Wrixte
Wrixte
  • Home
  • Company
    • About
    • Career
    • Blog
  • Products
    • Wrixte SIEM
    • Wrixte SOAR
    • Wrixte Case & Incident Management
    • Wrixte Threat Analytics Engine
    • Wrixte Network Analytics Engine
    • Wrixte Malware Analytics Engine
    • Wrixte Cyber Threat Intelligence
    • Wrixte aiPentest Platform
  • Solutions
    • Log Management & Analytics
    • Endpoint Detection & Response
    • Network Detection & Response
    • Cloud Detection & Response
    • Container Security Monitoring
    • Attack Surface Management
    • Distributed Tracing & Analytics
    • Policies & Compliance Monitoring
    • Infrastructure Monitoring
    • ICS/SCADA/OT Security
  • Services
    • Managed SOC
    • Managed OT SOC
    • Incident Response
    • Cyber Threat Hunting
    • Red Team Assessment
    • Penetration Test
  • Industries
    • Banking & Finance (BFSI)
    • Medical And Healthcare
    • Compliance Solutions
    • Manufacturing
    • Government
    • Legal
  • Partners
    • MSSP Partner
    • Solution Provider
  • Contact
  • February 21, 2023
  • wrixte.co

Thailand’s Personal Data Protection Act (PDPA) was finally approved in February 2019 by the Thai National Legislative Assembly, after several legislative attempts. The PDPA was published in the Royal Thai Government Gazette following the passage of the bill, and came into effect on May 28, 2019. Organizations now have one year to fully comply with their policies by May 27th 2020.

Overall, the PDPA will change Thailand’s data protection landscape as this is the country’s first comprehensive legislation on the issue. Many of the standards and responsibilities under the PDPA have been adapted from the EU General Data Protection Regulation (GDPR), reflecting Thailand’s expectation of obtaining a European Commission decision on adequacy. The implementation of this legislation by Thailand has been partly inspired by many GDPR standards, and will significantly increase privacy protections for Thailand-based companies. Although an official English translation of the PDPA is not yet available, companies working in Thailand or handling Thai personal data will need to get to know this law quickly before its implementation date, which is less than a year away.

Overview

Similar to the GDPR, the purpose of the PDPA is to protect data proprietors (i.e. data subjects under the GDPR) in Thailand from unauthorized or illegal collection, use or release and processing of their personal data. The PDPA applies to non-Thailand organizations that either provide products and services to Thailand individuals or monitor individual behavior in Thailand. The legislation is expected to have a significant effect on non-Thailand-based online service providers, who hope to continue serving the Thai market.

The GDPR borrows a variety of criteria from Thailand’s PDPA. First, the law sets out a series of legal bases that entities must use to process information from data owners. These legal bases, like the GDPR, include agreement, legal obligation, public interest, and legitimate interest. However, individual rights under the PDPA are quite close to those found under the GDPR, covering the right of access, content, erasure and rectification. And eventually, like the Data Protection Authorities (DPAs) of the GPDR, the PDPA must set up a Personal Data Protection Committee (PDPC) to enforce the law and provide guidance to help companies ensure that the PDPA complies. Let’s look at the main criteria and concepts found in the new legislation in Thailand.

Key Definitions

The specified terms used in the PDPA are generally consistent with other GDPR-inspired legislation, further suggesting that Thailand may be following an EU-inspired agreement.

Personal Data: Broadly defined as information that can identify an entity directly or indirectly, excluding data from a deceased person and private business data such as contact information, names, or addresses.

Data Controller: A person or agency allowed to decide on the collection, use or disclosure of personal data.

Data Processor: A person or organization that gathers, uses or discloses personal data according to the data controller’s orders.

What is Sensitive Personal Data?

The PDPA sets out stringent requirements for the collection and preservation of sensitive personal data, including personal data relating to:

racial or ethnic origin

Political opinions

Religious or philosophical convictions

Criminal records

Trade union memberships

Genetic data

Biometric data

Medical records

Sexual orientation or preferences

Collection of confidential personal data is illegal, except in certain cases, such as medical emergencies or as required by law, without the express consent of the data owner.

Rights of Data Owner

The subject rights under the PDPA match those in the GDPR. Under the PDPA, Thai data owners will have the right to request access to their personal data and may make requests for the deletion, destruction or anonymisation of their personal data.

Consent Requirements

Consent Requirements The PDPA specifies that direct, express consent must be obtained on or before the collection of personal data (whether in writing or through an electronic system), and that the requests should not be false or deceptive. Data owners may revoke their consent at any time, but the revoke can not impact the previous compilation, use or release of legally consented personal data. The exemptions from the conditions for consent are quite broad, covering contractual obligations, public interest and rational reasoning.

To minors the PDPA requires parental consent to data owners under the age of 10 (and in specific circumstances for minors over the age of 10), whereas in GDPR, all children under the age of 16, requires parental consent.

Enforcement and Penalties

The implementation of the PDPA must fall under the jurisdiction of a Committee for Personal Data Protection Committee (PDPC), formed to enforce compliance. The PDPC will be developing recommendations for the introduction of a data protection framework.

Organizations will face both civil and criminal penalties if found non-compliant. Total PDPA penalties will be large (though not as extreme as the GDPR), with each violation having the potential to incur administrative fines of up to TBH 5 million (US$ 165,000) and criminal fines of up to TBH 1 million (US$ 33,000). The PDPA also gives the court the power to pay punitive damages up to twice the amount of actual damages and up to one year’s imprisonment. Additionally, it is now possible for data owners to pursue their own class action lawsuits.

Cross-Border Data Transfers

Under the PDPA, criteria for cross-border transfer are only broadly specified which increases the risk of enforcement.

The PDPA would require one of three conditions for international transfers:

  • Transfer to a country which has developed strong data protection measures in line with the guidelines laid down by the Personal Data Protection Committee
  • Consent
  • Pre-existing relationship between data controller and data owner

Data Protection Officer

Similar to the GDPR, data controllers or processors gathering, using, tracking, and releasing vast amounts of personal data will need to name a Data Protection Officer (DPO) to track and check compliance.

Preparing for Compliance

Given the short enforcement grace period, it is important that companies begin to review their activities related to personal data (e.g. data of customer, supplier, employee, billing and payment, etc.) and take the necessary steps to ensure that PDPA policies comply with all these requirements, by 27 May 2020.

  • Data mapping to explain the collection, processing, dissemination and storage of your company information, including the definition of the legal basis for personal data collection and use
  • Review of internal policies, agreements and practices regarding personal data
  • Implementation of data management and operating systems
  • Updating existing privacy records and producing relevant legal documentation
  • Ensure that managers and personnel are fully trained in the PDPA criteria
  • Conduct a gap assessment to evaluate existing enforcement rates
  • A process in place to exercise the rights of individuals with regard to their personal data

And with significant penalties for non-compliance and less than a year to the deadline, companies managing Thailand’s data owners ‘ personal data should not wait to start compliance work.

Tags:

Cloud ServicesData Center
Previous Post
Next Post

Leave a comment

Cancel reply

Recent Posts

  • The Threat of AI-Augmented Phishing Attacks
  • Protecting Industrial Control Systems (ICS) from Cyber Attacks
  • Cybersecurity Implications of Brain-Computer Interfaces (BCIs)
  • Blockchain Technology in Cybersecurity: Beyond Cryptocurrencies
  • Ethical Hacking: Balancing Security and Privacy

Recent Comments

No comments to show.

Recent Post

  • crysa
    October 25, 2024
    The Threat of AI-Augmented Phishing Attacks
  • crysa
    October 25, 2024
    Protecting Industrial Control Systems (ICS) from Cyber Attacks
  • crysa
    October 25, 2024
    Cybersecurity Implications of Brain-Computer Interfaces (BCIs)

Categories

  • Cloud Service
  • Compliance
  • CyberSecurity
  • Data Center
  • DataSecurity
  • Policy Monitoring
  • SFIM
  • SIEM
  • Uncategorized

Tags

Cloud Services Compliance Cybersecurity Data Center DataPrivacy DataSecurity ISO27001 SecurityControls Web

Archives

  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • January 2024
  • November 2023
  • September 2023
  • August 2023
  • June 2023
  • May 2023
  • March 2023
  • February 2023
  • June 2022
  • April 2022

Wrixte is a leading provider of cybersecurity solutions, offering Managed SOC Services to help organizations protect against cyber threats. Our services are tailored to the unique needs of each client and backed by a team of experienced security professionals and dual AI powered Wrixte SOC Suite.

We Serve

  • Products
  • Services
  • Industries
  • Solutions

Contact Info

  • #310, 3rd Floor, B- Wing, Blue Cross Chambers, Infantry Road Cross, Bengaluru - 560001
  • Opening Hours: 9:00 AM – 09.00 PM
  • Phone: +91 984 5536 176
Subscribe to our Newsletter

Join our subscribers list to get the latest news and special offers.

    © Copyright 2023. All Rights Reserved By Wrixte Infosec Private Limited
     

    We use cookies on this website to improve your browsing experience and analyze site traffic. By clicking 'Accept,' you consent to our use of cookies. To learn more about how we use cookies, please read our Privacy Policy.
    Accept
    Change Settings
    Cookie Box Settings
    Cookie Box Settings

    Privacy settings

    Decide which cookies you want to allow. You can change these settings at any time. However, this can result in some functions no longer being available. For information on deleting the cookies, please consult your browser’s help function. Learn more about the cookies we use.

    With the slider, you can enable or disable different types of cookies:

    • Block all
    • Essentials
    • Functionality
    • Analytics
    • Advertising

    This website will:

    This website won't:

    • Essential: Remember your cookie permission setting
    • Essential: Allow session cookies
    • Essential: Gather information you input into a contact forms, newsletter and other forms across all pages
    • Essential: Keep track of what you input in a shopping cart
    • Essential: Authenticate that you are logged into your user account
    • Essential: Remember language version you selected
    • Functionality: Remember social media settings
    • Functionality: Remember selected region and country
    • Analytics: Keep track of your visited pages and interaction taken
    • Analytics: Keep track about your location and region based on your IP number
    • Analytics: Keep track of the time spent on each page
    • Analytics: Increase the data quality of the statistics functions
    • Advertising: Tailor information and advertising to your interests based on e.g. the content you have visited before. (Currently we do not use targeting or targeting cookies.
    • Advertising: Gather personally identifiable information such as name and location
    • Remember your login details
    • Essential: Remember your cookie permission setting
    • Essential: Allow session cookies
    • Essential: Gather information you input into a contact forms, newsletter and other forms across all pages
    • Essential: Keep track of what you input in a shopping cart
    • Essential: Authenticate that you are logged into your user account
    • Essential: Remember language version you selected
    • Functionality: Remember social media settings
    • Functionality: Remember selected region and country
    • Analytics: Keep track of your visited pages and interaction taken
    • Analytics: Keep track about your location and region based on your IP number
    • Analytics: Keep track of the time spent on each page
    • Analytics: Increase the data quality of the statistics functions
    • Advertising: Tailor information and advertising to your interests based on e.g. the content you have visited before. (Currently we do not use targeting or targeting cookies.
    • Advertising: Gather personally identifiable information such as name and location
    Save & Close
    Go to mobile version
    • →
    • Contact Us

      Contact Form

    • WhatsApp
    • Facebook Messenger
    • Telegram