· Read 8 min
An 8-point PDPA checklist for business websites
What a business website needs under Thailand's PDPA before hiring an expensive consultant: notice, consent, cookies, forms and processors.
Thailand's Personal Data Protection Act B.E. 2562, or PDPA, has been fully in force since mid-2022 and applies to businesses of every size that collect data about people in Thailand, which includes a website with a single contact form.
This is not legal advice, and we recommend talking to a lawyer before your first client. But the list below is what most business websites need, and you can check your own site today without waiting for anyone.
1. A privacy notice written from the truth
Section 23 requires you to tell people, before or at the time of collection, what you collect, why, on which legal basis, for how long, who receives it, and what rights they have.
The most common problem is not a missing notice but one copied from another site that does not match what the site actually does: a notice that says "we use no third-party cookies" on a site running Google Analytics and the Facebook Pixel. A false notice is worse than none, because it is evidence that you knew you had to do it and did it wrong.
Check: open your notice and compare it with the services the site really loads (the Network tab in your browser, or ask your developer).
2. A consent box that is not pre-ticked
Consent under PDPA must be a clear action by the person. A box already ticked that the user has to untick does not count, and the wording must state the purpose, not "I accept all terms".
Wording that works: "I consent to the company storing my name and phone number to contact me about the service I enquired about. Data is kept for no more than 24 months."
Check: open your contact form on a phone. Is the consent box empty? Can the form be sent without ticking it? (It must not be.)
3. Analytics cookies that stay off until allowed
A cookie banner with a single "OK" button while Google Analytics has already been running since page load is not consent. It is notification after the fact.
What is correct: non-essential cookies do not run until accept is pressed, the reject button is as easy to press as accept (not buried under "settings"), and the choice can be changed later.
Check: open the site in a private window, touch nothing on the banner, and look for requests to google-analytics.com or facebook.com. If they are there, your banner is decoration.
4. Forms that collect only what is needed
Data minimisation: collect only what you will use. A contact form does not need a national ID number. A clinic appointment form should not ask about symptoms on the website (health data is sensitive data under Section 26 and needs explicit consent and stronger safeguards).
Every field you add is liability you add. If there is no clear reason for it, remove it.
Check: go through every field on every form and ask "could we really not reply without this?"
5. Know where the data goes
When a customer submits a form, where does it go? Whose email, which system, who can see it, and which country are those providers in?
Sending data abroad (Gmail, Google Sheets, Mailchimp) is allowed, but it must be stated in the notice and the provider must have adequate safeguards.
Check: write down the path of one form's data from start to finish. If you cannot, that is the first problem to fix.
6. A retention period that is stated and actually applied
A notice that says "no more than 24 months" needs someone to actually delete the data at 24 months. If the form emails you and those emails are never deleted, the notice is false.
The simplest approach for a small business: an email rule that deletes form messages older than 24 months automatically, or a system that does it for you.
Check: how old is the oldest form submission you still have?
7. A channel for data-subject requests
People have the right to see, correct and delete their data and to withdraw consent. You need a channel for those requests stated in the notice (email or LINE is fine) and to respond within 30 days.
Check: if someone emailed today asking you to delete their data, do you know everywhere you would need to delete it?
8. Business identity in the footer
Not strictly a PDPA requirement, but it is how Thai customers decide whether a business is real: legal entity name, 13-digit registration number, address and contact channel at the bottom of the site.
A site without them looks like a site ready to disappear, and as a data controller under PDPA, people have to know whom to contact.
Check: scroll to the bottom of your homepage. Are all four there?
Summary
These eight items can be done within a week for most sites, and the cost is mostly time, not money. What is expensive is a complaint after an incident, with a false notice sitting on your site as evidence.
Every site we build passes this list before handover, and our audit covers all eight in the PDPA section of the report.
