PDPA Bares Its Teeth –  Slaps A Hefty Fine On A Non-Compliant Company

Home » PDPA Bares Its Teeth –  Slaps A Hefty Fine On A Non-Compliant Company

In our previous discussions on Thailand’s Personal Data Protection Act (PDPA), we emphasized the critical need for organizations to establish a robust response plan during a data breach. The recent actions taken by the Personal Data Protection Committee (PDPC) have underscored this urgency, as the first administrative fine under the PDPA has been levied against a prominent Thai company.

The company, a major player in Thailand’s business landscape, was fined THB 7 million for failing to adhere to PDPA requirements. This resulted in the unauthorized disclosure of personal data to a call center gang involved in phone scams. This breach is particularly concerning given the widespread impact of such scams across the country, which result in significant financial losses.

Understanding the Liabilities under the PDPA

The violations that led to this fine were multifaceted:

  • Absence of a Data Protection Officer (DPO): Despite handling the personal data of over 100,000 individuals, the company failed to appoint a DPO, as mandated by the PDPA. The DPO serves as the primary contact for issues related to personal data protection, and the absence of this role was a critical oversight.
  • Insufficient Security Measures: The company’s inadequate security infrastructure allowed the data breach to occur, causing significant damage.
  • Delayed Breach Notification: The company failed to notify the relevant authorities within the required timeframe and did not promptly address the breach, exacerbating the situation.

Under the PDPA, data controllers and processors can face significant liabilities, including actual and punitive damages that may amount to twice the actual damages awarded by the court. The risks include civil, criminal, and administrative liabilities, with administrative fines imposed for various violations, including failure to notify data subjects of data collection purposes, not providing access to personal data upon request, and delayed breach notifications.

In this case, the PDPC, along with the PDPA’s Expert Committee, not only imposed a monetary fine but also issued a corrective order. The company was required to upgrade its security protocols to prevent future breaches, ensuring that these measures keep pace with evolving technologies. It must also implement mandatory training for relevant personnel to ensure compliance with data protection practices.

Implications for Thailand’s Business Community

This administrative action marks a significant moment in Thailand’s data protection landscape. It sends a clear message to all organizations that the PDPA will be enforced, and non-compliance will result in severe consequences.

The enforcement of these penalties establishes a precedent for both governmental and commercial sectors in Thailand. It reinforces the importance of PDPA compliance, particularly regarding implementing robust security measures, timely notification of breaches, and appointing a designated DPO as required by the regulation. The financial and reputational risks associated with non-compliance are more evident than ever.

Additionally, businesses must take note of the recently published notification on the Criteria for Personal Data Deletion, Destruction, and De-identification, set to take effect on November 11, 2024. Under this notification, data controllers must delete, destroy, or de-identify personal data upon request within 90 days, up from the previous 60 days.

This landmark decision sets a new data protection and compliance standard in Thailand. Businesses operating in or connected to Thailand must reassess their data protection strategies to ensure they meet the latest legal requirements and avoid similar breaches and penalties in the future. Enforcing the PDPA is no longer just a theoretical risk but an absolute and present necessity for all organizations handling personal data in Thailand.

Silk Legal can provide a range of services for several practice areas in including Data Privacy and ESG Compliance. This article is for information only. While we have tried to keep our updates as accurate as possible, changes to legislation or other factors may affect your decisions. Please feel free to contact us for a free consultation at [email protected].

Author

Contact Us

Shopping Basket