Thailand’s Personal Data Protection Act requires certain data controllers and processors with no establishment in Thailand to designate a representative in the Kingdom. The duty sits at PDPA section 37(5), triggered by section 5 paragraph two.
The short answer: if section 5 paragraph two reaches you and the section 38 exemption does not apply, section 37(5) requires you to designate in writing a representative who is in the Kingdom of Thailand. The Act only requires presence in Thailand, not Thai nationality or incorporation, so we hold this appointment directly. We are equally direct about what we do not know: the section 38 exemption’s exact volume threshold is set by the Committee under section 41(2) and is not a fixed figure in the Act itself, so whether a given company qualifies for the exemption is confirmed at scoping rather than assumed either way.
What the Thai requirement is
The Personal Data Protection Act, B.E. 2562 (2019), is Thailand’s general data protection statute, published in the Government Gazette on 27 May 2019. Section 5 sets its territorial scope. Section 5 paragraph one applies the Act to any data controller or processor in the Kingdom, regardless of where the processing itself happens. Section 5 paragraph two extends it extraterritorially: where a data controller or processor is outside Thailand, the Act still applies to their collection, use, or disclosure of the personal data of data subjects in Thailand, if the controller or processor either offers goods or services to those data subjects, irrespective of payment, or monitors their behavior where that behavior takes place in Thailand. The structure mirrors GDPR Article 3(2) closely enough that the same scoping questions apply: does your product or service reach people in Thailand, and is that reach deliberate enough to count as offering rather than incidental access.
Section 37 lists the data controller’s duties, and clause (5) is the representative duty: “in the event of being the Data Controller pursuant to section 5 paragraph two, the Data Controller shall designate in writing a representative of the Data Controller who must be in the Kingdom of Thailand and be authorized to act on behalf of the Data Controller without any limitation of liability with respect to the collection, use or disclosure of the Personal Data according to the purposes of the Data Controller.”
The exemption
Section 38 carves two exemptions out of the section 37(5) duty: a data controller that is a public authority as prescribed and announced by the Committee, and a data controller whose business does not have the nature described in section 26, the list of sensitive personal data categories, and does not hold a large amount of personal data as prescribed by the Committee under section 41(2). Section 41(2) itself does not state a number; it leaves the volume threshold to the Committee’s own announcement, the same pattern Korea uses for its Enforcement Decree thresholds. We do not state a figure here we cannot trace to that announcement, and confirm it as part of scoping.
Who it applies to, and who is exempt
Section 38’s final paragraph extends both the section 37(5) duty and the section 38 exemption to a data processor of a controller caught under section 5 paragraph two, mutatis mutandis. So the representative question is not only a controller’s question: a processor handling Thai data subjects’ personal data on a controller’s instructions, with no establishment in Thailand, is caught the same way, and Section 86 sets its own administrative fine, not exceeding Baht three million, for a processor that fails to comply.
Who can hold the role
The Act’s own wording is narrower than it might first appear. Section 37(5) requires the representative to be in the Kingdom of Thailand and authorized to act without limitation of liability. It does not say the representative must be a Thai national or a Thai-incorporated legal entity, which is the explicit rule Turkey’s Registry Regulation states for its own KVKK representative. Because Thai law asks for presence in the Kingdom rather than Thai establishment or nationality, we deliver this appointment directly, the same way we deliver the EU, UK, and Swiss mandates, rather than through a local partner.
What we do
- Representative designation, made in writing and satisfying section 37(5)‘s presence-in-Thailand requirement directly.
- Section 5 paragraph two and section 38 scoping, a written answer on whether the extraterritorial trigger and the exemption apply to your processing before anything is designated.
- Coordination with your wider footprint, including an EU or UK Article 27 representative and a DPO, where you need more than one appointment.
- Ongoing availability as the designated Thai contact for the duration of the appointment.
How it works
Scoping. We confirm whether section 5 paragraph two reaches your processing and whether the section 38 exemption applies, in writing, before anything is designated.
Designation. The representative appointment is made in writing, satisfying section 37(5) directly.
Ongoing. We remain the designated Thai contact and keep the designation current as your processing changes.
What it costs
Thailand does not yet have a published flat price on this site the way the twelve EU, UK, and Swiss mandates do; see pricing for those. A Thailand appointment is scoped per engagement until it has a published figure, priced on the same basis as our other direct representative appointments. Where it sits inside a wider privacy program, it is scoped alongside the DPO tiers, which start From €1,000 per month for DPO Foundation.
Why Engage Compliance
We hold this appointment directly rather than through a local partner, because the PDPA’s own wording only asks for presence in the Kingdom of Thailand, not Thai nationality or incorporation. Where a duty is genuinely unsettled, such as the exact section 41(2) exemption threshold, we say so and confirm it at scoping rather than publish a figure we cannot trace to the Committee’s own announcement. Where you also need an EU or UK representative or a DPO, we scope all of it together. Every engagement carries professional indemnity and cyber insurance.
Sources and references
- Personal Data Protection Act, B.E. 2562 (2019), Government Gazette No. 136 Chapter 69 Gor, 27 May 2019, sections 5, 37, 38, 41, 83, and 86 (unofficial translation, cross-referenced against the gazetted Thai text)
- Personal Data Protection Committee (PDPC) Thailand, the Thai data protection regulator