Data Protection and Privacy 2025

THAILAND Law and Practice Contributed by: Pranat Laohapairoj, Suphakorn Chueabunchai and Pitchaya Roongroajsataporn, Chandler Mori Hamada

5.4 Blocking Statutes There are no blocking statutes under Thai pri - vacy laws. 5.5 Recent Developments On 25 December 2023, the PDPC introduced two notifications regarding cross-border trans - fers of personal data under Sections 28 and 29, with the details summarised as follows. Notification Regarding Criteria for Adequate Countries (Section 28) This notification outlines two key criteria for determining if a destination country qualifies as having adequate data protection standards: • the legal system pertaining to personal data protection in the destination country must be at least equivalent to or more stringent than the PDPA; and • the country must have a proper authority or organisation to enforce its data protection laws. In any case, the transferor is entitled to assess the adequacy of the destination country’s data protection standard by itself. Additionally, the PDPC may consider and issue a list of adequate countries in the near future.

Notification Regarding Appropriate Safeguards (Section 29)

In the absence of an “adequacy list”, cross- border transfers can only occur if data export - ers implement appropriate safeguards to ensure PDPA-compliant protection standards. This noti - fication sets out types of and criteria for certain acceptable safeguards under the PDPA, which shall include BCRs, SCCs and certifications. • BCRs are legally binding data protection policies adhered to by related parties, includ - ing related groups or affiliated companies, for cross-border data transfers. In any case, the parties to the transfer must obtain PDPC approval prior to the application of BCRs. • SCCs are standardised data protection provisions that ensure compliance with data protection laws. They must address data processing activities and legal compliance, regulating controllers and processors to main - tain data security standards. This notification allows the parties involved in data transfer to refer to SCCs from certain international mod - els, including those of the EU and ASEAN. • Controllers or processors may consider obtaining a certification for their cross- border data transfer and related processing activities; the details are subject to further announcement.

466 CHAMBERS.COM

Powered by