Thailand Thailand PDPA digital economy

Thailand's New Data Access Rules Are Procedural Catch-Up, Not New Regulation — and That's the Right Call

PDPC's July 2026 notification finally operationalizes a data access right that existed on paper since 2019, with capped fees and clear timelines.

Thailand's New Data Access Rules, by the Numbers People of Internet Research · Thailand 30 days Response deadline Extendable once by up to 30 more d… 2 years Record retention Controllers must log every request… 1 baht/page Max photocopy fee Digital delivery is generally free… ~21.5M baht Cumulative PDPC fines Enforcement since 2024 targeted se… peopleofinternet.com
Thailand's New Data Access Rules, by t… People of Internet Research · Thailand 30 days Response deadline 2 years Record retention 1 baht/page Max photocopy fee ~21.5M baht Cumulative PDPC fines peopleofinternet.com

Key Takeaways

A Right That Existed Before the Rulebook

Thailand's Personal Data Protection Act, B.E. 2562 (2019), already gave every data subject the right to request access to, and copies of, their personal data held by a controller, with a response deadline of no more than 30 days. That right has been on the books since the Act took effect. What was missing for seven years was the operational detail: which channels count as a valid request, how identity gets verified, what a controller may charge, and how long records of the process must be retained.

The Personal Data Protection Committee (PDPC) has now closed that gap. Its Notification on rules for accessing and obtaining copies of personal data — B.E. 2569 — was published in the Royal Gazette on July 16, 2026, and takes effect September 14, 2026, sixty days after publication. It followed a public consultation that ran from mid-April to mid-May 2026, per Baker McKenzie's summary of the text.

What the Notification Actually Requires

The procedural core is modest and specific. Controllers must comply with a valid, complete request within 30 days of receipt, with one permitted extension of up to 30 additional days — typically invoked for requests involving large volumes of data — provided the requester is notified of the delay. Preliminary verification of a request must happen within seven business days, and if supporting identity documents are incomplete, the controller must give the requester at least ten days to supply them before treating the request as abandoned.

On channels, the baseline is deliberately low-tech: controllers must accept requests submitted in person or by registered mail; electronic channels are permitted and encouraged but not mandatory. Fees are capped near cost recovery — roughly 1 baht per photocopied page, 3 baht per computer-printed page, and 5 baht for a certified copy, with digital delivery generally free. Controllers must log every request, the identity documents provided, the action taken, and any refusal, and keep that record for at least two years. Refusals are permitted only on narrow grounds: legal prohibition, a court order, risk to a third party's rights (including intellectual property), or a request the PDPC considers unfounded.

The Case for Standardizing First

Regulators who wait years to operationalize a right they've already legislated deserve real scrutiny — ambiguity is not free. Every year a company had no template for handling a data access request was a year some requests were quietly slow-walked, over-refused out of caution, or handled inconsistently across departments, with no PDPC guidance to appeal to. Individuals with a real, legally granted right had no reliable way to exercise it in practice. That is the strongest case for this notification: codified procedure protects the data subject more than an unenforced statutory promise does, and it protects good-faith companies from ad hoc liability by telling them exactly what compliance looks like.

Seen that way, this is not new regulatory reach — it's regulatory maintenance, and it is calibrated sensibly. The fee schedule is trivial, not a revenue mechanism. The requirement to accept only in-person and postal requests, rather than mandating an electronic portal, is a real concession to smaller controllers who lack GDPR-scale compliance budgets — a contrast worth noting given how DSAR-processing has become its own cottage industry in the EU. And the refusal grounds, including protection of others' IP rights and a backstop against unfounded requests, prevent the access right from becoming a vector for competitive harassment or fishing expeditions.

Enforcement Context Matters Here

This notification lands against a PDPC that has shown it will actually fine companies. The regulator issued its first major administrative penalty — 7 million baht against a single company — in 2024, and on August 1, 2025, announced eight further fines across five cases totaling 14.5 million baht, pushing cumulative PDPA penalties above 21 million baht. Those cases involved weak security, missing data protection officers, and mishandled breach notifications — not access-request failures. That distinction matters: this notification does not expand the universe of things that can get a company fined. It tells companies, with unusual specificity, exactly how to discharge an obligation that already existed, which should reduce enforcement risk for anyone acting in good faith rather than increase it.

What to Watch

The residual friction is operational rather than legal. Companies with legacy or siloed IT systems will still need to build cross-database retrieval, redaction, and secure-transmission workflows to meet a firm 30-day clock, and the two-year retention requirement is a genuine new administrative line item, however small. The vaguest term in the notification — a controller's ability to refuse an "unfounded" request — will need PDPC guidance or early case decisions to avoid becoming a discretionary escape hatch. If the PDPC continues in this mode — clarifying procedure rather than layering new substantive obligations onto the 2019 Act — Thailand's PDPA regime will keep looking like a model of proportionate, workable data protection rather than a compliance trap. That is a template Thailand's own regulator, and others in the region still legislating access rights in the abstract, should keep using.

Sources & Citations

  1. PDPC Government Platform for PDPA Compliance (GPPC)
  2. Personal Data Protection Act B.E. 2562 (2019), English text
  3. Baker McKenzie: Thailand Notification on Data Subject Access Requests
  4. it24hrs: Thailand's new PDPA access-request rules
  5. Mondaq: PDPC signals tougher enforcement with multi-million baht fines