Data Protection Officer

ตัวแทนตามกฎหมายคุ้มครองข้อมูลส่วนบุคคลของไทย

บริษัทต่างชาติมักเริ่มต้นด้วยคำถามง่าย ๆ ภายใต้ พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล (PDPA) ของไทยว่า เราจำเป็นต้องมีตัวแทนในประเทศไทยหรือไม่ แม้จะเป็นจุดเริ่มต้นที่ดี แต่ตัวแทนตาม PDPA ของไทยไม่ได้มีบทบาทเป็นเพียงช่องทางติดต่อในประเทศเท่านั้น หากร่างเอกสารไม่รอบคอบ อาจนำไปสู่ความเสี่ยงทางกฎหมาย ทั้งการมอบอำนาจเกินขอบเขต หรือการสับสนกับบทบาทของเจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (DPO) … Read More

Read More »

Thai PDPA Representatives: More Than a Local Contact Point

Foreign companies often start with a simple question under Thailand’s Personal Data Protection Act (PDPA): Do we need a representative in Thailand? While useful, a Thai PDPA representative is far more than a local contact point or inbox. Improper drafting can create significant legal risks, from unintentionally granting broad commercial agency to confusing representative functions with a Data Protection Officer (DPO). … Read More

Read More »

Thailand’s PDPA: Enforcement in Action and Cross-Border Data Transfers

Thailand’s Personal Data Protection Act (PDPA), enforced since June 2022, demands robust compliance to avoid fines exceeding THB 21.5 million. The PDPC penalizes weak governance, inadequate security, and delayed breach responses. Key steps include appointing Data Protection Officers, implementing encryption, and ensuring 72-hour breach reporting. The PDPA’s cross-border data transfer rules, clarified in 2023, require Standard Contractual Clauses or Binding Corporate Rules for compliance. Adhering to PDPA not only mitigates penalties but boosts consumer trust by 15% and market access by 10%, offering strategic business advantages.
Read More

Read More »