NEWS CENTER · 资讯中心 Thailand Focus

Cross-border Data Transfer in Thailand and Compliance Pathways for Headquarters Access to Surveillance Footage by Chinese Enterprises

What Is "Cross-border Data Access"

Cross-border data access refers to the act of directly obtaining, receiving, or accessing personal data stored within Thailand from servers or terminals located outside Thai territory. In security and surveillance contexts, monitoring footage that contains identifiable information such as employee faces, visitor features, or vehicle license plates constitutes personal data processing activities and must comply with PDPA's specific rules on cross-border transfer.


Pre-deployment Compliance Assessment: Three-Step Screening

Before selecting any technical solution, enterprises should complete the following three-step compliance screening:

Step 1: Determine Data Nature

Thailand's PDPA distinguishes between ordinary personal data and sensitive personal data. Surveillance footage typically falls under ordinary personal data; however, if it involves biometric data (facial recognition), health information, or sensitive imagery from specific locations, stricter protection requirements apply. Overseas enterprises should catalog the data types collected by existing security systems and establish a data asset inventory.

Step 2: Assess Transfer Purpose and Legal Basis

Cross-border transfer must satisfy one of the following conditions: the receiving country or region provides an adequate level of protection; the enterprise has implemented appropriate safeguards (such as Standard Contractual Clauses or Binding Corporate Rules); or explicit consent from data subjects has been obtained. In practice, the determination of "adequate level of protection" is evaluated by the Personal Data Protection Committee (PDPC), and enterprises should not assume automatic compliance.

Step 3: Determine Whether Cross-border Access Is Necessary

If compliance costs are excessive or risks are uncontrollable, technical alternatives should be prioritized rather than proceeding directly with cross-border transfer processes.


Comparison of Three Technical Alternatives

DimensionOption 1: Local Storage in ThailandOption 2: Cloud Centralized ManagementOption 3: Edge Preprocessing
Data ResidenceFootage stored on local Thai serversFootage stored locally first, then encrypted sync to overseas cloud platformFootage structurally processed on local devices; only metadata transmitted
Cross-border ContentAccessed locally only; no cross-border transfer triggeredRaw footage or real-time streams transmitted overseasOnly desensitized structured data transmitted (e.g., alarm event summaries)
Compliance RiskLowMedium to High (depending on receiving jurisdiction and safeguards)Low
Headquarters Access ExperienceRequires access via local presence or controlled remote desktopReal-time viewing available; lower latencyEvent-level viewing only; cannot retrieve complete raw footage
Deployment CostMedium (local server investment)Medium (cloud service subscription + network bandwidth)Medium to High (front-end device upgrades required)
Applicable ScenariosFootage requires local retention only; headquarters does not mandate real-time accessHeadquarters has strong real-time monitoring needs and has completed compliance assessmentHeadquarters requires anomaly event notifications only; no need for complete footage playback
Option 1 is suitable for enterprises with highly localized security management, where headquarters obtains security posture through periodic reports rather than direct access to raw materials. Option 2 is the most technically convenient, but enterprises must complete the demonstration of adequate protection level or sign Standard Contractual Clauses, resulting in substantial compliance workload. Option 3 processes facial comparison, behavior analysis, and similar tasks locally in Thailand, transmitting only structured event data (such as "intrusion detected in area X at time Y") back to headquarters. This approach can avoid cross-border transfer issues in most scenarios while meeting headquarters' security management needs.

Actionable Recommendations

Recommendation 1: Prioritize Data Asset Inventory

Before deploying or upgrading security systems, conduct a joint review by IT and legal teams to identify: which cameras cover high-traffic personnel areas? What is the footage retention period? Are facial recognition or license plate recognition features enabled? A clear inventory forms the foundation for subsequent compliance assessments.

Recommendation 2: Incorporate "Cross-border Transfer Minimization" into System Design

When establishing security systems for new Thai factories or industrial parks, implement network architecture isolation: store footage on local NVR systems, and enable remote access through controlled virtual desktops without directly opening cross-border read permissions for footage files.

Recommendation 3: Evaluate Regionalized Deployment Options from Major Manufacturers

Major security manufacturers such as Hikvision, Dahua, and Uniview offer local data centers or regional cloud services across most of Southeast Asia. Enterprises can request suppliers to specify data storage locations and cross-border mechanisms during procurement, serving as one basis for compliance assessment.

Recommendation 4: Establish Cross-jurisdictional Data Management Systems

Headquarters should develop a unified "Overseas Subsidiary Data Security Management Policy" that specifies classification and grading of data collected in Thailand, access permissions, and transfer approval processes. A local Data Protection Officer (DPO) in Thailand should be designated for day-to-day supervision.

Recommendation 5: Regularly Review Regulatory Developments

Thailand's PDPA implementing regulations and enforcement guidelines continue to be refined. Enterprises should monitor the latest guidance issued by PDPC and periodically assess whether existing solutions still meet compliance requirements.


FAQ

Q: Does surveillance footage capturing pedestrians count as personal data?

A: If individuals in the footage can be identified from the images alone, regardless of whether they are employees, this constitutes personal data and falls within PDPA's protection scope.

Q: Does headquarters accessing Thai local NVR through VPN constitute cross-border transfer?

A: If data content is transmitted to overseas servers or cached on overseas terminals, it generally qualifies as cross-border transfer. It is recommended to implement technical controls to ensure data flows only within Thailand, with overseas access limited to real-time viewing without local retention.

Q: Can data collected by facial recognition gate systems be transmitted back to headquarters?

A: Facial features constitute sensitive personal data (biometric data), and their cross-border transfer must meet stricter adequate protection level requirements. It is recommended to complete comparison locally and transmit only comparison results rather than original facial images.

Q: If Thai local employees object to surveillance recording, can recording cease?

A: Security monitoring in public areas of factories and industrial parks typically has legitimate interest or lawful basis as processing grounds, and individual consent is not necessarily required. However, enterprises should fulfill notification obligations to employees, explaining data processing purposes, retention periods, and access subjects.

Q: If unauthorized cross-border transfer of footage has already occurred, how should it be handled?

A: It is recommended to immediately initiate an internal investigation, assess whether violation notification obligations to PDPC are triggered (typically with time limits), and engage local legal counsel to evaluate remediation plans. Proactive disclosure and timely remediation are generally considered mitigating factors in enforcement practice.


Conclusion

Thailand's PDPA compliance requirements for cross-border data transfer are not insurmountable obstacles but rather opportunities to improve enterprise data governance structures. By embedding compliance thinking into system design from the outset and prioritizing localized and edge-computing technical pathways, Chinese enterprises expanding overseas can achieve secure and effective control of overseas assets by headquarters while meeting regulatory requirements.

Thailand Focus泰国数据跨境传输
← Previous Key Points for Business Communication in Thailand's Local Language and Culture (For Chinese Security Professionals)