• HOME
  • Publications
  • Thailand PDPA Update: PDPC Issues Long-Awaited Rules on Data Subject Access Requests Under Section 30

Publication

Newsletters

Thailand PDPA Update: PDPC Issues Long-Awaited Rules on Data Subject Access Requests Under Section 30

Author
Shohei Sasaki, Shunsuke Minowa, Poonyisa Sornchangwat, Niparat Pothong (Co-author)
Publisher
Nagashima Ohno & Tsunematsu
Journal /
Book
NO&T Thailand Legal Update No.52 (August, 2026)
Reference
Practice Areas

*Please note that this newsletter is for informational purposes only and does not constitute legal advice. In addition, it is based on information as of its date of publication and does not reflect information after such date. In particular, please also note that preliminary reports in this newsletter may differ from current interpretations and practice depending on the nature of the report.

Introduction

Since the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) came into force in 2022, data subjects have been entitled, pursuant to Section 30, to exercise their right to request access to and obtain copies of personal data relating to them from data controllers as well as to request disclosure in respect of the acquisition of personal data which the data subject did not consent to (“Right of Access”). Nevertheless, in the absence of specific procedural guidance, both data subjects and data controllers have in practice faced practical uncertainties regarding the proper exercise and management of such rights.

To address such uncertainties, the Personal Data Protection Committee (“PDPC”) has issued the Notification of the Personal Data Protection Committee Re: Criteria for Access to and Obtaining Copies of Personal Data Relating to the Data Subject, which is under the Responsibility of the Data Controller, or Requesting Disclosure of the Acquisition of Personal Data for which the Data Subject Has Not Given Consent, B.E. 2569 (2026) dated 6 July 2026 (“Notification”), which was published in the Government Gazette on 16 July 2026. The Notification will take effect upon the expiration of 60 days from the date of publication, i.e., 14 September 2026.

The Notification establishes a clearer procedural framework for handling requests by data subjects to exercise their Right of Access under Section 30 of the PDPA, i.e., a Data Subject Access Request (“DSAR”), and sets out requirements relating to request submission, identity verification, response timelines, refusal, fees, and record retention. The framework aims to facilitate the exercise of data subjects’ rights while providing data controllers with clearer guidance for managing DSARs in a consistent and reasonable manner.

Key Requirements of the Notification

The Notification introduces detailed procedures governing the handling of DSARs under Section 30 of the PDPA. The following are the key requirements and procedures:

(1) Information Subject to DSARs (Clause 4 of the Notification)

In anticipation of DSARs, data controllers must make available information enabling data subjects to exercise their Right of Access, including:

  • personal data collected directly from the data subject;
  • personal data collected from sources other than the data subject;
  • to the extent practicable, the source of or the fact of acquisition of personal data where the data subject has not provided consent;
  • information required to be notified under Section 23 of the PDPA (i.e., privacy notices); and
  • records required to be maintained under Section 39 of the PDPA (i.e., records of processing activities (“RoPA”).

(2) Submission of DSARs (Clauses 5 and 6 of the Notification)

DSARs can be submitted by the data subject or their authorized representative and must be in writing or in electronic form and signed by the data subject or their authorized representative.

Data controllers must provide channels for submission of DSARs, including:

  • submission directly at the data controller’s office or notified contact address;
  • submission by post to the data controller’s office or notified contact address; or
  • submission through an electronic channel (this channel is not mandatory: it is an alternative channel that data controllers may consider providing).

(3) ID Verification Procedure and DSARs Consideration Timelines (Clauses 7 and 10 of the Notification)

For identity verification purposes, DSARs must be accompanied by the national ID card, passport, or other official identification document of the data subject or, where applicable, of their authorized representative. If the DSAR is submitted in person, the original identification document must be presented; while if the DSAR is submitted by post or electronic means, a copy of the relevant identification document must be provided. Data controllers must verify the correctness and completeness of the DSAR and supporting documents, and must also verify the identity of the requester. In principle, the verification must be completed within 15 days from receipt of the DSAR.

After data controllers confirm the correctness and completeness of a DSAR and verify the identity of the requester, the data controllers must, if the DSAR is not subject to a refusal circumstance under Clause 8 of the Notification, respond to the DSAR by either (i) granting the data subject the access to personal data relating to them and furnishing details in respect of the acquisition of personal data to which the data subject has not consented; (ii) providing copies of the requested information; or (iii) granting data subjects the access to, or providing copies of, the requested information via electronic means.

Such responses must be processed without delay and within 30 days from receipt of the DSAR. The processing period may be extended for up to an additional 30 days where the request involves a large volume of data or where other necessary circumstances prevent timely completion. The data controller must notify the data subject or the data subject’s authorized representative of the reasons for such extension.

(4) Refusal Right of Data Controllers (Clause 8 of the Notification)

Data controllers may refuse to proceed with a DSAR only in limited circumstances as follows:

  • the refusal is pursuant to the law or a court order;
  • disclosure would adversely affect the rights and freedoms of other individuals, including where the requested information contains another person’s personal data; confidential government information; trade secrets; copyrights; or other intellectual property rights – in these circumstances, data controllers are to proceed with the DSAR to the extent practicable by deleting, redacting, or otherwise withholding the problematic information; or
  • the request is clearly insignificant or would impose an unreasonable burden on the data controller.

Any refusal must be notified to the data subject or the authorized representative, and the reasons therefore must be recorded in the RoPA.

(5) Record Retention (Clause 12 of the Notification)

For verification and reference purposes, data controllers must for two years retain, whether physically or electronically, records of (i) DSARs and the supporting documents received; and (ii) the actions taken in response to, including any refusals of, the DSARs.

(6) Obligations with respect to Responding to DSARs under Other Laws (Clause 13 of the Notification)

Where data controllers are subject to obligations under other laws governing DSARs, they must comply with such laws while also ensuring that their procedures remain compliant with the Notification.

Conclusion and Recommendations

While the Notification primarily clarifies the procedural obligations of data controllers, it also underscores the need for organizations to move beyond merely maintaining privacy documentation, and establishes practical internal procedures to facilitate the effective exercise of data subjects’ rights.

The Notification, which is procedural in its nature, does not directly require data controllers to prepare any new documents or revise existing standard documents, such as privacy notices, consent forms, or RoPA, solely as a result of its enactment. This is because the Notification primarily sets out the procedures and requirements governing a data controller’s handling of DSARs, including the relevant process, timing, and manner of response. However, from a practical compliance perspective, it is advisable for data controllers to review their internal guidelines, templates, and other relevant documents to ensure that their internal processes are capable of supporting compliance with the Notification. Any necessary revisions would depend on the data controller’s existing documentation and internal practices, rather than arising as a mandatory requirement under the Notification itself.

In practice, handling DSARs often requires coordination across multiple functions, including legal, IT, human resources, and customer service – a process which may create complexity and confusion. Establishing a clear and well-documented DSAR workflow will enable relevant personnel within the organization to manage requests more efficiently; facilitate compliance with the PDPA; and mitigate the legal and operational risks arising from the inconsistent handling of access requests.

This newsletter is given as general information for reference purposes only and therefore does not constitute our firm’s legal advice. Any opinion stated in this newsletter is a personal view of the author(s) and not our firm’s official view. Given the nature of this newsletter as general information, statutory provisions and source citations may have been intentionally omitted. For any specific matter or legal issue, please do not rely on this newsletter but make sure to consult a legal adviser. We would be delighted to answer your questions, if any.

Download full text(PDF)

Lawyers

Data Protection and Privacy Related Publications

Global Practice Related Publications

Asia and Oceania Related Publications

Thailand Related Publications

  • HOME
  • Publications
  • Thailand PDPA Update: PDPC Issues Long-Awaited Rules on Data Subject Access Requests Under Section 30