Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

Thailand · PDPA

Processing records & 72-hour breach notice.

Applies to: Controllers/processors under Thai PDPA. Built · fully effective 1 Jun 2022

What the signed record shows

Records of processing, processor signals, and breach detail for PDPC notification.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: PDPA B.E. 2562 s.37/39/40

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Personal Data Protection Act B.E. 2562 (2019) (Thailand PDPA), published in the Government Gazette 27 May 2019. Provisions addressed:

s. 37
Duties of the data controller: appropriate security measures; and notification of a data breach to the Office (PDPC) without delay and where feasible within 72 hours, plus affected data subjects where high risk.
s. 39
Record of processing activities (ROPA) maintained by the data controller.
s. 40
Duties of the data processor: process per controller instruction; provide security measures; maintain records of processing activities. Main operative chapters (incl. ss. 37-40) became fully effective 1 June 2022. Note: the authoritative text is the Thai-language Gazette; English is reference.

Taken from the Regulayer entry for this instrument, which is built against the primary text.