Only one month after enforcing the law to protect the Thai people’s personal data security and privacy, the government had a change of heart.
Instead of imposing the PDPA law on all organisations that handle data, the government has helped some government agencies to bypass the Personal Data Protection Act (PDPA) in the name of “national security” and “public service”. As a result, government, national security agencies, the courts, public attorneys, police and tax authorities will be permitted to collect, access, and transfer our data with impunity.
In addition, the government can access citizens’ personal data to fulfil those obligations.
A scary scenario indeed.
The Personal Data Protection Act (PDPA) took effect on June 1 this year after a two-year delay. The long-overdue law sets rules and standards for the private and public sectors to follow on collecting and using personal data to protect privacy and security.
While the business community is busy setting up new security mechanisms to comply with the PDPA’s complex rules and avoid legal punishment, the government has hatched a plan to bypass the PDPA altogether.
On July 5, 2022, the cabinet approved the draft of the royal decree by the Ministry of Digital Economy and Society to exempt government agencies from the PDPA law if the data is to be used for public service, national security protection or the inspection of crimes such as narcotics offences, human trafficking and money laundering.
Following cabinet approval, the royal decree can bypass parliament as an urgent piece of law. The legislation will be effective after it is signed by His Majesty the King.
This royal decree will affect citizens’ rights and freedoms for many reasons.
Firstly, the areas of exemption are too broad. Under the drafted royal decree, the PDPA’s stipulations on data protection rights, petition procedures, financial compensation and the punishment for violators will not apply to those state authorities which are exempted by the royal decree.
In short, the officials will freely enjoy legal immunity from prosecution under data protection laws.
Secondly, the exemptions granted to protect “national security” and allow operations of “public service” are too wide-ranging and unclear. This ambiguity allows officials to interpret “national security” and “public service” as they see fit, making it easy for them to abuse power. Allowing all levels of the judiciary — from police and attorneys to the courts — and tax collectors to freely access and transfer the citizens’ personal data creates similar worries.
Public concern over data safety is valid when trust is already so low and power abuse is so widespread.
The public sector has repeatedly failed to protect the personal data of those it should be serving. Government agencies experienced at least five data breaches last year alone. The hacked data involved users’ health records and other sensitive information.
Apart from data breaches from external violators, the government also faces allegations of breaching public privacy and freedom by using spyware to track and record activists’ and journalists’ mobile phone use. Only governments can buy this spyware to hack people’s cell phones.
The government’s alleged violations have raised questions about state responsibility and accountability. Exempting the state from the PDPA further intensifies public concern about abuse of power and political persecution. It also perpetuates a culture of impunity, which aggravates state violence against the citizens.
The exemption may also affect the economy. The PDPA is an important part of a host of digital economic laws to set standards and regulations on the cross-border transfer of personal data, which is essential for digital economic transactions.
Public trust in a secure cross-border transfer of personal data is crucial for the growth of the digital economy. As a result, most international trade agreements, such as the Regional Comprehensive Economic Partnership or Comprehensive and Progressive Agreement for Trans-Pacific Partnership, require members to honour personal data protection. Even China, an economic powerhouse, agreed to pass the law on personal data protection last year.
The core principle of data protection and privacy in international trade is that the data senders’ and receivers’ countries must share similar data protection standards. To safeguard citizens’ rights and freedoms, the General Data Protection Regulation of the European Union, the gold standard on data protection and privacy, prohibits intervention by the government or security agencies.
The government’s attempt to free itself from the PDPA’s legal obligations violates EU standards on data protection. It will backfire economically.
Data transfer to Thailand will become problematic from failure to meet international standards. The local businesses will be hit hard. The private sector will therefore miss the opportunities to grow in the era of the digital economy.
The government must realise the risks of allowing officials to tamper with people’s privacy and threaten people’s safety. The economic loss will be huge. So will the impact on the citizens’ rights and freedoms.
This royal decree effort violates citizens’ rights enshrined in the constitution. It protects the officialdom, not the people. It perpetuates state oppression and a culture of impunity. It risks seeing Thailand slide into becoming a pariah state. It must be stopped before it is too late.
ซึ่งตาม GDPR หรือ General Data Protection Regulation ของสหภาพยุโรปกำหนดว่า มาตรฐานที่เพียงพอนี้รวมถึงการคุ้มครองข้อมูลส่วนบุคคลตามกฎหมายจะต้องไม่ถูกแทรกแซงโดยรัฐหรือหน่วยงานด้านความมั่นคงของรัฐ ซึ่งเป็นหลักการพื้นฐานของรัฐที่เป็นนิติรัฐที่มุ่งคุ้มครองสิทธิและเสรีภาพของประชาชน
A Study of the Necessity of and Approaches to the Preparation of Personal Data Protection Guidelines
Published in TDRI Quarterly Review, Vol. 37 No.2 (June 2022)
Suggested Bibliographic Citation: Trisadikoon, K. (2022). “A Study of the Necessity of and Approaches to the Preparation of Personal Data Protection Guidelines.” TDRI Quarterly Review, 37(2). 23-44.
Summary
This article examines the necessity of developing personal data protection guidelines to support the effective enforcement of Thailand’s Personal Data Protection Act B.E. 2562 (2019). Although the Act establishes fundamental principles, data subject rights, obligations of data controllers and processors, and legal penalties, it lacks detailed practical instructions for real-world implementation. As a result, organizations with legal duties may face uncertainty in compliance, which could undermine the effectiveness of personal data protection. The study argues that practical guidelines are therefore essential as an instrument for translating legal principles into concrete procedures, standards, and operational practices tailored to organizational contexts.
The paper outlines key elements of the Thai legal framework, including the scope of application, rights of data subjects, relationships among data subjects, controllers, and processors, rules governing data processing throughout the data life cycle, and enforcement mechanisms. It then conducts a comparative analysis of personal data protection systems and guidelines in the European Union, the United Kingdom, Japan, Singapore, and the United States. The findings indicate that effective guidance typically exists at multiple levels, including general conceptual guidelines, sector-specific guidelines tailored to particular industries, and topic- or activity-specific guidelines addressing concrete situations. Such multi-layered guidance enables organizations to interpret and apply legal requirements in a manner consistent with actual operational realities.
Based on these insights, the article proposes an approach for developing personal data protection guidelines in Thailand that aligns with the characteristics of different sectors and the life cycle of personal data processing. The recommended structure includes general principles, practical examples of data processing activities, and frequently asked questions to facilitate usability. The study also suggests phased dissemination according to the readiness of each industry and continuous updates to reflect secondary regulations and evolving circumstances. In conclusion, the article emphasizes that clear, context-sensitive guidelines are a critical condition for enabling the Personal Data Protection Act to achieve its intended goal of effectively safeguarding individuals’ privacy rights in practice.
For the past two years, Thailand’s tourism industry has been in a coma due to the Covid-19 pandemic. To revive the economy, the government has now relaxed Covid-19 control measures to reopen the country. Big hotels now have a chance to recover but for a majority of small hotels, however, it is already too late — many of them had their fate sealed by outdated laws regulating hotels that made it near impossible for them to gain an operating licence.
Ask operators of small hotels and hostels, and they will pour out the same grievances; the laws regulating hotels not only favour big hotels and discriminate against small operators, but they also prevented small players from receiving state assistance during the pandemic.
For example, when the government launched the Sandbox Programme to revive the tourism industry last year, small hotel operators cried foul with only big hotels eligible for the programme. Small hotel operators petitioned Prime Minister Prayut Chan-o-cha for intervention for they, too, desperately needed help.
The state authorities argued that most small hotels were not eligible because they did not have an operating licence. But not having the licence is not their fault, smaller operators claimed. The crux of the problem is that the laws regulating hotels make it next to impossible for small operators to obtain a licence.
For starters, laws governing hotels do not differentiate between big and small businesses. They have fixed, uniform standards that require high investment for all hotels regardless of business size. While big hotels with money can meet such requirements, most small hotels and those run by local communities cannot.
“Without an operating licence, they cannot get emergency assistance from the government when hit by the pandemic. Worse, they are considered illegal businesses.”
The smaller operators’ requests for more flexible and timely regulations to fit local conditions and adapt to changes have been rejected. Without an operating licence, they cannot get emergency assistance from the government when hit by the pandemic. Worse, they are considered illegal businesses.
At present, hotel operators are governed by the 2004 Hotel Act, the 1990 Town and Country Planning Act and the 1979 Building Control Act. Apart from being outdated, the standards required by these laws are based on the operations of large hotels. When small operators cannot meet the legal requirements more suited for big hotels such as noise control, the size of a water treatment system, and parking spaces, they are denied the licences.
Similarly, the building law is designed for the construction and safety of large buildings. Many small hotels, meanwhile, are renovations of old homes or commercial buildings. Although the authorities at the Department of Public Works and Town and Country Planning have adjusted some requirements to accommodate small buildings, the changes still do not cover many types of accommodation such as boathouses or treehouses.
The tourists’ increasing preference for cosy accommodations with quaint charms has led to the mushrooming of boutique hotels and small hotels across the country. The locals finally have a chance to benefit from tourism, not only big investors. The outdated laws, however, make it very difficult for them to obtain an operating licence.
According to the Department of Provincial Administration, there are 30,000 registered hotels nationwide. Meanwhile, over 60,000 hotels are listed on the Online Travel Agency website.
Apart from specifying the size and structure of the buildings, hotel laws also require a separation between the operators’ homes and hotel areas. They also prohibit homestays to have more than four rooms and receive more than 20 customers.
These rules affect homestay businesses where the owners live on the same premises. It also prevents homestays from growing, thus making it difficult for the owners to improve their venues and services.
Furthermore, hotel laws specify in detail what services must be provided. When small hotel customers only need clean rooms to stay in, this rule on mandatory services has put an extra financial burden on small hotel operators.
In 2019, the government initiated a temporary solution for small hotels, giving them two years to improve their premises so they comply with the laws and file for a licence. The grace period expired in August last year.
The reprieve was no use, however, because it came when the country was hit by Covid which almost wiped out the whole tourism industry. Small hotels, struggling to survive, simply have no resources to develop their operations and file for the licence within the deadline.
Instead of forcing small operators to comply with outdated laws, the government must overhaul the laws that prevent small players and local communities from benefiting from the tourism industry.
True, the hotel and building laws aim to protect customers and the public but the situation has changed and the laws are now out-of-date. They must be modernised to help small hotels conduct business.
Changing the rules and regulations here and there does not suffice, however. The laws governing the tourism industry must be comprehensively revamped.
First, since the grace period for applying for the operating licence is over, the government should consider issuing an emergency decree to extend the reprieve. This will give the operators more time to develop their premises and apply for the licence.
For a long-term solution, the government must overhaul the laws and ministerial regulations that affect small hotel operations and licensing. Building standards and other requirements should accommodate a wide range of accommodations, especially small hotels and special categories such as boathouses and treehouses.
With tourism markets becoming more niche, hotel laws should support the operations of small hotels to answer the customers’ particular needs. Unnecessary requirements and rules should be lifted. Importantly, the laws on hotel operations and building control should not be implemented separately, not combined in one package to govern the hotel industry as it is now.
Importantly, the oversight authority should be in the hands of local governments instead of being centralised by the Department of Provincial Administration. The local administration bodies understand better local conditions and can provide faster remedies when problems occur. Also, local governments have more incentives to support tourism in their jurisdictions much more so than the officialdom based in Bangkok.
Such a legal overhaul will help small hotels develop and expand their businesses. For not having to meet large hotel standards will give them more resources to improve their venues and services in other ways. The customers will then have more high-quality choices for their different tastes and needs.
Modernising the laws is necessary if Thailand wants to recover from the pandemic quickly. Importantly, the legal overhaul will ensure that tourism benefits will be distributed fairly to all players, especially local communities. After all, it is the duty of the government to ensure fair play and prevent the law from aggravating injustices.
ในด้านดีของดุลพินิจคือ การสร้างความเป็นยุธรรมเฉพาะกรณี หรือความยุติธรรมเชิงปัจเจก ซึ่งในทางเศรษฐศาสตร์มองว่ามีต้นทุนที่จะต้องจ่าย โดยความยุติธรรมเชิงปัจเจกสร้างต้นทุนให้กับสังคมและในขณะเดียวกันก็เป็นการทำลายความยุติธรรมเชิงสังคมไป เพราะบรรทัดฐานซึ่งถูกนำมาใช้ในเรื่องหนึ่งๆ ต่างกัน เช่น การตัดสินคดีลักทรัพย์ 2 คดีระหว่าง A กับ B โดย A ลักทรัพย์ เพราะอยากได้ของคนอื่น และ B ลักทรัพย์ เพราะอยากได้นมผงมาเลี้ยงลูก ในแง่นี้การที่ศาลมีดุลพินิจที่จะลงโทษแก่ทั้งสองกรณีซึ่งศาลอาจลงโทษ B เบากว่าก็ได้ เป็นต้น
ในเชิงนี้อ.ธานี ชัยวัฒน์ ไม่ได้บอกว่าดุลพินิจไม่ดีนะ แต่ในการใช้ดุลพินิจสังคมหนึ่งๆ จึงต้องชั่งน้ำหนักเพื่อเลือกระหว่างความยุติธรรมในทั้งสองกรณี แต่หากข้อเท็จจริงกลับกันเป็น B ก็ขโมยของด้วยเหตุผลเดียวกับ A (บนข้อเท็จจริงที่เหมือนกันทุกประการ) แต่ศาลกับลงโทษ B ต่างจาก A กรณีนี้จะทำให้เห็นภาพชัดขึ้นว่า จะเกิดความรู้สึกในสังคมว่า เกิดความไม่ยุติธรรมขึ้นมาแล้ว และเกิดความรู้สึกว่ากฎหมายในฐานะเครื่องมือรักษาความสงบของสังคมที่ทุกคนยอมรับร่วมกันนั้นบกพร่องหรืออีกตัวอย่างหนึ่งซึ่งส่วนตัวมองว่าไม่ใช่เรื่องดุลพินิจ แต่เป็นเรื่องของการบังคับใช้กฎหมายมากกว่า