Regulatory landscape ยท Southeast Asia
Thailand: file security and audit obligations
Thailand's PDPA has been fully in force since June 2022, with the PDPC issuing subordinate regulations on security measures and breach notification.
At a glance
How Thailand regulates file security
- 01
Regime
GDPR-modelled data protection statute with an established regulator
- 02
File security
PDPC security-measures notifications over personal data
- 03
Audit and evidence
72-hour breach notification to the PDPC
Overview
The regulatory picture
The Personal Data Protection Act B.E. 2562 (2019) became fully enforceable on 1 June 2022 after repeated deferrals. It is modelled closely on the GDPR: lawful basis requirements, data subject rights, appointment of data protection officers for certain controllers, and notification of breaches to the Personal Data Protection Committee (PDPC) within 72 hours where there is a risk to rights and freedoms.
The PDPC has since issued subordinate notifications covering security measures, records of processing and cross-border transfer. Separately the Cybersecurity Act B.E. 2562 (2019) establishes a critical information infrastructure regime under the National Cyber Security Committee, though it operates with a lighter touch than comparable regimes in Singapore or Malaysia. We track headline developments here rather than claiming deep coverage.
The landscape
Instruments that reach file security and audit
| Instrument | Authority | Status | Relevance |
|---|---|---|---|
| Personal Data Protection Act B.E. 2562 (2019) | PDPC | In force | Direct |
PDPC
Personal Data Protection Act B.E. 2562 (2019)
Fully enforceable since 1 June 2022. GDPR-modelled obligations including security measures over personal data and 72-hour breach notification to the PDPC.
Why it matters for file security. Security-measures notifications reach personal data held in documents, and the notification clock rewards having processing evidence readily available.
How Glasswall addresses it. Find & Redact removes named data patterns from documents before storage or sharing, reducing the personal data population exposed in a breach and the scope of a notification assessment.
Find & RedactStorage Monitor + SM AuditGlasswall Halo
Elsewhere in the region
Other APAC territories
Scope
About this page
This page is a working reference for organisations operating in Thailand.
It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.