Thailand’s Personal Data Protection Committee has proposed major amendments to the Personal Data Protection Act (PDPA) that would exempt small and medium-sized enterprises, startups, and community enterprises from strict compliance burdens. According to legal analysis published by Tilleke & Gibbins on Mondaq, the draft revisions aim to reduce administrative and financial hurdles for smaller entities while maintaining baseline security standards for handling consumer data.
Exemptions and Relief for SMEs and Startups
Under the proposed regulatory changes, qualifying small and medium-sized enterprises, startups, and community ventures will receive partial or full relief from specific statutory obligations. According to Tilleke & Gibbins, lawmakers designed the adjustments to prevent compliance costs from stifling innovation among early-stage businesses. While large corporations and data-heavy industries will still face rigorous oversight, smaller operators gain breathing room on record-keeping and administrative workflows.
The adjustments respond to widespread feedback from the Thai business community since the comprehensive enforcement of the PDPA began. Business groups previously argued that applying identical data controller standards to corner shops and multinational tech firms created disproportionate operational friction.
Refining Enforcement and Accountability Standards
Beyond small business relief, the draft amendments clarify obligations regarding data protection officers (DPOs) and data breach notifications. According to regulatory summaries provided by legal experts, the revisions fine-tune the thresholds that mandate appointing a dedicated DPO, focusing on actual risk levels rather than blunt sector-wide rules. Companies handling sensitive personal data or large-scale profiling will still face strict mandates, but lower-risk operators will see streamlined requirements.
The Personal Data Protection Committee continues to review stakeholder feedback on the text before submitting final legislative packages to the Thai cabinet and parliament for formal enactment.
Frequently Asked Questions
Which businesses qualify for the proposed PDPA exemptions?
According to legal analyses of the draft text, qualifying small and medium-sized enterprises, certified startups, and registered community enterprises stand to benefit from reduced administrative burdens.
Do the amendments remove all data privacy rules for small businesses?
No. While compliance workflows and record-keeping rules become more flexible, baseline consumer privacy protections and fundamental data security duties remain active under Thai law.
What is the next step for the proposed amendments?
The Personal Data Protection Committee is processing public and stakeholder commentary before advancing the final draft to the Thai government for legislative review and approval.
Keep reading