Safeware Glasswall APAC Partner Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Compliance hub
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongoliaAPAC overview

More

Trust & certificationsAboutDocumentation Book a demo

Regulatory landscape ยท Southeast Asia

Thailand: file security and audit obligations

Thailand's PDPA has been fully in force since June 2022, with the PDPC issuing subordinate regulations on security measures and breach notification.

At a glance

How Thailand regulates file security

  • 01

    Regime

    GDPR-modelled data protection statute with an established regulator

  • 02

    File security

    PDPC security-measures notifications over personal data

  • 03

    Audit and evidence

    72-hour breach notification to the PDPC

Overview

The regulatory picture

The Personal Data Protection Act B.E. 2562 (2019) became fully enforceable on 1 June 2022 after repeated deferrals. It is modelled closely on the GDPR: lawful basis requirements, data subject rights, appointment of data protection officers for certain controllers, and notification of breaches to the Personal Data Protection Committee (PDPC) within 72 hours where there is a risk to rights and freedoms.

The PDPC has since issued subordinate notifications covering security measures, records of processing and cross-border transfer. Separately the Cybersecurity Act B.E. 2562 (2019) establishes a critical information infrastructure regime under the National Cyber Security Committee, though it operates with a lighter touch than comparable regimes in Singapore or Malaysia. We track headline developments here rather than claiming deep coverage.

The landscape

Instruments that reach file security and audit

InstrumentAuthorityStatusRelevance
Personal Data Protection Act B.E. 2562 (2019)PDPCIn forceDirect

PDPC

Personal Data Protection Act B.E. 2562 (2019)

Fully enforceable since 1 June 2022. GDPR-modelled obligations including security measures over personal data and 72-hour breach notification to the PDPC.

Why it matters for file security. Security-measures notifications reach personal data held in documents, and the notification clock rewards having processing evidence readily available.

How Glasswall addresses it. Find & Redact removes named data patterns from documents before storage or sharing, reducing the personal data population exposed in a breach and the scope of a notification assessment.

Find & RedactStorage Monitor + SM AuditGlasswall Halo

Source: PDPC

Scope

About this page

This page is a working reference for organisations operating in Thailand.

It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.

Planning a deployment in Thailand?