Thailand PDPA (PDPA B.E. 2562 + PDPC Thailand)
Thailand’s Personal Data Protection Act B.E. 2562, in force since
2022, reads closer to the EU shape than Singapore’s regime does:
express consent at collection for marketing, a rights chapter
administered by the Personal Data Protection Committee (PDPC
Thailand), and explicit processing-records duties in sections 39–41.
The access-and-correction clock both markets share is the 30-day
pdpa family on the DSAR page. Two things
separate Thailand from Singapore for an operator: there is no
national DNC register to scrub, so your own suppression layer answers
for every recipient who revoked, and the consent line is the strict
one — unbacked contacts should receive no marketing at all. The
combined
Singapore and Thailand PDPA Posture
page holds the cross-market obligation map; this page is the
Thailand-only checklist and worked sequence. Singapore’s
self-standing page is
Singapore PDPA.
This page describes Orbit’s platform controls. It is not legal
advice. Which PDPA obligations apply to you — express consent or
an exception, what basis fits a cross-border transfer — depends on
your processing. Confirm with qualified counsel.
The TH checklist
Data-residency posture.
Thailand’s cross-border transfer rule accepts the adequate-
destination, BCR, and consent-style bases; which fits is the
assessment you run on your transfer facts. For voice, the residency
pin (Voice Data Residency)
records where recordings physically live, and BYOK
(BYOK Customer Managed Keys)
carries the localization claim where you need it. Map the whole
transfer posture per
Data Residency Overview.
Sender registration.
Read the TH rows returned by
GET /compliance/country-rules?channel=sms for the channel you send;
Thailand’s PDPC regime is consent-led, so sender registration sits
at the operator and aggregator level rather than in a regulator
pre-approval. The row, not this page, is authoritative, and
Country Compliance Requirements
documents the read.
KYC document roles.
Operator- and aggregator-facing filings attach to the
KYC identity model: corporate
identity as business_doc, address evidence as address_proof,
individual signers as id_proof. Orbit never files a registration on
your behalf; it exposes the row and the gate and delivers once the
row reports approved.
Opt-in aliases.
Thailand takes the express-consent line: record the grant per channel
with lawful_basis: consent and the purpose string your TH notice
disclosed (s6 turns on the disclosed purpose), and keep
unknown_marketing_policy: refuse plus
consent_default_policy: deny_on_missing for TH recipients so an
unbacked contact receives no marketing — the two knobs are
tenant-owned, see
Consent Posture: The Unknown-Consent Policies.
English STOP aliases are the canonical APAC expectation; extend the
vocabulary on the
Opt-Out Keyword Alias Table
and treat every reply as a suppression entry.
DSAR clock.
Requests from Thai data subjects file under the same coded
jurisdiction, applicable_jurisdiction: "pdpa" — the 30-day
clock tracks the request with or without the SG/TH split. Erasure
outcomes flow into suppression the same way as Singapore subjects.
DST concern.
Thailand sits at a fixed UTC+7 with no DST. No statutory quiet-hours
window exists; the restraint inherits from carrier practice. Set a
recipient-timezone-resolved default (21:00–08:00 TH time) on
Quiet-Hours Configuration and
validate it with
Quiet-Hours Preview.
Worked sequence for a Thailand recipient
Step 1 — capture consent explicitly.
Step 2 — sender and scrub. Thailand has no DNC register in the
scrub chain; your suppression layer answers for every recipient who
revoked regardless. The country-rules row for TH on the channel you
send is the sender-registration answer.
Step 3 — wire withdrawal to suppression. STOP replies and the
consent API with opt_in: false land on the same list —
Opt-Out & Suppression Lists.
Step 4 — file a DSAR on the same pdpa code.
Step 5 — register TH activities separately. File the TH-facing
processing activities in the
Privacy Register separately from any
Singapore ones — the s39–41 RoPA-class inventory answers against the
activities you filed, not against a cross-market merge. Record
notifications to the PDPC Thailand in the
Breach Incident Register
(s48); the notification itself is your act. The
Evidence Binder reads both sets when a
reviewer asks for the whole program.