawn. Each activity should be matched to the basis that actually supports it.
A published policy that nobody follows is worse than none
If the notice promises retention limits or controls the organisation does not implement, the document itself becomes evidence of the gap. Policies and practice are aligned rather than drafted separately.
Vendor arrangements are part of your compliance
Using a processor without appropriate terms, or transferring data overseas without addressing the transfer conditions, leaves the organisation exposed even where the vendor is at fault.
Consent, contractual necessity and legitimate interest
Choosing the right lawful basis determines what you must document and what a data subject can require of you.
| Point | Consent | Contractual necessity | Legitimate interest |
|---|---|---|---|
| Best suited to | Marketing and optional activities | Processing needed to deliver the service | Security, fraud prevention and comparable purposes |
| What to document | Clear, specific consent records and withdrawal | The contract and why the data is necessary | A balancing assessment and mitigations |
| Data subject's position | May withdraw consent at any time | Cannot withdraw while the contract requires it | May object; the balance is reconsidered |
| Main risk | Bundled or unclear consent is ineffective | Collecting more than the contract needs | No assessment on file to show the balance |
| Common pitfall | Using consent for everything | Treating optional extras as necessary | Asserting it without any documented analysis |
The right basis depends on the specific activity. A single organisation normally relies on several across different activities.
Hand the whole matter to the firm
The firm can take the whole programme: the data mapping, the notices and policies, the vendor terms, the request and incident procedures, and training for the team that handles requests day to day.
Data Protection & PDPA: frequently asked questions
- Which organisations must comply with the PDPA?
- In broad terms, organisations that collect, use or disclose personal data in Thailand, and in defined circumstances those outside Thailand that handle data of people here. Size is not the deciding factor, so small businesses handling customer or employee data are within scope.
- Is a privacy notice on the website enough?
- No. The notice is the visible part, but compliance rests on knowing what data you hold, having a lawful basis for each use, controlling vendor access, and being able to handle requests and incidents. A notice that does not match practice creates risk of its own.
- How should a data-subject request be handled?
- Verify who is asking, identify what data you hold and where, decide what the request covers under the applicable exceptions, and respond within the required timeframe with a record of what you did. Having the procedure written before the first request is what makes this manageable.
- What should happen after a suspected breach?
- Contain it, then assess what data and how many people are affected and what the risk is, because that assessment drives whether notification is required and in what timeframe. Keep the log from the first hour; it is what the assessment is later built on.
- Can personal data be sent to overseas vendors?
- Cross-border transfers are permitted where the conditions in the law are met, which usually means addressing them in the vendor contract and documenting the basis. Using an overseas cloud provider without those terms is one of the most common gaps we see.
- Do employees' and applicants' data need the same treatment?
- Yes. HR and recruitment data is personal data, and retention of unsuccessful applicants' files without a policy is a frequent issue. Sensitive categories such as health information require additional care.
- Is CCTV covered?
- Images of identifiable people are personal data, so notice, purpose limitation, retention and access controls all apply. Cameras installed without any notice or retention rule are a common finding in reviews.
- Does the organisation need a data protection officer?
- That depends on the nature and scale of the processing and on the criteria in the law. Where one is not required, someone still needs clear responsibility for requests and incidents, otherwise deadlines are missed by default.
Practice areas often handled together with this one
- Corporate & Commercial
Company formation, registry changes, contracts and foreign-investment structures
- Employment & Labour
Employment contracts, work rules, termination and Labour Court disputes
- Intellectual Property
Trademarks, copyright, trade secrets and enforcement
Speak with the lawyer responsible for Data Protection & PDPA
เล่าเรื่องหรือส่งภาพเอกสารมาให้ทีมงานตรวจเบื้องต้น ทนายจะแจ้งแนวทาง เอกสารที่ต้องใช้ กำหนดเวลาที่ต้องระวัง และค่าบริการเป็นลายลักษณ์อักษรก่อนเริ่มงาน






