Enabler Space

What is PDPA and Why It Matter?

Nowadays our personal information is used everywhere – whether it be processing transactions and applications such as opening a bank account, applying for membership, shopping online, etc. The issue is we fill these data only for those services but, in reality, our data is being used commercially or shared with other parties because companies are looking to gain as much data as possible for their analytics. The more data a company has – the more advantage they have competing in the same industry.

[Originally posted on April 2, 2020]

[Updated on May 21, 2020, due to the update from the Cabinet of Thailand] The effective date of PDPA will be postponed from May 27, 2020, to May 31, 2021.

One such experience many of you may have encountered already – is getting a random call from a company and tried to sell their products or services to you. The catch is – you don’t know them or have never contacted them before. This counts as a personal rights violation. These calls and approaches make people feel uneasy and sometimes scared but we couldn’t do anything since there were no specific laws that regulated this aspect of our digital footprint in Thailand until PDPA or Personal Data Protection Act was published on 27 May 2019 in Thailand’s Government Gazette.

Under the supervision of the Data Protection Committee, Ministry of Digital Economy and Society – here is some summarized key compliance of the act:

pdpa-eng

Therefore, all organizations should revisit their processes and identify if they have complied with this act prior to collecting personal information. If not, we highly recommend to learn the details of this act, verify, and adjust internal processes to comply with PDPA before it’s too late.

For website owners – there’s one thing that can be done right away – that is a consent form that indicates what data will be collected when using the website and why. For those with tools such as  Google Analytics, Facebook Pixel, and other analytic tools in place, a cookie banner should be set-up to ensure compliance with PDPA. You can also consult one of our experts for additional guidance and implementation methods.

At the end of the day, the publication of this act is a good start to developing meaningful measures for the Thai economy and society in this digital age. It is regarded as a concrete standard to control the use of personal data and also conforms with other developed countries that have enforced similar regulations such as the European Union’s GDPR (General Data Protection Regulation) and Singapore’s PDPA which was enacted prior to Thailand.

Exit mobile version