ข้ามไปยังเนื้อหาหลัก

ฉบับภาษาไทย: อ่านหน้านี้เป็นภาษาไทย

How quickly must a personal data breach be notified under Thailand's PDPA?

Short answer

The Personal Data Protection Act B.E. 2562 (2019) requires a data controller to notify the Personal Data Protection Committee without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, those individuals must be notified as well, together with the remedial measures taken.

The 72 hours run from awareness, not from full understanding, so the notification is expected to be made on partial information and supplemented later. Organisations that wait for a complete forensic picture routinely miss the window. A short internal escalation rule — whoever sees it tells the DPO the same day — is worth more than a long incident policy nobody reads.

Processors have a separate duty: they must notify their controller, and the controller then decides on the regulatory notification. Get that chain into the data processing agreement rather than discovering it during an incident, and keep a breach register even for events you conclude are not notifiable, because the reasoning is what a regulator will ask to see.

Reviewed as of 2026-08-04. General guidance only, not case-specific advice and not a guarantee of outcome. Government fees, conditions and processing times are set by the responsible authority and can change. This site does not publish prices — please ask our staff.

ให้เจ้าหน้าที่ตรวจขอบเขตงานและเอกสารก่อนเริ่ม

สอบถามรายละเอียดและเงื่อนไขได้ทางโทรศัพท์ LINE หรืออีเมล

Related questions and topics