Skip to main content

Data Protection Officer in Thailand: 2026 PDPA Guide

Appointing a data protection officer in Thailand is no longer a box-ticking exercise. Since the Personal Data Protection Act B.E. 2562 (2019) (PDPA) took full effect, the Office of the Personal Data Protection Committee (PDPC) has steadily tightened its expectations for how the role should work in practice. In July 2026 the regulator went a step further and released draft guidance that spells out when a company must appoint a data protection officer, how that officer must operate independently, and which senior executives should never hold the position. For foreign-invested companies handling customer, employee, or patient data in Thailand, these developments turn a familiar compliance question into a live operational risk.

What Is a Data Protection Officer in Thailand?

A data protection officer, or DPO, is the person a business designates to oversee its compliance with the PDPA. The role sits at the centre of an organisation’s privacy governance. The officer advises the business, monitors how it collects and uses personal data, and acts as the point of contact for both data subjects and the regulator.

Crucially, appointing a DPO does not transfer legal responsibility. The data controller and data processor remain accountable for compliance at all times. The officer supports that compliance; the officer does not absorb the liability. Foreign investors sometimes assume a DPO is simply an IT or legal hire. In reality, the position carries statutory duties, independence requirements, and its own exposure to regulatory scrutiny. It also sits alongside other privacy tools, such as Thailand’s new PDPA certification framework, which organisations can use to demonstrate mature data governance.

When Must You Appoint a Data Protection Officer in Thailand?

Section 41 of the PDPA sets out when the appointment becomes mandatory. A business does not need a DPO for every processing activity. Instead, the obligation is triggered by the nature and scale of the data work. The following table summarises the three principal triggers.

Trigger under Section 41What it means in practice
Public authorityThe data controller or processor is a public authority designated in a PDPC notification.
Large-scale regular monitoringCore activities require regular and systematic monitoring of personal data or systems on a large scale, such as tracking, profiling, or behavioural analysis.
Large-scale sensitive dataCore activities involve large-scale processing of sensitive personal data under Section 26, such as health, biometric, or criminal-record data.

Two points matter for international businesses. First, the draft 2026 guidance indicates that processing involving 100,000 or more data subjects may be treated as “large scale.” That threshold captures many e-commerce operators, hospitals, hotels, insurers, and consumer-facing platforms. Second, certain foreign-organisation representative arrangements can also trigger the appointment. Companies based outside Thailand that fall within the PDPA’s reach should therefore review the requirement carefully rather than assume it does not apply.

Key Takeaway: The duty to appoint a data protection officer in Thailand hinges on scale and sensitivity, not company size. If your core business depends on tracking users or handling health, biometric, or other sensitive data at volume, you likely fall within Section 41.

Duties of a Data Protection Officer Under Section 42

Section 42 of the PDPA defines what the officer actually does. The duties are functional rather than symbolic, and the regulator increasingly expects to see them performed in practice. A DPO in Thailand must:

  • Advise the organisation and its staff on their obligations under the PDPA.
  • Monitor and investigate compliance across the collection, use, and disclosure of personal data.
  • Coordinate and cooperate with the PDPC Office when issues arise.
  • Maintain the confidentiality of personal data learned in the course of the role.

The law also protects the officer. The organisation must give the DPO adequate resources and support, and it cannot dismiss or penalise the officer for properly carrying out these duties. In addition, the business must publish the DPO’s contact details and notify the PDPC of who holds the role. These are not optional courtesies. They are the operational spine of an accountable privacy programme. In practice, the DPO also becomes the internal owner of routine compliance workflows, including data subject access requests, which carry their own statutory response deadlines.

The 2026 Draft PDPC Guidance: What May Change

On 7 July 2026, the Office of the PDPC presented draft guidance on data protection officers as part of a public consultation covering a wider set of draft privacy manuals and recommendations. The guidance is not yet binding. Even so, it offers the clearest signal yet of how the regulator wants the role to function, and companies can use the consultation window to prepare before the rules are finalised.

Independence and reporting lines

The draft treats a lack of independence as the central risk. A constrained officer cannot escalate problems, so the guidance expects organisations to give the DPO enough time, budget, personnel, tools, and access to information. The officer should report directly to the highest level of management. Where management declines to follow the DPO’s advice, the officer should record the reasons in writing. That paper trail matters if the regulator later asks how a decision was made.

Conflicts of interest

The draft guidance is direct about who should not serve as DPO. It cautions against appointing anyone who decides the purposes and means of processing, including the chief executive, chief operating officer, chief financial officer, head of marketing, or head of human resources. General IT support staff may hold the role, but senior IT leaders who choose systems or decide what data to centralise may create a conflict. For smaller teams, the guidance allows some flexibility, yet it still recommends shifting monitoring duties to a neutral department.

Key Takeaway: Treat the July 2026 guidance as a preview, not a rulebook. It remains in draft, but its emphasis on independence, contactability, and conflict management shows the direction of travel. Reviewing your DPO arrangements now is far cheaper than retrofitting them under enforcement pressure.

In-House, Outsourced, or Group DPO?

The draft guidance recognises that one structure does not fit every organisation. Businesses can choose the model that matches their size, complexity, and internal capability. The comparison below sets out the main options.

StructureBest suited toKey condition
In-house DPOMedium and large organisations with complex internal systemsAvoid appointing anyone who decides how personal data is used.
Outsourced DPOBusinesses lacking in-house privacy expertise or resourcesDefine access rights, response duties, and internal coordination clearly.
Group DPOCompanies within the same corporate groupThe officer must be easily contactable by each entity and understand each business.
Voluntary DPOOrganisations raising their governance standards by choiceMust still meet the legal standards that apply to a mandatory DPO.

Many multinationals in Thailand favour a group or outsourced model. Both work well, provided the officer remains genuinely reachable and independent. A group DPO who cannot service each subsidiary, or an outsourced provider with no defined escalation path, will not satisfy the regulator’s expectations.

Penalties and Why the DPO Matters

Failing to designate a data protection officer in Thailand where the PDPA requires one is not a minor slip. The Act imposes an administrative fine of up to THB 1 million for non-compliance with the appointment obligation. The same exposure applies where an organisation fails to support the officer as the law demands.

Beyond the fine, the officer plays a defensive role during a data breach. When breach notification is required, the notification should identify the DPO by name and provide the officer’s contact details, alongside information about the breach, its likely impact, and the remedial steps taken. A well-run DPO function therefore reduces both the chance of a breach and the fallout when one occurs.

Key Takeaway: A THB 1 million fine is only the visible cost. The larger risk is regulatory attention, reputational harm, and disrupted operations after a breach. A capable, independent DPO is a practical safeguard, not an overhead.

Practical Steps for Foreign-Invested Companies

Companies that want to get ahead of the finalised guidance can act now. A focused review of your data protection officer in Thailand arrangements closes the most common gaps. Consider the following steps:

  • Map your processing activities and confirm whether any Section 41 trigger applies to your business.
  • Assess any current or proposed DPO for conflicts of interest, especially where the candidate sits in senior management.
  • Review reporting lines so the officer can reach the highest level of management directly.
  • Document access rights, scope of work, and escalation processes, particularly for outsourced or group arrangements.
  • Update privacy notices and public contact points so data subjects can reach the DPO easily.
  • Integrate the officer into data protection impact assessments, records of processing, staff training, and breach response.

Businesses outside Thailand should also remember that a DPO is not the same as a local representative. A controller based abroad may need to appoint a separate PDPA local representative in Thailand, in addition to any DPO. The two roles serve different functions and should not be conflated. Official guidance and the statutory text are published by the PDPC, and the full PDPA is available through the Office of the Council of State.

Frequently Asked Questions

Does every company in Thailand need a data protection officer?
No. The PDPA requires a DPO only where Section 41 applies, namely for designated public authorities, for large-scale regular monitoring of personal data, or for large-scale processing of sensitive data. Many small businesses fall outside these triggers, although any organisation may appoint a DPO voluntarily.
Can a foreign national serve as a DPO in Thailand?
The PDPA does not impose a nationality restriction on the role. The priority is competence, independence, and the ability to perform the Section 42 duties and remain contactable for data subjects and the regulator. Businesses should still confirm work-authorisation and practical availability for any appointee based abroad.
Can our CEO or head of HR act as the data protection officer?
The draft 2026 guidance advises against it. Senior executives who decide the purposes and means of processing, such as the CEO, CFO, head of marketing, or head of HR, may face a conflict of interest. A more neutral function within the organisation is preferable.
Is the July 2026 PDPC guidance legally binding?
Not yet. It was released in draft for public consultation on 7 July 2026. The underlying obligation to appoint a DPO under Section 41 is already in force, but the detailed guidance on independence, conflicts, and structuring options remains subject to change until finalised.
What happens if we do not appoint a required DPO?
An organisation that fails to designate a DPO where the PDPA requires one faces an administrative fine of up to THB 1 million. The same exposure can arise where the business does not properly support or protect the officer.
Can one DPO cover several companies in our group?
Yes. The draft guidance recognises a group DPO for companies within the same corporate group, provided the officer is easily contactable by each entity and understands each business’s context. The arrangement should be documented so responsibilities and escalation paths are clear.
Legal note: This article provides general information on the data protection officer requirement in Thailand and does not constitute legal advice. The PDPA appointment obligation under Sections 41 and 42 is in force. The PDPC guidance released on 7 July 2026 remains in draft and under public consultation, and its final form may differ. Businesses should obtain tailored advice on their specific processing activities before acting.

Need Help Appointing a Data Protection Officer in Thailand?

Lex Bangkok advises international companies, expatriate employers, and foreign investors on PDPA compliance, from assessing whether you need a DPO to structuring in-house, outsourced, or group arrangements that satisfy the regulator. Our team turns evolving privacy rules into clear, commercially practical steps.

Schedule a Consultation