Bangkok Lad
Systems & Society

Taken down, not fined

Thailand's data protection law binds state and companies alike. In four years, nine fines: eight on companies, one on a state agency, ฿153,120. Most exposed data the regulator finds is on state websites, and is taken down.

1 of 9 PDPA fine orders has gone to a state agency THE PDPA, FOUR YEARS IN 1 of 9 PDPA fine orders has gone to a state agency ฿153,120, out of more than ฿21.5 million in fines since 2024. The regulator's own web searches find most exposed personal data on local-government and state websites, and ask for it to be taken down. Source: PDPC announcements, Aug 2024 and 1 Aug 2025; PDPC Eagle Eye releases BANGKOK LAD

Thailand’s Personal Data Protection Act came fully into force on 1 June 2022, after two postponements, and it applies to the state as well as to business. Four years on, its fines have fallen almost entirely on companies. The leaks the regulator finds for itself are almost entirely in the state.

What the Act requires

The Act covers anyone who collects, uses or discloses personal data, with exceptions listed in section 4 and any others made by royal decree. Section 4’s list: personal and family use; state agencies responsible for national security, including fiscal security, public safety, money laundering, forensics and cybersecurity; the press, art and literature acting ethically or in the public interest; Parliament and its committees; the courts, enforcement and the criminal-justice process; and credit bureaus. Apart from personal use, even the exempt bodies must still keep data secure to a set standard.

Everyone else needs a lawful basis. Consent is one; section 24 lists six others, including a task in the public interest or the exercise of state authority, and compliance with a law. Health, criminal records, religion, biometrics and the other “sensitive” categories in section 26 need explicit consent, with narrower exceptions.

Two duties matter most for leaks. Section 37 requires appropriate security, and notice of a breach to the regulator “without delay, within 72 hours” of learning of it where there is a risk to people’s rights. Section 41 requires a data protection officer at state agencies the committee designates, at organisations monitoring data at scale, and where sensitive data is the core business.

The fines are administrative, set by expert committees:

SectionWhat it punishesCeiling
82No notice to people, no data protection officer, no records฿1 million
83No lawful basis; no security or no breach notice (s.37)฿3 million
84Sensitive data without a basis฿5 million

Section 90 lets the committee order a fix or give a warning first, and tells it to weigh the seriousness of the conduct and the size of the organisation. Courts can add damages of up to twice the actual loss (section 78), and misuse of sensitive data is a crime under section 79.

The nine fines

The first fine was announced on 21 August 2024: ฿7 million on an online computer retailer whose customers’ data reached call-centre scam gangs. The company had no data protection officer, inadequate security, and had not reported the breach in time. A law firm’s reading of the order breaks it down as ฿1 million for the missing officer and ฿3 million each for security and for the late report — the ceilings of sections 82 and 83 added together.

On 1 August 2025 the regulator announced eight more orders in five cases, bringing the total to six cases, nine orders and more than ฿21.5 million. The eight orders of August 2025:

WhoFine
A computer and accessories seller฿7,000,000
A data processor running a toy company’s reservation system฿3,000,000
A cosmetics company฿2,500,000
A private hospital whose patient records were used to wrap sweets฿1,210,000
The toy company itself฿500,000
A state agency whose web app was breached, data of 200,000 people sold on the dark web฿153,120
The software developer that built it฿153,120
The individual contractor hired to shred the hospital’s records฿16,940

The state agency’s failings, in the regulator’s words: no appropriate security, weak passwords, no risk assessment, and no data processing agreement with its developer. Its fine was the same as its contractor’s, and about 5% of the ฿3 million ceiling for a security failure. This site found no fine announced after August 2025.

The nine fines The nine fines PDPA administrative fine orders, August 2024 to August 2025 Total ฿21,533,180. No later fine was found. Computer retailer, 2024 ฿7m Computer seller, 2025 ฿7m Toy firm's data processor ฿3m Cosmetics company ฿2.5m Private hospital ฿1.21m Toy company ฿0.5m State agency ฿153,120 State agency's developer ฿153,120 Shredding contractor ฿16,940 Source: PDPC, 1 Aug 2025 (Thai Post); 2024 order via DLA Piper BANGKOK LAD

Where the leaks are found

In November 2023 the digital economy ministry set the regulator a new job: search public websites for exposed personal data, under a centre called PDPC Eagle Eye. Its counts, as the ministry and the regulator released them:

  • 9 November to 28 December 2023: 15,820 organisations checked, 4,801 with leaks — 2,600 local governments, 1,975 other state agencies, 153 educational institutions and 25 private companies.
  • November 2023 to May 2024: 26,301 organisations checked, 5,978 leaks found — local governments 2,833, central government 2,421, education 680, others 35. The regulator’s monthly leak rate fell from 31.40% to 1.21% over the period.
  • October 2025 to March 2026: more than 590,000 web addresses checked, 205 leak risks — local governments 159, state agencies 31, education 15.

In the first count, 95% of the organisations with leaks were local governments or other state agencies; private companies were 0.5%. (This site’s arithmetic.) In every period the regulator says almost all were fixed: 99.85% in the 2024 count, all 205 in the 2026 one.

What this measures matters. Eagle Eye searches what is published on the open web, and state agencies publish far more documents online than companies do. It is not a count of all breaches: a hacked company database does not show up on its own website. The regulator’s separate tally of breaches reported to it — 564 by June 2024 — gave human error (203) and disclosure beyond what was necessary (145) as the leading causes, without a split by sector.

But it is the regulator’s own finding, and the pattern holds across three periods. When the regulator finds exposed data on a state website, the record shows a request to take it down. In December 2023 the digital economy minister said agencies that let data leak, or repeated it, would be punished “strictly and decisively under the law.” Since then, one state agency has been fined.

Why the difference

Nothing in the Act treats a state agency more gently. Sections 82 to 84 apply to “any data controller”, and the one state agency fined shows they reach the state.

What the record shows is a difference in route. The fined cases, the state agency’s included, reached the regulator through complaints from people who had been defrauded or through a breach that became public: the regulator’s 2025 statement describes complaints, scam calls, photographs on social media and a sale on the dark web. The exposures Eagle Eye finds come through the regulator’s own search, and are handled by asking for a fix — the approach section 90 also allows before any fine. That is a defensible choice. It also means the Act’s heaviest tool has, in practice, been used against business.

The complaints route is slow. By November 2024 the regulator’s complaint centre had received 823 complaints and concluded 181, almost all by administrative order; 450 were still being examined and 192 had been closed for incomplete documents.

The cases now open

On 29 July 2026 the regulator said it had asked two bodies for evidence: the Ministry of Public Health, after more than 30 complaints about personal data connected with its Mor Prom health app; and a securities-depository company that had reported unauthorised access to about 200,000 users’ data in its investor portal. The regulator stressed that a breach is not automatically an offence: the question is whether security was adequate beforehand and whether the breach was reported and handled as the law requires.

If the ministry’s case ends in a fine, it will be the second on a state body since the Act came into force.

And a new rule widens the field. A Prime Minister’s Office regulation on sharing digital data, published on 4 September 2026, sets up a central system for state agencies to exchange data, beginning with disaster-response datasets. It lets agencies refuse to share personal data unless it has been anonymised, consented to, or collected lawfully under the PDPA. Writing in Thai Post a few days later, the regulator’s own head of communications warned that sharing health data under a regulation, without consent or a basis in an Act, could put the officials who do it in breach of the PDPA.

Where the exposed data was found Where the exposed data was found Leaks found by the regulator's web monitoring, November 2023 to May 2024 Oct 2025 to Mar 2026: 159 local government, 31 state agency, 15 education. Local government 2,833 Central government 2,421 Education 680 Other 35 Source: PDPC, as reported by Thai Post, 21 June 2024 BANGKOK LAD

What this adds up to

The PDPA is universal on paper. Apart from the bodies section 4 lists and any exempted by decree, the state is bound exactly as a shop is.

Its enforcement has not been. Eight of the nine fines have gone to companies, a private hospital among them, and to one individual contractor; one has gone to a state agency, for ฿153,120. The exposures the regulator keeps finding for itself are overwhelmingly on state, local-government and school websites, and are taken down.

None of this says the companies did not deserve their fines, or that a takedown is the wrong response to an exposed PDF. It says that the people whose data most often turns up on a public website have mostly been protected by a request, not a penalty.


Common misconceptions

“The PDPA doesn’t apply to the government.” It does. Section 4 exempts specific bodies — security, the courts, Parliament, credit bureaus and a few others — not the state as a whole. A state agency was fined in 2025.

“Posting a photo with strangers in it breaks the PDPA.” Section 4 exempts collection and use for purely personal or family purposes.

“Every breach means a fine.” The regulator itself says a breach is not automatically an offence, and section 90 lets its committees order a fix or warn first.

“PDPA fines run to ฿5 million per case.” ฿5 million is the ceiling for sensitive-data offences. The largest fine so far, ฿7 million, combined three lesser ceilings.

Common questions

Does the PDPA apply to government agencies?
Yes. Section 4 exempts specific bodies — security agencies, the courts and enforcement, Parliament, the press, credit bureaus, and personal or family use — but not the state as a whole.
What are the PDPA fines?
Administrative fines of up to ฿1 million, ฿3 million or ฿5 million depending on the duty breached (sections 82 to 84), plus court damages of up to twice the actual loss and criminal penalties for misuse of sensitive data.
Has anyone actually been fined?
Yes. By August 2025 there were nine fine orders in six cases, worth more than ฿21.5 million. Eight went to companies, a hospital and an individual contractor; one, of ฿153,120, to a state agency.
What is PDPC Eagle Eye?
The regulator's centre that searches public websites for exposed personal data and asks the organisation responsible to remove it. Most of what it has found has been on local-government and state websites.
How fast must a breach be reported?
To the regulator without delay, within 72 hours of learning of it, where it risks people's rights; and to the people affected, with remedies, where the risk is high.