Latest News & Insights

Athentic Consulting’s team of experienced experts bring you the
latest news and insights in law and regulations.

PDPA guideline

Thailand to introduce sector-specific PDPA guidelines for 11 industries

PDPA guideline

The Office of the Personal Data Protection Committee (PDPC) has held its first public consultation on draft sector-specific personal data protection guidelines (PDPA Guidelines), under the PDPA Platform for Private Sector project, also known as the GPPC PLUS project. Athentic Consulting Co., Ltd. served as the lead in developing the guidelines across all 11 industries under the project, with a role that spanned the drafting of the content itself, covering both the general chapter providing an overview of personal data protection law and the sector-specific guidelines, through to preparing a complete suite of standard legal document templates, namely a Privacy Policy, a Privacy Notice, a Consent Form, a standard Data Processing Agreement, an Incident Report for notifying personal data breaches, and a request and response form for handling data subjects' rights requests.

The draft guidelines for the 11 target industries follow the PDPC's National Master Plan for the Promotion and Protection of Personal Data B.E. 2567 – 2570 (2024 – 2027), covering finance, investment and insurance; wholesale, retail and online commerce; tourism; information technology and telecommunications; transportation and logistics; energy and utilities; real estate; national security; essential public services; public health; and education.

Why the guidelines are drafted sector by sector

The guidelines are intended to serve as a practical compliance checklist for organisations, a reference framework for regulators, a means of promoting Privacy by Design within each industry, and a way of building confidence among data subjects. A further important reason lies in a practical problem: the difficulty organisations face in preparing Records of Processing Activities (RoPA). Maintaining such records is an obligation under the Personal Data Protection Act B.E. 2562 (2019) and is the starting point for seeing an organisation's overall use of its data, since a RoPA determines how an organisation identifies the legal basis, the retention period, the recipients of the data and the security measures applicable to each activity.

In practice today, organisations may encounter difficulties arising from an insufficient understanding of the rationale, methodology and components of a RoPA, including how to determine what constitutes a Processing Activity and how to select a legal basis that genuinely reflects the underlying purpose. The result is that the RoPA prepared often do not mirror actual operations and are incomplete.

Drafting the guidelines by industry is therefore intended to provide a template that allows organisations to adapt the Processing Activities identified for their own sector and build their RoPA without starting from scratch. Processing Activities differ significantly from one industry to another, and the guidelines can serve as an initial reference to be read together with sector-specific legislation and the requirements of the relevant sector regulators.


Key issues by sector

The guidelines are divided into three main parts, the details of which differ by industry:

  • Description and nature of the business
  • A table of Processing Activities and the relevant legal bases
  • The relevant approach to personal data protection

Finance, investment and insurance

  • Disclosure of policy information to related parties. A single insurance policy may involve several individuals, namely the policyholder, the beneficiary, a legal guardian or an agent. However, being connected to a policy does not automatically confer a right of access to all information relating to it. Organisations should verify the identity and authority of the person making the request before disclosing anything, particularly where contact is made by telephone.
  • Artificial intelligence and sensitive personal data. Organisations using AI to assess risk or analyse customer behaviour should ensure transparency and maintain human review where the outcome may significantly affect the customer. The same care applies to the processing of health data, digital identity verification, and cross-border transfers of personal data.

Wholesale, retail and online commerce

  • Marketing and customer communications. The question most frequently raised by businesses is which activities may rely on legitimate interests and which require consent, particularly in the case of direct marketing and telesales.
  • Data combined from multiple channels. Businesses integrating physical stores with online channels should review the scope of their stated purposes and the necessity of each data element, including sensitive data collected incidentally, such as food allergy information arising from customer service, which may require explicit consent where no other legal basis applies.

Tourism

  • Sensitive data of customers. Hotels, tour operators and wellness establishments should collect health information, religious beliefs or dietary restrictions only to the extent necessary, and should consider allowing customers to select their preferences directly rather than requiring the underlying reason.
  • Personalised services and minors. Analysing travel behaviour in order to personalise services should be assessed for its risk to the rights of data subjects, while clear rules on consent are needed where minors travel with their parents or guardians.

Information technology and telecommunications

  • The role of cloud service providers. One of the points on which the industry most sought clarity is when a provider acts as a data processor and when it becomes a data controller, since this distinction bears directly on contractual terms and liability.
  • Data collected through digital channels. Cookies, chatbots and network usage data may reveal user behaviour in considerable detail, and should be accompanied by clear notices, restricted access and appropriate retention periods.

Transportation and logistics

  • Digital platforms and location data. Ride-hailing through digital platforms results in the continuous processing of passenger and driver data, which calls for clearly defined access controls and retention periods.
  • AI and biometric data. Using automated systems to screen drivers' criminal records is a high-risk activity, while the use of fingerprints or facial recognition to record working hours will, as a general rule, require explicit consent and should be accompanied by an alternative method for employees.

Energy and utilities

  • Biometrics and CCTV. Collecting biometric data to control access to restricted areas requires a legal basis under Section 26, while disclosure of CCTV footage to third parties should follow a defined process for assessing requests and recording each disclosure.
  • Background checks in recruitment. There has been extensive discussion as to whether simply recording that a candidate does or does not have a criminal record amounts to sensitive personal data. A record stating that "no criminal record was found", where it is not linked to information about criminal proceedings, presents a lower risk to the data subject, although the necessity of retaining it should still be assessed case by case.

Real estate

  • Biometric systems and CCTV in condominiums. Using facial or fingerprint recognition to control building access is a high-risk activity, as are requests by residents or third parties to view recorded footage, which should be subject to a process for verifying entitlement and supporting documentation.
  • Oversight of counterparties. Real estate businesses engage numerous contractors and service providers with access to resident data, and their policies and contractual terms should therefore extend to sub-contractors, as well as to cases where authority is delegated through government digital platforms.

National security

  • The scope of the Section 4 exemption. The central point is that not every national security function is exempt from the PDPA, so agencies must classify their activities clearly.
  • Obligations that survive the exemption. Agencies remain required to maintain minimum security standards under the 2023 PDPC notification, including in relation to the recording of members of the public through officers' body-worn cameras and the transfer of data between agencies.

Essential public services

  • Disclosure and data sharing between agencies. Where both agencies act as data controllers, risk arises if the scope and respective responsibilities are not defined in advance. Agencies should verify whether the purposes originally notified to data subjects extend to the transfer in question.
  • Data arising in administrative and academic processes, such as appeals against administrative orders or the processing of employee benefits, where supporting documents often contain more information than is necessary, as well as the use of data for research and academic services.

Public health

  • Digital health services and artificial intelligence. Electronic medical records, health-tracking applications and the use of AI to assist in analysing patient symptoms all require data governance and transparent notices, as does the transfer of patient information between hospitals, clinics and laboratories.
  • Outsourcing and research. Healthcare providers engaging medical record system vendors or document processing contractors should put data processing agreements in place and align their measures with the relevant Ministry of Public Health notification, while the use of sensitive data for research and statistical purposes must be supported by appropriate security measures.

Education

  • Processing children's data is the central issue for the education sector, covering the choice of legal basis, obtaining consent from those with parental authority, and the limits on disclosing information about learners.
  • Biometric systems and learning analytics. Facial scanning of students and large-scale analysis of learning behaviour fall within the activities for which a Data Protection Impact Assessment (DPIA) should be carried out before deployment. Sensitive data and information on learners' special needs should be collected only as necessary, with separate consent forms for each category.

What organisations should do next

The draft guidelines are being revised in light of the comments received, before being submitted to the relevant sub-committee, the Committee overseeing the Office, and the Personal Data Protection Committee in turn. The period before they take effect is a suitable moment for organisations to review their readiness, and in particular to align their RoPA and legal bases with the activities identified in the guidelines for their sector, to identify high-risk activities warranting a DPIA, and to review contracts with external service providers that have access to personal data.

Surasit Kwiansoongnern
Legal Technology Counselor
Palita Rungravee
Lead - Legal Technology Counselor
About ATHENTIC News & Insights Our Services Contact us Career