ANALYSISMEMBER

Thailand's PDPC clarifies data breach notification requirements

Published
Subscribe to IAPP Newsletters

Contributors:

Piyatida Pavasutti

AIGP, CIPP/E, CIPM, FIP

Data protection officer, life sciences

MyData-Trust

While Thailand's Personal Data Protection Act continues to shape the country's data protection landscape since it took effect in June 2022, the Personal Data Protection Committee issued clarifications on data breach reporting obligations in response to a company-led public consultation.

Referencing the PDPC's Notification on the Criteria and Procedures for Handling Personal Data Breaches, the clarifications offer essential guidance for organizations striving to meet the PDPA's breach notification requirements.

Clarifying the obligation to notify the PDPC in low-risk breaches

The PDPC clarified data controllers are exempt from notifying it of a personal data breach if the event poses no risk to the rights and freedoms of individuals.

It explained, under Section 37(4) of the PDPA and Section 5(3) of the notification, data controllers are required to notify the PDPC of a personal data breach without undue delay and, when feasible, within 72 hours of becoming aware of the breach. However, this obligation does not apply if the breach is assessed as posing no risk to the rights and freedoms of individuals. In such cases, data controllers are not required to notify the PDPC.

To justify this exemption, data controllers must conduct a risk evaluation based on the criteria specified in Section 12 of the notification. If the evaluation determines the breach has no potential to impact individuals' rights or freedoms, the obligation to report the breach is waived.

Examples include minor administrative errors — for example, a misdirected email that does not expose sensitive information. However, organizations must document these incidents and retain the related risk assessments as evidence of compliance in case of future inquiries or complaints.

Are exemption support documents restricted to PDPC requests?

Contributors:

Piyatida Pavasutti

AIGP, CIPP/E, CIPM, FIP

Data protection officer, life sciences

MyData-Trust

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership