In an era where data has become a primary driver of the economy, technological infrastructure has become the backbone of operations across every sector. Whether it is scanning to pay through PromptPay, backing up photos to the cloud, or artificial intelligence (AI) processing information in a split second, all of these depend on Data Centers, which handle streaming, data backup, processing, and signal distribution around the clock. Digital transformation has caused both the public and private sectors in Thailand to rely significantly on Data Center providers, both domestic and international.
From an information technology standpoint, a Data Center refers to a facility, location, or room used to house computer servers and various network systems in order to centralize the storage, collection, and management of information technology equipment such as servers, storage systems, and network devices in one organized place. This supports the processing and delivery of large volumes of data to various systems or applications. A Data Center functions as a central hub for storing data, processing information, and distributing digital data so that users can access and share it efficiently from a central location.
However, when the data stored or processed in a Data Center qualifies as "personal data" under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), the technological relationship immediately becomes a legal relationship as well. The main challenge lies in determining the legal status of the Data Center provider: whether it functions merely as a storage provider, as a data processor, or whether it carries additional duties and liabilities under the law.
Under personal data protection law, a Data Controller means a person or juristic entity that determines the purposes and methods of processing personal data, such as a company using employee personal data it has collected to process payroll. A Data Processor means a person or juristic entity that processes data according to the instructions of the Data Controller, without authority to decide the purposes of using the data, such as an outsourced payroll company that must calculate and disburse employee salaries based on the data and instructions sent by the hiring company.
From these examples, it becomes clear that determining the correct status does not depend solely on the labels agreed upon in a document, but is instead determined by who, in practice, actually holds authority over the processing of the data. Applying this to the context of Data Centers makes the picture even clearer.
Generally, when an organization (the Data Controller) hires a Data Center provider (the Data Processor) to host its database, the provider's role is limited to facilitating the infrastructure according to instructions, without any right to use the data for other purposes on its own.
Therefore, when we define the hiring organization as the Data Controller and it places data in the care of a hired provider that holds the status of Data Processor, the hiring organization, in its capacity as Data Controller, has three legal duties as follows.
Even when an organization moves its data to a Data Center, legal responsibility still remains with the organization. Under Section 40 of the PDPA, the Data Controller must arrange for an agreement or contract, commonly called a Data Processing Agreement (DPA), to govern the Data Center's processing of data so that it acts only according to the instructions given to it.
At minimum, a DPA prepared under the requirements of the PDPA must address the following essential matters:
In addition, the DPA serves as a legal safeguard demonstrating the organization's due care, and it also serves as important evidence for pursuing claims for damages if a data breach occurs on the Data Center's side.
Throughout the delivery of data and the entire data processing cycle, Section 37(1) and Section 40(2) of the PDPA, together with Clause 6 of the Notification of the Personal Data Protection Committee on Security Measures for Data Controllers B.E. 2565 (2022), do not treat this as the duty of only one party. Rather, both the Data Controller and the Data Processor share the legal duty to arrange appropriate security measures. The Data Controller must specify in the agreement that the Processor maintain measures equivalent to the minimum security standard, in order to preserve the confidentiality, integrity, and availability of the organization's personal data. These measures must cover three main dimensions:
2.1 Organizational Measures: such as establishing policies and practices for personal data protection, defining roles and access rights based on the need to know and least privilege principles, entering into confidentiality agreements with personnel, conducting awareness training, and preparing a data breach response plan.
2.2 Technical Measures: such as data encryption and cybersecurity systems to prevent hacking or interception of data during storage and transmission.
2.3 Physical Measures: such as access control systems for server rooms to prevent loss, unauthorized access, alteration, correction, or disclosure of data, in order to keep unauthorized individuals from reaching the servers.
These measures should be reviewed and improved according to the organization's policy, whenever necessary, when there is a change in technology, or immediately upon the occurrence of a personal data breach.
When an organization decides to store or process data at a Data Center or cloud service whose main or backup servers are located abroad, the law does not treat this in every case as a cross border transfer of data. This is because, under the Notification of the Personal Data Protection Committee on Criteria for the Protection of Personal Data Sent or Transferred Abroad B.E. 2566 (2023), if the service is limited to data storage or data transit, and no person other than the Data Controller and the Data Processor is able to access the personal data (for example, the organization encrypts the data using robust techniques and alone holds the encryption key, such that the cloud provider or any third party cannot decrypt or view the content), such an arrangement will not be considered a sending or transfer of personal data abroad under Section 28.
However, if the overseas Data Center or cloud provider, or any third party, has the right or ability to access the content of the personal data, such an arrangement will be treated as a transfer of data abroad. In that case, the Data Controller has a duty to assess whether the destination country maintains an adequate standard of personal data protection, or to put in place appropriate protective measures, such as entering into a contract based on Standard Contractual Clauses (SCCs), to ensure that the personal data continues to receive protection consistent with legal standards. If the destination country does not have an adequate standard and no appropriate protective measures are in place, the transfer of data may proceed only if it falls within a legal exception under Section 28, such as:
In theory, many organizations put measures in place to oversee Data Center providers through three key mechanisms: executing a DPA, arranging security measures, and overseeing cross border data transfers. In practice, however, enforcing all three mechanisms still involves unexpected challenges and gaps. Many organizations believe that storing data in a Data Center located within Thailand is the best answer for security. In reality, however, physical location is only one dimension of the issue, because in the digital world, hidden risks can still arise even when the data an organization has stored has never left the country and has never been transferred across any border. The first risk is remote access by individuals located abroad, and the next risk is the nationality obligations of the provider, which may cause a Data Center in Thailand to become subject to enforcement under foreign law, potentially conflicting with Thai law. This can be explained through the following points.
People commonly hold a mistaken belief that choosing a Data Center located in Thailand (a local Data Center) means the data will remain stored within the Kingdom and can never raise the issue of cross border data transfer. In reality, however, important information systems, such as core banking systems, even when their servers are located in Thailand, are often managed under a follow the sun model, which relies on IT support teams from abroad accessing the systems remotely to resolve issues around the clock.
Legally, the essential principle under Section 28 of the PDPA and international guidance (such as EDPB Guidelines 05/2021, Example 8.1) focuses primarily on the granting of access to data rather than the physical location of the server. Therefore, allowing a person abroad to access personal data remotely, even without downloading any file, may still raise issues concerning processing and cross border data transfer. This must be considered together with the status of the person accessing the data and the nature of that access.
1.1 Key considerations depend on the legal status of the person accessing the data:
A policy level challenge arises when a Data Center is located in Thailand but operates as a branch or subsidiary of a company not registered as a juristic entity in Thailand, such as a provider subject to the jurisdiction of the United States, which may fall under U.S. law such as the U.S. CLOUD Act (2018).
From the example above, it can be seen that a Data Center provider may find itself in a difficult position, forced to choose between following the orders of the government of the country where the company is based, or violating Thailand's PDPA as the country where the data is located. This requires finding practical approaches and technical measures to mitigate this legal risk.
Based on the case studies and legal challenges discussed above, the following practical guidelines can be summarized for organizations selecting and managing a Data Center in compliance with the PDPA:
Selecting and managing a Data Center in the current era should not focus solely on the physical location of the server cabinet. It is necessary to consider the matter comprehensively, including the type of system, the rights to access data, and the legal structure of the provider, so that the use of the Data Center complies with the PDPA. Organizations should assess and manage risk across multiple dimensions at the same time, whether it is the conditions surrounding remote access by overseas teams that may amount to a cross border data transfer, preparing an approach to deal with foreign laws that may affect the privacy of data, or applying advanced technical measures such as data encryption to limit access rights. Taking these steps not only helps an organization comply with the law correctly, but also plays a key role in protecting the rights and freedoms of data subjects effectively and sustainably, while raising the organization's overall standard of privacy protection.