What Thailand's PDPA expects from your website: privacy notice, cookie consent, forms, security and breach plans — in plain English.
Most business owners think of data protection as something for banks and hospitals. Then they look at their own website: a contact form collecting names and phone numbers, a booking system storing addresses, Google Analytics tracking visitors, a Facebook pixel, a newsletter sign-up. Every one of those collects personal data — and in Thailand, that means the PDPA applies.
This guide explains what Thailand's Personal Data Protection Act means for an ordinary business website, and gives you a checklist you can work through. It's written in plain language, not legalese.
This article is general information, not legal advice. For your specific situation — especially if you handle health, financial or children's data — speak to a qualified Thai lawyer.
What is the PDPA?
The Personal Data Protection Act B.E. 2562 (2019) is Thailand's main data protection law. Its key sections came fully into force on 1 June 2022, after two postponements. It's enforced by the Personal Data Protection Committee (PDPC), and it borrows many ideas from Europe's GDPR: businesses need a lawful reason to collect personal data, must tell people what they do with it, keep it secure, and respect people's rights over their information.
Does it apply to my small business?
Almost certainly, yes. The PDPA applies to any organisation that collects, uses or discloses personal data of people in Thailand — there's no minimum company size. "Personal data" means any information that can identify a person directly or indirectly: names, phone numbers, email addresses, LINE IDs, addresses, photos, ID card numbers, and often IP addresses and cookie identifiers.
Some data is sensitive and needs extra care and explicit consent: health information, religion, biometric data (like fingerprints or face scans), criminal records, ethnicity, political opinions and sexual behaviour, among others. Clinics, gyms, spas and HR platforms deal with this regularly.
What your website collects (more than you think)
Each of these is a place your website collects personal data — and needs a clear purpose and notice.
What the PDPA expects from your website
1. A clear privacy notice
You must tell people, at or before the time you collect their data, what you collect, why, how long you keep it, who you share it with, and how they can exercise their rights. On a website this is usually a Privacy Policy page, linked in your footer and next to every form.
Write it for humans: which forms collect what, which tools you use (e.g. Google Analytics, Meta Pixel, LINE), whether data leaves Thailand (most cloud services store data abroad), and how to contact you. Copying a template from another company's site is a common mistake — it describes their data, not yours.
2. A lawful basis for each use
Consent is only one of several legal bases. Many everyday uses don't need a consent checkbox at all:
- Contract: using someone's address to deliver the order they placed.
- Legitimate interest: basic security logs, or replying to an enquiry someone sent you.
- Legal obligation: keeping tax invoices for the period the law requires.
- Consent: marketing emails or LINE broadcasts, most advertising and analytics cookies, and sensitive data.
Where you rely on consent, it must be freely given, specific and clear — not a pre-ticked box, and not bundled as a condition for something unrelated. People must be able to withdraw it as easily as they gave it.
3. Cookie consent that actually works
Cookies that are strictly necessary for your site to function (keeping someone logged in, remembering a shopping cart) generally don't need consent. Cookies for analytics, advertising and tracking — including Google Analytics and Facebook/Meta pixels — are generally treated as needing consent, in line with the PDPA's consent rules and the PDPC's guidance.
- Show a clear banner on the first visit with Accept and Reject options given equal prominence.
- Don't load analytics or ad scripts until the visitor has accepted them.
- Let people change their mind later (a "Cookie settings" link in the footer).
- Keep a record of consent choices.
The most common failure we see: a cookie banner that looks compliant, while Google Analytics and the Meta pixel load before anyone clicks anything. The banner has to actually control the scripts.
4. Forms that collect only what you need
Data minimisation is one of the easiest wins. A contact form needs a name and a way to reply — not a national ID number, date of birth and home address. Every extra field is extra risk, extra responsibility and, frankly, fewer people completing the form.
- Mark optional fields as optional.
- Link to the privacy notice right next to the submit button.
- Use a separate, unticked checkbox if you want to add people to marketing.
5. Security
The PDPA requires appropriate security measures. For a website, the basics are non-negotiable:
- HTTPS everywhere (the padlock in the address bar).
- Keep the CMS, plugins and server software updated — outdated WordPress plugins are a leading cause of small-business hacks.
- Strong, unique passwords and two-factor login for everyone with admin access; remove ex-staff promptly.
- Don't email form submissions containing sensitive data around in plain text; store them in a secure system with limited access.
- Regular backups, stored separately from the website.
6. Respect people's rights
People can ask to access, correct or delete their data, object to certain uses, withdraw consent, and receive their data in a portable format. Put a clear contact (email or form) in your privacy notice, and have a simple internal process for handling requests — generally within 30 days.
7. Have a plan for data breaches
If personal data is leaked or hacked, the PDPA generally requires you to notify the PDPC within 72 hours of becoming aware of it (unless the breach is unlikely to pose a risk), and to inform affected people when the risk is high. Know in advance who your web developer, host and lawyer are, and how to reach them quickly.
What happens if you ignore it?
The PDPA includes administrative fines of up to THB 5 million, criminal penalties (including imprisonment of up to one year and fines of up to THB 1 million for certain offences involving sensitive data), and civil liability where courts can award compensation plus punitive damages of up to twice the actual damage. Enforcement started gently, but the PDPC has issued its first fines, and customers increasingly notice how businesses treat their data.
For most small businesses, the bigger risk isn't a fine — it's a hack, a leaked customer list, or a customer complaint that damages trust. The good news is that doing the basics well is mostly about good website practice.
Work through this list with your web developer. Most items are one-time setup.
How we handle it
Every site we build uses HTTPS, collects only the fields a form actually needs, links the privacy notice beside each form, and can load analytics and ad scripts only after consent. Our own contact form, for example, asks for a name, email and a message, with phone and company optional. If you're not sure where your current site stands, send us the link and we'll point out the gaps. You might also find what pages a business website should have useful.
Frequently asked questions
Does my website need a cookie banner in Thailand?
If your site uses cookies or similar tracking for analytics or advertising — for example Google Analytics or a Meta pixel — you should generally get consent before loading them, which in practice means a cookie banner with real accept and reject choices. Sites that only use strictly necessary cookies may not need one.
Can I copy a privacy policy from another website?
You can use a template as a starting point, but your notice must describe what your business actually collects, why, which tools and partners receive it, and how long you keep it. A copied policy that doesn't match your practices doesn't meet the requirement.
Does the PDPA apply to foreign customers?
It applies to personal data of people in Thailand, and to overseas businesses that offer goods or services to people in Thailand or monitor their behaviour. If you also serve customers in Europe, the GDPR may apply as well.
Do I need a Data Protection Officer (DPO)?
Only in certain cases — for example if your core activities involve large-scale regular monitoring of people or large-scale processing of sensitive data. Most small businesses don't need a formal DPO, but someone should still be responsible for data protection.