Thai Language version available here: https://fosrlaw.com/2026/ตัวแทน-pdpa-ในไทย-ผู้ประสานง/
Foreign companies often start with a simple question under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA):
Do we need a representative in Thailand?
The question is useful, but incomplete.
A Thai PDPA representative is not just a name, address, or inbox in Thailand. The appointment document can affect how the foreign company, the Thai representative, data subjects, and the Office of the Personal Data Protection Committee (PDPC) understand the foreign company’s role under the PDPA.
Poor drafting can create real problems. A narrow appointment may fail to fulfill the function the PDPA contemplates. A broad appointment may suggest that the Thai representative is also a controller, a processor, a data protection officer, a commercial agent, a litigation agent, or a person authorized to admit liability.
The appointment should follow legal analysis. It should not replace it.
For the cross-border transfer side of this issue, including Sections 28 and 29, EU Standard Contractual Clauses, ASEAN Model Contractual Clauses, and transfer safeguards, see our related article, Cross-Border Customer Data Under Thailand’s PDPA. This article focuses on the appointment document itself.
What is a Thai PDPA representative?
The PDPA can apply to foreign controllers and processors outside Thailand.
Section 5 applies where a foreign controller or processor collects, uses, or discloses personal data in connection with either:
1. offering goods or services to data subjects in Thailand, whether or not payment is required; or
2. monitoring the behavior of data subjects where that behavior takes place in Thailand.
If a foreign controller falls within Section 5 paragraph two, Section 37(5) requires it to appoint a written representative in Thailand. The statutory wording matters. The representative must be in Thailand and authorized to act on behalf of the controller “without any limitation of liability” with respect to the collection, use, or disclosure of personal data according to the controller’s purposes.
That phrase carries weight.
The appointment can describe how the representative will exercise its authority in practice. It can describe communication channels, escalation procedures, records, and internal approval requirements. But those arrangements should not purport to restrict the authority required under Section 37(5) or suggest that the foreign controller can limit its PDPA exposure by narrowing the representative’s role.
The representative gives data subjects and the PDPC a reachable point in Thailand while leaving the foreign company responsible for its own compliance. That distinction is increasingly important as Thailand’s PDPA moves from basic policy adoption toward more operational accountability, a shift we discussed in Thailand PDPA in Its Second Phase.
Start with Section 5, not the form
A company should ask whether Section 5 applies before it selects the local representative or starts marking up a template.
A foreign company does not need a Thai representative merely because data about a person in Thailand appears in its system. The relevant activity must relate to offering goods or services to data subjects in Thailand, or monitoring their behavior in Thailand.
This distinction matters for platforms, cloud providers, software vendors, regional support hubs, manufacturers, analytics providers, and group companies.
A foreign company that markets to data subjects in Thailand, offers a digital service into Thailand, tracks, profiles, or personalizes services based on behavior taking place in Thailand may have a clear Section 5 issue.
A foreign company that performs limited back-end processing under another company’s instructions may have a different position. Labels do not decide the issue. “Technical support,” “quality review,” “analytics,” “system maintenance,” and “product improvement” can still raise Section 5 questions if the foreign entity uses Thai personal data to monitor, evaluate, profile, personalize, or make independent decisions about individuals in Thailand.
This issue becomes more important where analytics, automated decision-making, machine learning, or behavioral profiling are involved. We discussed the wider Thai regulatory context for these technologies in AI, Machine Learning, and Big Data in Thailand.
The actual activity matters more than the label.
Processors also need to check Section 38
Some foreign companies assume the representative requirement applies only to controllers.
Section 37(5) refers to foreign controllers. Section 38 then extends the representative framework to processors of those foreign controllers, applied mutatis mutandis, meaning with the necessary modifications.
A foreign entity should therefore not end the analysis by saying, “We are only a processor.” That may be correct for the role analysis, but Section 38 can still matter.
Section 38 also contains two exemptions. The representative requirement does not apply to:
1. a controller that is a public authority as prescribed and announced by the PDPC; or
2. a controller whose collection, use, or disclosure does not involve sensitive personal data under Section 26 and does not involve a large amount of personal data as prescribed under Section 41(2).
The second exemption requires careful consideration. A company cannot rely solely on the argument that the operation is small. If the processing involves sensitive personal data under Section 26, the exemption may not be available even if the volume is limited.
The appointment does not fix the role analysis
The PDPA separates controllers from processors.
A controller decides the purposes and means of collecting, using, or disclosing personal data. A processor acts under the controller’s instructions.
A representative appointment cannot repair an inaccurate role description.
If the foreign entity decides why Thai personal data is used, combines it with other data for its own purposes, controls retention independently, shares it onward for its own business reasons, or uses it for independent analytics or product development, the documents should not simply call it a processor and move on.
The opposite also applies. If the foreign entity genuinely acts only as a processor, the representative appointment should not use controller-style language. It should not suggest that the processor decides legal bases, controls data-subject communications, determines transparency obligations, or makes independent decisions about Thai personal data.
This is also where foreign templates can mislead. GDPR-based documents may provide a useful starting point, but they do not automatically answer the Thai-law question. We discussed some of those differences in GDPR vs. Thailand PDPA.
The appointment should reflect role analysis. It should not be rewritten.
Do not confuse the representative with the DPO
A Thai PDPA representative is not automatically a data protection officer.
Sections 41 and 42 address DPO appointments and duties. Section 26 may require a DPO in specific cases, including certain public authority processing, large-scale regular monitoring, or core activities involving sensitive personal data. The DPO advises on compliance, investigates compliance, coordinates with the PDPC, and maintains confidentiality.
The representative performs a different function.
A representative may receive or coordinate communications involving the PDPC, data subjects, or the foreign company’s DPO. But that does not make the representative the DPO. However, if the foreign controller or processor must appoint a DPO, its Thai representative must also comply with that requirement under Section 41. This does not mean that the representative must act as the DPO.
The appointment should state this clearly if the roles are separate. A local affiliate, vendor, or service provider may agree to act as a PDPA representative. That does not mean it should also accept the statutory DPO role unless the parties have separately assessed and agreed that structure.
Do not create a general agent by accident
The word “representative” can cause trouble because it carries different meanings in different contexts.
A PDPA representative should act for PDPA-related purposes. Unless the parties clearly intend otherwise, the appointment should not make the Thai representative:
- a general commercial agent;
- a contracting agent;
- an agent for civil court service of process;
- a person authorized to admit liability;
- a person authorized to settle claims;
- a person authorized to waive rights; or
- a person authorized to make binding statements outside the PDPA function.
This does not mean the appointment should be artificial. Section 37(5) requires a real representative with authority to act in relation to the relevant collection, use, or disclosure of personal data.
Good drafting draws the line. Receiving, forwarding, coordinating, and facilitating PDPA communications is different from binding the foreign company in commercial, litigation, or settlement matters.
Align the records, DPA, and representative appointment
A representative appointment should not sit alone.
Section 39 requires controllers to maintain records covering matters such as the personal data collected, purposes of collection, controller details, retention periods, access rights, certain uses and disclosures, rejected requests or objections, and security measures. Section 39 also applies to the representative of a foreign controller under Section 5 paragraph two, with the necessary modifications.
Section 40 imposes separate duties on processors. A processor must act only under the controller’s instructions, maintain security measures, notify the controller of personal data breaches, and keep records of processing activities as prescribed by the PDPC. Section 40 also requires the controller and processor to enter into an agreement governing the processing activities, commonly referred to as a data processing agreement (DPA). If the processor acts outside the controller’s instructions, the PDPA may treat it as a controller for that collection, use, or disclosure.
The documents should tell the same story.
The privacy notice, data processing agreement, transfer clauses, records of processing activities, breach procedure, and representative appointment should all match the actual data flow. If each document describes a different structure, the company will have a problem when a data-subject request, complaint, breach, or PDPC inquiry arises.
That alignment also matters in a breach scenario. A breach response will require the organization to identify who controlled the data, who processed it, who received it, who must notify whom, and who can communicate with the PDPC or affected data subjects. We discussed the notification side of that issue in Breach Notification Under Thailand’s PDPA.
What should the appointment cover?
Before signing a Thai PDPA representative appointment, foreign companies and Thai representatives should answer these questions.
Territorial scope
Does Section 5 paragraph two apply? Is the foreign entity offering goods or services to data subjects in Thailand, monitoring behavior in Thailand, or only performing limited back-end processing under another party’s instructions?
Role allocation
Is the foreign entity a controller, processor, or both for different activities? Does Section 37(5) apply directly? Does Section 38 apply because a foreign controller has engaged a processor?
Exemptions
Does a Section 38 exemption apply? Does the processing involve sensitive personal data under Section 26? Does it involve a large amount of personal data as prescribed under Section 41(2)?
Authority
Can the representative only receive, forward, and coordinate PDPA communications, or can it take substantive action for the foreign company? What must it escalate, and how quickly?
Records and requests
Who maintains the relevant Section 39 or Section 40 records? Who handles data-subject requests? Who communicates with the PDPC? What information must the foreign entity provide to the representative?
DPO and agency limits
Is the representative also the DPO, or is that role separate? Does the appointment avoid language suggesting general agency, civil service-of-process authority, settlement authority, or authority to admit liability?
These points should be settled before the document is signed, not after a complaint or breach.
The practical point
A Thai PDPA representative appointment is a role-allocation document.
The foreign company should first analyze Section 5, its controller or processor status, the actual data flow, and any Section 38 exemption. Only then should it draft the appointment.
For Thai entities asked to act as representatives, the same point applies in reverse. They should understand what they are accepting. The appointment should define the scope of authority, communication duties, recordkeeping expectations, DPO boundaries, and agency limits.
The risk is not only failing to appoint a representative where the PDPA requires one. The risk is also appointing one in a way that creates confusion about who controls the data, who processes it, who speaks to the regulator, who handles data-subject requests, and who carries legal responsibility.
A Thai representative may be the local face of the foreign company for PDPA purposes. The appointment should say exactly what that means, and what it does not.
The comments herein are provided for discussion and informational purposes only and may not reflect the most current legal developments. Nothing contained in this publication should be relied upon as legal advice.