• HOME
  • Publications
  • Enhancing Data Governance under Thailand’s PDPA: The Introduction of PDPA Compliance Certificate and Certification Mark (Thailand)

Publication

Newsletters

Enhancing Data Governance under Thailand’s PDPA: The Introduction of PDPA Compliance Certificate and Certification Mark (Thailand)

Author
Shohei Sasaki, Shunsuke Minowa, Ponpun Krataykhwan, Poonyisa Sornchangwat (Co-author)
Publisher
Nagashima Ohno & Tsunematsu
Journal /
Book
NO&T Thailand Legal Update No.48 (August, 2026)
Reference
Practice Areas

*Please note that this newsletter is for informational purposes only and does not constitute legal advice. In addition, it is based on information as of its date of publication and does not reflect information after such date. In particular, please also note that preliminary reports in this newsletter may differ from current interpretations and practice depending on the nature of the report.

A. Introduction

For a long time, the activities of both business operators and regulatory authorities have necessarily involved the collection, use, and disclosure of personal data, which constitutes information of significant value and sensitivity to individuals. Following the enforcement of the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), organizations in both the public and private sectors have been subject to heightened requirements on the protection of personal data. Over time, the PDPA compliance has become no longer regarded merely as the discharge of a statutory obligation, but has assumed broader significance as a mechanism for promoting accountability, strengthening data governance, and enhancing organizational credibility and trust among shareholders, stakeholders, data subjects, and the public at large.

The Personal Data Protection Committee (“PDPC”) has been developing a regulatory framework to enable organizations to apply for certification of their compliance with the PDPA. In this regard, the following two subordinate regulations issued under the PDPA were published in the Royal Gazette on 18 June 2026 and came into effect on the same date:

  1. Notification of the PDPC re: Criteria for the Grant of the Certificate and Certification Mark for Personal Data Protection Standard B.E. 2569 (2026) dated 27 February 2026 (“Notification on the Criteria for the Grant of the Certification”); and
  2. Notification of the PDPC re: Methods and Conditions for the Certification for Personal Data Protection Standard B.E. 2569 (2026) dated 27 February 2026 (“Notification on Methods and Conditions for the Certification”).

The key points arising from these two subordinate regulations are further summarized in this article.

B. Key Points of the Subordinate Regulations

The principal objectives of the certification of compliance with the PDPA are to support and promote organizations in: (i) conducting their operations in accordance with the accountability principle and ensuring the effective management of personal data; and (ii) establishing systems capable of supporting cross-border recognition in the future.

An application for a PDPA Compliance Certificate and Certification Mark must be submitted to the PDPC Office. Subject to the score achieved, an organization may be granted a PDPA Compliance Certificate and/or Certification Mark after going through the verification and assessment by the PDPC Office based on the criteria for verification of the personal data protection standard, with the following key details summarized below (“Verification and Assessment”).

No. Issue Details
1. Applicant The applicant may be government authorities or juristic persons in the private sector.
2. Qualification of the Applicant in the Private Sector Qualifications of an applicant who is a juristic person in the private sector are as follows:

  1. The applicant must be established in Thailand and have its office in Thailand, or may be established in an overseas country but must have a branch office in Thailand or appoint an authorized representative in Thailand;
  2. The applicant must have passed the Privacy Maturity Model※1 with a score of level 5;
  3. The applicant must not have been rejected for application within 45 days prior to the recent application date;
  4. The applicant must not have been subject to the revocation of the certification within 1 year prior to the application date; and
  5. If the applicant has been subject to a judgment under the personal data protection law, the applicant must have fully complied with such judgment and at least two years must have elapsed from the date of such compliance.
3. Criteria for Verification and Assessment Criteria for Verification and Assessment cover 4 categories, divided into 10 aspects totaling 128 items of criteria, as annexed to the Notification on the Criteria for the Grant of the Certification.

Category 1 Policy and Governance
Aspect 1: Organization and Oversight (13 items)
Aspect 2: Policies and Procedures (10 items)
Category 2 Human Resource Development (HRD)
Aspect 3: Training and Awareness (7 items)
Category 3 Process and Procedure
Aspect 4: Individual Rights (11 items)
Aspect 5: Transparency (11 items)
Aspect 6: Record of Processing Activities (RoPA) and Lawful Basis (17 items)
Aspect 7: Data Processing Agreement and Data Sharing Agreement (19 items)
Aspect 8: Risks and Data Protection Impact Assessment (7 items)
Category 4 Technology Security and Breach Response
Aspect 9: Data Security (17 items)
Aspect 10: Breach Response (16 items)

For the purpose of conducting the Verification and Assessment, the PDPC will take into consideration the documentary and empirical evidence, the legal provisions stipulating such obligations, and also the good practices prescribed in the Notification on the Criteria for the Grant of the Certification.

4. Criteria of score
  1. In the case where the applicant duly complies with the obligations under legal provisions, if the scores earned are not less than 80% but not more than 89.9% for each topic, the PDPA Compliance Certificate (Passing Level) will be granted.
  2. In the case where the applicant duly complies with both the obligations under legal provisions and good practices, if the scores earned are not less than 90% for each topic, the PDPA Certificate (Achievement Level) and Certification Mark will be granted.

Note that the certificates and certification mark will be issued with watermark hologram to prevent counterfeit.
The PDPC will publish on its website the list of organizations that have been granted a certificate or certification mark. However, as of the date of this article, no organization has yet been granted either of them.

5. Fee There are fees chargeable for submission of the application, Verification and Assessment, and issuance of certification and mark. However, no further details regarding the chargeable fees have been published.
6. Validity period The PDPA Certificate and Certification Mark will be valid for 3 years from the date of issuance. The applicant may apply for the renewal of the certificate and certification mark 6 months before its expiration or within 6 months after the expiration.

C. Legal Analysis and Recommendation

The introduction of PDPA certification standards represents an important development in Thailand’s personal data protection framework. The two subordinate regulations establish a formal mechanism through which organizations may demonstrate compliance with the PDPA in a structured and credible manner. Certification may function as a trust mark for the data subjects and may also serve as a risk-mitigation measure in the event of an audit or inspection by the relevant authorities, or in response to complaints or objections raised by data subjects.

In light of these developments, organizations should consider reviewing their existing data protection documentation, security measures, and related practices to assess whether they align with the applicable certification criteria.

Even where certification is not immediately pursued, the criteria for Verification and Assessment introduced by Notification on the Criteria for the Grant of the Certification may serve as a useful self-assessment tool for evaluating and strengthening an organization’s overall PDPA compliance framework.

As implementation progresses, the certification regime may become an increasingly important component of data governance and regulatory compliance in Thailand. It is also possible that the PDPC may issue additional subordinate regulations or further guidance in relation to this certification regime. We will continue to monitor any such developments and keep you updated accordingly.

Should any organization be interested in obtaining a certificate or certification mark, conducting a pre-assessment, or preparing the necessary documents to support an application, we would be pleased to provide advice and assistance.

Endnotes

*1
The Privacy Maturity Model (“PMM”) is an online self-assessment tool developed by the PDPC for Thai organizations to voluntarily assess their compliance with the PDPA across various areas. However, as of the date of this article, the PMM is not publicly available to all organizations; rather, it is made available periodically during designated sessions or upon specific request.

This newsletter is given as general information for reference purposes only and therefore does not constitute our firm’s legal advice. Any opinion stated in this newsletter is a personal view of the author(s) and not our firm’s official view. Given the nature of this newsletter as general information, statutory provisions and source citations may have been intentionally omitted. For any specific matter or legal issue, please do not rely on this newsletter but make sure to consult a legal adviser. We would be delighted to answer your questions, if any.

Download full text(PDF)

Lawyers

Data Protection and Privacy Related Publications

Global Practice Related Publications

Asia and Oceania Related Publications

Thailand Related Publications

  • HOME
  • Publications
  • Enhancing Data Governance under Thailand’s PDPA: The Introduction of PDPA Compliance Certificate and Certification Mark (Thailand)