Thailand

PDPA Thailand

38 controls. 132 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

38 controls 132 frameworks share controls with it Thailand verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

Thailand PDPA Evidence & Implementation Kit

38 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
PDPATH-1Scope, Extra-Territorial Application, Lawful Basis, and Notice0
PDPATH-2Consent Requirements and Special Consent for Sensitive Data0
PDPATH-3Data Subject Rights, Automated Decisions, Accuracy25
PDPATH-4DPIA, Privacy by Design, Children's Data75
PDPATH-5Security Measures and Data Protection89
PDPATH-6Cross-Border Transfer and Processor Engagement26
PDPATH-7DPO, Records of Processing, Retention, Marketing, Training48
PDPATH-8Data Breach Notification, Complaints, Compliance, Enforcement82
Section 19Lawful Basis and Consent Requirements0
Section 20Consent for Minors0
Section 21Purpose Limitation0
Section 22Data Minimisation0
Section 23Privacy Notice Requirements0
Section 24Lawful Bases Other Than Consent0
Section 25Historical and Pre-PDPA Data0
Section 26Sensitive Personal Data0
Section 27Disclosure to Third Parties0
Section 28Cross-Border Data Transfer0
Section 29Intra-Group Transfer Rules0
Section 30Right of Access0
Section 31Right to Data Portability0
Section 32Right to Object0
Section 33Right to Erasure0
Section 34Right to Restriction of Processing0
Section 35Right to Rectification0
Section 36Retention and Deletion0
Section 37Controller Security Obligations0
Section 37(4)Breach Notification to Data Subjects0
Section 39Record of Processing Activities (RoPA)0
Section 40Processor Obligations0
Section 41Appointment of Data Protection Officer0
Section 42DPO Duties0
Section 43PDPC Authority and Powers0
Section 5Extraterritorial Application0
Section 6Definitions and Scope of Personal Data0
Section 7Local Representative Requirement0
Section 95Effective Date and Enforcement0
Section 95(2)Complaint Handling0

Tell me when PDPA Thailand files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Withdrawal mechanism as easy as giving
  • Lawful basis register per processing
  • Consent records (granular and withdrawable)
  • Direct collection notification evidence
  • consent records
  • lawful basis register
  • security charter
  • board reporting pack
  • risk register
  • policy library

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for PDPA Thailand, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition