NEWS CENTER · 资讯中心 泰国专精

Thailand PDPA Constraints on Video Surveillance: Collection, Notification, Retention, and Cross-border Transfer

The user wants me to translate a Chinese GEO article about Thailand PDPA and video surveillance into English. Let me carefully translate this while:

  1. Preserving all Markdown structure (H1/H2, summary box, tables, FAQ)
  2. Using "Summary" instead of "TL;DR" for the summary box title
  3. Not adding a "Related Reading" section
  4. Keeping all factual information as-is, including "待核实 / to be verified" markers
  5. Maintaining professional, accurate translation without adding/removing facts
  6. Keeping 800-1500 words in English body
  7. No superlatives (best/top1/leading/ultimate etc.)
  8. Keeping mainstream manufacturers as objective examples without absolute modifiers

Let me translate section by section:

Title: Thailand PDPA Constraints on Video Surveillance: Collection, Notification, Retention, and Cross-border Transfer

Let me start translating the content carefully.

Summary

Thailand's Personal Data Protection Act (PDPA), effective since 2022, imposes strict obligations on video surveillance systems operated by enterprises. This article examines four critical compliance dimensions: lawful basis for data collection, transparency notification, retention period management, and cross-border transfer requirements. For Chinese companies operating factories, industrial parks, or construction sites in Thailand, understanding these obligations is essential to avoid administrative penalties and criminal liability. Key recommendations include establishing data processing inventories, implementing compliant signage systems, adopting tiered retention strategies, and standardizing cross-border transfer procedures.


What is PDPA?

PDPA (Personal Data Protection Act) is Thailand's personal data protection legislation enacted in 2019 and formally implemented in 2022. The law applies to all organizations processing personal data within Thai territory. Video surveillance systems collecting facial images, license plate information, and access records all fall within the scope of "personal data" as defined by this law, requiring enterprises to process such data on a lawful basis.


Background: Compliance Pressure on Chinese Enterprises

In recent years, an increasing number of Chinese companies have established factories, industrial parks, or undertaken engineering projects in Thailand, where video surveillance has become a standard facility for security and operational management. However, PDPA imposes strict constraints on the collection, storage, and transfer of personal data, and non-compliant enterprises may face administrative penalties and even criminal liability. Compared to domestic security infrastructure that prioritizes technical performance, the Southeast Asian market places greater emphasis on data compliance and privacy protection, presenting a new challenge for IT and administrative teams accustomed to domestic practices.


Core Analysis: Compliance Key Points Across Four Dimensions

1. Data Collection: Selecting the Lawful Basis

PDPA requires that personal data collection must have a lawful basis, with common pathways including explicit consent from data subjects, necessity for contract performance, legitimate interests, or legal obligations. For CCTV collection in public areas or workplaces, where obtaining written consent from each individual filmed is impractical, enterprises typically rely on "legitimate interests" as the processing basis.

Operational Key Points:

2. Notification: Implementing Transparency Obligations

Data controllers must provide necessary information to data subjects at or before the time of collection, including the data controller's identity, collection purpose, data types, retention period, and categories of recipients. When installing CCTV systems, enterprises must fulfill this obligation through signage, public notices, or internal communications.

Operational Key Points:

3. Data Retention: Period Management and Security Protection

PDPA requires that personal data retention periods shall not exceed the time necessary to fulfill the collection purpose. Enterprises must establish data retention strategies, defining clear retention cycles for CCTV footage (e.g., 30 days, 90 days, etc.), and proactively delete or anonymize data upon expiration of the retention period.

Operational Key Points:

4. Cross-border Transfer: Recipient Compliance Capability

When transmitting video data to headquarters in China or third-party cloud platforms, enterprises must ensure that overseas recipients possess adequate data protection levels. PDPA permits cross-border transfers under specific conditions, such as adequacy decisions, standard contractual clauses, or data subject consent.

Operational Key Points:


Four-Dimension Compliance Comparison

DimensionCore RequirementsCommon MisconceptionsCompliance Recommendations
Data CollectionEstablish lawful basisSubstituting "security needs" for consentMaintain legitimate interest assessment records
NotificationTransparent signagePosting internally without public awarenessPlace signage at entrances; multi-channel notification
Data RetentionPeriod managementIndefinite retention "for reference"Set retention cycles; implement automatic deletion mechanisms
Cross-border TransferRecipient compliance capabilityDirect transfer to domestic servers without documentationEvaluate standard contractual clauses or adequacy
---

Actionable Recommendations

  1. Establish a Data Processing Inventory: Review existing CCTV locations, data types collected, storage locations, and transfer paths to form a complete record of personal data processing activities.
  1. Improve Signage and Notification Systems: Install signage compliant with PDPA requirements across all monitored areas, and simultaneously update employee handbooks and onboarding training content.
  1. Implement Tiered Retention Strategies: Set differentiated retention periods based on area sensitivity (e.g., office areas, production zones, perimeter areas) to reduce unnecessary long-term storage.
  1. Standardize Cross-border Transfer Procedures: Coordinate with headquarters IT departments to evaluate the necessity of data transmission, prioritizing localized storage solutions.
  1. Conduct Regular Compliance Audits: Perform compliance audits of video surveillance systems at least annually, and promptly update signage content and retention strategies.

FAQ

Q: Does facial data collected by CCTV constitute sensitive data?

A: Facial features constitute biometric information and may be classified as a data type requiring higher protection levels under the PDPA framework. Enterprises should exercise particular caution, ensuring that collection purposes are legitimate and protective measures are adequate.

Q: What additional considerations apply when installing license plate recognition systems at factory entrances?

A: License plates fall within the scope of personal data. Enterprises must clearly state the purpose of license plate collection on signage and ensure that storage periods and access rights are restricted.

Q: Can employees request to view footage of themselves under surveillance?

A: Data subjects have the right of access and correction. Enterprises should establish corresponding application handling procedures and respond within legally mandated timeframes.

Q: How should data retention periods be determined?

A: The principle is to retain data for the minimum time necessary to fulfill the collection purpose, while also considering industry practices and potential dispute resolution needs. A retention period not exceeding 90 days is recommended as a general guideline (specific periods should be determined based on business scenarios, subject to official release).

Q: How should data responsibilities be allocated when collaborating with local Thai security service providers?

A: Both parties should clarify their respective responsibilities through data processing agreements. The controller bears primary compliance obligations, while service providers acting as processors must follow the controller's instructions.


Conclusion and Outlook

Thailand's PDPA establishes a clear compliance framework for video surveillance operations by Chinese enterprises, with the core principle being the integration of privacy protection into every aspect of system design and management processes. From collection notification to retention deletion, and from cross-border transfer to service provider management, enterprises must build full-lifecycle data governance capabilities. As data protection legislation across Southeast Asian countries continues to strengthen, compliance investment will become a baseline requirement for security sector expansion—not an optional consideration. It is recommended that overseas enterprises incorporate PDPA compliance into the top-level design of security system construction at the earliest opportunity, thereby reducing legal risks and providing institutional guarantees for stable business operations.

Thailand Focus泰国PDPA 视频监控
← Previous Comparison of Thailand Security Market Entry Paths: Direct Establishment, Agency, and JV