← SOVEREIGNTY LAW ATLAS

SOVEREIGNTY LAW ATLAS — TH

Thailand

TIER DEMO · STATUS PUBLISHED · LAST FULL REVIEW 2026-08-04 · 1 INSTRUMENTS ON RECORD

The verdict.

FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04
Data residency & localizationD1 — WHERE DATA MUST LIVE Transfer controls not localizationREPORTED
AI-specific regulationD2 — AI ACTS & REGISTRATION DUTIES Draft onlyVERIFIED ABSENCE
Cloud & procurement sovereigntyD3 — CERTIFICATION & MANDATES No national schemeVERIFIED ABSENCE
Export & access lawsD4 — EXTRATERRITORIAL REACH Low external exposureJUDGMENT
Instruments on record 1
Last full review 2026-08-04
Status PUBLISHED
For a buyer

Thailand's regime is GDPR-shaped and enforcement is maturing — the operative question is transfer mechanics, not hosting location.

Configure your SovereigntyBox for Thailand →

ATLAS RECOMMENDATION — DOCUMENTED MIXED-ORIGIN · No scheme, transfer-mechanics regime — local runtime with governed overflow available. Seeded into the configurator; adjust anything.

The dossier.

SOURCES FOOTNOTED · EVIDENCE STATE LABELLED

Domains

D1 — Data residency & localization

The PDPA, fully in force since June 2022, governs cross-border transfers through sections 28/29: transfer is permitted where the destination has adequate protection standards or where safeguards/bindings apply, with derogations including consent.1 Sub-regulations detailing transfer criteria were issued through 2023–24 as the PDPC stood up full operations. (REPORTED) There is no general data localization mandate.

D2 — AI-specific regulation

No AI statute in force. Draft AI legislation has been under development with public consultation rounds reported; as of capture nothing binding had been enacted.

D3 — Cloud & procurement sovereignty

No sovereign-cloud certification scheme identified at demo depth. Government cloud usage is guided by central IT policy rather than a qualification regime comparable to SecNumCloud or C5.

D4 — Export & access

Thailand is outside the major access alliances. Exposure is provider-level: US-controlled providers operating in Thailand remain within CLOUD Act reach; no Thai extraterritorial access statute of comparable scope was identified at demo depth.

Extraterritorial exposure

US lawful-access exposure tracks provider control. The PDPA's transfer rules address protection standards of the destination, not the nationality of the provider — a buyer needing insulation from non-Thai lawful access must solve that at provider-selection level. The official gazette text (Thai) was fetch-blocked at capture (403); analysis is based on the statute's known provisions and secondary official materials — translation review pending. US reference record deferred to Phase 2.

Disclaimer

This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied. Thai-language sources are summarized in English; the official text governs.

  1. Personal Data Protection Act B.E. 2562 (2019) — Royal Thai Government Gazette — fetch blocked (403), cited to official source. (REPORTED)

The instruments.

1 ON RECORD · 3 GAPS

Personal Data Protection Act B.E. 2562 (2019)

REPORTED
TYPE STATUTESTATUS IN-FORCEENACTED 2019-05-27 · IN FORCE 2022-06-01
Evidencefetch-blocked — Royal Gazette returns 403 to scripted fetch (2026-08-04)
RAGnot-submitted
GAP — D2 · VERIFIED 2026-08-04VERIFIED ABSENCE

No AI-specific statute in force; draft legislation reported

GAP — D3 · VERIFIED 2026-08-04VERIFIED ABSENCE

No sovereign-cloud certification scheme identified at demo depth

GAP — D4 · VERIFIED 2026-08-04VERIFIED ABSENCE

No material export/access regime identified at demo depth

This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.

SBX CONCIERGEnothing leaves this page