Thailand Thailand PDPA digital economy

Thailand's PDPA Rewrite Fixes a Real Consent Problem, But Widens an Anticorruption Loophole

Thailand's PDPA rewrite fixes a real consent problem with GDPR-style lawful bases, but its widened anticorruption exemption deserves scrutiny.

Thailand's PDPA Rewrite, by the Numbers People of Internet Research · Thailand 7 New lawful processing bases Section 24 would list seven coequa… 30 days Public consultation period Thailand's draft PDPA amendment is… ~$655K PDPC fines imposed in 2025 Thailand's regulator levied roughl… peopleofinternet.com
Thailand's PDPA Rewrite, by the Number… People of Internet Research · Thailand 7 New lawful processing bases 30 days Public consultation per… ~$655K PDPC fines imposed in 2025 peopleofinternet.com

Key Takeaways

A Compliance Fix Bundled With a Loophole

On July 16, 2026, Thailand's public-hearing process opened comments on a draft bill that would rewrite the operative core of the Personal Data Protection Act B.E. 2562 (2019), the country's first comprehensive privacy statute (Central Legal System listening portal; PDPA B.E. 2562 text). Comments close August 15, 2026. The headline change restructures Section 24, which today treats consent as the law's default gatekeeper, into seven coequal lawful bases for processing personal data: archival, research and statistical use; public-task necessity; vital interests; contractual necessity; legitimate interests; legal obligation; and consent itself (Mondaq). Folded into the same bill is an expanded exemption for "prevention and suppression of corruption and misconduct," which would let the National Anti-Corruption Commission and other government bodies process personal data for anticorruption operations without the PDPA's ordinary constraints, alongside a new statutory definition of "government agency" spanning central, regional and local government, state enterprises, courts, Parliament and independent constitutional organizations.

The Case for Retiring Consent-as-Default

The strongest argument for this rewrite is one privacy regulators around the world have made before: a law that treats consent as the default basis for every processing activity produces theater, not protection. When consent is the only reliable legal basis, companies paper over legitimate, low-risk processing — fraud checks, payroll, contract fulfillment — with consent boxes that data subjects click through without reading, while the law offers no clean path for processing that plainly serves the data subject's own interest but wasn't, in the moment, consented to. Thailand's own regulator has been flagging this problem from the guidance side: on July 7, 2026, the Personal Data Protection Committee opened a parallel consultation on draft guidance explicitly warning against using "consent as a default or catch-all basis where another lawful basis is more appropriate" (Mondaq). A seven-basis structure modeled on GDPR Article 6 gives Thai businesses — and the hospitals, banks and platforms that now face real enforcement risk — a defensible route to process data for contract performance or legitimate interests without extracting hollow consent from every user. That is a genuine compliance improvement, and critics of GDPR-style frameworks elsewhere should note that Thailand is adopting the deliberative, multi-basis version of that model rather than a maximalist one.

Where the Rewrite Overreaches

The anticorruption exemption is a different animal, and it deserves to be judged on its own terms rather than waved through under the same GDPR-alignment banner. Government bodies conducting anticorruption investigations do have a real, defensible need to access financial and personal records that a rigid consent requirement would obstruct — nobody expects the NACC to get a suspect's sign-off before investigating them. But the current draft, as reported, does the opposite of narrow tailoring: it exempts an open-ended category of "prevention and suppression of corruption and misconduct" from the PDPA's constraints, without the purpose limitation, judicial authorization, or proportionality tests that most anticorruption-specific data-access regimes elsewhere pair with such exemptions. "Misconduct" in particular is elastic enough to cover far more than bribery and embezzlement. Combined with a broadened statutory definition of "government agency" that now explicitly reaches courts, Parliament and independent constitutional organizations, the exemption's practical effect is to carve a widening set of state actors out of the PDPA's core discipline at precisely the moment the law is being marketed to the public as a modernization.

This matters because the PDPC has shown, over the past year, that it is willing to use its enforcement powers against private actors: the regulator disclosed eight administrative fines across five cases in 2025 alone, totaling roughly ฿21.5 million (about $655,000), with individual penalties ranging from ฿16,940 against a hospital contractor to ฿7 million against a computer-retail company (Tilleke & Gibbins). A regime that enforces real money against private data controllers while simultaneously loosening the leash on government data processing invites an asymmetry that undercuts public trust in the law precisely when Thailand needs that trust to support a digital economy built on cross-border data flows and foreign investment.

The Right Fix Is Narrower, Not Broader

None of this argues for scrapping the bill. The seven-basis restructuring is overdue, evidence-based, and consistent with how Singapore, the EU and a growing list of Asia-Pacific jurisdictions have already moved past pure consent-first models — it should proceed on the current August 15 timeline. What the consultation record should press for is separating the two halves of this bill: keep the lawful-bases restructuring intact, and send the anticorruption exemption back with statutory guardrails — a defined scope tied to specific investigative powers, a proportionality requirement, and independent oversight of how the exemption is invoked. Thailand's PDPC has spent two years building credibility as an active, technically serious regulator. That credibility is the asset actually at stake in this consultation, and it survives a narrower anticorruption carve-out far better than it survives a broad one that only becomes visible once the next high-profile data-access controversy forces the question.

Sources & Citations

  1. Central Legal System public hearing portal
  2. Personal Data Protection Act B.E. 2562 (Dept. of Public Relations)
  3. Mondaq: Thailand Proposes Significant Amendments to the PDPA
  4. Mondaq: Thailand Releases New Draft PDPA Guidance on Lawful Bases and Marketing
  5. Tilleke & Gibbins: Eight Serious Fines Imposed in Thai Data Protection Cases