NEWS CENTER · 资讯中心 Policy & Compliance

Thailand PDPA vs. EU GDPR: Practical Implications for Security Companies

Concept Definitions

PDPA (Personal Data Protection Act) is Thailand's data protection law that officially took effect in 2022, designed to regulate the collection, use, and disclosure of personal data. GDPR (General Data Protection Regulation) is the EU's data protection framework that took effect in 2018, applicable to organizations operating within the EU and those providing services to EU residents from abroad. Both regulations classify footage and biometric data generated from video surveillance, biometric access control, and other security scenarios as personal data falling under protection requirements.

Core Dimension Comparison

Scope and Jurisdictional Nexus

DimensionThailand PDPAEU GDPR
Geographic ScopeData controllers and processors operating in Thailand; overseas entities providing services in ThailandOverseas entities providing goods or services to EU residents; overseas entities monitoring EU data subjects
Threshold RequirementsNo turnover thresholdNo turnover threshold, but partial exemptions for SMEs
Nexus DeterminationData processing activities occur within ThailandData subjects are located in the EU
For Chinese security enterprises with multi-country operations across Southeast Asia, assessing each regulation's applicability separately is necessary when serving both Thai and European markets. PDPA's nexus is primarily based on where data processing activities occur, while GDPR uses the data subject's location as the core determinant.

Lawful Basis for Processing

Both regulations require that data processing have a lawful basis, yet they differ in specific wording and flexibility of application.

Thailand PDPA establishes seven lawful bases: consent of the data subject, contract performance, legal obligation, protection of life interests, public interest, government execution, and legitimate interests.

EU GDPR establishes six lawful bases: consent, contract performance, legal obligation, protection of vital interests, public task, and legitimate interests.

In video surveillance scenarios, both regulations recognize "legitimate interests" as a valid basis for data processing. For instance, enterprises can claim legitimate interests by posting visible notices in monitored factory, campus, or construction site areas, clearly stating the monitoring purpose and scope. However, GDPR imposes more detailed balancing test requirements for legitimate interests, requiring demonstration that enterprise interests are not overridden by data subject rights.

For processing involving biometric data such as facial recognition or fingerprint attendance systems, GDPR classifies these as special category data requiring explicit consent or specific exceptions. PDPA similarly categorizes biometric data as sensitive personal data, requiring stricter conditions for processing. Intelligent surveillance solutions offered by mainstream manufacturers (such as Hikvision, Dahua, Uniview, Axis, and Bosch) require compliance adaptation for both European and Thai markets.

Cross-Border Data Transfer Mechanisms

DimensionThailand PDPAEU GDPR
Transfer RestrictionsRestricts transfers to overseas recipients without adequate protection levelsRestricts transfers to third countries without adequate protection levels
Compliance MechanismsData subject consent, specific certifications, standard contractual clausesAdequacy decisions, standard contractual clauses, binding corporate rules, certification mechanisms
Data LocalizationNo mandatory localization, but recipient protection levels must be assessedNo mandatory localization, but transfer mechanisms must be in place
When Chinese security enterprises operating in Southeast Asia and Europe need to transfer surveillance data to domestic data centers or cloud platforms, they must satisfy each regulation's cross-border transfer requirements. PDPA requires assessment of the destination country's protection level, while GDPR provides a more defined transfer mechanism framework.

Data Subject Rights Protection

Right TypeThailand PDPAEU GDPR
Right of AccessData subjects may request access to their personal data and processing informationData subjects may request access to their personal data
Right to RectificationRight to request correction of incomplete or inaccurate dataRight to request correction of inaccurate data
Right to ErasureRight to request deletion of data no longer necessaryRight to request deletion under specific circumstances (right to be forgotten)
Right to RestrictionRight to request restriction of processingRight to request restriction of processing
Right to PortabilityNot explicitly established as separate legislationRight to receive data in structured, commonly used format
Right to ObjectRight to object based on legitimate interestsRight to object based on legitimate interests or public task
When data subjects exercise these rights in video surveillance contexts, enterprises must respond within specified timeframes. GDPR typically requires response within one month; PDPA requires processing within a reasonable timeframe after receiving the request, with specific timeframes subject to official release.

Penalties and Enforcement Mechanisms

DimensionThailand PDPAEU GDPR
Maximum PenaltiesMaximum criminal fines of 1 million THB; maximum civil fines of 5 million THB (to be verified / subject to official release)Maximum of 20 million EUR or 4% of global annual turnover, whichever is higher
Enforcement AuthorityPersonal Data Protection Committee (PDPC)Data Protection Authorities (DPAs) in each EU member state
Enforcement FocusCompliance obligations of data controllers and processorsCompliance obligations of data controllers and processors
GDPR's penalty levels rank among the highest globally, creating significant compliance pressure for large multinational enterprises. PDPA's enforcement mechanism encompasses both criminal and civil dimensions, though overall penalty caps are comparatively lower.

Compliance Recommendations

For security enterprises operating in both Southeast Asia and Europe, the following measures are recommended:

Develop region-specific privacy policies. Create privacy notices and data processing disclosures tailored to Thai and EU markets respectively, addressing each regulation's distinct requirements.

Improve monitoring area disclosures. Install visible notices at all monitoring points explaining monitoring purposes, data retention periods, and contact channels to satisfy transparency requirements under both regulations.

Establish data subject request response procedures. Develop standardized processes for handling access, rectification, and erasure requests, ensuring responses within stipulated timeframes.

Evaluate cross-border transfer compliance pathways. If transferring overseas surveillance data to domestic infrastructure is necessary, assess and implement compliant cross-border transfer mechanisms in advance.

FAQ

Can Thailand PDPA and GDPR apply simultaneously?

Yes. If an enterprise operates in both Thailand and the EU, and monitoring subjects include Thai and EU residents, compliance with both regulations is required. The two frameworks align on core principles but differ in specific provisions and application details.

Does facial recognition systems used by security enterprises require additional permits?

Both regulations classify biometric data as sensitive data requiring stricter conditions for processing. Whether additional permits are necessary depends on factors including actual application scenarios, data types, and processing purposes. Consultation with local legal counsel is recommended.

What are the requirements for data retention periods?

Both regulations require that data retention periods not exceed what is necessary for processing purposes. Surveillance data retention periods should be reasonably set based on specific scenarios (such as factory safety, access control, public area monitoring) and clearly disclosed in privacy notices.

Do employee monitoring rules apply identically?

Workplace monitoring is restricted under both frameworks. GDPR requires employers to balance legitimate interests against employee privacy rights; PDPA similarly requires employers to fulfill transparency obligations and limit monitoring scope. Enterprises are advised to develop dedicated employee privacy policies before implementing employee monitoring.

What are the consequences of non-compliance?

Beyond monetary penalties, both regulations empower regulatory authorities to take enforcement actions, including issuing corrective orders and suspending data processing activities. Specific penalty amounts and enforcement procedures are subject to official release. Enterprises are advised to integrate compliance into day-to-day operations management.

Policy & Compliance泰国PDPA GDPR对比
← Previous Data Protection Laws Across Southeast Asia: Thailand PDPA, Indonesia PDP and Vietnam (2026 Edition)