Overview
Thailand's Personal Data Protection Act applies to organisations in Thailand, and to many outside it that offer goods or services to people in Thailand or monitor their behaviour there. For operations that handle passports, faces, health records or payment details, a privacy policy is where compliance starts, not how it is proven.
PDPA Compliance treats data protection as a property of the systems rather than a document beside them. We map where personal data enters, where it is stored, who can reach it and where it goes, then build the controls that close the gaps: consent captured before collection, retention enforced, requests from individuals handled and every access logged.
Biometric and health data are sensitive personal data under the Act and generally require explicit consent, so we give them separate consent, tighter access and a documented retention period. Our delivery team in Thailand can support the organisation's data protection officer day to day.
Capabilities
Data mapping and gap analysis
A record of what personal data is collected, why, where it is stored and who receives it, assessed against the requirements of the Act.
Consent management
Consent captured before collection, specific to each purpose, stored in a ledger and as easy to withdraw as it was to give.
Retention and deletion
Retention periods defined for each type of data and enforced by the systems themselves, with deletion that can be shown to have happened.
Data subject requests
Requests to access, correct, export or delete personal data handled through a defined process, with every deadline tracked.
Audit trails and access logging
Every access to personal data logged against a named user, so the organisation can show who saw what and when.
DPO support
Practical support for the data protection officer, including policies, processor agreements, breach response plans and staff training.
Technical detail
Industries
Questions
- Does this replace our lawyers or our DPO?
- No. Legal advisers interpret the Act and the data protection officer remains accountable. We map the data, build the controls and keep the evidence that shows they work.
- We already have a privacy policy. Is that enough?
- A policy says what should happen. An audit or a complaint asks what did happen, which is why consent, access and deletion need records behind them.
- How is biometric data treated?
- As sensitive personal data. It generally requires explicit consent collected separately, access limited to the people who need it, and a documented period after which it is deleted.
More services
- 01AI DefenseAI securityProtection against prompt injection, data leakage and model abuse, with red teaming, AI governance and monitoring, and AI-assisted threat detection across your systems.
- 02Cyber SecuritySecuritySecurity assessments, identity and access control, monitoring and incident response for the systems that hold identities, payments and operational data.
- 03ConsultingAdvisoryStrategy, architecture and governance advice for leadership teams, starting with an audit delivered as a document you own and are free to take elsewhere.