Services

Compliance

PDPA Compliance

Compliance with Thailand's Personal Data Protection Act that can be proven, not only documented.

Overview

Thailand's Personal Data Protection Act applies to organisations in Thailand, and to many outside it that offer goods or services to people in Thailand or monitor their behaviour there. For operations that handle passports, faces, health records or payment details, a privacy policy is where compliance starts, not how it is proven.

PDPA Compliance treats data protection as a property of the systems rather than a document beside them. We map where personal data enters, where it is stored, who can reach it and where it goes, then build the controls that close the gaps: consent captured before collection, retention enforced, requests from individuals handled and every access logged.

Biometric and health data are sensitive personal data under the Act and generally require explicit consent, so we give them separate consent, tighter access and a documented retention period. Our delivery team in Thailand can support the organisation's data protection officer day to day.

Capabilities

Data mapping and gap analysis

A record of what personal data is collected, why, where it is stored and who receives it, assessed against the requirements of the Act.

Consent management

Consent captured before collection, specific to each purpose, stored in a ledger and as easy to withdraw as it was to give.

Retention and deletion

Retention periods defined for each type of data and enforced by the systems themselves, with deletion that can be shown to have happened.

Data subject requests

Requests to access, correct, export or delete personal data handled through a defined process, with every deadline tracked.

Audit trails and access logging

Every access to personal data logged against a named user, so the organisation can show who saw what and when.

DPO support

Practical support for the data protection officer, including policies, processor agreements, breach response plans and staff training.

Technical detail

Industries

Questions

Does this replace our lawyers or our DPO?
No. Legal advisers interpret the Act and the data protection officer remains accountable. We map the data, build the controls and keep the evidence that shows they work.
We already have a privacy policy. Is that enough?
A policy says what should happen. An audit or a complaint asks what did happen, which is why consent, access and deletion need records behind them.
How is biometric data treated?
As sensitive personal data. It generally requires explicit consent collected separately, access limited to the people who need it, and a documented period after which it is deleted.
Talk to us about PDPA Compliance

More services