Law / Thailand

Thailand

9 of 12 named instruments researched to a stage, across four of the six areas of law we track: 9 in force. As of 17 September 2026.

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (159 words)

Thailand's comprehensive private-sector data-protection law is the Personal Data Protection Act B.E. 2562 (2019), published in the Government Gazette 27 May 2019 and fully enforceable since 1 June 2022.

Lawful basis is consent by default under Section 24, General Data Protection Regulation (GDPR)-style, with an explicit consent standard for sensitive categories under Section 26, which names biometric data directly and gives facial recognition data as an express statutory example; a voiceprint is not separately named but falls within the same catch-all covering any data that may affect the data subject in the same manner.

Cross-border transfer requires the destination to have an adequate data protection standard (Section 28), and breach notification to the regulator's Office is required within 72 hours where feasible (Section 37(4)). Thailand arms a private plaintiff: Section 78 lets a court award punitive damages up to twice actual compensation, on top of the civil liability Section 77 creates, alongside administrative fines that reach Baht 5,000,000 for the most serious violations.

Breach notification

Personal Data Protection Act, breach notification

Personal Data Protection Act B.E. 2562 (2019), Section 37(4)unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)

In force since 1 June 2022. Binds private bodies.

What this law does

The Data Controller must notify the Office of any personal data breach without delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the affected individuals. Where the breach is likely to cause high risk, the Data Controller must also notify the data subject without delay, together with remedial measures.

This section number is inferred from a cross-reference in the retention clause rather than confirmed against its own article heading directly.

What it requires

Comprehensive regime

Personal Data Protection Act, comprehensive regime

Personal Data Protection Act B.E. 2562 (2019), Government Gazette Vol. 136, Special Issue 69 Kor, fully enforceable 2022-06-01unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)

In force since 1 June 2022. Binds private bodies.

What this law does

The Personal Data Protection Act (PDPA) is Thailand's comprehensive personal-data statute, published in the Government Gazette 27 May 2019 and, after enforcement of most operative provisions was twice postponed, fully enforceable since 1 June 2022. Lawful basis is consent by default under Section 24, a General Data Protection Regulation (GDPR)-style model, with heightened requirements for sensitive categories under Section 26. The Personal Data Protection Committee and its Office enforce the Act. The text cited is the Ministry of Digital Economy and Society (MDES) copy of the Act.

What it requires

Cross border transfer

Personal Data Protection Act, cross-border transfer

Personal Data Protection Act B.E. 2562 (2019), Section 28unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)

In force since 1 June 2022. Binds private bodies.

What this law does

Section 28 requires that where a Data Controller sends or transfers personal data to a foreign country, the destination country or international organization must have an adequate data protection standard and the transfer must follow rules the Personal Data Protection Committee prescribes, subject to exceptions including legal compliance, informed consent where the data subject is told the destination's standard is inadequate, and contract necessity. This is an adequacy-based restriction; no data-localization mandate was found.

What it requires

Enforcement supervision

Personal Data Protection Act, enforcement and private right of action

Personal Data Protection Act B.E. 2562 (2019), Sections 77, 78, 84-88unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)

In force since 1 June 2022. Binds private bodies.

What this law does

The Personal Data Protection Committee and its Office enforce the Act with administrative fines that vary by provision violated: up to Baht 5,000,000 for Section 26 sensitive-category, Section 27 use or disclosure, and Section 28/29 cross-border transfer violations (Section 84 and Section 87), up to Baht 1,000,000 for data processor non-compliance (Section 85), and up to Baht 3,000,000 under Section 86.

Separately, Section 77 creates civil liability for a Data Controller or Data Processor whose PDPA operation causes damage, subject to narrow defenses of force majeure, the data subject's own act, or compliance with an official order, and Section 78 lets the court additionally order punitive damages up to twice the actual compensation awarded. This is a genuine private right of action with punitive-damages exposure, distinct from the administrative fine regime.

What it requires

Sensitive categories

Personal Data Protection Act, sensitive and biometric categories

Personal Data Protection Act B.E. 2562 (2019), Section 26unofficial English translation hosted by a government mirror, Ministry of Digital Economy and Society (MDES)

In force since 1 June 2022. Binds private bodies.

What this law does

Section 26 prohibits collecting personal data on race, ethnic origin, political opinions, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, or biometric data, or any data that may affect the data subject in the same manner, without the data subject's explicit consent, subject to enumerated exceptions such as vital interest and substantial public interest.

Biometric data is defined as data arising from technical processing of a person's physical or behavioral characteristics used to identify them, with facial recognition, iris recognition, and fingerprint recognition data given as express statutory examples. A voiceprint is not named as an express example, but the same-manner catch-all and the general physical-or-behavioral-dominance definition plausibly reach it; no provision was found excluding voice.

What it requires

Scraping law2 instruments, 2 in force

Research summary (236 words)

The Act on Computer Crime B.E. 2550 (2007) criminalises accessing a computer system or computer data protected by a security measure not intended for the accessor's use (Sections 5 and 7), and illegally disclosing another person's security measures or intercepting computer data (Sections 6 and 8), so a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of these provisions; no reported Thai case tests the point.

No Thai statute or reported case addresses the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Act B.E. 2537 (1994) gives the copyright owner exclusive reproduction and communication-to-the-public rights, subject to a general exception, in Section 32, for an act that does not conflict with normal exploitation of the work and does not unreasonably prejudice the owner's legitimate rights, plus a narrower acknowledged-quotation exception in Section 33; Thailand has not enacted a specific text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the general Section 32 test, an unsettled fit for large-scale automated copying.

The Copyright Act creates no sui generis database right. The personal-data dimension is covered in this jurisdiction's privacy-topic record under the Personal Data Protection Act B.E. 2562 (2019), which applies to personal data with no general public-availability carve-out. No source located assigns legal weight to a robots.txt directive, states an AI-training-specific rule, or establishes a scraping-specific unfair-competition or misappropriation doctrine.

Computer misuse

Act on Computer Crime, unauthorized access and interception

Act on Computer Crime B.E. 2550 (2007), Sections 5 to 8tentative English translation of the Act on Computer Crime B.E. 2550 (2007), hosted by the International Commission of Jurists

In force. Binds public and private bodies.

What this law does

Section 5 punishes illegally accessing a computer system that has specific security measures not intended for the accessor's use. Section 7 punishes the same act against computer data.

Section 6 punishes knowing another person's security measures and illegally disclosing them in a manner likely to cause injury, and Section 8 punishes illegally intercepting, by electronic or any other means, computer data of another person transmitting in a computer system where that data is not for public benefit or available to others.

The Act's own Section 2 sets commencement at thirty days after publication in the Government Gazette, but the International Commission of Jurists' translation of the Act's original 2007 text does not itself state that publication date.

What it requires

Age gating law1 instrument, 1 in force

Research summary (165 words)

Thailand binds a private film-exhibition licensee and a private film rental, exchange, or sale licensee to an age-based access restriction under the Film and Video Act, B.E. 2551 (2008), whose rating system reserves its most restricted viewable category to persons twenty years of age or older and requires the category to be displayed and enforced at the point of admission or sale. No other reviewed instrument reaches an online or on-demand service, a social media platform, or an app store.

The Computer Crime Act B.E. 2550 (2007) and the Child Protection Act B.E. 2546 (2003) bind any person to general criminal or protective prohibitions rather than a service duty. The Broadcasting and Television Businesses Act B.E. 2551 (2008) gives a television licensee a content-suspension duty naming no age threshold.

The Royal Decree on the Operation of Digital Platform Service Businesses B.E. 2565 (2022) registers a digital platform service provider and sets transparency and standards requirements for that registration, and names no minor-access or age-verification duty.

Adult content age verification (AV)

Film and Video Act, Age-Rating Categories and Restriction on Admission or Sale to Minors

Film and Video Act, B.E. 2551 (2008), secs. 26, 44, 45, 80Official text of the Film and Video Act, B.E. 2551, mirrored by the Thailand Film Office from the Office of the Council of State's text

In force. Binds private bodies.

What this law does

A cinema-exhibition licensee must post the age-rating category assigned to each film in a clearly visible place and must not knowingly or negligently admit a person below the age set for that category during its screening. A film rental, exchange, or sale licensee must not rent, exchange, or sell a film in that category to a person below that age.

The most restricted viewable category is reserved to persons twenty years of age or older, and a licensee who violates either duty is liable to a fine.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (126 words)

Thailand has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining code, and no reported hot-news misappropriation doctrine or case addressing hyperlinking or framing of news content.

The Copyright Act B.E. 2537 (1994) reaches an aggregator's reproduction of headlines and snippets only through two general exceptions: Section 32 paragraph two (4) excepts news reporting through mass media that acknowledges the copyright owner, and Section 33 excepts a reasonable recitation, quotation, copying, emulation, or reference in part from a copyright work with the same acknowledgement, both subject to the Section 32 paragraph one condition that the act not conflict with normal exploitation or unreasonably prejudice the owner's legitimate rights.

Neither exception is aggregation-specific, and no Thai court decision has been located applying either to an automated news aggregator.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.