top of page
ค้นหา

Businesses Must Update Data Access Response Mechanisms Within 60 Days企業需於 60 天內全面更新存取回應機制

  • 3 ชั่วโมงที่ผ่านมา
  • ยาว 4 นาที
泰國個資法PDPA新公告資訊圖表,說明企業需於60天內更新個資存取回應機制、時程與費用標準。

Thai Personal Data Protection Committee (PDPC) issued Notification of the Personal Data Protection Committee re: Criteria for Accessing and Obtaining Copies of Personal Data under the Responsibility of a Data Controller or Requesting Disclosure of the Acquisition of Personal Data Obtained Without Consent, B.E. 2569 (2026) on 16 July 2026, and will be effective on 14 September 2026.

泰國個人資料保護委員會(PDPC)於 2026 年 7 月 16 日發布《佛曆 2569 年(2026 年)個人資料保護委員會公告:關於存取及獲取資料控管者責任範圍內之個人資料副本或請求公開未經同意獲取之個人資料來源之標準》,並將於 2026 年 9 月 14 日生效。

 

The notification includes details of handling requests by data subjects to access and obtain copies of their personal data, as well as requests for information on the source of personal data collected without consent. It introduces requirements relating to request submission, identity verification, extensions of response timelines, access methods, fees, and record retention.

該公告包含處理資料當事人存取及獲取其個人資料副本之請求,以及針對未經同意收集之個人資料來源資訊請求的處理細節。其引入了與請求提出、身份驗證、回覆時限延長、存取方式、費用及紀錄留存相關的要求。

 

此份公告包含13個條文以及1份收費表,重點摘要如下:

The Notification includes 13 clauses and 1 fee schedule, the details are as follows:

 

1.     Scope of Application: Regulates the standard operating procedures for Data Controllers handling requests from Data Subjects (or their authorized representatives) to access, obtain copies of, or disclose the sources of personal data collected without consent under Section 30 of the PDPA.

適用範圍: 規範資料主體(Data Subject)或其授權代理人依 PDPA 第 30 條向資料控制者(Data Controller)提出個人資料存取、索取副本及查詢未經同意之資料來源時的處理標準。

2.     Mandatory Application Channels and Identity Verification: Data Controllers must provide at least two submission channels (in-person at the business location and registered mail). Electronic channels are optional. Requests must be submitted in writing or in an electronic format. Controllers may require reasonable identity verification documents (e.g., ID cards, powers of attorney). Authorized representatives must provide a power of attorney affixed with duty stamps, and official identity documents for both the data subject and the representative.

強制申請管道與身份驗證: 資料控制者必須提供至少兩種申請管道(臨櫃與掛號郵寄),可選擇電子方式。須以書面或電子方式提出申請,控制者可要求合理的身份證明文件(如身分證、委託書)授權代理人必須提供貼有印花稅票的授權書,以及資料主體與代理人雙方的官方身分證明文件。

3.     Review and Processing Timelines

審查與處理時程

Formal Review: The review shall be completed within 15 days of receiving the application. If the documentation is incomplete, the applicant must be notified to submit the necessary corrections or additional materials; the deadline for such submission shall be at least 10 days, and failure to meet this deadline may result in the application being deemed abandoned.

形式審查: 收到申請後 15 天內完成審查。若文件不齊全須通知補正,補正期限至少 10 天,逾期得視為放棄申請。

Processing Deadline: Once verified, the request must be fulfilled within 30 days. For large-volume or complex requests, this period may be extended by up to an additional 30 days with written notice of the reasons.

處理期限: 確認無誤後,必須在 30 天內提供資料;若為大批量或複雜案件,可延長 30 天,須書面通知理由。

4.     Grounds for Refusal and Recordkeeping: Requests may be refused if permitted by law, court order, or if compliance would adversely affect the rights and freedoms of third parties (e.g., trade secrets, IP, or personal data of others). Requests may also be refused if they are manifestly unfounded or unreasonably burdensome. Any refusal must be accompanied by written reasons. All data subject access request requests and action records must be retained for at least 2 years.

拒絕事由與紀錄留存: 若依法律、法院命令或因影響第三方權益(如商業機密、他人個資);若請求顯無理由或負擔過重,亦得予以拒絕,必須提供書面理由並留下紀錄。另外,所有資料主體存取請求申請與處理紀錄必須至少留存 2 年。

5.     Fee Caps for Providing Information: electronic provision is in principle free of charge, while paper photocopying incurs fees. For example, photocopying fees must not exceed 1 THB per page for A4 size, and data certification fees are capped at 5 THB per certification.

資料提供收費上限標準: 電子提供原則上免費,紙本影印有費用產生。例如,A4 尺寸的影印費每頁不得超過 1 泰銖,資料認證費每份最高 5 泰銖。

 

Thai companies must maintain data access request mechanism before the Access Request Notification takes effect.

泰國企業必須在《存取請求公告》正式生效前,建置並維護資料存取請求機制。


 
 
 

ความคิดเห็น


© 2026 by International Business Consultancy Co.,Ltd. 

  • Facebook Social Icon
bottom of page