PDPA

ตัวแทนตามกฎหมายคุ้มครองข้อมูลส่วนบุคคลของไทย

บริษัทต่างชาติมักเริ่มต้นด้วยคำถามง่าย ๆ ภายใต้ พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล (PDPA) ของไทยว่า เราจำเป็นต้องมีตัวแทนในประเทศไทยหรือไม่ แม้จะเป็นจุดเริ่มต้นที่ดี แต่ตัวแทนตาม PDPA ของไทยไม่ได้มีบทบาทเป็นเพียงช่องทางติดต่อในประเทศเท่านั้น หากร่างเอกสารไม่รอบคอบ อาจนำไปสู่ความเสี่ยงทางกฎหมาย ทั้งการมอบอำนาจเกินขอบเขต หรือการสับสนกับบทบาทของเจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (DPO) … Read More

Read More »

Thai PDPA Representatives: More Than a Local Contact Point

Foreign companies often start with a simple question under Thailand’s Personal Data Protection Act (PDPA): Do we need a representative in Thailand? While useful, a Thai PDPA representative is far more than a local contact point or inbox. Improper drafting can create significant legal risks, from unintentionally granting broad commercial agency to confusing representative functions with a Data Protection Officer (DPO). … Read More

Read More »

Thailand’s Data-Center Boom Enters a Second Regulatory Phase

Cloud, Connectivity, Energy Readiness, and the Limits of Investment Promotion Thailand is no longer merely trying to attract data-center investment. That phase has already arrived. In recent years, Thailand has seen major commitments and approvals across cloud regions, hyperscale facilities,

Read More »

Cross-Border Customer Data Under Thailand’s PDPA

The Transfer Mechanism Is Only Part of the Compliance Multinational groups often treat foreign back-end processing as a technical matter rather than a legal one. A local business collects customer data in Thailand, and some of that data is then

Read More »

From Awareness to Accountability: Breach Notification Under Thailand’s PDPA

Thai Language version available here: https://fosrlaw.com/2026/การแจ้งเหตุละเมิดข้อมู/ Why the 72-Hour Rule Is Only the Beginning Data breach notification under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) is often reduced to a single rule: notification to the Office of Personal

Read More »

Thailand PDPA in Its Second Phase: What Recent Developments Really Indicate

Thai Language version available here: https://fosrlaw.com/2026/pdpa-ของประเทศไทยในระยะที่/ Many organizations continue to approach Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) as a first-generation compliance exercise. The emphasis remains on privacy notices, consent wording, template clauses, and remediation projects undertaken during the

Read More »

PDPA ของประเทศไทยในระยะที่สอง: สิ่งที่พัฒนาการล่าสุดสะท้อนให้เห็นอย่างแท้จริง

พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคลของไทยกำลังเข้าสู่ระยะที่สอง หน่วยงานกำกับดูแลไม่ได้มองเพียงว่าองค์กรมีนโยบายและเอกสารครบถ้วนหรือไม่ แต่คาดหวัง “ความรับผิดชอบที่พิสูจน์ได้จริง” ในทางปฏิบัติ บทความนี้วิเคราะห์พัฒนาการสำคัญ 5 ด้าน ได้แก่ สิทธิของเจ้าของข้อมูล การถ่ายโอนข้อมูลข้ามพรมแดน การคุ้มครองข้อมูลเด็ก การกำกับดูแล AI และมาตรฐานความรับผิดชอบองค์กร … Read More

Read More »