Thailand's Personal Data Protection Committee (PDPC) has finally written down how the right of access is supposed to work. Its Notification on access requests was published in the Government Gazette on 16 July 2026 and took effect on 14 September 2026, 60 days later, according to Baker McKenzie's analysis. The direction is right. Some of the design choices deserve a harder look.
What changed
Section 30 of the Personal Data Protection Act B.E. 2562 (2019) already gave data subjects the right to request access to, and a copy of, their personal data, or to ask how data obtained without their consent was acquired. The statute has been available in unofficial English translation from the Ministry of Digital Economy and Society. It has been fully in force since 1 June 2022, per the IAPP. What it lacked was procedure. Baker McKenzie describes the Notification as the mechanism that fills that gap. Its main requirements are:
- Controllers must offer at least physical and postal channels for requests. Electronic channels are welcome but not required.
- Controllers must verify the requester's identity and the details of the request.
- Controllers must respond within 30 days of a complete request. They may extend by up to 30 more days by notifying the requester, for example where the request involves a large volume of information.
- Access is generally free. Fees are allowed only for special formats, delivery costs, or repetitive or excessive requests.
- Controllers must keep records of requests for at least two years.
Baker McKenzie also lists the grounds for refusal. These include disclosure prohibited by law or court order, harm to third parties' rights, and requests that are unfounded.
The strongest case for the rules
The case for the Notification is strong. A right that has no deadline, no defined channel and no fee rule is easy to defeat in practice. A controller can ignore a request, demand an arbitrary fee, or lose the paper trail. A fixed 30-day clock, a free default and mandatory record-keeping turn an abstract right into something a citizen can invoke and a regulator can audit. A bounded extension also protects requesters from open-ended stalling. Thailand's digital economy depends on public trust in data handling, and predictable procedure builds that trust.
The timeline also compares reasonably with other regimes. A 30-day response window, extendable in complex cases, is a conventional design. It is not an outlier that would strand Thai firms in cross-border compliance.
Where proportionality is at risk
The weak point is the channel mandate. The Notification's floor is physical and postal submission, with digital channels merely welcome. That protects people without internet access. But for an online platform, a fintech or a software-as-a-service firm, the required channel is the one users are least likely to use. The Notification does not require the channel where nearly all requests will arrive. A policy that requires a mailbox and a form and does not require the online channel most requesters will actually use is aimed at procedure more than at outcomes.
The burden falls unevenly. Mondaq's summary argues the requirements strain smaller organisations without dedicated data protection staff. That is plausible. The gap analyses, tracking systems and staff training the rules imply are cheap for a bank and costly for a ten-person startup. Thailand's PDPC has previously recognised this. The IAPP notes it exempts certain small businesses, meaning SMEs under set employee or revenue thresholds, from maintaining processing records, though not for rejected data subject requests. That carve-out shows a tiered approach is workable. The access-request rules would benefit from the same logic, for instance longer response windows or lighter channel duties for micro-enterprises.
There is also a drafting risk in the refusal grounds. Law-firm summaries agree on the categories, but their wording of the standards varies. One frames it as "unfounded" requests, another as "manifestly unfounded or unreasonably burdensome", according to Hogan Lovells' summary. The details of the timing steps for incomplete requests also differ between summaries. Practitioners are working from secondary summaries, and small differences in wording matter when a controller decides whether it may refuse. The PDPC should publish plain-language guidance and worked examples. That would cost little and would prevent both over-refusal by controllers and vexatious requests.
Identity verification is a further balancing point. Verification protects the data subject, because handing personal data to an impostor is a breach in itself. But the rules should not become a barrier. Hogan Lovells reports the Notification's verification standard as one that "should not create unreasonable barriers for data subjects". Controllers should ask only for what is needed to confirm identity, and should not use verification to collect more data than they already hold.
What regulators and firms should do next
Three steps would keep the benefits and limit the costs.
- Treat electronic channels as the norm in guidance. Keep the postal floor for inclusion, but publish templates and a standard web form so firms do not build bespoke systems.
- Scale the duties. Use the existing SME thresholds as a reference point for lighter obligations where the risk to data subjects is low.
- Publish official English and Thai guidance on refusals and extensions. Clear standards reduce disputes and keep the right of access from being used to harass firms.
A fair reading is that Thailand has done the harder part: it has made access a working right rather than a slogan. Enforcement will decide whether it stays proportionate. If the PDPC audits for response times and record-keeping, and not for the elegance of a postal form, firms that build simple, honest access workflows will do well. Thailand's digital economy is better served by a right that people can use in practice than by one that is easy to invoke and expensive to answer.
One caveat on sourcing: the PDPC's own site was not retrievable for this analysis. The Notification's provisions above are drawn from law-firm analyses that agree on the core terms, including the 16 July publication date, the 14 September effective date, the 30-day response period and the two-year record-keeping requirement.