Thailand's Personal Data Protection Act (PDPA) applies in full to every organization that collects customer or employee data, with no exemption for business size. Many entrepreneurs still believe this law only concerns large corporations. That misunderstanding carries a price of up to 5 million baht.
The most expensive risk is the one you do not know you have.
Who falls under the PDPA
If your business does any of the following, the PDPA already applies to you
- Collecting customer names, phone numbers, or emails, whether in store, on a website, or via social media
- Employing staff and keeping personnel records
- Operating CCTV on business premises
- Marketing through a customer database
Three first steps to take now
A sound PDPA program does not start with expensive systems. It starts with understanding your own data.
- Map the data flows in your organization: what you collect, from whom, where it is stored, and who can access it
- Draft a privacy policy that reflects how data is actually used, not a boilerplate document
- Appoint a responsible person and a channel for data subject requests
Penalties business owners should know
The PDPA carries administrative, civil, and criminal liability. Administrative fines reach 5 million baht, and where a data breach causes damage, data subjects may claim additional compensation. Company directors may face personal liability in certain cases.
HARIN's PDPA advisory team covers everything from data mapping audits and policy drafting to staff training. Initial consultations are available 24 hours a day.