What the Thailand Data-Sharing Law Actually Is (and Is Not Yet)
First, the status matters. The draft is a set of principles for public consultation. It is not a binding statute. No implementing guidelines exist yet. No obligations currently bind businesses. The final text could still change before the Cabinet or Parliament considers it. Treat the proposal as an early policy signal, not a rulebook to follow today.
That said, the ambition is real. Thailand already regulates personal data through the Personal Data Protection Act (PDPA). Yet it has never had a single framework for how data moves between government bodies and private organizations. The draft law aims to fill that gap. It would build a systematic, secure, and transparent regime. Its stated goals include better analytics, evidence-based policymaking, research, and innovation.
For international businesses, the practical message is clear. Thailand is moving toward a more structured data economy. A firm that maps its data flows and tightens governance now will adapt smoothly. A firm that waits for a final gazette notification will scramble later.
The Central Data-Sharing Platform (D2)
A central system for data exchange sits at the heart of the proposal, and the BDI would manage it. Under the draft, every government agency must connect to the BDI’s Data Integration and Intelligence Platform, known as D2. The BDI built D2 as a unified platform to share and analyze data. It links government bodies, private-sector organizations, and allied networks.
Centralizing government data through one platform brings clear efficiency gains. It also concentrates security, access control, and governance in a single institution. The BDI’s safeguards will therefore decide whether businesses and citizens trust the platform. Foreign companies will want three answers: who can access shared data, on what legal basis, and what audit trail records each request.
The Draft Framework’s Dimensions of Data Sharing
The draft maps data flows across three domains: government (G), business (B), and consumers (C). It contemplates several distinct sharing relationships. Each one carries different implications for private organizations in Thailand.
Government-to-Business (G2B)
Private organizations could request government-held data for research and development. First, the BDI would check whether the applicant meets prescribed standards for data governance, security, and privacy. It would then forward qualifying requests to the relevant agency within 90 days. A new Data-Sharing Promotion Committee would settle any dispute. For data-driven businesses, this channel is the most attractive part of the reform. Reliable government datasets can sharpen market analysis and product development.
Government-to-Government (G2G)
Agencies could request data from one another through the central system. The data-holding agency would respond within 90 days. It would weigh legality, necessity, proportionality, public interest, and personal data protection. Disputes would again reach the Data-Sharing Promotion Committee. This dimension is internal to the state, yet it affects businesses too. Smoother inter-agency data flows can speed up licensing, tax, and regulatory processes.
Business-to-Government (B2G)
This dimension deserves the closest attention from foreign investors. In emergencies involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society could require private entities to provide data through the platform. The draft builds in limits. An agency would have to specify the data, prove its necessity, and show the expected benefits. It could request only data reasonably available to the holder. Any request for personal data would stay at the minimum needed. Even so, a mandatory disclosure power is a meaningful obligation. Companies should watch how the final text defines “emergency” and “economic security.”
Business-to-Consumer (B2C)
The draft also contemplates consumer-facing data rights. Royal decrees would set out the detailed mechanics later. Those decrees do not exist yet, so businesses cannot map their exact obligations here. The signal, however, is clear. Thai policy is moving toward giving individuals more control and portability over their own data. This trend already appears under the PDPA.
How the Data-Sharing Law Would Interact With the PDPA
The data-sharing law would not replace the PDPA. Instead, the two would operate together. Where shared data includes personal data, PDPA principles still apply. That means a lawful basis, purpose limitation, data minimization, and security safeguards. In practice, an organization would run two checks at once. Does the sharing framework authorize the transfer? And does the PDPA permit it?
This overlap raises the stakes for strong PDPA compliance. Imagine a company that already keeps clear records of processing, a working consent and legitimate-interest analysis, and a designated data protection officer. That company will assess and answer sharing requests far more easily. If you have not addressed these basics, a coming data-sharing regime gives you a strong reason to start. Our guides on the Data Protection Officer role under the PDPA and on data subject access requests offer a useful starting point.
The draft law also forms part of a broader wave of Thai digital-economy reform. Read it together with the draft Thailand AI Act and the overhaul of the Electronic Transactions Act. Both reshape how the law governs data, algorithms, and digital records. Together, these measures point toward a more codified, compliance-heavy digital environment.
What the Data-Sharing Law Means for Foreign Investors
For international businesses, the reform cuts two ways. On the opportunity side, the G2B channel offers structured access to government datasets. That access can support better analytics, site selection, and R&D. Firms in fintech, logistics, healthcare, and consumer sectors stand to gain the most from reliable, machine-readable public data.
On the obligation side, the B2G power introduces a new category of risk. In defined circumstances, a business could have to hand operational or customer data to the state. That prospect raises the value of data classification, retention discipline, and clear internal ownership. It also raises cross-border questions for multinationals. If mandatory sharing reaches Thai-held data, group data policies and intra-group transfer agreements may need a review.
Because the framework is still a draft, the consultation window is an opportunity, not just a deadline. Trade associations, chambers of commerce, and individual companies can submit evidence-based comments before 31 August 2026. Sharp input now can shape workable definitions, proportionate safeguards, and realistic timelines.
Practical Steps to Prepare Now
You cannot comply with a law that does not exist yet. You can, however, build the foundations that any data-sharing regime will demand. Sensible preparation includes the following steps:
- Map your data. Know what you hold, where it sits, which categories are personal or sensitive, and who owns each dataset internally.
- Strengthen PDPA compliance. Confirm that your lawful bases, records of processing, retention schedules, and DPO arrangements stay current and documented.
- Classify by sensitivity and shareability. Flag data that could fall within an emergency B2G request, and decide in advance how you would respond.
- Review cross-border and intra-group agreements. Make sure your transfer mechanisms can absorb a new domestic sharing obligation.
- Engage with the consultation. Submit comments, directly or through an industry body, on definitions, safeguards, and timelines.
- Monitor developments. Track the draft toward implementing guidelines, and reassess your position when the final text and royal decrees appear.
A structured readiness review today turns a distant regulatory change into a manageable project. Preparing early for the Thailand data-sharing law costs far less than reacting once it becomes binding.
Frequently Asked Questions
Is the Thailand data-sharing law in force yet?
What is the D2 platform under the draft law?
Could my company be forced to share data with the government?
How does the data-sharing law relate to the PDPA?
How should foreign businesses prepare for the data-sharing law?
Prepare Your Business for Thailand’s Data-Sharing Framework
Lex Bangkok advises international companies, investors, and expat-led businesses on Thailand’s evolving data and digital-economy laws. Our lawyers can review your data governance, assess your exposure under the draft data-sharing framework, and prepare a consultation submission on your behalf.
Schedule a ConsultationAuthoritative references: the Big Data Institute (BDI) and Thailand’s Personal Data Protection Committee (PDPC).