ข้ามไปยังเนื้อหาหลัก

ฉบับภาษาไทย: อ่านหน้านี้เป็นภาษาไทย

Which organisations must appoint a Data Protection Officer under Thai PDPA?

Short answer

The Personal Data Protection Act B.E. 2562 (2019) requires a DPO where the controller or processor is a public authority, where the core activity requires regular and systematic monitoring of personal data on a large scale, or where the core activity involves sensitive personal data. Outside those cases a DPO is optional but often sensible.

'Core activity' is the test people get wrong. Monitoring is only caught when it is central to what the organisation does — a platform that profiles users, a security operation running continuous CCTV analytics, a health or HR service handling sensitive categories. A shop that keeps a customer list is not automatically in scope. Where you are close to the line, document the assessment; a defensible written analysis is worth more than an unexplained conclusion.

The role has substance attached. A DPO must be reachable by data subjects and by the regulator, must be able to advise without penalty, and cannot be dismissed for performing the function. A group can share one DPO if each entity remains contactable. Publishing the contact point and logging what the DPO reviewed is the evidence a regulator asks for first. Scope, turnaround and fees are confirmed by IVC staff by phone, LINE or email — this site does not publish prices.

Reviewed as of 2026-08-04. General guidance only, not case-specific advice and not a guarantee of outcome. Government fees, conditions and processing times are set by the responsible authority and can change. This site does not publish prices — please ask our staff.

ให้เจ้าหน้าที่ตรวจขอบเขตงานและเอกสารก่อนเริ่ม

สอบถามรายละเอียดและเงื่อนไขได้ทางโทรศัพท์ LINE หรืออีเมล

Related questions and topics