Personal Data Protection Act, cross-border transfer
Personal Data Protection Act B.E. 2562 (2019), Section 28
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 June 2022.
A cross border transfer rule binding private bodies.
As of 29 August 2026.
What it requires
- An app transferring the personal data of an individual in Thailand to a recipient in another country must ensure the destination has an adequate data protection standard, following the Committee's prescribed rules, unless a statutory exception such as informed consent to an inadequate destination applies.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 28 requires that where a Data Controller sends or transfers personal data to a foreign country, the destination country or international organization must have an adequate data protection standard and the transfer must follow rules the Personal Data Protection Committee prescribes, subject to exceptions including legal compliance, informed consent where the data subject is told the destination's standard is inadequate, and contract necessity. This is an adequacy-based restriction; no data-localization mandate was found.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.