INSIGHT

Stay informed with in-depth analysis from our legal team.
We believe that knowledge is power, and a comprehensive understanding of the legal landscape is key to making confident decisions. In this Insight section, you’ll find articles, updates, and expert perspectives designed to clarify complex legal issues and keep you up to date.

Golden 72 hours after a data breach: How should companies in Thailand respond? | DRKI

Customer data being mispublished, employee computers being lost, databases being attacked, security incidents at cloud service providers... The statutory 72-hour countdown may have begun when a business discovers that a relevant incident may involve personal data.

In accordance with Thailand's Personal Data Protection Act B.E. 2562 (2019) (Personal Data Protection Act, Article 37 (4) of the PDPA and related supporting provisions stipulate that data controllers who become aware of a breach of personal data shall, without undue delay, communicate to the Office of the Personal Data Protection Commission of Thailand (PDPA) Personal Data Protection Committee Office ("PDPC Office") and, where practicable, complete the report within 72 hours.

It's important to note that the 72-hour period is usually calculated when the data controller "becomes aware" of a breach, not when the company completes an internal investigation or confirms the full facts. As a result, the ability of an enterprise to complete internal upgrades, evidentiary preservation and initial risk assessments within the first few hours of an incident often directly affects its ability to comply with its legal reporting obligations.

1. What constitutes a personal data breach?

Personal data breaches are not limited to hacking or large-scale database breaches.

In accordance with the PDPA and related provisions, any security incident that results in the accidental or unlawful destruction, loss, modification, unauthorized disclosure, access or use of personal data may constitute a personal data breach. It usually involves one or more of the following situations:

  • Confidentiality has been compromised (Confidentiality Breach):
  • Personal data has been accessed, disclosed, or used without authorization;
  • Integrity is compromised (Integrity Breach) :
  • Personal data was modified or destroyed without authorization;
  • Availability is compromised (Availability Breach) :
  • Personal data is accidentally or illegally destroyed, lost, or cannot be accessed or used normally.

Common events include:

  • Send customer, employee or supplier information to the wrong recipient;
  • Folders, shared links, or database permissions have been set incorrectly, making them accessible to outsiders;
  • The loss of a computer, mobile phone, mobile hard drive or other device containing personal data;
  • Employees unauthorized to download, copy, forward or disclose personal data;
  • Unauthorized access to databases, email addresses or business systems;
  • Ransomware encrypts, deletes or destroys personal data;
  • A breach occurs at a cloud service provider, data center, outsourcer or other data processor;
  • Paper documents were lost, incorrectly delivered or unauthorized access.

Even if an organization has not yet discovered that the data has been actually misused, a breach assessment process should be initiated immediately whenever the confidentiality, integrity or availability of personal data is affected.

Businesses first need to determine who is responsible for reporting.

Data Controller

The data controller is responsible for determining the purpose and manner of personal data processing. According to Art. 37 (4) of the PDPA, the data controller has the primary responsibility to assess the risk of a breach, report it to the PDPC Office and, if necessary, notify affected individuals.

Data Processor

Data processors process personal data according to the instructions of data controllers, such as cloud providers, IT providers, payroll outsourcers or data storage providers.

When a data processor discovers a breach of personal data, it must notify the data controller without undue delay and provide the data controller with the information necessary for risk assessment and regulatory reporting. The data processor should not wait until the survey is complete before issuing a notification.

Therefore, when signing data processing agreements with cloud service providers, data centers and other outsourcers, enterprises should clearly agree to:

  • Time limit for notification of incidents;
  • The content of the notice and the person responsible;
  • Log and evidentiary preservation obligations;
  • Investigations and regulatory reporting obligations;
  • Incident remediation and cost-sharing mechanisms.

If the supplier, in its capacity as a data processor, does not notify the enterprise until 60 or even 70 hours, the data controller may have difficulty completing the assessment and reporting within the statutory deadline.

The Golden 72 Hour: How should companies respond?

0-24 hours: Controlling events and preserving evidence

Enterprises should immediately initiate incident response mechanisms involving IT, legal, DPO, security, business units and management.

The first actions usually include:

  • Block or restrict unauthorized access;
  • Isolate affected devices, accounts, systems or networks;
  • Suspense user privileges or external interfaces at risk;
  • Reset passwords, access keys, and authentication credentials;
  • Keep system logs, access logs, mail, devices, and other relevant evidence;
  • Confirm whether the leak is continuing;
  • Identify data systems and business processes that may be involved;
  • Require relevant employees, suppliers and service providers to provide information immediately;
  • Keep a record of when an event first became known to the organization and the internal processing timeline.

When controlling measures are taken, care should be taken to avoid improperly deleting logs, covering data or damaging electronic evidence required for subsequent investigations.

24-48 hours: investigate the facts and conduct risk assessment

Enterprises should judge on the basis of available information:

  • Which personal data and data subjects are involved;
  • Number of people affected and size of data;
  • Whether there is a severe impact or damage to the individuals;
  • Whether it involves identity documents, bank accounts, account passwords, health information, biometric information or other sensitive personal data;
  • Whether the data is encrypted, anonymized or otherwise protected;
  • Whether the data has been viewed, downloaded, copied, disclosed or used by unauthorized third parties;
  • Whether the disclosure is likely to result in fraud, identity theft, financial loss, risk to personal security, discrimination, or reputational damage;
  • Whether there is a broader impact on its business and public;
  • Whether the event is likely to continue to expand;
  • Whether the enterprise is a data controller or a data processor in relation to the processing activity;
  • Whether other States or territories are involved and whether the reporting obligations of other jurisdictions are triggered.

Risk assessments should not be based solely on the number of people affected. Even if only a small number of individuals are involved, a disclosure that contains health data, biometric data, financial information or account credentials may pose a higher risk.

If an enterprise believes that the relevant incident does not pose a risk to individuals' rights and freedoms , it may choose not to report it to the PDPC Office, but should retain complete records of the investigation, risk assessment process, and the reasons for non-reporting to facilitate subsequent regulatory reviews.

48-72 hours: Making a report decision and preparing for submission

If a breach may pose a risk to the rights and freedoms of the individual, the data controller should, in principle, report it to the PDPC Office within 72 hours of becoming aware of the breach.

The content of the report should normally include:

  • The nature of the breach, when it occurred and how it was discovered;
  • The type of personal data involved;
  • The type of data subject affected and the approximate number of data subjects;
  • The approximate number of data records affected;
  • Possible consequences and risks;
  • Controls, mitigations and remediation measures that the company has taken or plans to take;
  • The name and contact details of the DPO or other designated associate;
  • Other information helps regulators understand and evaluate events.

If a company cannot confirm all the facts within 72 hours, it can submit a preliminary report based on the information at that time and supplement it in stages when further findings are available.

It is not advisable for companies to wait for all the facts to be clear before reporting on the grounds that the investigation has not been completed. If a report is not reported within 72 hours, a reason for the delay should be provided and a complete record of internal decision-making and investigations maintained.

2. When does the affected individual need to be notified?

If personal data is breached and may pose a high risk to individuals' rights and freedoms , the data controller, in addition to reporting to the PDPC Office, shall notify the affected individuals without undue delay and simultaneously explain the corresponding remedial measures.

The notice should be in clear and understandable language and usually include:

  • What happened?
  • What personal data are involved;
  • The possible impact of the event;
  • What measures the company has taken or plans to take;
  • What measures individuals can take to protect themselves;
  • How to contact the business, DPO or designated person in charge.

Depending on the specific incident, businesses may need to advise affected individuals on:

  • Modify their account password;
  • Enables multi-factor authentication;
  • Freeze bank cards or payment accounts;
  • Beware of unusual transactions and fraudulent information;
  • Protect against phishing emails, phone calls or text messages;
  • Report the case to the relevant agency or request identity protection measures.

The content of the notice should strike a balance between meeting legal disclosure requirements and avoiding the expansion of security risks. For example, organizations should not disclose technical details in public notices that could help attackers continue to exploit system vulnerabilities.

3. What legal liabilities may companies face?

Data controllers who fail to fulfill their obligation to report personal data breaches as required by law may face a maximum fine of 3 million Thai baht in administrative penalties.

If the incident also involves other non-compliance matters, such as:

  • Failure to take appropriate technical and organizational security measures;
  • Failure to appoint a DPO in accordance with the law;
  • No record of data processing activities has been established;
  • Illegal collection, use or disclosure of personal data;
  • Illegal processing of sensitive personal data;
  • The data processor was not properly managed;
  • If you do not cooperate with the PDPC Office's investigation or rectification requirements, the relevant acts may be identified as independent illegal matters, and may have superimposed responsibilities.

In addition to administrative penalties, businesses may face:

  • Civil liability for the affected individuals;
  • Punitive compensation not exceeding a maximum of twice the actual amount of damages;
  • Contract claims by customers, partners or data controllers;
  • Penalties or rectification measures taken by industry regulators;
  • Business interruption, incident investigation, and system repair costs;
  • Customer loss and reputational damage;
  • Criminal liability arises in a particular case of disclosure of a serious violation.

Actual liability will depend on the nature of the incident, the type of data involved, the security measures taken by the company, the speed of response, the effectiveness of remediation and the extent to which the company cooperates with regulatory investigations.

4. What mechanisms should companies put in place in advance?

72 hours is not a window of time for companies to build a response mechanism from scratch. Effective incident response relies on prior preparation.

Businesses should at least establish:

  • Response system for personal data breaches Clarify incident identification, internal escalation, investigation, risk assessment, reporting and remediation processes.
  • Cross-department response teams Define the responsibilities and decision-making authority of IT, Security, Legal, DPO, Business Department, PR and Management.
  • Models for regulatory reports and personal notifications Prepare the Chinese, English or Thai versions in advance to avoid drafting them on a temporary basis after an event occurs.
  • Evidence preservation and incident recording mechanisms Keep a record of the time of discovery, the investigation process, the risk assessment, the rationale for the decision, and the remedial measures taken.
  • Supplier incident notification system Strict notice deadlines, investigative assistance and liability mechanisms are agreed upon in data processing agreements and service contracts.
  • Regular exercises and staff training By simulating scenarios such as mis-sent emails, lost devices, ransomware and vendor leaks, companies can test whether they can complete a response within 72 hours.

epilogue

The 72 hours after a data breach is a critical window for companies to contain losses, meet regulatory obligations and mitigate legal risks. Companies should avoid treating data breaches as simply a technical issue for the IT department. Whether to report to regulators, whether to notify affected individuals, and how to preserve evidence and communicate externally all involve legal, technical, regulatory and commercial judgments.

An effective response can be summarized as follows:

Immediate control, preservation of evidence, rapid investigation, accurate assessment, legal reporting, and continuous remedy.

The sooner an enterprise establishes an incident response process, reporting templates, and supplier notification mechanism, the more likely it is to make timely, explainable, and legally appropriate decisions when real events occur.

Legal basis

  • Section 37 (4) of the Personal Data Protection Act B.E. 2562 (2019) of Thailand;
  • Personal Data Protection Commission of Thailand Notice on Standards and Methods for Notification of Personal Data Breaches B.E. 2565 (2022).

This article is for general informational purposes only and does not constitute legal advice on any specific facts or matters. Whether a company needs to report a data breach or notify an affected individual should be assessed on a case-by-case basis, taking into account the nature of the incident, the type of data involved, the potential impact and the information available at the time.

[Contact Person: Ms. Ritima Jirasuradate | Partner]