Thailand’s PDPA and cross-border data transfers
Thailand’s PDPA is now an enforcement reality. Transfers, cookies, and consent records need the same rigor as EU programs.

Thailand’s Personal Data Protection Act requires a lawful basis for processing and sets conditions for sending personal data outside the country. Adequacy, appropriate safeguards, and exceptions should be documented — not improvised in a vendor form.
Consent remains a common basis for marketing and cookies. If you collect consent, you must be able to show it and honor withdrawal.
CMP as transfer hygiene
Tag a vendor as in-country or out-of-country, bind it to purposes, and block it when the user declines. That is simpler than discovering a transfer path during an audit.
Educational overview only — not legal advice. Confirm requirements with counsel for your products and markets.


