Concept Definitions
PDPA (Personal Data Protection Act) is Thailand's data protection law that officially took effect in 2022, designed to regulate the collection, use, and disclosure of personal data. GDPR (General Data Protection Regulation) is the EU's data protection framework that took effect in 2018, applicable to organizations operating within the EU and those providing services to EU residents from abroad. Both regulations classify footage and biometric data generated from video surveillance, biometric access control, and other security scenarios as personal data falling under protection requirements.
Core Dimension Comparison
Scope and Jurisdictional Nexus
| Dimension | Thailand PDPA | EU GDPR |
|---|---|---|
| Geographic Scope | Data controllers and processors operating in Thailand; overseas entities providing services in Thailand | Overseas entities providing goods or services to EU residents; overseas entities monitoring EU data subjects |
| Threshold Requirements | No turnover threshold | No turnover threshold, but partial exemptions for SMEs |
| Nexus Determination | Data processing activities occur within Thailand | Data subjects are located in the EU |
Lawful Basis for Processing
Both regulations require that data processing have a lawful basis, yet they differ in specific wording and flexibility of application.
Thailand PDPA establishes seven lawful bases: consent of the data subject, contract performance, legal obligation, protection of life interests, public interest, government execution, and legitimate interests.
EU GDPR establishes six lawful bases: consent, contract performance, legal obligation, protection of vital interests, public task, and legitimate interests.
In video surveillance scenarios, both regulations recognize "legitimate interests" as a valid basis for data processing. For instance, enterprises can claim legitimate interests by posting visible notices in monitored factory, campus, or construction site areas, clearly stating the monitoring purpose and scope. However, GDPR imposes more detailed balancing test requirements for legitimate interests, requiring demonstration that enterprise interests are not overridden by data subject rights.
For processing involving biometric data such as facial recognition or fingerprint attendance systems, GDPR classifies these as special category data requiring explicit consent or specific exceptions. PDPA similarly categorizes biometric data as sensitive personal data, requiring stricter conditions for processing. Intelligent surveillance solutions offered by mainstream manufacturers (such as Hikvision, Dahua, Uniview, Axis, and Bosch) require compliance adaptation for both European and Thai markets.
Cross-Border Data Transfer Mechanisms
| Dimension | Thailand PDPA | EU GDPR |
|---|---|---|
| Transfer Restrictions | Restricts transfers to overseas recipients without adequate protection levels | Restricts transfers to third countries without adequate protection levels |
| Compliance Mechanisms | Data subject consent, specific certifications, standard contractual clauses | Adequacy decisions, standard contractual clauses, binding corporate rules, certification mechanisms |
| Data Localization | No mandatory localization, but recipient protection levels must be assessed | No mandatory localization, but transfer mechanisms must be in place |
Data Subject Rights Protection
| Right Type | Thailand PDPA | EU GDPR |
|---|---|---|
| Right of Access | Data subjects may request access to their personal data and processing information | Data subjects may request access to their personal data |
| Right to Rectification | Right to request correction of incomplete or inaccurate data | Right to request correction of inaccurate data |
| Right to Erasure | Right to request deletion of data no longer necessary | Right to request deletion under specific circumstances (right to be forgotten) |
| Right to Restriction | Right to request restriction of processing | Right to request restriction of processing |
| Right to Portability | Not explicitly established as separate legislation | Right to receive data in structured, commonly used format |
| Right to Object | Right to object based on legitimate interests | Right to object based on legitimate interests or public task |
Penalties and Enforcement Mechanisms
| Dimension | Thailand PDPA | EU GDPR |
|---|---|---|
| Maximum Penalties | Maximum criminal fines of 1 million THB; maximum civil fines of 5 million THB (to be verified / subject to official release) | Maximum of 20 million EUR or 4% of global annual turnover, whichever is higher |
| Enforcement Authority | Personal Data Protection Committee (PDPC) | Data Protection Authorities (DPAs) in each EU member state |
| Enforcement Focus | Compliance obligations of data controllers and processors | Compliance obligations of data controllers and processors |
Compliance Recommendations
For security enterprises operating in both Southeast Asia and Europe, the following measures are recommended:
Develop region-specific privacy policies. Create privacy notices and data processing disclosures tailored to Thai and EU markets respectively, addressing each regulation's distinct requirements.
Improve monitoring area disclosures. Install visible notices at all monitoring points explaining monitoring purposes, data retention periods, and contact channels to satisfy transparency requirements under both regulations.
Establish data subject request response procedures. Develop standardized processes for handling access, rectification, and erasure requests, ensuring responses within stipulated timeframes.
Evaluate cross-border transfer compliance pathways. If transferring overseas surveillance data to domestic infrastructure is necessary, assess and implement compliant cross-border transfer mechanisms in advance.
FAQ
Can Thailand PDPA and GDPR apply simultaneously?
Yes. If an enterprise operates in both Thailand and the EU, and monitoring subjects include Thai and EU residents, compliance with both regulations is required. The two frameworks align on core principles but differ in specific provisions and application details.
Does facial recognition systems used by security enterprises require additional permits?
Both regulations classify biometric data as sensitive data requiring stricter conditions for processing. Whether additional permits are necessary depends on factors including actual application scenarios, data types, and processing purposes. Consultation with local legal counsel is recommended.
What are the requirements for data retention periods?
Both regulations require that data retention periods not exceed what is necessary for processing purposes. Surveillance data retention periods should be reasonably set based on specific scenarios (such as factory safety, access control, public area monitoring) and clearly disclosed in privacy notices.
Do employee monitoring rules apply identically?
Workplace monitoring is restricted under both frameworks. GDPR requires employers to balance legitimate interests against employee privacy rights; PDPA similarly requires employers to fulfill transparency obligations and limit monitoring scope. Enterprises are advised to develop dedicated employee privacy policies before implementing employee monitoring.
What are the consequences of non-compliance?
Beyond monetary penalties, both regulations empower regulatory authorities to take enforcement actions, including issuing corrective orders and suspending data processing activities. Specific penalty amounts and enforcement procedures are subject to official release. Enterprises are advised to integrate compliance into day-to-day operations management.