Thailand PDPA Fines: 5 Mistakes to Avoid

Primary Guard · October 1, 2026 · 4 min read

Thailand's PDPC issued eight fines across five cases in one day. See the five PDPA mistakes behind them and how to avoid each one.

Thailand's data protection regulator is no longer just issuing warnings. On 1 August 2025, the Personal Data Protection Committee (PDPC) announced eight administrative fines across five cases. If your business handles Thai customer data, these Thailand PDPA fines show what regulators now check first.

What the Thailand PDPA fines tell us

The PDPA is Thailand's Personal Data Protection Act. The August 2025 cases covered a government agency and its software developer. They also covered a private hospital and its contractor, an IT products retailer, a cosmetics company, and a toy company with its data processor.

The organisations were very different. The failures were not. The same basic gaps appeared again and again, and none of them needed advanced technology to fix.

Five compliance mistakes behind the fines

1. No Data Protection Officer

A Data Protection Officer (DPO) is the person responsible for overseeing PDPA compliance. Law firm Tilleke & Gibbins reported an earlier landmark case where a company processed data for over 100,000 people without appointing one. It was fined THB 7 million. Commentators also treat a missing DPO as a serious aggravating factor.

2. Reporting a breach too late

Controllers must report a breach to the PDPC within 72 hours of becoming aware of it. The exception is when the breach is unlikely to risk people's rights and freedoms. Late or missing notification appeared in several of the cases. A written incident plan helps, with named people who decide when and how to report.

3. Weak security basics

Fined organisations were cited for weak password management and no risk assessment. In the earlier landmark case, a call centre fraud ring gained unauthorised access to personal data. Regulators expect basic controls, checked often. Review passwords and access on a set schedule, and write down what you found.

4. No data processing agreements

When a vendor handles your data, you need a written data processing agreement. It sets out what the vendor may do with the data and how it must protect it. Missing agreements were one of the cited failures.

5. Poor supervision of contractors

Hiring a vendor does not hand your duty to them. The hospital's contractor and the toy company's processor were both fined alongside the main organisation. Check what your vendors do, and keep a record of it. Ask how they store data, who can access it, and how fast they report problems.

Personal liability is a separate risk

Company fines are only part of the picture. Thailand's Emergency Decree on Technology Crimes took effect on 13 April 2025. When personal data misuse is commercial, penalties can reach five years in prison and THB 500,000. That risk can fall on individuals, not only on companies.

How Primary Guard helps

Most of these mistakes come down to visibility and control. Primary Guard's managed SOC/MDR service offers 24/7 monitoring managed from Malaysia, so suspicious activity is seen and reported on a clear timeline. Our identity and access management service covers single sign-on, zero-trust access controls and device management. It is delivered on JumpCloud, with Primary Guard handling deployment and policy setup.

Not sure where your business stands against these five gaps? Primary Guard offers a free assessment. Request your free assessment to start the conversation.

Frequently asked questions

Who decides the penalties under Thailand's PDPA?

The Personal Data Protection Committee (PDPC) enforces the law. Its expert committee sets administrative penalties based on how serious the offence is, so a missing officer or a late report can raise the fine.

What changed in Thailand's data protection rules in 2026?

The Binding Corporate Rules Regulation took effect on 17 February 2026. The PDPC also held a public hearing on AI guidelines in March 2026. Commentators see a shift from paperwork to proof that controls work in practice.

What is the difference between a controller and a processor?

A controller decides why and how personal data is used. A processor handles that data on the controller's behalf. In the August 2025 cases, both controllers and their processors or contractors were fined.

Key takeaway

Thai regulators are fining on the basics: a DPO, fast breach reporting, sound security, written vendor agreements and supervised contractors. Check these five areas before an incident happens, not after.

Sources

Legal 500, Oct 2025 | Chambers, Mar 2026 | Tilleke & Gibbins, Aug 2024 | Formichella & Sritawat, May 2026

This article is general information, not legal advice. Please confirm your obligations with a qualified Thai legal adviser.

Frequently Asked Questions

Who decides the penalties under Thailand's PDPA?

The Personal Data Protection Committee (PDPC) enforces the law. Its expert committee sets administrative penalties based on how serious the offence is, so a missing officer or a late report can raise the fine.

What changed in Thailand's data protection rules in 2026?

The Binding Corporate Rules Regulation took effect on 17 February 2026. The PDPC also held a public hearing on AI guidelines in March 2026. Commentators see a shift from paperwork to proof that controls work in practice.

What is the difference between a controller and a processor?

A controller decides why and how personal data is used. A processor handles that data on the controller's behalf. In the August 2025 cases, both controllers and their processors or contractors were fined.