Thailand Thailand PDPA digital economy

Thailand's Access-Request Rules Give Data Subjects Real Procedure, but Postal-Channel Mandates Reward Paperwork Over Privacy

Thailand's PDPC access-request notification took effect 14 September 2026, setting 30-day deadlines and two-year records. Its channel rules risk burdening smaller firms.

Thailand's New Access Request Rules People of Internet Research · Thailand 30 Days to respond Counted from a complete, verified … +30 days Maximum extension Allowed with notice to the request… 2 years Minimum record retention Controllers must keep request reco… 60 Days from gazette to effect Published 16 July, effective 14 Se… peopleofinternet.com
Thailand's New Access Request Rules People of Internet Research · Thailand 30 Days to respond +30 days Maximum extension 2 years Minimum record retention 60 Days from gazette to effect peopleofinternet.com

Key Takeaways

Thailand's Personal Data Protection Committee (PDPC) has finally written down how the right of access is supposed to work. Its Notification on access requests was published in the Government Gazette on 16 July 2026 and took effect on 14 September 2026, 60 days later, according to Baker McKenzie's analysis. The direction is right. Some of the design choices deserve a harder look.

What changed

Section 30 of the Personal Data Protection Act B.E. 2562 (2019) already gave data subjects the right to request access to, and a copy of, their personal data, or to ask how data obtained without their consent was acquired. The statute has been available in unofficial English translation from the Ministry of Digital Economy and Society. It has been fully in force since 1 June 2022, per the IAPP. What it lacked was procedure. Baker McKenzie describes the Notification as the mechanism that fills that gap. Its main requirements are:

Baker McKenzie also lists the grounds for refusal. These include disclosure prohibited by law or court order, harm to third parties' rights, and requests that are unfounded.

The strongest case for the rules

The case for the Notification is strong. A right that has no deadline, no defined channel and no fee rule is easy to defeat in practice. A controller can ignore a request, demand an arbitrary fee, or lose the paper trail. A fixed 30-day clock, a free default and mandatory record-keeping turn an abstract right into something a citizen can invoke and a regulator can audit. A bounded extension also protects requesters from open-ended stalling. Thailand's digital economy depends on public trust in data handling, and predictable procedure builds that trust.

The timeline also compares reasonably with other regimes. A 30-day response window, extendable in complex cases, is a conventional design. It is not an outlier that would strand Thai firms in cross-border compliance.

Where proportionality is at risk

The weak point is the channel mandate. The Notification's floor is physical and postal submission, with digital channels merely welcome. That protects people without internet access. But for an online platform, a fintech or a software-as-a-service firm, the required channel is the one users are least likely to use. The Notification does not require the channel where nearly all requests will arrive. A policy that requires a mailbox and a form and does not require the online channel most requesters will actually use is aimed at procedure more than at outcomes.

The burden falls unevenly. Mondaq's summary argues the requirements strain smaller organisations without dedicated data protection staff. That is plausible. The gap analyses, tracking systems and staff training the rules imply are cheap for a bank and costly for a ten-person startup. Thailand's PDPC has previously recognised this. The IAPP notes it exempts certain small businesses, meaning SMEs under set employee or revenue thresholds, from maintaining processing records, though not for rejected data subject requests. That carve-out shows a tiered approach is workable. The access-request rules would benefit from the same logic, for instance longer response windows or lighter channel duties for micro-enterprises.

There is also a drafting risk in the refusal grounds. Law-firm summaries agree on the categories, but their wording of the standards varies. One frames it as "unfounded" requests, another as "manifestly unfounded or unreasonably burdensome", according to Hogan Lovells' summary. The details of the timing steps for incomplete requests also differ between summaries. Practitioners are working from secondary summaries, and small differences in wording matter when a controller decides whether it may refuse. The PDPC should publish plain-language guidance and worked examples. That would cost little and would prevent both over-refusal by controllers and vexatious requests.

Identity verification is a further balancing point. Verification protects the data subject, because handing personal data to an impostor is a breach in itself. But the rules should not become a barrier. Hogan Lovells reports the Notification's verification standard as one that "should not create unreasonable barriers for data subjects". Controllers should ask only for what is needed to confirm identity, and should not use verification to collect more data than they already hold.

What regulators and firms should do next

Three steps would keep the benefits and limit the costs.

A fair reading is that Thailand has done the harder part: it has made access a working right rather than a slogan. Enforcement will decide whether it stays proportionate. If the PDPC audits for response times and record-keeping, and not for the elegance of a postal form, firms that build simple, honest access workflows will do well. Thailand's digital economy is better served by a right that people can use in practice than by one that is easy to invoke and expensive to answer.

One caveat on sourcing: the PDPC's own site was not retrievable for this analysis. The Notification's provisions above are drawn from law-firm analyses that agree on the core terms, including the 16 July publication date, the 14 September effective date, the 30-day response period and the two-year record-keeping requirement.

Sources & Citations

  1. Baker McKenzie: Thailand Notification on Data Subject Access Requests
  2. MDES: Personal Data Protection Act B.E. 2562 (2019), unofficial translation
  3. MDES: Personal Data Protection Act B.E. 2562 (2019), Government Gazette translation
  4. IAPP: Key developments in Thailand's PDPA regulations
  5. Mondaq: Thailand Issues New Rules On Data Subject Access Requests
  6. Hogan Lovells: Thailand refines rules on data subject access rights