Skip to main content
Layered glass panels representing the Thailand data-sharing law framework

Thailand Data-Sharing Law: What the 2026 Draft Proposes

The proposed Thailand data-sharing law could reshape how data moves between the government and private business. If enacted, it would create the country’s first comprehensive framework for exchanging data across the public and private sectors. Thailand’s Big Data Institute (BDI) opened the draft principles for public consultation on 31 July 2026 and invites comments until 31 August 2026. The measure is not yet law. Even so, its direction matters now. Any foreign investor, expat-run company, or international business that holds data in Thailand should take note. This guide explains what the data-sharing law proposes, how it fits with the PDPA, and how to prepare.

What the Thailand Data-Sharing Law Actually Is (and Is Not Yet)

First, the status matters. The draft is a set of principles for public consultation. It is not a binding statute. No implementing guidelines exist yet. No obligations currently bind businesses. The final text could still change before the Cabinet or Parliament considers it. Treat the proposal as an early policy signal, not a rulebook to follow today.

That said, the ambition is real. Thailand already regulates personal data through the Personal Data Protection Act (PDPA). Yet it has never had a single framework for how data moves between government bodies and private organizations. The draft law aims to fill that gap. It would build a systematic, secure, and transparent regime. Its stated goals include better analytics, evidence-based policymaking, research, and innovation.

For international businesses, the practical message is clear. Thailand is moving toward a more structured data economy. A firm that maps its data flows and tightens governance now will adapt smoothly. A firm that waits for a final gazette notification will scramble later.

Key TakeawayThe data-sharing law is a draft under public consultation until 31 August 2026. It imposes no obligations yet. Still, it signals a clear shift toward a formal, cross-sector data-sharing regime. Forward-looking businesses should start preparing now.

The Central Data-Sharing Platform (D2)

A central system for data exchange sits at the heart of the proposal, and the BDI would manage it. Under the draft, every government agency must connect to the BDI’s Data Integration and Intelligence Platform, known as D2. The BDI built D2 as a unified platform to share and analyze data. It links government bodies, private-sector organizations, and allied networks.

Centralizing government data through one platform brings clear efficiency gains. It also concentrates security, access control, and governance in a single institution. The BDI’s safeguards will therefore decide whether businesses and citizens trust the platform. Foreign companies will want three answers: who can access shared data, on what legal basis, and what audit trail records each request.

The Draft Framework’s Dimensions of Data Sharing

The draft maps data flows across three domains: government (G), business (B), and consumers (C). It contemplates several distinct sharing relationships. Each one carries different implications for private organizations in Thailand.

Government-to-Business (G2B)

Private organizations could request government-held data for research and development. First, the BDI would check whether the applicant meets prescribed standards for data governance, security, and privacy. It would then forward qualifying requests to the relevant agency within 90 days. A new Data-Sharing Promotion Committee would settle any dispute. For data-driven businesses, this channel is the most attractive part of the reform. Reliable government datasets can sharpen market analysis and product development.

Government-to-Government (G2G)

Agencies could request data from one another through the central system. The data-holding agency would respond within 90 days. It would weigh legality, necessity, proportionality, public interest, and personal data protection. Disputes would again reach the Data-Sharing Promotion Committee. This dimension is internal to the state, yet it affects businesses too. Smoother inter-agency data flows can speed up licensing, tax, and regulatory processes.

Business-to-Government (B2G)

This dimension deserves the closest attention from foreign investors. In emergencies involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society could require private entities to provide data through the platform. The draft builds in limits. An agency would have to specify the data, prove its necessity, and show the expected benefits. It could request only data reasonably available to the holder. Any request for personal data would stay at the minimum needed. Even so, a mandatory disclosure power is a meaningful obligation. Companies should watch how the final text defines “emergency” and “economic security.”

Business-to-Consumer (B2C)

The draft also contemplates consumer-facing data rights. Royal decrees would set out the detailed mechanics later. Those decrees do not exist yet, so businesses cannot map their exact obligations here. The signal, however, is clear. Thai policy is moving toward giving individuals more control and portability over their own data. This trend already appears under the PDPA.

Key TakeawayWatch the B2G dimension most closely. It would let the Minister of Digital Economy and Society compel private entities to share data in defined emergencies. Necessity and data-minimization limits would apply, and businesses should press for tight definitions in the consultation.

How the Data-Sharing Law Would Interact With the PDPA

The data-sharing law would not replace the PDPA. Instead, the two would operate together. Where shared data includes personal data, PDPA principles still apply. That means a lawful basis, purpose limitation, data minimization, and security safeguards. In practice, an organization would run two checks at once. Does the sharing framework authorize the transfer? And does the PDPA permit it?

This overlap raises the stakes for strong PDPA compliance. Imagine a company that already keeps clear records of processing, a working consent and legitimate-interest analysis, and a designated data protection officer. That company will assess and answer sharing requests far more easily. If you have not addressed these basics, a coming data-sharing regime gives you a strong reason to start. Our guides on the Data Protection Officer role under the PDPA and on data subject access requests offer a useful starting point.

The draft law also forms part of a broader wave of Thai digital-economy reform. Read it together with the draft Thailand AI Act and the overhaul of the Electronic Transactions Act. Both reshape how the law governs data, algorithms, and digital records. Together, these measures point toward a more codified, compliance-heavy digital environment.

What the Data-Sharing Law Means for Foreign Investors

For international businesses, the reform cuts two ways. On the opportunity side, the G2B channel offers structured access to government datasets. That access can support better analytics, site selection, and R&D. Firms in fintech, logistics, healthcare, and consumer sectors stand to gain the most from reliable, machine-readable public data.

On the obligation side, the B2G power introduces a new category of risk. In defined circumstances, a business could have to hand operational or customer data to the state. That prospect raises the value of data classification, retention discipline, and clear internal ownership. It also raises cross-border questions for multinationals. If mandatory sharing reaches Thai-held data, group data policies and intra-group transfer agreements may need a review.

Because the framework is still a draft, the consultation window is an opportunity, not just a deadline. Trade associations, chambers of commerce, and individual companies can submit evidence-based comments before 31 August 2026. Sharp input now can shape workable definitions, proportionate safeguards, and realistic timelines.

Key TakeawayThe data-sharing law offers new access to government data. At the same time, it introduces a potential duty to share your own data in emergencies. Weigh both sides, and consider using the consultation to influence the final rules.

Practical Steps to Prepare Now

You cannot comply with a law that does not exist yet. You can, however, build the foundations that any data-sharing regime will demand. Sensible preparation includes the following steps:

  • Map your data. Know what you hold, where it sits, which categories are personal or sensitive, and who owns each dataset internally.
  • Strengthen PDPA compliance. Confirm that your lawful bases, records of processing, retention schedules, and DPO arrangements stay current and documented.
  • Classify by sensitivity and shareability. Flag data that could fall within an emergency B2G request, and decide in advance how you would respond.
  • Review cross-border and intra-group agreements. Make sure your transfer mechanisms can absorb a new domestic sharing obligation.
  • Engage with the consultation. Submit comments, directly or through an industry body, on definitions, safeguards, and timelines.
  • Monitor developments. Track the draft toward implementing guidelines, and reassess your position when the final text and royal decrees appear.

A structured readiness review today turns a distant regulatory change into a manageable project. Preparing early for the Thailand data-sharing law costs far less than reacting once it becomes binding.

Legal status note: This article discusses a draft law released for public consultation on 31 July 2026. It is not yet enacted, imposes no current obligations, and may change. It offers general information only and does not constitute legal advice. Businesses should seek tailored advice before acting on the proposal.

Frequently Asked Questions

Is the Thailand data-sharing law in force yet?
No. The Thailand data-sharing law is a draft. The Big Data Institute released it for public consultation on 31 July 2026 and accepts comments until 31 August 2026. Lawmakers have not enacted it, and it imposes no binding obligations yet. The final framework may differ from the current principles.
What is the D2 platform under the draft law?
D2 is the BDI’s Data Integration and Intelligence Platform. It is the central system for data sharing under the proposal. Government agencies would connect to D2, and the BDI would manage access, security, and governance across government, business, and allied networks.
Could my company be forced to share data with the government?
Potentially, but only in defined circumstances. Under the business-to-government dimension, the Minister of Digital Economy and Society could require private entities to provide data during emergencies. These cover public safety, economic security, or disaster response. Requests would stay necessary, proportionate, and, for personal data, limited to the minimum required. These limits remain in draft form.
How does the data-sharing law relate to the PDPA?
The two would work together. The PDPA still governs personal data, so any sharing of personal data would need a lawful basis. It must also respect data-minimization and security duties. Strong PDPA compliance, including records of processing and a DPO, makes sharing requests far easier to handle.
How should foreign businesses prepare for the data-sharing law?
Start with a data map. Then tighten PDPA compliance, classify data by sensitivity and shareability, and review cross-border and intra-group transfer agreements. Businesses can also submit comments during the consultation to help shape practical definitions and safeguards before the draft becomes final.

Prepare Your Business for Thailand’s Data-Sharing Framework

Lex Bangkok advises international companies, investors, and expat-led businesses on Thailand’s evolving data and digital-economy laws. Our lawyers can review your data governance, assess your exposure under the draft data-sharing framework, and prepare a consultation submission on your behalf.

Schedule a Consultation

Authoritative references: the Big Data Institute (BDI) and Thailand’s Personal Data Protection Committee (PDPC).