In today’s data-driven economy, Thai enterprises increasingly interact with both local and international customers. Protecting personal data is no longer optional—it is a legal and reputational necessity. Two major data protection frameworks govern operations: the European Union’s General Data Protection Regulation (GDPR) and Thailand’s Personal Data Protection Act (PDPA). Understanding how these regulations align—and differ—is critical for enterprises managing personal information domestically and internationally.
Overview of GDPR and PDPA

GDPR, enforced in May 2018, is a comprehensive data protection law covering all EU member states and applies to organizations processing EU residents’ personal data, regardless of their location. It emphasizes consent, transparency, accountability, and individual rights.
PDPA, enacted in 2019 and enforced in 2022, is Thailand’s national data protection law. Modeled in part on GDPR, it establishes rules for collecting, using, and disclosing personal data of Thai individuals. The PDPA aims to balance privacy protection with business innovation, emphasizing consent, purpose limitation, and security measures.
Key Definitions
| Aspect | GDPR | PDPA Thailand |
| Personal Data | Any information relating to an identifiable individual | Information that can identify a person directly or indirectly |
| Sensitive Data | Racial/ethnic origin, health, genetics, biometrics, sexual orientation, political opinion, religious belief | Racial/ethnic origin, political opinion, religious beliefs, sexual life, health, criminal record, biometrics |
| Data Controller | Determines purposes and means of processing | Person or entity that determines the purposes and methods of personal data use |
| Data Processor | Processes data on behalf of the controller | Person who processes personal data for a controller |
Consent and Legal Basis
Both GDPR and PDPA require clear and informed consent for data processing. Key points:
- GDPR: Consent must be freely given, specific, informed, and unambiguous. Other lawful bases include contract necessity, legal obligation, vital interests, public task, and legitimate interests.
- PDPA: Emphasizes explicit consent for data collection, use, or disclosure. Exceptions exist for contractual necessity, legal obligations, emergency situations, or other legal allowances.
For Thai enterprises dealing with EU clients, understanding GDPR’s additional legal bases is critical.
Data Subject Rights
Both frameworks grant individuals rights over their personal data:
- Right to Access: Request copies of personal data held.
- Right to Rectification: Correct inaccuracies.
- Right to Erasure (“Right to be Forgotten”): Remove personal data under certain conditions.
- Right to Data Portability: Obtain and transfer data to another provider.
- Right to Restrict Processing or Object: Limit use or object to certain processing activities.
PDPA rights are similar but generally narrower in scope, and Thai authorities provide transitional guidance to implement these rights.
Cross-Border Data Transfers
GDPR: Transfers to countries outside the EU are permitted only if the destination ensures adequate data protection or via mechanisms such as Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or explicit consent.
PDPA: Transfers abroad are allowed only to countries or organizations recognized by the Personal Data Protection Committee (PDPC) as having equivalent protection, or under contractual agreements with safeguards.
Enterprises must evaluate their cross-border operations to ensure both PDPA and GDPR compliance.
Accountability and Security Requirements
Both GDPR and PDPA require data controllers and processors to:
- Implement technical and organizational measures to safeguard personal data
- Conduct risk assessments and maintain records of processing activities
- Report data breaches to authorities within a specific timeframe
GDPR imposes stricter documentation and breach notification requirements, often including 72-hour notification windows.
Penalties and Enforcement

- GDPR: Fines can reach €20 million or 4% of annual global turnover, whichever is higher. Enforcement is active across all EU member states.
- PDPA Thailand: Administrative fines and penalties apply, with criminal liability in severe breaches. Fines are generally lower than GDPR but remain significant.
Compliance ensures not only legal safety but also customer trust and brand reputation.
Practical Compliance Tips for Thai Enterprises
- Conduct Data Mapping: Identify personal data collected, stored, and transferred.
- Update Privacy Policies: Ensure transparency for both local and international users.
- Obtain Clear Consent: Implement granular consent mechanisms in digital platforms.
- Review Contracts: Include data protection clauses in agreements with processors and partners.
- Implement Security Measures: Encryption, access control, and regular audits.
- Prepare for Breaches: Establish an incident response plan and reporting protocol.
- Monitor Regulatory Updates: Both PDPA and GDPR evolve; staying informed is critical.
Conclusion
While GDPR and PDPA share the common goal of protecting personal data, they differ in scope, enforcement, and detailed obligations. For Thai enterprises, understanding both frameworks is essential—especially when handling cross-border transactions or serving international clients. By implementing strong policies, consent management, and security practices, Thai businesses can remain compliant, protect customer trust, and compete effectively in the global digital economy.