Thailand’s Information Security Laws and What Companies Need to Do

Masaki Fujiwara, Managing Director and Attorney at Law (Japan), One Asia Lawyers (Thailand) Co., Ltd.
Hiroyasu Chiba, Partner and Attorney at Law (Japan), One Asia Lawyers (Thailand) Co., Ltd.

Practical Guidance on the Computer Crime Act and PDPA for Japanese IT Managers

Japanese professionals responsible for IT operations at Thai subsidiaries often ask: “What information security laws apply in Thailand, and what level of compliance is expected of us?”

Thailand’s information security framework is built around three key laws:

  1. The Computer Crime Act B.E. 2550 (2007), as amended in 2017
  2. The Cybersecurity Act B.E. 2562 (2019)
  3. The Personal Data Protection Act (PDPA) B.E. 2562 (2019)

From a practical perspective, these laws can be understood as follows:

  • What you must not do: Computer Crime Act
  • What you must prepare for: PDPA and Cybersecurity Act
  • How to respond when an incident occurs: PDPA and law enforcement authorities

This article highlights the key points that Japanese IT managers should be aware of when operating in Thailand.


1. Computer Crime Act: Even Well-Intentioned Actions Can Create Legal Risk

The Computer Crime Act criminalizes a range of activities, including:

  • Unauthorized access to systems protected by security measures (Section 5: imprisonment of up to 6 months and/or a fine of up to THB 10,000)
  • Unauthorized access to another person’s computer data (Section 7: up to 2 years and/or THB 40,000)
  • Interception of communications (Section 8: up to 3 years and/or THB 60,000)
  • Damage to, alteration of, or interference with computer data or systems (Sections 9 and 10: up to 5 years and/or THB 100,000)

Penalties can be significantly enhanced where the offense affects critical information infrastructure related to national security, public safety, economic security, or public services.

A particularly important consideration for IT managers is that actions taken for legitimate business purposes may still fall within the scope of these offenses if proper authorization is lacking. Examples include:

  • Accessing the mailbox or computer of a former employee or employee on leave without consent or a clear basis under company policy
  • Logging into a system using another employee’s credentials, including account sharing
  • Installing monitoring software on employee devices to capture communications without appropriate authorization
  • Conducting vulnerability assessments on a customer’s, supplier’s, or group company’s systems without explicit permission

To reduce legal risk, companies should clearly inform employees in advance about the scope, purpose, and methods of monitoring through IT usage policies and work rules. This is also consistent with the PDPA’s transparency requirements regarding the collection and use of personal data. Formal approval procedures should be established and followed. Where penetration testing is outsourced, the scope of testing and authorization should be clearly documented in writing.


2. The Often-Overlooked Requirement to Retain Communication Logs for 90 Days

Section 26 of the Computer Crime Act requires service providers to retain computer traffic data for at least 90 days. Failure to comply may result in fines of up to THB 500,000.

Importantly, the term “service provider” is not limited to telecommunications operators. A 2021 notification issued by Thailand’s Ministry of Digital Economy and Society broadly categorizes entities providing internet access, communication services, or data storage services. As a result, ordinary businesses that provide internet or Wi-Fi access to employees or visitors may also fall within the scope of this obligation.

Many Thai subsidiaries of Japanese companies have yet to fully address this requirement.

From a practical standpoint, companies should verify the following:

  • Are firewall, proxy, DHCP, authentication, and related logs retained for at least 90 days (preferably one year or longer)?
  • Can individual users be identified from the available logs? For example, is guest Wi-Fi subject to authentication controls?
  • Are appropriate safeguards in place to prevent log tampering, and are systems synchronized through NTP or equivalent time synchronization mechanisms?

3. What Level of Security Does the PDPA Require?

The PDPA does not prescribe detailed technical specifications. However, a 2022 notification issued by Thailand’s Personal Data Protection Committee (PDPC) requires organizations to implement organizational and technical measures, and where appropriate physical measures, that are proportionate to the level of risk and ensure the confidentiality, integrity, and availability of personal data.

Examples of required controls include:

  • Access control mechanisms
  • User privilege management
  • Clear assignment of responsibilities
  • Maintenance of audit trails and access logs

Organizations are also expected to:

  • Conduct security awareness training for employees
  • Review security measures when technologies change or incidents occur
  • Establish security requirements for outsourced service providers and data processors

Because the PDPA adopts a risk-based approach, there is no single standard that applies to all organizations. Businesses should consider internationally recognized frameworks such as ISO/IEC 27001 and implement controls that are appropriate for the sensitivity and volume of the data they process.

Equally important is documenting the rationale behind security decisions. Maintaining records of why a particular level of protection was deemed appropriate can be valuable when responding to regulatory inquiries.

The PDPC has intensified enforcement efforts in recent years. Publicly reported cases have involved administrative penalties ranging from several hundred thousand to several million baht for issues such as:

  • Failure to appoint a Data Protection Officer (DPO)
  • Inadequate security measures
  • Failure to report data breaches within the prescribed 72-hour period

Administrative fines vary depending on the type of violation, with the most serious offenses carrying penalties of up to THB 5 million. Where multiple violations are identified, the total administrative penalty may exceed THB 5 million.

In addition, under the Cybersecurity Act, the National Cyber Security Committee (NCSC) has published Cloud Security Standards and Website Security Standards 1.0, which are scheduled to take effect in September 2026. Although these standards primarily apply to government agencies and Critical Information Infrastructure (CII) operators, they provide useful guidance for private-sector organizations as well. Recommended controls include:

  • TLS encryption
  • Multi-factor authentication for administrator accounts
  • Input validation controls
  • Logging and monitoring of system access
  • Backup and recovery testing

These standards can serve as a practical checklist when reviewing corporate websites and information systems.


4. Responding to Security Incidents

When a security incident occurs, the IT department’s immediate priorities should be:

  1. Containing the damage by isolating affected systems from the network and disabling compromised accounts.
  2. Preserving evidence by securing logs, system images, and other forensic data.

A common mistake is to prioritize recovery by reimaging or rebuilding infected systems too quickly. Doing so may hinder root-cause analysis, regulatory reporting, and insurance claims.

Reporting Obligations

Where personal data is involved, the PDPA generally requires that data breaches be reported to the PDPC within 72 hours of becoming aware of the incident. If the breach is likely to pose a high risk to the rights and freedoms of affected individuals, notification to those individuals may also be required.

For cybercrime incidents such as ransomware attacks or Business Email Compromise (BEC) fraud, companies should consider filing a report with Thailand’s Cyber Crime Investigation Bureau.

In cases involving online fraud or unauthorized fund transfers, reporting through Thailand’s government fraud-reporting channels, including the 1441 hotline and online reporting system, may facilitate faster action such as account freezing.

As interaction with authorities is typically conducted in Thai, companies should establish communication protocols and clearly allocate responsibilities among both Japanese and Thai staff before an incident occurs.

Conclusion: A Minimum Compliance Checklist

Before an incident occurs, companies should confirm the following:

  • Communication logs are retained for at least 90 days and can be linked to individual users.
  • Privileged accounts and access rights are reviewed regularly, and accounts belonging to departing employees are promptly disabled.
  • IT usage policies and monitoring policies have been communicated to employees, with a clear legal and operational basis for monitoring activities.
  • Vendor and outsourcing agreements include security requirements and incident-notification obligations.
  • Incident response procedures, including the PDPA’s 72-hour reporting requirement, are documented, and emergency contact frameworks have been established and tested.

While it is impossible to eliminate security incidents entirely, implementing legally required safeguards in advance and maintaining appropriate records can significantly reduce corporate and individual liability when incidents occur. Ultimately, the quality of an organization’s initial response often has a greater impact on corporate reputation than the statutory penalties themselves.

" + NS Solutions" is register trade mark of NS Solutions corporation.

Other description about company name and product name are trademark or register trade mark of each companies.