Skip to main content
News

New PDPA Rules in Force Since 14 September 2026: Organisations Must Answer Personal Data Access Requests Within 30 Days

The Personal Data Protection Committee notification on access to and copies of personal data took effect on 14 September 2026. Organisations must offer request channels, verify identity, respond within 30 days and keep records for at least two years. What it requires, and how to prepare your data so you can answer on time.

3 Oct 20266 minTilleke & Gibbins
PDPARight of AccessDSARPDPCComplianceData Governance

Say a registered letter reaches your office on Monday. A former customer asks for a copy of all the personal data you hold on them, and how you got their phone number.

Who in the company handles it? Which systems hold this customer's data? And from today, how long do you have?

Since 14 September 2026, the last question has a clear answer: 30 days.

What happened

Thailand's Personal Data Protection Committee (PDPC) issued a notification setting rules for access to and copies of personal data, B.E. 2569 (2026). It was published in the Royal Gazette on 16 July 2026 and took effect 60 days later, on 14 September 2026.

The PDPA has given people the right to access their own data since section 30, but until now there was little detail on how organisations must handle it. The notification sets out the whole process: request channels, identity verification, deadlines, grounds for refusal, fees and record keeping. It also covers requests to disclose where data collected without consent came from.

What organisations must do

Request channels

Organisations must accept requests through at least two channels: in person at their place of business, and by registered mail. Electronic channels such as email or a web form are optional.

A request must state the data subject's name, how they want to receive the data, which data they are asking for, and the requester's signature.

Identity verification

Organisations may ask for identity documents, and may use digital verification as long as it does not make the right unreasonably hard to use. A representative must provide a letter of authorisation and identity documents for both the data subject and themselves.

Deadlines

Organisations must review a request within 15 days. If it is incomplete, the requester must get at least 15 days to fix it; if they don't, the request can be treated as abandoned.

Once a request is complete, the organisation must respond within 30 days. For large or complex requests this can be extended by up to another 30 days, with notice to the requester.

The 30 days start when a complete request arrives, not when your team starts searching.

When you can refuse

Organisations can refuse when a law or court order prohibits disclosure, when disclosure would harm others' rights (other people's personal data, trade secrets or intellectual property), or when a request is manifestly unfounded or unreasonably burdensome. A refusal must be explained in writing and recorded.

Fees

Access is generally free, especially electronic access with no special cost. Fees are allowed only in some cases, such as a special format, delivery costs or excessive repeat requests, and must not exceed actual cost.

Record keeping

Organisations must keep records of requests and responses for at least two years. Those records are your evidence of compliance if a complaint follows.

The real work is finding the data, not the form

Opening request channels takes a day. Answering completely within 30 days is the hard part.

A typical company keeps one customer's data in many places: the sales system, accounting, the CRM, salespeople's email, marketing's Excel files, the after-sales service system and CCTV. If nobody knows where personal data lives, every request turns into a search that goes department by department, with a real risk of an incomplete answer.

The question about where data came from is harder still. If you bought a contact list or received data from a partner and never recorded the source, you cannot answer it.

Organisations that already keep a record of processing activities (ROPA) and hold customer data in one core system answer much faster, because they already know where to look.

What to do in the next 30 days

  1. Name the person responsible for requests, and tell front-desk, mailroom and call-centre staff who to pass requests to.
  2. Make the in-person and registered-mail channels clear, and state them in your privacy notice.
  3. Set identity checks that are not overly burdensome, for both direct and representative requests.
  4. Map which systems hold each type of personal data, who owns it and where it came from.
  5. Set up a request log with the date received, date complete, due date, outcome and any reason for refusal, and keep it for at least two years.
  6. Rehearse one request and time how long the team takes to gather data from every system.

What Enersys does

Our PrivacyHub platform receives and tracks data subject requests (DSR), routes each request to the responsible team, counts down to the due date and keeps a record of every response as evidence, without storing personal data in PrivacyHub itself. For organisations on Odoo, we bring customer data into one system and set permissions so one person's data can be found completely from one place.

If you are not sure your organisation could answer its first request within 30 days, talk to the Enersys team. We start by mapping where your personal data lives.

Sources

"Empowering Innovation,
Transforming Futures."

Contact us to make your project a reality.