Thailand Launches Its First PDPA Certification Framework
Thailand has taken a significant step in the institutional development of its privacy regime. On 18 June 2026, the Office of the Personal Data Protection Committee (PDPC) published two notifications in the Royal Gazette establishing Thailand’s first certification framework for personal data protection standards under the Personal Data Protection Act B.E. 2562 (2019) (PDPA).
The framework is voluntary, but it is likely to become commercially important for organizations whose customers, regulators, counterparties, investors or group companies expect demonstrable privacy governance.
Key takeaways

Why this matters
The PDPA has been in full force since 1 June 2022, following several extensions and the subsequent issuance of subordinate regulations. Since then, the Thai privacy regime has moved from legislative commencement to implementation, regulator guidance, breach response, enforcement activity and now certification. Current public legal commentary notes that the PDPA was influenced by the EU GDPR, but retains local features, including distinctive notice and consent requirements and a broad territorial reach for processing activities relating to Thailand-based data subjects. [1]
The certification framework is therefore best understood as part of the PDPA’s maturation. It does three things that ordinary compliance obligations do not do. First, it translates privacy governance into a structured assessment exercise. Secondly, it creates a visible assurance mechanism through certificates and certification marks. Thirdly, it gives the market a regulator-backed signal for distinguishing between organizations that merely assert compliance and those prepared to submit their privacy program to PDPC review.
That assurance function should not be overstated. Certification is not a statutory safe harbor, and the notifications do not impose a penalty on organizations that choose not to apply. A certificate also should not be read as a permanent guarantee of compliance, particularly because privacy practices, systems, vendors and data flows change constantly. Its value lies instead in disciplined preparation, documentary evidence and continuing governance.
Who may apply
The framework is open to specified public and private applicants. Government agencies may apply where the PDPC requires them to appoint a data protection officer at department level or an equivalent level. Private applicants may apply if they are juristic entities incorporated under Thai law with an office in Thailand, or foreign juristic entities with either a branch office in Thailand or an appointed authorized representative.
Eligibility is not automatic. Before filing, the applicant must have passed the PDPC’s Privacy Maturity Model self-assessment at Level 5. It must also not have had a certification application refused within the preceding 45 days, and must not have had a certification revoked during the preceding year. This threshold is important. It signals that certification is intended for organizations with an already mature privacy management system, not as a remedial pathway for organizations beginning their PDPA compliance journey.
Figure 1. Eligibility funnel: applicant type and pre-application gates.
What the PDPC will assess
Applicants are assessed against 128 criteria across 10 focus areas, grouped into four categories: policy and governance; human resource development; process and procedure; and technology security and breach response. The categories mirror the operational architecture of a credible privacy program. They cover board or management oversight, policies, training, data subject rights handling, transparency, records of processing activities, lawful basis analysis, data processing and data-sharing agreements, risk assessment, data protection impact assessment, security and personal data breach response.
Figure 2. Assessment map: 10 focus areas grouped into four certification categories.
This breadth matters. It prevents certification from becoming a document-only exercise. An applicant will need to demonstrate not only that policies exist, but that governance, people, procedures, technology and incident response are aligned. The overlap with current PDPA obligations is clear: data controllers are expected to maintain appropriate security measures, keep records for certain uses and disclosures, manage processor arrangements, respond to data subject rights, and handle personal data breaches within the PDPA’s notification framework.
The security and breach-response component is especially significant. Publicly available research published in 2026 identified large-scale exposure of Thai national identification numbers and other sensitive data online, with a substantial share attributed to Thai government-sector websites. Although that research is not itself part of the certification framework, it underscores why a regulator-backed assessment that tests governance, security and breach readiness may be attractive to both public and private-sector organizations.
Two certification outcomes
The framework distinguishes between two levels of outcome. An applicant that achieves 80% to 89.9% of the assessed items may receive a PDPA Compliance Certificate. An applicant that achieves at least 90% and satisfies all mandatory legal requirements and best-practice items may receive a PDPA Certificate together with a Certification Mark. The PDPC applies a hologram watermark to both the certificate and the certification mark to help prevent forgery.
Figure 3. Certification threshold ladder: outcomes depend on score and mandatory conditions.
For publication and market-facing purposes, the distinction should be handled carefully. A PDPA Compliance Certificate indicates a high level of assessed compliance, but the higher outcome carries both the PDPA Certificate and the visible mark. Organizations using either credential should ensure that marketing statements, tender responses and vendor questionnaires accurately reflect the level obtained, the scope of assessment and the validity period.
Application process and timing
The process begins with submission of the application form and supporting documents to the PDPC, either in person or through the PDPC’s electronic system. After the PDPC confirms that the application is complete, the applicant must pay the review fee within seven days. An incomplete application may be corrected once. If it remains incomplete after that correction, the PDPC will reject it without further notice.
The PDPC then audits the application by document review, on-site inspection, or both. The audit must be completed within 60 days after it begins. If the applicant does not pass, it may correct identified deficiencies once within 15 days and request reassessment. The PDPC working group reviews and endorses the audit result before the Secretary-General decides whether to approve certification. If approved, the applicant must pay the issuance fee within 15 days after receiving notice; the PDPC then issues the certificate and, where applicable, the certification mark.
Figure 4. Certification journey: key process steps and statutory timing points.
The overall process must be completed within 180 days from application to issuance. The PDPC may extend that period once by up to 30 days where necessary. Fees must be paid through Krung Thai Bank e-Banking or another PDPC-designated channel, at rates the PDPC will announce separately.
Validity, renewal and publication
A certificate and certification mark remain valid for three years from the date of issuance. The PDPC may conduct a follow-up review after the first year. Renewal is available both before and after expiry: an organization may apply up to six months before expiry or within six months after expiry. The PDPC will publish a list of certified organizations on its website.
Publication is likely to be one of the framework’s most important practical features. A public list allows counterparties and data subjects to verify certification status, but it also increases reputational consequences if an organization loses certification or allows it to expire. Certified organizations should therefore treat certification maintenance as an ongoing governance obligation, not a one-off project.
Practical implications for organizations
For organizations with mature PDPA programs, certification may offer a useful assurance tool. It can support procurement responses, regulated-sector governance, intra-group reporting and customer trust. It may also reduce friction in vendor onboarding where customers ask for evidence of privacy controls, provided that the certification scope matches the relevant processing activity.
For organizations that are not yet ready to apply, the framework still has immediate value as a roadmap. The 128 criteria and 10 focus areas identify what the PDPC considers a mature privacy program. Even without applying, organizations can use the framework to run a gap assessment, prioritize remediation and prepare for future certification or regulator inquiry.
The key caution is that certification should not be treated as a substitute for legal compliance. The PDPA continues to impose underlying obligations on data controllers and processors, including obligations relating to lawful basis, notice, consent, data subject rights, security, data processing agreements, cross-border transfers and breach notification. DLA Piper’s current Thailand summary notes that breach notification to the regulator is generally required without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach; data subject notification is required where the breach is likely to result in high risks to rights and freedoms. [1]
Recommended next steps
✓ Map the 128 criteria against the organization’s existing PDPA compliance framework and evidence files.
✓ Confirm whether the organization meets the Privacy Maturity Model Level 5 pre-application threshold.
✓ Review governance records, including board or management oversight, DPO appointment analysis and responsibility matrices.
✓ Refresh records of processing activities, lawful basis analysis, privacy notices and data subject rights procedures.
✓ Check data processing agreements, data-sharing agreements and cross-border transfer documentation.
✓ Test breach response procedures against the PDPA’s 72-hour regulator notification expectation and internal escalation timelines.
✓ Run a mock audit before applying, including document review and operational interviews with legal, IT, HR, security, procurement and business teams.
✓ Prepare a certification maintenance calendar covering first-year follow-up review risk, renewal timing and public-list monitoring.
Our Take
Thailand’s first PDPA certification framework marks an important transition in the country’s privacy regime. The PDPA is no longer only a compliance statute enforced through obligations, complaints and penalties. It now includes a voluntary recognition mechanism for organizations that can demonstrate mature privacy governance. The organizations most likely to benefit are those that approach certification not as a badge, but as a disciplined evidence exercise: a way to prove that policies, records, controls, contracts, people and incident response operate together in practice.
For others, the framework provides a clear signal of where the Thai regulator expects privacy programs to go. Even if certification is not pursued immediately, the new standards can be used now as a practical benchmark for PDPA readiness, vendor risk management and accountable data governance.
This article was prepared by Mahanakorn Partners Group (MPG). For further information or guidance on Thailand’s PDPA certification framework, please contact Mahanakorn Partners Group at [email protected].





