Skip to content
Esta es una traduccion de conveniencia. La version en ingles es la version oficial y legalmente vinculante. Ver version en ingles
THMEDIUM coverage2 enforcement actions

Thailand Personal Data Protection Act (PDPA) — AI Provisions: AI Compliance Requirements

Thailand's Personal Data Protection Act B.E. 2562 (2019) became fully effective June 1, 2022, and the PDPC imposed its first administrative penalty (THB 7,000,000) in August 2024. The Personal Data Protection Committee (PDPC) has been developing draft Guidelines on Personal Data Protection in AI Development and Use (at draft/consultation stage — NOT independently enforceable; AI obligations derive from the PDPA itself). Key PDPA obligations as applied to AI: (1) DPIAs are mandatory for high-risk AI processing. (2) Automated decisions with legal effects require human-in-the-loop capability and a mechanism for individuals to contest decisions. (3) AI model training contracts must include model training prohibitions (preventing vendors from using your data to train third-party models). (4) Data processing agreements with AI vendors must specifically address model training restrictions. Applies to any organization processing personal data of Thai residents.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

June 1, 2022

Maximum Penalty

Administrative fine up to THB 5,000,000 (~$135K USD) per violation; criminal penalties up to THB 1,000,000 + imprisonment for intentional violations

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Data Protection Impact Assessment for AI (Thailand PDPA)

High Priority

DPIAs are advisable for AI systems that: (1) Make automated decisions with legal effects. (2) Involve large-scale processing of personal data. (3) Use sensitive categories (health, biometric, financial). (4) Are deployed using new or experimental technology. Conduct a DPIA before deployment and review annually or on material change. NOTE: this derives from PDPA best practice and general principles — any PDPC AI-specific guideline remains at draft/consultation stage and is not independently enforceable.

Deadline: June 1, 2022

PDPA B.E. 2562 (2019), general principles (ss. 24, 37)

Human-in-the-Loop for Automated Decisions

High Priority

Thailand PDPA principles: AI systems making significant automated decisions affecting Thai residents should provide a mechanism for individuals to: (1) Be informed that a decision was automated. (2) Request human review of the decision. (3) Contest or provide their viewpoint on the decision. Implement a documented escalation path for automated decision challenges. NOTE: no dedicated automated-decision-making article equivalent to GDPR Art. 22 has been independently confirmed in the PDPA text this cycle — treat as a data-subject-rights/objection-based best practice, not a codified standalone right, pending counsel confirmation.

Deadline: June 1, 2022

PDPA B.E. 2562 (2019), general principles (ss. 24, 37) — no codified GDPR-Art.22-equivalent right independently confirmed this cycle, see description.

AI Vendor Contract — Model Training Prohibition

Medium Priority

Best practice (not independently confirmed as a specific enacted PDPC rule this cycle): contracts with AI service providers (OpenAI, Google, Anthropic, etc.) should include explicit provisions prohibiting the vendor from using your customers' personal data to train third-party AI models, consistent with the PDPA's purpose-limitation principle. Review and update all AI vendor DPAs/ToS to include this restriction. Document evidence of vendor compliance.

PDPA B.E. 2562 (2019) purpose-limitation principle (best-practice application, not an independently confirmed PDPC rule)

Who Does This Apply To?

Applies to: any organisation that collects, uses, or discloses the personal data of individuals in Thailand, including data controllers and processors located outside Thailand that offer goods/services to, or monitor the behaviour of, data subjects in Thailand (PDPA B.E. 2562/2019 has extraterritorial reach). There is no small-business exemption from the core duties. AI-relevant obligations derive from the PDPA itself (any PDPC AI-specific guideline remains at draft/consultation stage and is not independently enforceable): a lawful basis for processing; a Data Protection Impact Assessment for high-risk AI (automated decisions with legal effects, large-scale processing, sensitive categories, or new/experimental technology); a human-in-the-loop mechanism letting individuals be informed of, contest, and seek human review of significant automated decisions; security measures under Section 37 and a Data Protection Officer under Section 41 where applicable; and AI-vendor contracts that prohibit the vendor from using your data to train third-party models. Enforced by the Personal Data Protection Committee (PDPC), which imposed its first administrative penalty (THB 7,000,000) in August 2024.

Recent Enforcement Actions

2024-08-21Source verified· as of 2026-08-22

Against:

2025-08-01Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2026-02

PDPC — enforcement escalation through Aug 2025 (THB 21M+ cumulative); AI guidance still at draft/consultation stage

Thailand's PDPA (B.E. 2562/2019) has been fully effective since 1 June 2022. The PDPC moved from guidance to enforcement with its first THB 7,000,000 penalty in August 2024, then significantly escalated with an 8-fine, 5-case, THB 14,500,000 wave announced 1 August 2025 (cumulative fines now exceed THB 21,000,000) — see enforcement actions. The PDPC published draft Guidelines on Personal Data Protection in AI Development and Use on 17 February 2026 (public comment closed 25 February 2026); as of this cycle (2026-08-22) no source confirms these have been finalized/gazetted — they remain draft and NOT independently enforceable on their own. AI obligations continue to derive from the PDPA itself (lawful basis, security under Section 37, breach notification under Section 37(4) — now a clear PDPC enforcement priority — DPO under Section 41, and data-subject rights including objection to automated processing). Treat AI-specific PDPC guideline references as draft until a final, gazetted instrument is confirmed.

Frequently Asked Questions

Does Thailand Personal Data Protection Act (PDPA) — AI Provisions apply to my business?

Thailand's Personal Data Protection Act B.E. 2562 (2019) became fully effective June 1, 2022, and the PDPC imposed its first administrative penalty (THB 7,000,000) in August 2024. The Personal Data Protection Committee (PDPC) has been developing… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Thailand Personal Data Protection Act (PDPA) — AI Provisions is: Administrative fine up to THB 5,000,000 (~$135K USD) per violation; criminal penalties up to THB 1,000,000 + imprisonment for intentional violations. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Thailand Personal Data Protection Act (PDPA) — AI Provisions?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://fosrlaw.com/2025/ai-machine-learning-big-data-thailand-legal-regulatory-2025/

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan