Say a registered letter reaches your office on Monday. A former customer asks for a copy of all the personal data you hold on them, and how you got their phone number.
Who in the company handles it? Which systems hold this customer's data? And from today, how long do you have?
Since 14 September 2026, the last question has a clear answer: 30 days.
What happened
Thailand's Personal Data Protection Committee (PDPC) issued a notification setting rules for access to and copies of personal data, B.E. 2569 (2026). It was published in the Royal Gazette on 16 July 2026 and took effect 60 days later, on 14 September 2026.
The PDPA has given people the right to access their own data since section 30, but until now there was little detail on how organisations must handle it. The notification sets out the whole process: request channels, identity verification, deadlines, grounds for refusal, fees and record keeping. It also covers requests to disclose where data collected without consent came from.
What organisations must do
Request channels
Organisations must accept requests through at least two channels: in person at their place of business, and by registered mail. Electronic channels such as email or a web form are optional.
A request must state the data subject's name, how they want to receive the data, which data they are asking for, and the requester's signature.
Identity verification
Organisations may ask for identity documents, and may use digital verification as long as it does not make the right unreasonably hard to use. A representative must provide a letter of authorisation and identity documents for both the data subject and themselves.
Deadlines
Organisations must review a request within 15 days. If it is incomplete, the requester must get at least 15 days to fix it; if they don't, the request can be treated as abandoned.
Once a request is complete, the organisation must respond within 30 days. For large or complex requests this can be extended by up to another 30 days, with notice to the requester.
The 30 days start when a complete request arrives, not when your team starts searching.
When you can refuse
Organisations can refuse when a law or court order prohibits disclosure, when disclosure would harm others' rights (other people's personal data, trade secrets or intellectual property), or when a request is manifestly unfounded or unreasonably burdensome. A refusal must be explained in writing and recorded.
Fees
Access is generally free, especially electronic access with no special cost. Fees are allowed only in some cases, such as a special format, delivery costs or excessive repeat requests, and must not exceed actual cost.
Record keeping
Organisations must keep records of requests and responses for at least two years. Those records are your evidence of compliance if a complaint follows.
The real work is finding the data, not the form
Opening request channels takes a day. Answering completely within 30 days is the hard part.
A typical company keeps one customer's data in many places: the sales system, accounting, the CRM, salespeople's email, marketing's Excel files, the after-sales service system and CCTV. If nobody knows where personal data lives, every request turns into a search that goes department by department, with a real risk of an incomplete answer.
The question about where data came from is harder still. If you bought a contact list or received data from a partner and never recorded the source, you cannot answer it.
Organisations that already keep a record of processing activities (ROPA) and hold customer data in one core system answer much faster, because they already know where to look.
What to do in the next 30 days
- Name the person responsible for requests, and tell front-desk, mailroom and call-centre staff who to pass requests to.
- Make the in-person and registered-mail channels clear, and state them in your privacy notice.
- Set identity checks that are not overly burdensome, for both direct and representative requests.
- Map which systems hold each type of personal data, who owns it and where it came from.
- Set up a request log with the date received, date complete, due date, outcome and any reason for refusal, and keep it for at least two years.
- Rehearse one request and time how long the team takes to gather data from every system.
What Enersys does
Our PrivacyHub platform receives and tracks data subject requests (DSR), routes each request to the responsible team, counts down to the due date and keeps a record of every response as evidence, without storing personal data in PrivacyHub itself. For organisations on Odoo, we bring customer data into one system and set permissions so one person's data can be found completely from one place.
If you are not sure your organisation could answer its first request within 30 days, talk to the Enersys team. We start by mapping where your personal data lives.
Sources