Personal Data Protection Act, breach notification
Personal Data Protection Act B.E. 2562 (2019), Section 37(4)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 June 2022.
A breach notification rule binding private bodies.
As of 29 August 2026.
What it requires
- An app that experiences a personal data breach affecting an individual in Thailand must notify the Personal Data Protection Committee's Office without delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to pose a risk to the affected individuals; where the breach is likely to cause high risk, the app must also notify each affected individual without delay.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Data Controller must notify the Office of any personal data breach without delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the affected individuals. Where the breach is likely to cause high risk, the Data Controller must also notify the data subject without delay, together with remedial measures.
This section number is inferred from a cross-reference in the retention clause rather than confirmed against its own article heading directly.
When LexLint raises it
processes_biometricsprocesses_voicecrawls_web
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.