August Newsletter: Thailand Launches the PDPA Compliance Certification

A new framework for certifying effective and well-implemented personal data protection measures

On 18 June 2026, the Personal Data Protection Committee (“PDPC”) published a Notification in the Government Gazette introducing Thailand’s personal data protection standards certification framework. The framework represents a shift from demonstrating PDPA readiness primarily through self-assessment toward an externally assessed standard of privacy governance.

The certification provides a recognized pathway for organizations to demonstrate that their PDPA measures are not only documented but also implemented in the organization and operating in practice. It is intended for organizations with established privacy programs and sufficient evidence of operational controls.

Who Can Apply?

The certification is available to all types of organizations across public and private sectors, including Thai and foreign entities as well as foreign branches. However, applicants must demonstrate a sufficiently mature privacy management framework before applying.

A High Bar for Certification

A key eligibility requirement is achievement of Privacy Maturity Model (“PMM”) Level 5. The PMM is a self-assessment framework used to evaluate the effectiveness of an organization’s PDPA management across areas such as risk management, internal controls, transparency and stakeholder participation. Level 5 represents the highest effective level and reflects an organization that focuses on continuous improvement and has data protection principles embedded within its culture.

At this level, organizations are expected to demonstrate practical implementation rather than rely solely on written policies. The use of automated tools, regular audits and international practices are among the indicators of an effective privacy program.

Applicants must also satisfy certain historical compliance conditions. In particular, there must not have been a certification refusal within 45 days before the application, or a certification revocation within one year before the application. Where an applicant has previously been convicted under the PDPA, the relevant court judgment must have been fully complied with and at least two years must have passed from the date of compliance.

How Does the Certification Process Work?

An application for certification may be submitted either in paper form or electronically. The review period may take up to 180 days and may be extended by a further 30 days. Once granted, the certification is valid for three years. A follow-up review may take place after the first year, while renewal may be requested from six months before expiry through six months after expiry.

What Will the PDPC Assess?

The assessment focuses on whether an organization’s privacy program is documented, embedded and functioning effectively. The PDPC may consider both documentary and empirical evidence, together with legal compliance and applicable best-practice guidelines.

The assessment is structured around four main areas, covering a total of 128 consideration points. These areas provide a practical picture of how privacy is managed throughout an organization:

Policy and Governance – This covers organizational oversight, as well as the policies and procedures supporting the privacy program.

Human Resource Development – The assessment considers employee training and awareness, reflecting the importance of staff understanding their responsibilities when handling personal data.

Process and Procedure – This includes the handling of individual rights, transparency, records of processing activities (ROPA), lawful bases, data processing and data sharing agreements, as well as risk management and Data Protection Impact Assessments.

Technology Security and Breach Response – The assessment considers data security controls and the organization’s ability to respond effectively to personal data breaches.

Certification outcome  An applicant that meets the assessed legal requirements and achieves a score of 80%–89.9% in each topic may receive a PDPA Compliance Certificate. Where the applicant meets both the legal and best-practice requirements and achieves at least 90% in each topic, it may receive a PDPA Certificate together with the Certification Mark.

What Does This Mean for Businesses?

The certification should be viewed as more than a compliance label. It provides a practical benchmark for demonstrating accountability to customers, regulators, vendors, business partners and other stakeholders.

For businesses, the most important change is the emphasis on effectiveness, organization-wide privacy operations. Written privacy notices, consent language and basic policies alone may not be sufficient. Organizations will need to demonstrate that privacy controls are implemented and work effectively in day-to-day operations, supported by appropriate evidence and records.

The certification may also have commercial value, particularly in tenders, outsourcing arrangements, regulated or data-intensive sectors, and cross-border data arrangements. Organizations seeking to strengthen their position with enterprise customers or international partners may therefore consider certification as part of their broader privacy and governance strategy.

Is Certification Right for Your Organization?

Certification may be particularly relevant for organizations that handle significant volumes of personal data, operate in regulated or data-intensive sectors, work with enterprise customers or international partners, or wish to differentiate themselves through stronger privacy governance and trust.

Before applying, organizations should first assess whether certification would provide meaningful compliance or commercial value. A practical starting point is a gap assessment against PMM Level 5 and the certification criteria, followed by a review of governance, documentation, individual rights handling, security and breach response. Organizations should also ensure that their controls are operational and supported by verifiable records, and plan for ongoing compliance, follow-up review and renewal throughout the certification lifecycle.

Looking Ahead

The introduction of the PDPA Compliance Certification framework signals a move toward a more mature and evidence-based approach to privacy governance in Thailand. For organizations that already have established privacy programs, the framework may provide an opportunity to formally demonstrate the effectiveness of those programs. For others, it may serve as a useful benchmark for identifying and addressing gaps in their current privacy practices.

Contributors by PKF Legal (Thailand) Ltd.,

 

Natkamon Paisarnsinchai

Senior Legal Associate

Related documents

Who to contact