As Thailand continues to refine its data protection landscape, business operators involved in collecting and handling personal data must be aware of a significant regulatory update. The recently published “Notification on the Criteria for Personal Data Deletion, Destruction, and De-identification” is set to take effect on November 11, 2024. This notification introduces critical changes that data controllers must adhere to, particularly regarding handling personal data deletion, destruction, or anonymization requests.
This regulatory update is the first administrative fine for non-compliance with the PDPA’s requirements recently levied on a major Thai company. This action reminds us that robust data management strategies are not just lip service to compliance but must be integral to maintaining strong, transparent relationships with stakeholders in an increasingly data-conscious world.
Key Changes and Requirements
Among the central tenets of the Personal Data Protection Act (PDPA) is the need to obtain explicit consent from stakeholders before collecting their personal data. This meets legal requirements and establishes a foundation of trust and transparency between businesses and their stakeholders. This ensures that stakeholders are fully informed about the purposes for which their data will be used and gives them control over their personal information.
Considering the new notification, businesses must be prepared to respond efficiently to requests to delete, destroy, or anonymize personal data. This entails developing and enforcing policies that guide the handling of personal data from collection through to deletion, ensuring alignment with the latest regulatory requirements.
Key elements of the Notification are as follows:
Extended Deadline for Compliance: Data controllers (DCs) must comply with requests for the deletion, destruction, or anonymization of personal data within 90 days, an extension from the previous 60-day requirement. This additional time provides DCs with the necessary window to ensure thorough compliance while maintaining the integrity of their data-handling processes.
Flexibility in Methods: The notification introduces flexibility for DCs by allowing them to employ alternative methods to handle personal data, provided these methods align with the criteria specified in the Notification. However, it is crucial to note that this flexibility does not apply to cases where personal data was unlawfully processed. In such instances, the data must be deleted or destroyed rather than anonymized, adhering to strict regulatory compliance.
Terminological Precision: A notable change in the notification is the shift in terminology from “risk” to “possibility” concerning de-identifying or anonymizing personal data. This change is intended to offer greater clarity and precision in interpreting the requirements, ensuring that DCs are fully aware of their obligations and regulators’ expectations.
Expanded Exemptions: The updated notification also broadens the scope of exemptions to data deletion, destruction, or de-identification requirements. These exemptions now include scenarios where technical limitations make compliance unfeasible or fulfilling such requests could infringe on another individual’s rights or interests. This consideration highlights the balance the regulation seeks to maintain between data protection and the practical realities of data management.
Organizational and Technical Measures: To ensure compliance with these new requirements, DCs must implement appropriate organizational, technical, and physical measures. These measures may include pseudonymization or other processes designed to render the data non-identifiable, both directly and indirectly. Furthermore, DCs must establish systems to verify and execute the deletion or destruction of personal data in line with the Notification and Section 37(3) of the Personal Data Protection Act B.E. 2562 (PDPA).
What will this Notification mean?
Under the new regulations, stakeholders possess various rights regarding their personal data, such as the right to access, correct, or request the deletion of their data. Businesses must be prepared to honor these rights while justifying their data collection practices based on legal grounds, such as consent, contractual necessity, or legitimate business interests.
This means having robust data management policies in place for businesses operating in Thailand or dealing with Thailand-based data subjects. Compliance with these new regulations will require a thorough review and potential overhaul of existing data handling practices.
Companies should anticipate increased data subject requests as awareness of these rights grows. As such, data controllers should ensure they are prepared to respond promptly and accurately to such requests, including establishing clear procedures for communication with data subjects regarding the fulfillment or potential limitations of their requests.
The Notification represents a critical evolution in Thailand’s data protection framework. By extending deadlines, introducing flexibility, and expanding exemptions, the notification aims to balance safeguarding personal data and accommodating the practical challenges data controllers face. Businesses must stay informed and proactive in their approach to data protection to remain compliant and uphold the trust of their customers and partners.
Silk Legal can provide services in several practice areas, including Data Privacy and ESG compliance. This article is for information only. While we have tried to keep our updates as accurate as possible, changes to legislation or other factors may affect your decisions. Please feel free to contact us for a free consultation at [email protected].
