What Actually Works Under Thai Law and in Cross-Border Engagements AI Clauses Are No Longer About Permission In sophisticated professional services engagements, particularly legal services, AI-related provisions have evolved quietly yet decisively. They no longer ask whether AI may be … Read More
Data Privacy
Thailand’s New Website Security Standards 2025: Implications for Compliance Under the Cybersecurity Act
Thailand has strengthened its national cybersecurity framework with the implementation of a Website Security Standard. The standard was officially released on September 16, 2025, and takes effect on the same day. Issued under the Cybersecurity Act B.E. 2562 (2019), this … Read More
Thailand’s PDPA: Enforcement in Action and Cross-Border Data Transfers
Thailand’s Personal Data Protection Act (PDPA), enforced since June 2022, demands robust compliance to avoid fines exceeding THB 21.5 million. The PDPC penalizes weak governance, inadequate security, and delayed breach responses. Key steps include appointing Data Protection Officers, implementing encryption, and ensuring 72-hour breach reporting. The PDPA’s cross-border data transfer rules, clarified in 2023, require Standard Contractual Clauses or Binding Corporate Rules for compliance. Adhering to PDPA not only mitigates penalties but boosts consumer trust by 15% and market access by 10%, offering strategic business advantages.
… Read More
Australia’s Bunnings Ruling Sounds Alarm for Facial Recognition Use in Thailand
HOW AN AUSTRALIAN DATA PRIVACY CASE SIGNALS STRICT LIMITS ON FACIAL RECOGNITION TECHNOLOGY USE IN THAILAND. A landmark ruling against Australia’s hardware store “Bunnings” for the unlawful use of facial recognition technology (FRT) serves as a wake-up call for Thai … Read More
Artificial Intelligence, Machine Learning, and Big Data in Thailand: Legal and Regulatory Developments 2025
1. Introduction to AI in Thailand Thailand continues to develop as a regional leader in artificial intelligence (AI), machine learning (ML), and big data regulation, balancing innovation with legal protections. In 2025, the legal environment will be shaped by existing … Read More
AI Regulation in Thailand: What Foreign and Domestic Providers Should Know
Thailand is establishing a regulatory framework for artificial intelligence, adopting a rights-based and risk-focused approach that will soon influence both domestic and international AI service providers. Introduction Thailand is developing formal regulations for artificial intelligence (AI) through a novel legal … Read More
GDPR vs. Thailand PDPA: Substantive Legal Comparison June 2025
Explore a detailed comparison of GDPR vs. Thailand’s PDPA, highlighting key differences in enforcement, fines, data subject rights, and cross-border transfers. Understand compliance challenges and practical implications for businesses navigating Thailand’s evolving data protection landscape. … Read More
Thailand: Medical Research, Pharmacovigilance, Data Management, And Data Privacy
The critical legislation on health and pharmaceuticals that relates to general privacy and data protection law in Thailand, including the Personal Data Protection Act 2019 (‘PDPA’), are as follows: … Read More
Personal Data Breach Notifications – Thailand Personal Data Privacy
November 2022 By John Formichella & Naytiwut Jamallsawat The obligation to report a personal data breach in Thailand under the Personal Data Protection Act B.E. 2562 (2019) (“PDPA“) is subject to the risk and impact on the owner of the … Read More
John Formichella has been listed among Super 50 TMT Lawyers Asia by Asian Legal Business
The lawyers in the Super 50 were selected based on recommendations to ALB, including in-house counsel and other decision-makers regarding client service. John is one of just three lawyers from Thailand to be listed. More than 200 in-house counsels across 13 jurisdictions in Asia and overseas sent in their recommendations for this list. … Read More