Law / Thailand

Personal Data Protection Act, enforcement and private right of action

Personal Data Protection Act B.E. 2562 (2019), Sections 77, 78, 84-88

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 June 2022.

An enforcement supervision rule binding private bodies.

As of 2 September 2026.

What it requires

  • An app processing the personal data of an individual in Thailand must be prepared to answer to the Personal Data Protection Committee for an administrative fine of up to Baht 5,000,000 for a serious violation, and a data subject harmed by the app's processing may separately sue for civil damages plus punitive damages up to twice the actual compensation awarded.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Sections 79 and 80, in the Act's Chapter VII Part I on criminal liability, sit outside this row's own citation (Sections 77, 78, 84-88) but describe the instrument's full enforcement and remedy scheme. Section 79 punishes a Data Controller who violates Section 27 paragraph one or two, or fails to comply with Section 28, concerning Section 26 sensitive-category data in a manner likely to cause damage, harm reputation, or expose the data subject to scorn, hatred, or humiliation, with imprisonment of up to six months, a fine of up to Baht 500,000, or both; where the same conduct is done to unlawfully benefit the offender or another person, the maximum rises to imprisonment of up to one year, a fine of up to Baht 1,000,000, or both, and these Section 79 offences are compoundable. Section 80 punishes a person who learns another person's personal data while performing duties under the Act and discloses it to anyone else, outside listed exceptions such as performance of duty or a data subject's written consent, with imprisonment of up to six months, a fine of up to Baht 500,000, or both. Section 81 extends liability to a director, manager, or other responsible person of a juristic-person offender who caused the offence or, having a duty to prevent it, omitted to do so.

Penalty structure

Sections 84 to 88 set five different administrative fine caps rather than one uniform rule. Section 84 (a Data Controller who violates Section 26 paragraph one or three, Section 27 paragraph one or two, Section 28 in relation to Section 26 data, or the Section 29 transfer duty as it applies to Section 26 data) and Section 87 (a Data Processor who transfers Section 26 data without complying with Section 29) each cap at Baht 5,000,000. Section 86 (a Data Processor who fails to comply with Section 40, the Section 29 transfer duty, or Section 37(5) as applied through Section 38 paragraph two) caps at Baht 3,000,000. Section 85 (a Data Processor who fails to comply with Section 41 paragraph one or Section 42 paragraph two or three) and Section 88 (a representative of the Data Controller or Data Processor under Sections 39 paragraph one and 41 paragraph one) each cap at Baht 1,000,000. The recorded fixed_cap is the highest of these tiers, the Baht 5,000,000 cap under Sections 84 and 87.

Rule
Fixed only
As of
2 September 2026
Currency
THB
Fixed cap
5,000,000

Who enforces it

Enforcement body

The Personal Data Protection Committee, acting through an expert committee it appoints under Section 71, imposes administrative fines under Section 90; the Office of the Personal Data Protection Committee, established as a juristic-person government agency under Section 43, carries out the Committee's academic and administrative work.

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Personal Data Protection Committee and its Office enforce the Act with administrative fines that vary by provision violated: up to Baht 5,000,000 for Section 26 sensitive-category, Section 27 use or disclosure, and Section 28/29 cross-border transfer violations (Section 84 and Section 87), up to Baht 1,000,000 for data processor non-compliance (Section 85), and up to Baht 3,000,000 under Section 86.

Separately, Section 77 creates civil liability for a Data Controller or Data Processor whose PDPA operation causes damage, subject to narrow defenses of force majeure, the data subject's own act, or compliance with an official order, and Section 78 lets the court additionally order punitive damages up to twice the actual compensation awarded. This is a genuine private right of action with punitive-damages exposure, distinct from the administrative fine regime.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app