What Is a Data Protection Officer in Thailand?
A data protection officer, or DPO, is the person a business designates to oversee its compliance with the PDPA. The role sits at the centre of an organisation’s privacy governance. The officer advises the business, monitors how it collects and uses personal data, and acts as the point of contact for both data subjects and the regulator.
Crucially, appointing a DPO does not transfer legal responsibility. The data controller and data processor remain accountable for compliance at all times. The officer supports that compliance; the officer does not absorb the liability. Foreign investors sometimes assume a DPO is simply an IT or legal hire. In reality, the position carries statutory duties, independence requirements, and its own exposure to regulatory scrutiny. It also sits alongside other privacy tools, such as Thailand’s new PDPA certification framework, which organisations can use to demonstrate mature data governance.
When Must You Appoint a Data Protection Officer in Thailand?
Section 41 of the PDPA sets out when the appointment becomes mandatory. A business does not need a DPO for every processing activity. Instead, the obligation is triggered by the nature and scale of the data work. The following table summarises the three principal triggers.
| Trigger under Section 41 | What it means in practice |
|---|---|
| Public authority | The data controller or processor is a public authority designated in a PDPC notification. |
| Large-scale regular monitoring | Core activities require regular and systematic monitoring of personal data or systems on a large scale, such as tracking, profiling, or behavioural analysis. |
| Large-scale sensitive data | Core activities involve large-scale processing of sensitive personal data under Section 26, such as health, biometric, or criminal-record data. |
Two points matter for international businesses. First, the draft 2026 guidance indicates that processing involving 100,000 or more data subjects may be treated as “large scale.” That threshold captures many e-commerce operators, hospitals, hotels, insurers, and consumer-facing platforms. Second, certain foreign-organisation representative arrangements can also trigger the appointment. Companies based outside Thailand that fall within the PDPA’s reach should therefore review the requirement carefully rather than assume it does not apply.
Duties of a Data Protection Officer Under Section 42
Section 42 of the PDPA defines what the officer actually does. The duties are functional rather than symbolic, and the regulator increasingly expects to see them performed in practice. A DPO in Thailand must:
- Advise the organisation and its staff on their obligations under the PDPA.
- Monitor and investigate compliance across the collection, use, and disclosure of personal data.
- Coordinate and cooperate with the PDPC Office when issues arise.
- Maintain the confidentiality of personal data learned in the course of the role.
The law also protects the officer. The organisation must give the DPO adequate resources and support, and it cannot dismiss or penalise the officer for properly carrying out these duties. In addition, the business must publish the DPO’s contact details and notify the PDPC of who holds the role. These are not optional courtesies. They are the operational spine of an accountable privacy programme. In practice, the DPO also becomes the internal owner of routine compliance workflows, including data subject access requests, which carry their own statutory response deadlines.
The 2026 Draft PDPC Guidance: What May Change
On 7 July 2026, the Office of the PDPC presented draft guidance on data protection officers as part of a public consultation covering a wider set of draft privacy manuals and recommendations. The guidance is not yet binding. Even so, it offers the clearest signal yet of how the regulator wants the role to function, and companies can use the consultation window to prepare before the rules are finalised.
Independence and reporting lines
The draft treats a lack of independence as the central risk. A constrained officer cannot escalate problems, so the guidance expects organisations to give the DPO enough time, budget, personnel, tools, and access to information. The officer should report directly to the highest level of management. Where management declines to follow the DPO’s advice, the officer should record the reasons in writing. That paper trail matters if the regulator later asks how a decision was made.
Conflicts of interest
The draft guidance is direct about who should not serve as DPO. It cautions against appointing anyone who decides the purposes and means of processing, including the chief executive, chief operating officer, chief financial officer, head of marketing, or head of human resources. General IT support staff may hold the role, but senior IT leaders who choose systems or decide what data to centralise may create a conflict. For smaller teams, the guidance allows some flexibility, yet it still recommends shifting monitoring duties to a neutral department.
In-House, Outsourced, or Group DPO?
The draft guidance recognises that one structure does not fit every organisation. Businesses can choose the model that matches their size, complexity, and internal capability. The comparison below sets out the main options.
| Structure | Best suited to | Key condition |
|---|---|---|
| In-house DPO | Medium and large organisations with complex internal systems | Avoid appointing anyone who decides how personal data is used. |
| Outsourced DPO | Businesses lacking in-house privacy expertise or resources | Define access rights, response duties, and internal coordination clearly. |
| Group DPO | Companies within the same corporate group | The officer must be easily contactable by each entity and understand each business. |
| Voluntary DPO | Organisations raising their governance standards by choice | Must still meet the legal standards that apply to a mandatory DPO. |
Many multinationals in Thailand favour a group or outsourced model. Both work well, provided the officer remains genuinely reachable and independent. A group DPO who cannot service each subsidiary, or an outsourced provider with no defined escalation path, will not satisfy the regulator’s expectations.
Penalties and Why the DPO Matters
Failing to designate a data protection officer in Thailand where the PDPA requires one is not a minor slip. The Act imposes an administrative fine of up to THB 1 million for non-compliance with the appointment obligation. The same exposure applies where an organisation fails to support the officer as the law demands.
Beyond the fine, the officer plays a defensive role during a data breach. When breach notification is required, the notification should identify the DPO by name and provide the officer’s contact details, alongside information about the breach, its likely impact, and the remedial steps taken. A well-run DPO function therefore reduces both the chance of a breach and the fallout when one occurs.
Practical Steps for Foreign-Invested Companies
Companies that want to get ahead of the finalised guidance can act now. A focused review of your data protection officer in Thailand arrangements closes the most common gaps. Consider the following steps:
- Map your processing activities and confirm whether any Section 41 trigger applies to your business.
- Assess any current or proposed DPO for conflicts of interest, especially where the candidate sits in senior management.
- Review reporting lines so the officer can reach the highest level of management directly.
- Document access rights, scope of work, and escalation processes, particularly for outsourced or group arrangements.
- Update privacy notices and public contact points so data subjects can reach the DPO easily.
- Integrate the officer into data protection impact assessments, records of processing, staff training, and breach response.
Businesses outside Thailand should also remember that a DPO is not the same as a local representative. A controller based abroad may need to appoint a separate PDPA local representative in Thailand, in addition to any DPO. The two roles serve different functions and should not be conflated. Official guidance and the statutory text are published by the PDPC, and the full PDPA is available through the Office of the Council of State.
Frequently Asked Questions
Does every company in Thailand need a data protection officer?
Can a foreign national serve as a DPO in Thailand?
Can our CEO or head of HR act as the data protection officer?
Is the July 2026 PDPC guidance legally binding?
What happens if we do not appoint a required DPO?
Can one DPO cover several companies in our group?
Need Help Appointing a Data Protection Officer in Thailand?
Lex Bangkok advises international companies, expatriate employers, and foreign investors on PDPA compliance, from assessing whether you need a DPO to structuring in-house, outsourced, or group arrangements that satisfy the regulator. Our team turns evolving privacy rules into clear, commercially practical steps.
Schedule a Consultation