β‘ Quick Facts
Enforced by Personal Data Protection Commission (PDPC). Applies to any organization collecting, using, or disclosing personal data in Singapore β including foreign companies with Singapore customers. Max penalty: S$1 million or 10% of annual turnover in Singapore (whichever is higher).
Enforced by the PDPC (Thailand). Applies to any organization processing personal data of individuals in Thailand, regardless of where the organization is located. Max penalty: 5 million THB administrative fine + criminal liability (up to 1 year imprisonment for certain violations).
Who These Laws Apply To
Both laws have extraterritorial reach β meaning your business does not need to be based in Singapore or Thailand to be covered. If you:
- β’ Sell products to customers in Singapore or Thailand
- β’ Collect email addresses, names, or payment information from Southeast Asian customers
- β’ Have a website or app used by people in these countries
- β’ Use analytics or tracking that captures data from Southeast Asian visitors
- β’ Drop-ship or fulfill orders through a Singapore or Thailand-based partner
...then you should understand these laws. While enforcement against small foreign businesses is still developing, the trend is clear: Asian privacy regulators are becoming more active, and cross-border e-commerce sellers are increasingly expected to comply.
Need a Privacy Policy for Southeast Asia?
Our compliance toolkit includes privacy policy templates that address PDPA and PDP requirements for cross-border e-commerce.
View Compliance Toolkit βSingapore PDPA: Key Requirements
1. Consent Obligation
You must obtain consent before collecting, using, or disclosing personal data. Consent can be explicit (opt-in checkbox) or deemed (voluntarily providing data for a reasonable purpose). Individuals can withdraw consent at any time with reasonable notice.
2. Purpose Limitation & Notification
Inform individuals of the purposes for collection at or before the time of collection. Only use data for those stated purposes.
3. Protection Obligation
Implement reasonable security measures to protect personal data. This is a "reasonableness" standard β small businesses are not held to the same standard as banks, but you must have basic security (encryption, access controls, MFA).
4. Data Breach Notification
Mandatory breach notification to PDPC and affected individuals if the breach: (a) results in significant harm, or (b) involves 500+ individuals. Notification must happen as soon as practicable.
5. Data Protection Officer (DPO)
Every organization must designate a DPO and publish their contact information. For small businesses, this can be the owner β it does not need to be a dedicated hire.
Thailand PDPA: Key Differences from Singapore PDPA
Closely Modeled on GDPR
Thailand's PDPA is structurally similar to GDPR β more so than Singapore's PDPA. It uses GDPR concepts like "data controller," "data processor," and "legitimate interest" as a lawful basis. If you understand GDPR, you are 80% of the way to understanding Thailand's PDPA.
Consent Is More Central
While both laws require consent, Thailand's PDPA makes consent the default lawful basis for processing, similar to GDPR. Consent must be explicit, freely given, and withdrawable. Pre-checked boxes and implied consent are not valid.
Criminal Liability β Unique to Thailand
Thailand's PDPA includes criminal penalties rarely seen in other data protection laws. Knowingly using or disclosing personal data in violation of the PDPA can result in up to 1 year imprisonment and/or fines up to 1 million THB.
Cross-Border Data Transfer Restrictions
Both laws restrict transferring personal data to countries without "adequate" data protection standards. However, both allow transfers based on consent or contractual safeguards β the same mechanisms GDPR uses.
GDPR Compliance Guide
Since Thailand's PDPA closely follows GDPR, understanding GDPR gives you a strong foundation. Check our GDPR guide for detailed implementation steps.
Read GDPR Guide βPractical Compliance Steps for Cross-Border Sellers
- 1 Post a privacy policy that covers all applicable jurisdictions.
Your privacy policy should disclose data collection and processing practices and address each relevant law's specific requirements. You do not need separate policies β one comprehensive policy works, as long as each jurisdiction's required disclosures are present.
- 2 Implement a consent management system.
A cookie consent banner that works for GDPR will also cover PDPA requirements. Ensure you capture and log consent (time, date, what was consented to) and provide an easy way to withdraw consent.
- 3 Designate a DPO and publish their contact.
Singapore PDPA requires a named Data Protection Officer. This can be you (the business owner). Add a DPO contact to your privacy policy. It costs nothing and satisfies a legal requirement.
- 4 Have a breach notification plan.
Both PDPA and PDP require breach notification. Know who to contact and in what timeframe. For Thailand PDPA, breach notification must be made within 72 hours to the PDPC.
- 5 Document your data flows across borders.
If customer data moves from Singapore/Thailand to your servers in the US, you need to document this transfer and ensure adequate protection. Standard Contractual Clauses (SCCs) or data processing agreements with your service providers help satisfy this requirement.