All guides

Thailand compliance guide

Thailand's PDPA for Cold Email and Outreach: The 2026 Guide

Thailand's Personal Data Protection Act is the most GDPR-like law in Southeast Asia, and that cuts both ways for an outbound team. There is no business contact exception of the kind Singapore offers, so a named prospect's work email is regulated personal data. But unlike Malaysia, Thailand gives you a lawful basis that fits cold outreach without consent: legitimate interest. This guide covers what the Act requires, why legitimate interest is the pivot for B2B email, the notice and objection duties that come attached, how the law reaches foreign senders, and what the penalties look like. It is written for sales operators, not lawyers.

Last reviewed 11 September 2026 · This guide is general information, not legal advice.

What the PDPA covers, and when it started to bite

The Personal Data Protection Act B.E. 2562 (2019) is Thailand's general data protection law. It was passed in 2019, postponed twice while the country dealt with the pandemic, and finally came into full force on 1 June 2022. It is administered by the Personal Data Protection Committee and its office, the PDPC, under the Ministry of Digital Economy and Society.

The Act was drafted closely on the European GDPR, so its architecture will look familiar: data controllers and data processors, a defined set of lawful bases, notice duties at the point of collection, a catalogue of data subject rights, security and breach obligations, and a separate stricter regime for sensitive personal data. Personal data means any information relating to an identifiable natural person, which puts a prospect's name, work email, direct line, and job title squarely in scope.

There is no equivalent of Singapore's section 4(5) business contact information exception. Thai law does not treat a work email address as a lower-risk category simply because it belongs to someone at a company. If you are emailing a named individual in Thailand, you are processing their personal data and you need a basis for it.

The lawful bases, and why legitimate interest is the pivot

Section 24 of the Act lists the bases on which you may collect and use personal data without consent. The ones that matter for a commercial team are performance of a contract with the data subject, compliance with a legal obligation, and legitimate interests pursued by the controller or a third party, provided those interests are not overridden by the data subject's fundamental rights.

That last basis is what makes Thailand more workable than Malaysia for B2B outreach. Malaysia's law has no legitimate interest route, so consent is effectively the only door. Thailand has the door, and business-to-business marketing to a relevant decision maker is a recognised use of it, in the same way the GDPR acknowledges direct marketing as a possible legitimate interest. It is not automatic. The basis only holds if the interest is real, the processing is proportionate to it, and the individual's rights do not outweigh it.

The practical test is one you should be able to answer in a sentence for any campaign: why is this person, in this role, at this company, a reasonable recipient of this message? Targeted outreach to a head of operations about an operations problem passes that test easily. A ten thousand contact blast to every Thai email address you could assemble does not, and the balancing test is where it fails.

Document the assessment before the campaign, not after a complaint. A short written record of the interest, the necessity, and the balancing outcome is the difference between a defensible position and an argument invented under pressure.

Notice at collection, even when the data came from elsewhere

Section 23 requires you to tell the data subject, at or before collection, what you are collecting, the purpose, the lawful basis, who you may disclose it to, how long you will keep it, and how to exercise their rights and complain. Where you did not collect the data from the person directly, the Act still expects that notice to reach them, and to reach them promptly rather than eventually.

For outbound this is the duty teams most often miss. You built a prospect list from public and commercial sources, so the person never gave you anything and never saw a privacy notice. The fix is not complicated: your first email is the notice moment. A short, plain line saying where you got their business details, why you are writing, and where the full privacy notice lives satisfies the spirit of section 23 and costs you two lines of copy.

Keep the privacy notice reachable in one click from every send, and keep it current. A notice that describes a data flow you stopped using two years ago is worse than no notice at all, because it documents an inaccuracy.

The right to object, and what an opt-out obliges you to do

Section 32 gives the data subject a right to object to processing. Where the processing rests on legitimate interest, an objection generally puts the burden on you to show compelling grounds that override the individual's rights. Where the purpose is direct marketing, treat the objection as absolute: there is no balancing left to do, and the only correct response is to stop.

Alongside objection sit the rest of the GDPR-shaped rights: access, data portability, erasure, restriction, and rectification. An access request from a Thai prospect means producing every field you hold on them, including the detail you appended after import and the record of where it came from, so a CRM that cannot say where a contact came from becomes a compliance problem rather than a data-hygiene one.

Operationally, treat any reply that says stop, remove me, or unsubscribe as a section 32 objection whatever form it arrives in. Suppress the contact permanently and across the entire organisation, not only the campaign or the mailbox that received it. Thailand has no Do Not Call registry equivalent for marketing, so your own suppression list is the only control standing between you and a repeat contact.

Spam itself is policed by the Computer Crime Act

Thailand has no dedicated anti-spam statute in the way Singapore has the Spam Control Act. The nearest provision sits in the Computer Crime Act B.E. 2550 (2007). Section 11 makes it an offence to send electronic mail in a way that conceals or falsifies its source, or that disturbs the recipient's normal use of their computer system without offering an easy way to decline further messages. The fine runs up to 200,000 baht.

Read that as a plain instruction about mechanics rather than about content. Send from a real, resolvable domain. Put a genuine company identity and a working reply route in every message. Give a one-click opt-out that works on the first click and needs no login. Those three habits keep you clear of section 11 regardless of what the PDPA analysis says about the underlying data.

The two laws stack rather than substitute. The PDPA governs whether you may hold and use the prospect's details; the Computer Crime Act governs how the message itself behaves. A campaign can be clean on one and exposed on the other.

Foreign senders: reach beyond Thailand, and the representative

Section 5 extends the Act to controllers and processors outside Thailand where the activity involves offering goods or services to data subjects in Thailand, whether or not payment is required, or monitoring the behaviour of data subjects in Thailand. A Singapore or Australian team running outbound into Thai accounts is offering services to people in Thailand, so the Act reaches them.

Where that applies to a foreign controller, the Act also expects a representative appointed in Thailand, in writing, able to act for the controller in dealings with data subjects and the PDPC. Narrow exemptions apply, including for limited and occasional processing that does not involve large volumes of sensitive data, and many small teams will sit inside them. That is worth establishing explicitly rather than by default, because the representative requirement is the obligation foreign senders most often discover late.

The pragmatic posture is the same one that works everywhere in the region. Behave as though the local law applies, keep volumes proportionate to genuine relevance, and make sure someone in the business can name the basis you are relying on if asked.

Cross-border transfers of Thai prospect data

Sections 28 and 29 govern sending personal data out of Thailand. The baseline rule is that the destination must have adequate data protection standards, with exceptions covering consent given after the person has been told the destination lacks adequacy, contractual necessity, vital interests, and legal obligations.

The PDPC filled in the detail with cross-border transfer notifications that took effect in March 2024, recognising binding corporate rules for transfers within a corporate group and appropriate safeguards, such as contractual protections, for transfers to unrelated recipients.

This matters more than it sounds for a sales team, because almost every outbound stack transfers data by default. If your CRM, your email platform, and your warehouse sit outside Thailand, Thai prospect records cross a border the moment they are created. Someone should be able to state which route covers that transfer and point at the paperwork behind it.

Penalties: three tiers, not one

The Act separates its consequences into administrative, criminal, and civil, and reading only the headline number understates the exposure. Administrative fines are imposed by the expert committee and run to a maximum of 5,000,000 baht for the most serious breaches, with lower ceilings for lesser ones.

Criminal liability is narrower and attaches mainly to unlawful use or disclosure of sensitive personal data in ways likely to cause harm, damage, or reputational injury, or done for unlawful benefit. Penalties there reach imprisonment of up to one year and fines of up to 1,000,000 baht, and directors can be personally liable where an offence by a company was committed on their instruction or through their neglect.

The civil tier is the one that scales. A data subject who suffers loss can claim compensation, and the court may award punitive damages of up to twice the actual damages. Ordinary B2B cold email is nowhere near the criminal tier, but the administrative and civil tiers reach ordinary marketing conduct comfortably.

A practical checklist for prospecting into Thailand

These rules compress the PDPA and the Computer Crime Act into operating habits for a team running outbound into Thailand.

  • Write down your legitimate interest assessment before the campaign: the interest, why the processing is necessary for it, and why it does not override the recipient's rights.
  • Keep targeting tight enough that the assessment is easy to defend; relevance is the evidence and volume is the counter-evidence.
  • Use your first email as the notice moment: say where their business details came from, why you are writing, and link the full privacy notice.
  • Identify your company honestly, send from a resolvable domain, and never obscure the source of the message.
  • Give a one-click opt-out that works without a login and without a reply.
  • Treat any stop, remove, or unsubscribe reply as a section 32 objection: suppress permanently and organisation-wide, not campaign by campaign.
  • Record the source of every contact so you can answer an access request with provenance rather than guesswork.
  • Check whether section 5 catches you as a foreign controller, and whether the Thailand representative requirement follows.
  • Know which cross-border route covers Thai prospect data held in offshore systems, and keep the supporting paperwork with it.
  • Keep sensitive personal data out of prospect records entirely; that is where the criminal tier lives.

Prospecting into Thailand?

HuntSales handles the operational half of this: honest sender identity on every send, one-click opt-outs written to a permanent suppression list that applies across your whole organisation, and a source record behind every contact. Start with the Thailand playbook.

Read the Thailand playbook

Frequently asked

Is B2B cold email legal in Thailand?

Yes, when it rests on a proper lawful basis and respects the notice and objection duties. Thailand's PDPA has no business contact exception, so a named prospect's work email is personal data, but section 24 allows processing on legitimate interest without consent. Targeted, relevant outreach to a decision maker, with honest identification and an instant opt-out, is the defensible pattern. Untargeted bulk sending is not.

Do I need consent to email a Thai prospect?

Not necessarily. Consent is one basis among several, and legitimate interest under section 24 is the one that fits B2B outreach. It requires a genuine interest, processing that is proportionate to it, and a balancing test that the recipient's rights do not win. Consent becomes the practical route only where the targeting is too broad for that balance to hold.

How is Thailand's PDPA different from Singapore's for outreach?

Singapore's section 4(5) disapplies the consent obligations for business contact information such as work emails and job titles, so B2B email starts from an easier position. Thailand has no such carve-out and instead offers legitimate interest as a basis you must justify. Singapore also runs a Do Not Call Registry for calls and SMS, which Thailand does not; in Thailand your own suppression list is the whole control.

How is Thailand different from Malaysia?

Malaysia's PDPA has neither a business contact exception nor a legitimate interest basis, which leaves consent as effectively the only route for named individuals and pushes teams toward company-level addresses. Thailand keeps the legitimate interest basis, so well-targeted outreach to a named decision maker has a lawful footing that Malaysia does not offer.

Does the PDPA apply to my company if we are based outside Thailand?

It can. Section 5 extends the Act to foreign controllers who offer goods or services to people in Thailand or monitor their behaviour there, so an offshore team prospecting into Thai accounts is generally in scope. Where that applies, the Act also expects a representative appointed in Thailand, subject to narrow exemptions for limited and occasional processing.

What must I do when a Thai prospect asks to be removed?

Stop. Where the purpose is direct marketing, an objection under section 32 leaves no balancing exercise to run. Suppress the contact permanently and across the whole organisation rather than only the campaign that received the reply, and keep the suppression record so a later import cannot resurrect them.

What are the penalties for getting this wrong?

Three tiers. Administrative fines reach 5,000,000 baht for the most serious breaches. Criminal liability, up to one year of imprisonment and a fine of up to 1,000,000 baht, is largely reserved for unlawful use or disclosure of sensitive personal data. Civil claims by affected individuals can carry punitive damages of up to twice the actual loss. Separately, concealing an email's source or omitting an easy opt-out can draw a fine of up to 200,000 baht under section 11 of the Computer Crime Act.

Can I store Thai prospect data in an overseas CRM?

Yes, with a route that covers the transfer. Sections 28 and 29 require adequate protection at the destination or one of the listed exceptions, and the PDPC notifications effective March 2024 recognise binding corporate rules within a group and appropriate contractual safeguards for other recipients. Decide which route applies to your stack and keep the evidence with it.

Outreach that stays on the right side of the rules

Suppression lists, unsubscribe handling, and a calling workflow built for APAC compliance, in one outreach CRM. Free for solo founders.

Start free

More guides