PDPA Website Compliance: A Practical Checklist

PDPA Website Compliance: A Practical Checklist

PDPA website compliance means obtaining valid opt-in consent before loading non-essential cookies, publishing a privacy notice, honouring data subject requests, and keeping consent records you can produce on demand. Thailand’s PDPC has moved from guidance to enforcement, with administrative fines reaching THB 7 million in a single case.

The PDPC fined a Thai retailer THB 7 million. The violation was not a hack. It was inadequate security, a missed breach notification, and no data protection officer.

That is the shift most Bangkok businesses have not registered. For three years after the law took effect, PDPA website compliance was treated as paperwork nobody enforced. That assumption is now expensive.

This is the implementation view, not the legal one. You will learn exactly what has to exist on your website, what a compliant consent banner actually does differently from the one you probably have, and which four artefacts you need before anyone asks for them.

Start with scope, because a lot of companies assume this does not apply to them and are wrong.

Does the PDPA Apply to Your Website?

If your website collects personal data from anyone in Thailand, yes. Where your company is registered does not matter.

Thailand’s Personal Data Protection Act was enacted on 27 May 2019 and came into full force on 1 June 2022, modelled on the European GDPR. It covers businesses operating in Thailand, and data controllers and processors located outside Thailand when they collect, use, or disclose the personal data of individuals in Thailand.

The second half of that sentence catches more companies than the first. A Singapore holding company running a Thai-language site, a UK firm selling to Bangkok customers, a regional SaaS product with Thai users: all in scope.

Then there is the question of what counts as personal data, and this is where most website owners misjudge their exposure. Personal data explicitly includes IP addresses, device identifiers, and cookie identifiers. Google Analytics alone puts you in scope. So does a Meta pixel, a remarketing tag, or a heatmap tool. You do not need a login system or a customer database to be processing personal data. A brochure site with analytics is processing personal data.

The regulator is the Personal Data Protection Committee, under the Ministry of Digital Economy and Society.

I am not a lawyer and this article is not legal advice. It covers what to build. For your specific obligations, particularly around sensitive data, employee data, or cross-border transfers, talk to a Thai firm.

If you run analytics, you are in scope. The question is not whether the PDPA applies but how much work you have left.

What PDPA Website Compliance Actually Requires

Four things need to exist, and most Thai business sites have one of them badly.

The four artefacts PDPA website compliance requires

The PDPA operates an opt-in model. Consent must be given before processing starts, not assumed from behaviour afterwards.

Treating continued browsing as consent does not count, and consent cannot be bundled into acceptance of your terms and conditions. That single rule invalidates the banner on a large share of Thai websites: the bar at the bottom of the screen with one button reading “OK” or “Accept”, which sets a dismissal flag and lets every tag fire regardless.

A compliant first-layer banner carries a concise summary of purposes, an accept control, a reject control, and a way to manage preferences. Reject has to be as easy as accept. A banner where accepting takes one click and refusing takes three is a design pattern the regulator reads as coercion.

A privacy notice in every language you publish

If your site serves Thai and English, both need the notice. Consent banners and privacy information are expected in all the languages the site requires. A Thai-language site with an English-only privacy policy is not compliant, and it is a common failure on bilingual builds where the Thai version was translated late.

This is the artefact almost nobody has. Records are expected to capture a timestamp, the user’s choices by purpose, and the version of the policy in force when consent was given. Consent is treated as valid for twelve months.

A banner that writes a cookie to the visitor’s browser and keeps no server-side log leaves you with nothing to show. When the PDPC asks what a specific user consented to and when, “our banner handles it” is not an answer.

A route for data subject requests

Individuals can request access to their data, correction, portability to another controller, erasure, and can object to processing in specific circumstances. They can also complain directly to the PDPC.

You need a monitored address and an internal process. The address on its own is not the hard part. Being able to find and delete one person’s data across your CMS, your email tool, your CRM, and your analytics is.

Audit your current site against these four. Most Bangkok sites have a banner, a privacy page, and nothing else.

INSPIRA INSIGHT

At Inspira, most of the Bangkok sites we inherit arrive with a cookie banner that does nothing. It displays, it sets a dismissal cookie, and the analytics and remarketing tags fire on page load regardless of what the visitor clicked. The banner was installed to look compliant rather than to be compliant. Here is what that taught us: consent is a tag-firing problem before it is a design problem, and nobody catches it because the page looks correct either way.

What the PDPC Has Actually Fined People For

Enforcement is real, and the pattern in the published cases is instructive.

On 1 August 2025 the PDPC announced eight fines across five cases. They are worth reading as a list of what the regulator cares about, because almost none of them are about consent banners.

PDPC fines issued in August 2025 by violation type

A computer retailer was fined THB 7 million after a breach fed a call-centre scam affecting over 100 complainants. The violations were inadequate security, failure to report the breach, and having no data protection officer. A cosmetics company was fined THB 2.5 million after personal data reached a scam call-centre, for inadequate security and failure to notify the PDPC. A private hospital was fined THB 1.21 million after a contractor hired to destroy medical records used them to wrap sweets, leaking over 1,000 records; the contractor was fined THB 16,940. A collectible toy company and its data processor were fined THB 500,000 and THB 3 million after an unauthorised party accessed a reservation system for roughly ten minutes and amended about 200,000 records. In a state agency case, weak password protection, no risk assessment, and no data processing agreement with the software developer produced fines of THB 153,120 each. The cases are set out in Tilleke and Gibbins’ review of the eight fines.

Three themes repeat. Inadequate security measures. Failure to notify within the deadline. No DPO where one was required.

The headline penalties sit above those numbers. Administrative fines reach THB 5 million, criminal fines reach THB 1 million, and civil damages can carry punitive damages of up to twice the actual compensation. The THB 7 million retailer figure reflects multiple violations in one case.

Note what is absent from that list: nobody was fined for a badly designed cookie banner. The money is in security failures and missed notifications.

So fix the banner, but do not stop there. The expensive failures are operational.

The Obligations That Are Not on Your Website

Three requirements sit behind the site, and two of them appear in every enforcement case above.

Breach notification within 72 hours. Breaches must be reported to the PDPC within 72 hours, and serious breaches require immediate notification. Seventy-two hours is not long if nobody has decided in advance who declares a breach, who writes the notification, and who signs it. Write that down before you need it.

A data protection officer where required. A DPO must be appointed where processing involves large-scale or sensitive data. The retailer fined THB 7 million did not have one. If you handle health data, financial data, or process at scale, take advice on whether the threshold applies to you, because guessing is how that line item appeared in a penalty notice.

Processor agreements. In the state agency case, the absence of a data processing agreement with the software developer was itself a cited violation. If an agency, a developer, or a marketing tool touches your customer data, the contract matters. That includes whoever maintains your website.

Security measures. This is the one that produced every large fine. Weak passwords and no ongoing risk review were named explicitly. Keeping WordPress core, plugins, and themes patched is a data protection obligation, not just housekeeping, which is part of why website maintenance in Bangkok is worth treating as a standing commitment rather than an occasional clean-up.

Compliance is a process with an owner, not a page you publish once.

How to Implement This on a WordPress Site

Work in this order. The sequence matters more than the tooling.

One. Inventory what fires. Open your site in a private window and list every script that loads before any interaction. Analytics, pixels, embedded maps, fonts loaded from third parties, chat widgets. That list is your scope. Most teams are surprised by its length.

Two. Classify. Strictly necessary cookies do not require consent. Everything else does: analytics, advertising, personalisation, and most embeds. Be honest at this step, because classifying analytics as necessary is the shortcut that makes the whole exercise worthless.

Three. Block before consent. This is the step that separates real compliance from theatre. Non-essential tags must not fire until consent is given. In practice that means routing tags through Google Tag Manager with consent mode, or using a consent platform that genuinely blocks rather than one that only displays a banner. Test it by loading the site, refusing, and watching the network tab. If the pixel still fires, you are not compliant whatever the banner says.

Compliant and non-compliant PDPA cookie consent banners compared

Four. Log consent server-side. Timestamp, choices by purpose, and policy version, stored where you can query it.

Five. Write the notice, in both languages. What you collect, why, your lawful basis, how long you keep it, who you share it with, and how to exercise rights.

Six. Set the review date. Consent is valid for twelve months, and your policy version will change. Put it in the calendar.

If you are planning a new build rather than fixing an existing one, decide the consent architecture during discovery. Retrofitting consent onto a finished site usually means reworking every script that fires before it, which is one of the five things that change when building a website in Thailand.

Test by refusing, not by accepting. Accepting always looks fine.

Frequently Asked Questions

Does the PDPA apply to my website if my company is not in Thailand?

Yes. The PDPA reaches data controllers and processors outside Thailand when they collect, use, or disclose the personal data of individuals in Thailand. A foreign company selling to Thai customers, or running a Thai-language site, is in scope. Where you are registered does not determine the obligation. What matters is whose data you process.

Yes. Personal data under the PDPA includes IP addresses, device identifiers, and cookie identifiers, so analytics counts as processing personal data. Analytics is not strictly necessary for delivering your website, which means it requires consent before it loads. A brochure site with nothing but Google Analytics still needs a compliant consent mechanism.

Treating continued browsing as consent, bundling consent into your terms and conditions, offering no reject option, or making refusal harder than acceptance. The most common failure is technical rather than visual: the banner displays, but analytics and advertising tags fire on page load regardless of what the visitor clicks. Test by refusing and checking the network tab.

What are the penalties for PDPA non-compliance?

Administrative fines reach THB 5 million, criminal fines reach THB 1 million, and civil damages can include punitive damages of up to twice the actual compensation. In August 2025 the PDPC announced eight fines across five cases, the largest being THB 7 million against a retailer for inadequate security, failure to report a breach, and having no data protection officer.

How long do I have to report a data breach?

Seventy-two hours to notify the PDPC, with immediate notification expected for serious breaches. Failure to notify was a cited violation in four of the five enforcement cases published in August 2025. Decide in advance who declares a breach and who writes the notification, because the deadline is short once an incident starts.

Does my privacy policy need to be in Thai?

If your website serves Thai-language visitors, yes. Consent banners and privacy information are expected in the languages the site requires. A bilingual site with an English-only privacy policy is a common gap, usually because the Thai version was translated after launch and the legal pages were skipped.

Conclusion

PDPA website compliance is not a banner. It is a consent mechanism that actually blocks tags, records you can produce, a notice in every language you publish, and an answer ready for the 72-hour clock.

You now know something more useful than the rules themselves: you know what the regulator has actually fined people for. Not banner design. Inadequate security, missed notifications, and a missing DPO. That tells you where to spend first.

The honest summary is that the cheap half of this is a day of work and the expensive half is an ongoing operational commitment.

If you want your consent setup tested properly, or a new build that handles this from the first line of code, that is part of what our web design and development Bangkok team does on every project.

Xavier Cloitre
Founder & Marketing Director, Inspira Digital Agency

Xavier Cloitre is Founder and Marketing Director of Inspira Digital Agency in Bangkok. He has run search and paid campaigns for Thai and international businesses since 2016, across healthcare, property, hospitality and international schools.