SOVEREIGNTY LAW ATLAS — TH
Thailand
The verdict.
FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04Thailand's regime is GDPR-shaped and enforcement is maturing — the operative question is transfer mechanics, not hosting location.
ATLAS RECOMMENDATION — DOCUMENTED MIXED-ORIGIN · No scheme, transfer-mechanics regime — local runtime with governed overflow available. Seeded into the configurator; adjust anything.
The dossier.
SOURCES FOOTNOTED · EVIDENCE STATE LABELLEDDomains
D1 — Data residency & localization
The PDPA, fully in force since June 2022, governs cross-border transfers through sections 28/29: transfer is permitted where the destination has adequate protection standards or where safeguards/bindings apply, with derogations including consent.1 Sub-regulations detailing transfer criteria were issued through 2023–24 as the PDPC stood up full operations. (REPORTED) There is no general data localization mandate.
D2 — AI-specific regulation
No AI statute in force. Draft AI legislation has been under development with public consultation rounds reported; as of capture nothing binding had been enacted.
D3 — Cloud & procurement sovereignty
No sovereign-cloud certification scheme identified at demo depth. Government cloud usage is guided by central IT policy rather than a qualification regime comparable to SecNumCloud or C5.
D4 — Export & access
Thailand is outside the major access alliances. Exposure is provider-level: US-controlled providers operating in Thailand remain within CLOUD Act reach; no Thai extraterritorial access statute of comparable scope was identified at demo depth.
Extraterritorial exposure
US lawful-access exposure tracks provider control. The PDPA's transfer rules address protection standards of the destination, not the nationality of the provider — a buyer needing insulation from non-Thai lawful access must solve that at provider-selection level. The official gazette text (Thai) was fetch-blocked at capture (403); analysis is based on the statute's known provisions and secondary official materials — translation review pending. US reference record deferred to Phase 2.
Disclaimer
This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied. Thai-language sources are summarized in English; the official text governs.
- Personal Data Protection Act B.E. 2562 (2019) — Royal Thai Government Gazette — fetch blocked (403), cited to official source. (REPORTED) ↑
The instruments.
1 ON RECORD · 3 GAPSPersonal Data Protection Act B.E. 2562 (2019)
REPORTEDNo AI-specific statute in force; draft legislation reported
No sovereign-cloud certification scheme identified at demo depth
No material export/access regime identified at demo depth
This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.