GDPR and PDPA: what Thailand-based companies with European clients need to know

Réunion entre professionnels thaïlandais et européens sur la conformité RGPD et PDPA
Contents

For a company based in Thailand, the relationship between GDPR and PDPA in Thailand depends on the processing activity. The Thai PDPA is the main framework, while the European GDPR may apply to certain activities. Simply having European clients does not make the GDPR applicable to every processing activity. The analysis must consider the company’s establishment, the people targeted and the services offered. It must also cover data flows between the European Union and Thailand.

For a Thai company working with Europe, the issue is not choosing between two regulations. It is building clear data governance. That governance must identify which law applies, to which processing activity and with which obligations.

Key takeaways

  • The PDPA is the main data protection framework for processing activities falling within the operations of a company established in Thailand.
  • The GDPR may also apply where there is an EU establishment, a targeted offering to people in the Union, or monitoring of their behaviour.
  • Having a European client alone does not automatically make the GDPR applicable to all of a company’s processing activities.
  • Personal data transfers from the EEA to Thailand must be identified and appropriately safeguarded when GDPR Chapter V applies.
  • A common governance framework for processing, rights, contracts, incidents and risks helps address GDPR and PDPA requirements without unnecessary duplication.

The PDPA is the reference framework in Thailand

The Personal Data Protection Act B.E. 2562 (2019), generally known as the PDPA, is Thailand’s main personal data protection law. Its principal provisions have been fully applicable since 1 June 2022. It governs, among other things, the collection, use, disclosure, retention and security of personal data.

Like the GDPR, the PDPA is built around several core principles. Organisations need a lawful basis, clear information for data subjects and justified limits on purposes and retention. They must also protect personal data and enable individuals to exercise their legal rights. Consent is therefore not the only possible legal basis for processing.

A company established in Thailand should first identify the processing activities subject to the PDPA and its role as controller or processor. It should then document the lawful bases used, any sensitive personal data involved and the associated security measures.

When can the GDPR apply to a Thai company?

The territorial scope of the GDPR is defined by Article 3. For a company based in Thailand, three situations in particular should be distinguished.

The company has an establishment in the European Union

The GDPR may apply when processing takes place in the context of the activities of an establishment in the European Union. This remains true even when the technical processing is carried out in Thailand. The physical location of the servers is therefore not decisive on its own.

The company targets people who are in the European Union

A company with no establishment in the Union may also fall within the GDPR when it processes data relating to people who are in the Union. The processing must be connected with an offer of goods or services to those people. Whether payment is required does not change this criterion.

The company monitors the behaviour of people in the European Union

The GDPR may also apply when a company outside the Union monitors the behaviour of people in the Union. This can include certain profiling or online tracking activities. Those activities may be used to analyse or predict preferences, behaviour or movements.

By contrast, having a French, German or other European client does not automatically make the GDPR applicable. Nationality is not the test under Article 3. The actual context of the processing must be assessed.

GDPR and PDPA share a common foundation

The two frameworks share enough core principles to support coherent governance. Under both regimes, organisations must identify processing activities and purposes, select an appropriate lawful basis and inform individuals. They must also manage retention and rights requests. Security measures must remain proportionate to risk.

  • Map processing activities and data flows.
  • Identify controllers, processors and recipients.
  • Document purposes and lawful bases.
  • Organise privacy information for data subjects and the handling of their rights.
  • Define justified retention periods.
  • Implement technical and organisational measures proportionate to risk.
  • Prepare procedures for managing and documenting personal data breaches.

This similarity does not mean that the two regulations are interchangeable. Specific obligations, exemptions, supervisory authorities and international transfer mechanisms must be assessed separately.

Differences should be handled as compliance gaps

The GDPR and the PDPA do not use exactly the same mechanisms or wording. A sound approach is therefore to build a common baseline and then perform a gap analysis for each jurisdiction.

  • Supervisory authorities and procedures differ. In the European Union, competence depends on the country and processing context. In Thailand, the framework falls under the Personal Data Protection Committee and its Office.
  • The conditions for appointing a Data Protection Officer must be assessed separately under each regime.
  • Documentation, record-keeping and risk assessment obligations are not formulated identically.
  • International transfer mechanisms differ and must be coordinated when data flows between Europe and Thailand.
  • Sanctions, administrative procedures and avenues of appeal are governed by distinct legal frameworks.

Data transfers between the European Union and Thailand are a central issue

For many companies, the most practical issue goes beyond the territorial scope of the GDPR. It also concerns the transfer of personal data from the European Economic Area to Thailand.

Thailand does not currently benefit from an adequacy decision from the European Commission. When the GDPR applies, a transfer from the EEA to Thailand must therefore rely on a mechanism provided for in Chapter V.

In ordinary commercial relationships, the European Commission’s Standard Contractual Clauses are frequently one of the tools used. Depending on the circumstances, an assessment of the transfer conditions and additional safeguards may also be required. Thai rules governing international transfers must be considered in parallel.

In practical terms, a company must identify which data leaves Europe, its purpose, its recipient, the relevant contractual role and the safeguards used. This mapping is essential before selecting a legal transfer mechanism.

A DPO and an EU representative are not the same thing

Two functions are frequently confused. A Data Protection Officer or DPO supports the organisation when appointment is mandatory or voluntary. An EU representative, required by Article 27 in certain situations, represents an organisation that is not established in the Union. That organisation must nevertheless fall within Article 3(2) of the GDPR.

A Thai company affected by the GDPR’s extraterritorial scope must assess two obligations separately. It must determine whether it needs an EU representative and whether it falls within a case requiring a DPO. One role does not replace the other.

Data breaches: the 72-hour benchmark exists in both frameworks

Contrary to a common assumption, the main notification timeframe is not a major difference between the GDPR and the PDPA. The GDPR requires notification to the competent supervisory authority without undue delay and, where feasible, within 72 hours. This duty does not apply when the breach is unlikely to result in a risk to individuals’ rights and freedoms.

The Thai PDPA also provides for notification without delay and, where feasible, within 72 hours. This obligation depends on the assessment of risk. Where the risk is high, affected individuals may also need to be informed.

The operational challenge is to maintain a common incident-management process. It should identify the data involved, assess risk and determine which authorities or individuals must be informed. It should also document decisions and ensure that the requirements of each regulation are met.

A common method reduces duplication

When an organisation genuinely falls under both frameworks, managing the GDPR and the PDPA as separate projects often creates duplication. Inventories, procedures and controls may then be repeated unnecessarily. A more efficient approach is to build a common data governance baseline and add the jurisdiction-specific requirements to it.

  1. Map processing activities, applications, providers and data transfers.
  2. Determine the company’s role and the regulation applicable to each processing activity.
  3. Document lawful bases, privacy information and retention periods.
  4. Review processor contracts and international transfer mechanisms.
  5. Assess requirements relating to the DPO, EU representative and impact or risk assessments.
  6. Formalise procedures for data subject rights and breach management.
  7. Establish ongoing monitoring rather than treating compliance as a one-off exercise.

This approach follows a compliance management model. Legal obligations are connected to the company’s processes, responsibilities, tools and security measures.

Questions to assess for your organisation

Before concluding that a Thai company is or is not subject to the GDPR, several questions should be documented.

  • Does the company have an establishment or stable presence in the European Union?
  • Does it intentionally offer goods or services to people who are in the Union?
  • Does it monitor the behaviour of people in the Union?
  • Does it receive personal data transferred from the EEA to Thailand?
  • Which processing activities fall under the Thai PDPA?
  • Do contracts with clients and providers correctly describe roles and data transfers?
  • Have the requirements relating to the DPO, EU representative and data breaches been assessed?

Building coherent compliance between Europe and Thailand

A coherent approach to GDPR and PDPA in Thailand can build on their common principles without ignoring their differences. A company based in Thailand should identify its processing activities and international data flows precisely. It can then apply the relevant legal framework to each one.

Cybersiam supports this approach by connecting cybersecurity and compliance with mapping, governance, security measures and clear responsibilities. The objective is to build a coherent management system. It should cover European and Thai requirements where they genuinely apply.

This article presents general principles. The exact application of the GDPR, the PDPA and international transfer mechanisms depends on each organisation’s legal and operational circumstances.

Do you have a project to move forward?

Tell us about your context, constraints and objective. We will tell you clearly whether Cybersiam can support you and how.

Free initial consultation, with no obligation.

CONTACT US