Personal Data Protection Act, comprehensive regime
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 June 2022.
A comprehensive regime rule binding private bodies.
As of 29 August 2026.
What it requires
- An app that collects, uses, or discloses the personal data of an individual in Thailand must obtain consent by default before processing, unless a Section 24 statutory exception applies.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Personal Data Protection Act (PDPA) is Thailand's comprehensive personal-data statute, published in the Government Gazette 27 May 2019 and, after enforcement of most operative provisions was twice postponed, fully enforceable since 1 June 2022. Lawful basis is consent by default under Section 24, a General Data Protection Regulation (GDPR)-style model, with heightened requirements for sensitive categories under Section 26. The Personal Data Protection Committee and its Office enforce the Act. The text cited is the Ministry of Digital Economy and Society (MDES) copy of the Act.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)
Government Gazette Vol. 136, Special Issue 69 Kor is the official citation
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.