Skip to main content
AI & Technology

Thailand’s PDPC Deploys Eagle Eye Crawler — The Automated PDPA Violation Detection System Organizations Need to Watch

สคส. ใช้ Eagle Eye Crawler ตรวจจับการละเมิด PDPA อัตโนมัติผ่านการ crawl เว็บไซต์องค์กร พร้อมเข้มงวดบังคับใช้กฎหมายมากขึ้นในปี 2026

28 Feb 20265 minHogan Lovells
PDPAสคส.Eagle EyeEnforcement

The PDPC Is No Longer Just Waiting for Complaints

If you still think PDPA enforcement in Thailand is mainly reactive—waiting for complaints before taking action—this news may change your view. Thailand’s PDPC has a tool called Eagle Eye Crawler, an automated PDPA violation detection system that crawls organizations’ websites and digital channels.

Put simply, the PDPC can inspect your website without your knowledge—checking whether your consent banner is compliant, what data is being collected, and whether your privacy policy is complete.

Fine Levels Are Becoming More Serious

In August 2025, the PDPC issued 8 penalty orders across 5 cases involving both public-sector and private-sector entities, totaling approximately THB 21.5 million.

That may not sound significant compared with GDPR, but the key points are:

  1. This is only the beginning — The PDPC has only recently begun enforcing the law more seriously, and penalties are likely to increase over time.
  2. Reputational damage can exceed the fine itself — Organizations that are penalized often become newsworthy, which can undermine customer trust more than the monetary penalty.
  3. Executives may bear personal liability — PDPA penalties do not apply only to companies; responsible executives may also face personal consequences.

Industries Under Closer Scrutiny

Based on current enforcement trends, the PDPC appears to be paying particular attention to these sectors:

  • E-commerce — Customer data collection and personalized marketing
  • Healthcare — Health data is sensitive personal data and carries heightened compliance risk
  • Telecommunications — Large customer databases create elevated exposure
  • Government agencies — Massive volumes of citizen data are subject to stricter review

In reality, however, any organization that collects personal data falls within scope, regardless of size.

5 Areas Eagle Eye Crawler Can Likely Detect

Based on available information, Eagle Eye Crawler is likely focused on these key areas:

  1. Cookie consent — Is there a compliant banner? Can users refuse consent? Is proof of consent being retained?
  2. Privacy Policy — Does it meet PDPA requirements? Is it easy to access? Is it written in clear, understandable language?
  3. Third-party trackers — What trackers are installed, and is consent obtained before data collection begins?
  4. Data collection forms — Do forms that collect personal data include consent checkboxes where required?
  5. Data minimization — Is the organization collecting more data than necessary?

What Should Organizations Do Now?

Before Eagle Eye comes knocking, there are several steps organizations can take immediately:

  • Review your website — Is your cookie consent mechanism compliant? Is your privacy policy up to date?
  • Conduct a consent audit — Do you have complete proof of consent for every consent you rely on?
  • Build a Data Inventory — Know what data you collect, where it is stored, and what it is used for
  • Prepare a DSR process — Can you respond to data subject rights requests within 30 days?
  • Appoint a DPO — If you do not yet have a dedicated PDPA owner, now is the time

PrivacyHub by Enersys helps organizations address these requirements end to end—from Consent Management, Data Inventory, and DSR Workflow to Breach Incident Management—using a Zero-PII Architecture that does not store personal data within the system itself, reducing organizational risk by design.


References: Hogan Lovells | Herbert Smith Freehills | PIM Legal

"Empowering Innovation,
Transforming Futures."

ติดต่อเราเพื่อทำให้โปรเจกต์ของคุณเป็นจริง