A Right That Existed Before the Rulebook
Thailand's Personal Data Protection Act, B.E. 2562 (2019), already gave every data subject the right to request access to, and copies of, their personal data held by a controller, with a response deadline of no more than 30 days. That right has been on the books since the Act took effect. What was missing for seven years was the operational detail: which channels count as a valid request, how identity gets verified, what a controller may charge, and how long records of the process must be retained.
The Personal Data Protection Committee (PDPC) has now closed that gap. Its Notification on rules for accessing and obtaining copies of personal data — B.E. 2569 — was published in the Royal Gazette on July 16, 2026, and takes effect September 14, 2026, sixty days after publication. It followed a public consultation that ran from mid-April to mid-May 2026, per Baker McKenzie's summary of the text.
What the Notification Actually Requires
The procedural core is modest and specific. Controllers must comply with a valid, complete request within 30 days of receipt, with one permitted extension of up to 30 additional days — typically invoked for requests involving large volumes of data — provided the requester is notified of the delay. Preliminary verification of a request must happen within seven business days, and if supporting identity documents are incomplete, the controller must give the requester at least ten days to supply them before treating the request as abandoned.
On channels, the baseline is deliberately low-tech: controllers must accept requests submitted in person or by registered mail; electronic channels are permitted and encouraged but not mandatory. Fees are capped near cost recovery — roughly 1 baht per photocopied page, 3 baht per computer-printed page, and 5 baht for a certified copy, with digital delivery generally free. Controllers must log every request, the identity documents provided, the action taken, and any refusal, and keep that record for at least two years. Refusals are permitted only on narrow grounds: legal prohibition, a court order, risk to a third party's rights (including intellectual property), or a request the PDPC considers unfounded.
The Case for Standardizing First
Regulators who wait years to operationalize a right they've already legislated deserve real scrutiny — ambiguity is not free. Every year a company had no template for handling a data access request was a year some requests were quietly slow-walked, over-refused out of caution, or handled inconsistently across departments, with no PDPC guidance to appeal to. Individuals with a real, legally granted right had no reliable way to exercise it in practice. That is the strongest case for this notification: codified procedure protects the data subject more than an unenforced statutory promise does, and it protects good-faith companies from ad hoc liability by telling them exactly what compliance looks like.
Seen that way, this is not new regulatory reach — it's regulatory maintenance, and it is calibrated sensibly. The fee schedule is trivial, not a revenue mechanism. The requirement to accept only in-person and postal requests, rather than mandating an electronic portal, is a real concession to smaller controllers who lack GDPR-scale compliance budgets — a contrast worth noting given how DSAR-processing has become its own cottage industry in the EU. And the refusal grounds, including protection of others' IP rights and a backstop against unfounded requests, prevent the access right from becoming a vector for competitive harassment or fishing expeditions.
Enforcement Context Matters Here
This notification lands against a PDPC that has shown it will actually fine companies. The regulator issued its first major administrative penalty — 7 million baht against a single company — in 2024, and on August 1, 2025, announced eight further fines across five cases totaling 14.5 million baht, pushing cumulative PDPA penalties above 21 million baht. Those cases involved weak security, missing data protection officers, and mishandled breach notifications — not access-request failures. That distinction matters: this notification does not expand the universe of things that can get a company fined. It tells companies, with unusual specificity, exactly how to discharge an obligation that already existed, which should reduce enforcement risk for anyone acting in good faith rather than increase it.
What to Watch
The residual friction is operational rather than legal. Companies with legacy or siloed IT systems will still need to build cross-database retrieval, redaction, and secure-transmission workflows to meet a firm 30-day clock, and the two-year retention requirement is a genuine new administrative line item, however small. The vaguest term in the notification — a controller's ability to refuse an "unfounded" request — will need PDPC guidance or early case decisions to avoid becoming a discretionary escape hatch. If the PDPC continues in this mode — clarifying procedure rather than layering new substantive obligations onto the 2019 Act — Thailand's PDPA regime will keep looking like a model of proportionate, workable data protection rather than a compliance trap. That is a template Thailand's own regulator, and others in the region still legislating access rights in the abstract, should keep using.