Database

Browse Database

THAILAND

Since May 2019, entry into force in June 2022

Pillar Domestic data policies  |  Indicator Framework for data protection
Personal Data Protection Act, B.E. 2562 (2019) (พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. ๒๕๖๒)
The Personal Data Protection Act provides a comprehensive regime of data protection in Thailand.
Coverage Horizontal

THAILAND

Since August 2006

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Notification of the National Telecommunications Commission regarding Telecommunications Service Users' Rights Concerning Personal Information Rights to Privacy and Freedom of Communication, 2006 (ประกาศ กทช. เรื่อง มาตรการคุ้มครองสิทธิของผู้ใช้บริการโทรคมนาคมเกี่ยวกับข้อมูลส่วนบุคคล สิทธิในความเป็นส่วนตัว และเสรีภาพในการสื่อสารถึงกันโดยทางโทรคมนาคม)
The Notification on Telecommunications Service Users' Rights 2006, issued by the National Telecommunications Commission (NTC), states that licensed telecommunications service providers must retain their users' data for the last three months after the service is terminated (Clause 8). The personal data of telecommunication users includes factual information that can identify the individual user, usage details, subscriber number and behavioural activity in the use of telecommunication services. In case of necessity, the service provider may be required to extend the period of data retention but will not exceed two years.
Coverage Telecommunications sector

THAILAND

Since June 2007, last amended in January 2017
Since August 2007

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Commission of Computer-Related Offences Act, 2007 (พรบ. ว่าด้วยการกระทำความผิดทางคอมพิวเตอร์ พ.ศ. 2550)

Notification of the Ministry of Information and Communications Technology regarding Computer Traffic Data Retention Criterias of Service Providers, 2007 (ประกาศกระทรวงเทคโนโลยีสารสนเทศและการสื่อสาร เรื่อง หลักเกณฑ์การเก็บรักษาข้อมูลจราจรทางคอมพิวเตอร์ของผู้ให้บริการ พ.ศ. 2550)
Section 26 of the Commission of Computer-Related Offences Act 2007 (so-called Computer Crimes Act 2007) (amended 2017) defines 'computer traffic data' as data in relation to the communication of computer system or the origin, time, duration, type of service, or else related to the computer system. The Act requires a service provider to retain computer traffic data for not less than 90 days from the date when the data was entered into the computer system. If necessary, the competent official may order any service provider to retain computer traffic data for a period exceeding 90 days but not exceeding 2 years as a matter of an individually exceptional case and on an ad hoc basis. Also, the service provider shall maintain client data, which is necessary for identifying the client since their first use of service and shall keep such data for not less than 90 days from the ending date of service. Those who fail to comply with this measure shall be liable to a fine not exceeding 500,000 Thai Baht (approx. USD 14,000).
The Notification on Computer Traffic Data Retention Criteria for Service Providers in 2007 provides detailed information regarding this matter. For example, the computer traffic data must be maintained under secured measures using a centralised log server, data archiving, or data hashing (Clause 8). Moreover, the service providers - telecommunication and broadcast carriers, access service providers, host service providers, and content service providers - need to retain the information as the law requires (Clause 5).
Coverage Telecommunication and broadcast carriers, access service providers, host service providers, and content service providers

THAILAND

Since May 2019, entry into force in June 2022

Pillar Domestic data policies  |  Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Personal Data Protection Act, B.E. 2562 (2019) (พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. ๒๕๖๒)
The appointment of a Data Protection Officer (DPO) is a mandatory condition under the Personal Data Protection Act (PDPA). Section 41 of the Act specifies that the data controller and data processor shall designate a DPO in the following circumstances: the activities such as collection, use, or disclosure of personal data.
The DPO's duties include advising the data controller and data processor, investigating the performance of the data controller and data processor, coordinating and cooperating with the Office of the Personal Data Protection Committee (PDPC) when there are problems and keeping confidentiality of the personal data (Section 42).
Coverage Horizontal

THAILAND

Since May 2019

Pillar Domestic data policies  |  Indicator Requirement to allow the government to access personal data collected
Cyber Security Act B.E. 2562 (พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์ พ.ศ. ๒๕๖๒)
Section 64 of the Cyber Security Maintenance Act (CSA) 2019 states that, if it is necessary for the prevention, handling, and reduction of cyber threat risks, the Cyber Security Supervisory Committee (CSSC) shall order State agencies to provide information in their possession and related to cybersecurity maintenance.
Also, in Section 66, the CSSC has the power to carry out or order competent officials to carry out operations, only to the extent necessary for preventing cyber threats, in the following matters:
- to enter a place for inspection upon written notification;
- to gain access, copying or filtering computer data, computer systems or other related data;
- to test the functionality of computers or computer systems;
- to seize or attach, only to the extent necessary, computers, computer systems, or equipment, not exceeding 30 days.
To carry out activities under (2), (3), (4), the CSSC must file a motion to the competent court. However, in case of emergency and the threat is critical to cybersecurity, the Secretary-General shall take immediate action to the extent necessary for preventing and remedying damage in advance without filing a motion with the Court (Section 68).
Coverage Horizontal

THAILAND

Since June 2007, as amended in January 2017

Pillar Domestic data policies  |  Indicator Requirement to allow the government to access personal data collected
Computer-Related Crime Act B.E. 2550 (พรบ. ว่าด้วยการกระทำความผิดทางคอมพิวเตอร์ พ.ศ. 2550)
Section 18 of the Computer-Related Crime Act allows the government to access user-related or traffic data without a court order and compel ISPs to decode programmed data.
Coverage Horizontal

THAILAND

Reported in 2017, last reported in 2024

Pillar Telecom infrastructure & competition  |  Indicator Passive infrastructure sharing obligation
Requirement of passive infrastructure sharing
It is reported that passive infrastructure sharing in Thailand to deliver telecom services to end users is mandated.
Coverage Telecommunications sector

THAILAND

Since November 1999
Since November 2001, last amended in January 2006

Pillar Telecom infrastructure & competition  |  Indicator Maximum foreign equity share for investment in the telecommunication sector
Foreign Business Act, B.E. 2542 (1999) (พระราชบัญญัติการประกอบธุรกิจของคน. ต างด าว พ.ศ. ๒๕๔๒)

Telecommunications Business Act, 2001 (พรบ. การประกอบกิจการโทรคมนาคม พ.ศ. 2544)
The Foreign Business Act (FBA) 1999 governs foreign investment in Thailand. Section 4 of the Act defines a "foreigner" as a company in which at least half of the capital or shares are held by foreigners, or a limited partnership or registered ordinary partnership with foreigners as the managing partner or manager.
According to Section 8 of the Telecommunications Business Act 2001, Type 2 licenses (telecommunications operators providing services to a specific group of customers, with or without operating their own telecommunications network) and Type 3 licenses (telecommunications operators providing their own telecommunications network for public use) cannot be granted to foreign applicants. As a result, foreign ownership in these sectors is capped at 49%.
Coverage Telecommunications sector

THAILAND

Last reported in 2026

Pillar Telecom infrastructure & competition  |  Indicator Presence of shares owned by the government in telecom companies
Presence of shares owned by the government in the telecom sector
The government maintains shareholdings in the National Telecom Public Company Limited, which was established on 7 January 2021 and provides a full range of domestic and international telecommunication services, holds the status of a state enterprise, with the Ministry of Finance fully owning its registered capital.
Coverage Telecommunications sector

THAILAND

N/A

Pillar Telecom infrastructure & competition  |  Indicator Functional/accounting separation for operators with significant market power
Lack of mandatory functional separation for dominant network operators
Thailand does not mandate functional separation for operators with significant market power (SMP) in the telecom market. However, accounting separation is mandated.
Coverage Telecommunications sector

THAILAND

N/A

Pillar Telecom infrastructure & competition  |  Indicator Signature of the WTO Telecom Reference Paper
Lack of appendment of WTO Telecom Reference Paper to schedule of commitments
Thailand has not appended the World Trade Organization (WTO) Telecom Reference Paper to its schedule of commitments.
Coverage Telecommunications sector

THAILAND

Since December 2010

Pillar Telecom infrastructure & competition  |  Indicator Presence of an independent telecom authority
Act on the Organisation to Assign Radio Frequency and to Regulate the Broadcasting and Telecommunications Services B.E. 2553 (พระราชบัญญัติ องค์กรจัดสรรคลื่นความถี่และกำกับการประกอบกิจการวิทยุกระจายเสียง วิทยุโทรทัศน์ และกิจการโทรคมนาคม พ.ศ. 2553)
According to the Act on the Organisation to Assign Radio Frequency and to Regulate the Broadcasting and Telecommunications Services B.E. 2553, the executive authority for the supervision and administration of services in the telecommunications sector in Thailand is the National Broadcasting and Telecommunications Commission. It is reported that the National Broadcasting and Telecommunications Commission is independent from the government in the decision-making process.
Coverage Telecommunications sector

THAILAND

Since November 2002

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Credit Information Business Operation Act BE 2545 (2002) (พระราชบัญญัติการประกอบธุรกิจข้อมูลเครดิต พ.ศ. 2545)
The Credit Information Business Act 2002 specifically covers the collection and processing of credit information. Section 9 states that only a credit information company has the right to operate the credit information business. Section 12 of the Act states that "No credit information company or information controller or information processor carrying on or operating the business in the Kingdom shall operate, control or process information outside the Kingdom."
Coverage Credit information companies

THAILAND

Since November 1999

Pillar Foreign Direct Investment (FDI) in sectors relevant to digital trade  |  Indicator Screening of investment and acquisitions
Foreign Business Act, B.E. 2542 (1999) (พระราชบัญญัติการประกอบธุรกิจของคน. ต างด าว พ.ศ. ๒๕๔๒)
Pursuant to Art. 14 of the Foreign Business Act, any initial foreign investment is subject to a minimum capital requirement of THB 2 million (approx. USD 56.000). In the case of restricted businesses (including advertising), the requirement is equivalent to 25% of the total three-year average expected annual expenditure but not less than THB 3 million (approx. USD 84.000).
Coverage Horizontal

THAILAND

Since March 1979 as amended in March 1999
Since September 1999

Pillar Intellectual Property Rights (IPRs)  |  Indicator Practical or legal restrictions related to the application process for patents
Patent Act, 1979 (พระราชบัญญัติสิทธิบัตร พ.ศ. ๒๕๒๒)

Ministerial Regulation No. 21 (1999) Issued Under the Patent Act B.E. 2522 on the Criteria for Applying for Patents (กฎกระทรวง ฉบับที่ 21 (พ.ศ. 2542) ออกตามความในพระราชบัญญัติสิทธิบัตร พ.ศ. 2522 ว่าด้วยหลักเกณฑ์การขอรับสิทธิบัตร)
Section 14 of the Patent Act 1979 (amended in 1999) stipulates that an applicant for a patent must possess one of the following qualifications: (i) be a Thai national or a juristic person with its headquarters located in Thailand; (ii) be a national of a country that is a party to a convention or international agreement on patent protection to which Thailand is also a party; (iii) be a national of a country that permits Thai nationals or juristic persons with headquarters in Thailand to apply for patents in that country; or (iv) be domiciled in, or have an industrial or commercial establishment in, Thailand or a country that is a party to a convention or international agreement on patent protection to which Thailand is also a party.
To file patents, the Ministerial Regulation No. 21 states that if the patent applicant does not reside in the Kingdom of Thailand, the applicant shall authorise an agent or patent attorney registered with the Director-General of the Department of Intellectual Property to act on his behalf (Clause 13). Moreover, the Power of Attorney (POA) shall be attached with the revenue stamp of 30 Thai Baht (around 1 USD) for each patent agent/patent attorney/application. The POA document, if not in a foreign language, must be translated into Thai (Clause 15).
Coverage Horizontal

Report issue     Report new measure