Skip to main content
AI & Technology

PDPC Announces “Privacy in Action” Theme — Moving from Awareness to Real Enforcement, with Tighter AI Governance

สำนักงาน สคส. จัด Data Privacy Day 2026 เปิดเผยว่ามีเรื่องร้องเรียน PDPA แล้วกว่า 2,672 เรื่อง พร้อมส่งสัญญาณเข้มงวดเรื่อง AI Governance และกำลังร่าง พ.ร.บ. AI ของไทย

26 Feb 20265 minThairath English
PDPAสคส.AI GovernanceThailand

From “Knowing” to “Doing” — The PDPC Is No Longer Waiting

If you think the PDPA is still just a law on paper, this news may make you reconsider.

The Personal Data Protection Committee Office (PDPC) held Data Privacy Day 2026 under the theme “Privacy in Action”—and the message is clear: it is time for real implementation, not just awareness

2,672 Complaints — A Number Businesses Should Not Ignore

The PDPC disclosed that, as of January 2026, there had already been 2,672 complaints related to the PDPA. The most common violations were:

  • Failure to comply with the Data Minimization principle — collecting more data than necessary
  • Collecting data without a legal basis — no consent or no legitimate interest
  • Using/disclosing data without a legal basis — sharing customer data without authorization

While 2,672 cases may not sound high in a country with millions of businesses, what is more concerning is the year-on-year upward trend, while the PDPC is also expanding both its workforce and its technology capabilities for enforcement.

AI Governance Is Coming — Faster Than Many Expect

One of the most important takeaways from Data Privacy Day was that the PDPC is preparing guidance on AI Governance to ensure that AI use aligns with personal data protection principles.

In addition, Thailand is drafting a separate AI Act, which would serve as dedicated legislation specifically regulating AI and operating alongside the PDPA.

The key point organizations need to understand is this: although the PDPA does not regulate AI directly, any personal data used in AI must still comply with the PDPA — and organizations, not the AI itself, bear full responsibility.

EU AI Act to Become Fully Enforceable on 2 August 2026

Another major development to watch is the EU AI Act, which will become fully enforceable on 2 August 2026 for high-risk AI systems, with penalties of up to EUR 35 million or 7% of global revenue.

Thai organizations doing business with Europe should prepare for this regulation as well.

What Should Thai Organizations Do Now?

  1. Assess your organization’s PDPA compliance — do not wait until a complaint is filed before taking action
  2. Build a data inventory — understand what data you collect, where it is stored, and how it is used
  3. Prepare for AI governance — if your organization uses AI, it should have clear policies and audit trails
  4. Manage consent properly — not just a cookie popup, but the entire consent lifecycle

PrivacyHub by Enersys is designed to address these needs — covering all six essential modules for PDPA compliance (Consent Management, DSR, Data Inventory, RoPA, Breach Management, and Vendor Management), built on a Zero PII Storage approach that helps reduce organizational risk, and combined with Genesis AI to identify gaps and provide automated recommendations.


References: Thairath English | Tilleke & Gibbins | Mondaq

"Empowering Innovation,
Transforming Futures."

ติดต่อเราเพื่อทำให้โปรเจกต์ของคุณเป็นจริง