Picture the reception counter of a beauty clinic. There's a notebook sitting open on the desk, turned to the latest page. Everyone who walks in has to write their name, phone number, and sometimes their national ID number — one line after the next. A good receptionist knows instinctively, without anyone telling her, that this notebook shouldn't be left open where people walking by can see the previous patient's name. It shouldn't be photographed and shared in a LINE group. It shouldn't be thrown in the trash at closing time without being shredded first. She knows that other people's names and phone numbers are things that need to be handled with care.
Your business website has the same notebook. It just takes the form of a contact form, a LINE chat button, or a field where customers enter their phone number to receive promotions. The problem is that most business owners have never opened this digital notebook to check how it's currently being stored, who can see it, and whether anyone asked the owner's permission before their data was collected.
Take Three Minutes to Audit Your Own Website
Before we get into the law, open your shop's website and go through each page to find every place where customers are asked to type in their name, phone number, or email address.
Contact forms or quotation request forms
LINE chat buttons or call buttons that send data somewhere in the background
Newsletter or discount coupon sign-up fields
Analytics scripts and advertising pixels embedded in your pages, which track browsing behavior
Then check whether each of those points includes text explaining what the data will be used for, whether there's a separate consent checkbox apart from the "Submit" button, and where the submitted data actually ends up — someone's email inbox, a shared spreadsheet link, or a system with access controls.
If your audit reveals no explanation, no consent checkbox, and no idea where the data goes — don't panic. Most Thai business websites I encounter are exactly like this. But that's precisely the starting point for this article.
Before Going Further, You Need to Know Who You Are Under This Law
Thailand's Personal Data Protection Act B.E. 2562 (PDPA) calls the person who collects a customer's name and phone number a "Data Controller." The customer whose data was collected is the "Data Subject." And if you hire another company to manage your backend system or social media pages, that company is a "Data Processor." The PDPA Guide for SME Operators published by the Personal Data Protection Committee (PDPC) itself uses a coffee shop that collects customer data for a membership system as an example of a Data Controller — you don't have to be a large corporation to fall under this law.
The definition of "personal data" in the law is also quite broad: any information that can identify a person, whether directly or indirectly (Section 6). A name and phone number in a contact form identify someone directly. Data from analytics or advertising pixels that tracks behavior tied to a specific device could potentially identify someone indirectly too. This is a point worth keeping in mind — rather than a definitive ruling, since exactly how it applies depends on the specifics of each case.
What Does Valid Consent Actually Look Like?
Section 19 of the Personal Data Protection Act states clearly that consent must be "given explicitly, in writing or through an electronic system," must be clearly separated from other text, must use plain and non-misleading language, and — critically — may not be made a condition for entering into a contract or receiving a service unless that data is genuinely necessary for that service.
In website terms: the consent checkbox must be a separate box from the "Submit" button, not hidden in small print below it that nobody reads. And it must not be pre-checked — requiring customers to uncheck it themselves — because a pre-checked box makes it difficult to demonstrate that the data subject gave explicit consent as required by Section 19.
Here's a practical example. If your shop's contact form has a "Submit" button at the bottom, there should be a separate checkbox above it with text along these lines:
☐ I consent to [Shop/Company Name] collecting and using my name, phone number, and email address solely to follow up on my product or service inquiry. Read more in our Privacy Policy.
This text stands as its own separate element, not buried in a long terms-of-service block nobody reads. It clearly states what data is collected and for what purpose, and includes a link to read more. If the customer doesn't check the box, the "Submit" button shouldn't work — this is appropriate here because name and phone number are genuinely necessary for a callback. However, if it's a newsletter sign-up that isn't required for the service, you cannot block the submit button this way. One important note: the example above is a guideline, not a ready-made template to copy and paste. Adjust the wording to match what your business actually collects, and have someone responsible for this area review it before you go live.
What Must You Tell Customers Before They Type Anything?
Section 23 specifies the details you must disclose to data subjects before or at the time of data collection: the purpose for which the data will be used; whether providing the data is required and what happens if they don't; what data is collected and how long it will be retained; who or which organization may have access to it; who the Data Controller is and how to contact them; and the data subject's own rights — including the right to access, correct, or delete their data.
Most of this information is typically gathered in a page called a Privacy Policy. A significant number of Thai business websites don't have this page at all — not out of deliberate avoidance, but simply because nobody brought it up when the website was first built.
If you're going to write this page, here's roughly what the essential sentences should say (adapt the wording to your own business — don't copy this verbatim):
State the purpose: "We collect your name and phone number solely to follow up on your quotation request."
State whether providing data is required and what happens if not: "Providing your name and phone number is voluntary, but without it we cannot contact you with a quote."
State what data is collected and how long it's kept: "We collect your name, phone number, and email address and retain it for no more than 2 years from your last contact."
State who can see the data: "Only our internal team has access to this information. It is not shared with outside parties, except for the email and data storage systems we use."
State who the Data Controller is and how to contact them: "The Data Controller is [Shop/Company Name], reachable at [email or phone number]."
State the data subject's rights: "You may request to view, correct, delete, restrict, object to, or withdraw consent for the use of your data, or file a complaint with the PDPC, by contacting us through the channels above."
These six points cover the topics required by Section 23, though the full rights details are more extensive than this summary. If your business collects more than just names and phone numbers, have someone responsible for this area review it.
Why This Is Gaining More Weight in 2026
This year there are two major data breach cases that the PDPC is currently investigating simultaneously: the "Mor Prom" health system case, which has received over 30 complaints from affected users, and the TSD Investor Portal case where approximately 200,000 users may have been impacted. Both are still under investigation with no rulings or penalties issued yet. (Infoquest, July 29, 2026)
What's notable is that the PDPC Secretary-General stated directly in the same news piece that "a personal data breach does not automatically mean the organization is legally liable" — the review looks at whether appropriate preventive measures were in place before the incident, how quickly it was detected and addressed, and whether data subjects were notified as required by law. In other words, the law doesn't judge only on outcomes; it also looks at the processes the organization had in place beforehand — which is something businesses can control starting today.
On the penalty side, the law distinguishes levels by type of violation. The two issues discussed above — failing to disclose information as required by Section 23 and collecting consent in a manner that doesn't comply with the form specified by the Committee under Section 19 — fall under Section 82, with administrative fines of up to 1 million THB. The 3-million-THB ceiling in Section 83 applies to different conduct, such as collecting consent through deception or misleading the data subject about the purpose (Section 21), using data beyond the stated purpose, or collecting more than necessary (Section 22). And for sensitive data under Section 26 — such as health information that clinics typically collect — violations carry a maximum of 5 million THB (Section 84). Worth noting: Section 90 requires the expert committee to consider the severity of the conduct alongside the "size of the business" of the Data Controller — it doesn't apply the same maximum penalty to every business uniformly.
Good News for Small Businesses: There Are Real Exemptions, but Not a Full Exemption
The PDPC has issued an announcement exempting some obligations for small business Data Controllers — including SMEs under the SME law, community enterprises, social enterprises, cooperatives, and household businesses — from the formal requirement to maintain a Record of Processing Activities (RoPA) under Section 39. (PDPA Guide for SME Operators, PDPC)
But to be clear: this exemption covers only that one record-keeping requirement. Core obligations — properly obtaining consent, disclosing information before collecting data, and maintaining data security — remain your responsibility as a business regardless of size. And this exemption doesn't apply if the data you collect poses risks to data subjects' rights and freedoms, or if it involves sensitive data under Section 26.
"We've Never Had Any Problems So Far" — Right?
I hear this often, and it's completely understandable. Most shops have been using the same form for years without a single customer complaint. That's entirely true.
The PDPA issue isn't about whether anyone has complained yet. It's about whether the system is currently collecting and using data correctly from the outset.
Like the open notebook at the reception counter — even if no one has actually peeked at it and made it a problem, that doesn't mean the notebook is being stored properly. And as your website adds new features — a membership system, a queue booking system — more data collection points are added with them. It's much easier to set up consent correctly when you have just a few forms than to go back and fix twenty data collection points scattered across your site later.
We're a Web Development Team, Not a Law Firm
To be direct: everything I've covered here is a broad framework derived from reading the law itself and PDPC's own documents. It is not specific legal advice for any particular business, because every business collects different data and carries different risks. If your business collects data more sensitive than names and phone numbers — such as health or financial information — or if you have questions about how much your specific situation requires, the most direct route is to contact the PDPC directly through their hotline at 1111, or to consult an attorney who handles this area. What our team can do fully is build websites and systems that support whatever your business has decided it needs to do.
If You're Going to Start, Where Do You Begin?
In practice, a general business website with just a contact form and a LINE button doesn't need to build a large system from day one. The things that are realistically doable and cover the core obligations are: a Privacy Policy page written in plain language that clearly states what's collected, what it's used for, how long it's kept, and who to contact to request deletion; a separate consent checkbox clearly distinct from the submit button, not pre-checked; and knowing where submitted data actually ends up — with a backend system that genuinely controls who has access, not just an open shared spreadsheet anyone can view.
A clearly written Privacy Policy isn't only useful for legal compliance — it's also one of the signals customers use to judge how trustworthy a shop is before they transfer money. I've written about this from the customer's perspective at Signals Customers Use to Decide Whether an Online Shop Is Trustworthy Enough to Pay.
The backend system point is one I see most often. Many shops connect their contact form to a shared email account that multiple people access, or send it to a LINE group that includes people outside the core team. When your website is connected to a backend system that genuinely controls access — logging who opened customer data and when — the data security concerns the law raises are addressed at the same time. I've written about setting up back-office systems for SMEs at Back-Office Setup Tips for 2026. If you want to see what an access-controlled system looks like in practice, view examples at our business systems page.
Online booking systems fall into the same category — every time a customer books through your website, that's another batch of personal data coming in. I've written about the benefits of online booking at 5 Reasons Your Shop Should Use an Online Booking System, but if you're going to use one, don't forget about the data it stores in the background.
If your website currently relies entirely on a Facebook Page, there's another angle worth thinking about alongside this: you have no control over customer data stored on someone else's platform. Even if you want to do everything correctly under the law, your options are far more limited than if you have your own website. More on that at Is a Facebook Page Enough? 5 Business Risks in 2026.
A 30-Day Plan to Start Aligning Your Website with PDPA
Week 1 — Map every data collection point: Go through each page of your website and list every form, LINE button, analytics script, and advertising pixel. Get a complete picture first.
Week 2 — Draft a plain-language Privacy Policy: Write it in language your customers can understand. State the purpose, retention period, and how to contact you to request deletion.
Week 3 — Update forms to have a real separate consent checkbox: Not tied to the submit button. Not pre-checked for the customer.
Week 4 — Verify where submitted data ends up: Move from open shared spreadsheets or shared email inboxes to a system that genuinely limits who has access.
How to Know You're on the Right Track
There's no conversion metric to track here the way there is with an ad campaign. But there are simple checks you can do yourself. Try asking a team member or a friend who hasn't seen your website before: if they filled out your contact form, would they know what their data will be used for? If they can't answer, your Privacy Policy isn't doing its job. Another check: review backend system access permissions every three months to see if anyone who has left the team can still view customer data. These two checks can be done without waiting for a problem to occur first.
Closing Thoughts
Going back to the clinic reception counter: the good receptionist didn't handle the notebook correctly because she had memorized the law. She did it because she had common sense about treating other people's information with care. The PDPA takes that same common sense and writes it into enforceable requirements — for a world where that notebook has become a digital form capable of storing thousands of people's data in a matter of months.
If your website has never gone through this kind of review, don't feel like you've been doing something wrong all this time. Most businesses are in the same position. What you can do is start checking today. Feel free to message us and tell us how your website currently collects customer data — we'll help identify which points to address first.
Follow TumWebSME
Follow us for tips on website development and online marketing:
Facebook: TumWebSME — Business Website Development
Instagram: @tumwebsme
TikTok: @tumwebsme
YouTube: TumWebSME
Contact Us
088-983-9386 (Ploy)
099-856-3198 (Saennan)




