Newsroom

July 28, 2026RegulationOpsian

Thailand's PDPA is being enforced. Operations data is where it bites

Thailand's Personal Data Protection Act has been fully in force since June 2022, and the regulator now issues administrative fines. Guest, patient and staff records held across operational systems are where most exposure sits.

Thailand's Personal Data Protection Act B.E. 2562 came fully into force on 1 June 2022 after two postponements. The Personal Data Protection Committee has since moved from guidance to enforcement, including administrative fines against organisations that failed to protect personal data.

Most PDPA programmes start with the website: a cookie banner, a privacy notice, a consent checkbox on the booking form. The larger exposure is usually elsewhere, in the operational systems that hold passports, health information, access logs and staff records, often copied between vendors that each keep their own version.

Where operational data leaks

In the audits Opsian runs, the same patterns recur:

  • Copies: passport scans in the property management system, the email inbox, a shared drive and the immigration portal, each with different access.
  • No retention rule: records kept indefinitely because nothing deletes them.
  • Shared logins at the front desk or nurses' station, so nobody can say who viewed a record.
  • Sensitive data in the wrong place: biometric and health data, which the Act treats as sensitive, stored alongside ordinary fields with the same controls.

Controls that hold up

The fixes are architectural rather than documentary. Capture consent at the moment data is collected, and store it with the record. Keep one canonical record for each person instead of a copy per system. Apply retention per site and per data type, and let the system delete on schedule. Give every user and every agent their own identity, and log every access.

That is the approach behind ENTRIX: consent captured before capture, retention rules applied per site, and a trail that shows who saw what and when. It is also the substance of Opsian's PDPA compliance service, which starts by finding every copy before deciding what to protect.

Sources

Related