PDPA HR Compliance in Thailand: What You Must Do Before You’re Audited
- Published Date:
Picture this: it’s a Tuesday morning, your coffee is still hot, and an email arrives from your legal team — “Please prepare all employee data records and employment contracts for PDPA audit review within 48 hours.” How ready are you?
For many HR teams across Thailand, PDPA HR compliance sits in that uncomfortable space of “we know it’s important, but we haven’t fully sorted it yet.” That’s a risk no organization can afford, because Thailand’s Personal Data Protection Act (PDPA) — which came into full effect in 2022 — doesn’t wait for anyone to feel ready.
This guide walks you through every step HR teams must take before an audit arrives, with practical actions you can start implementing today.
Why PDPA HR Compliance Matters More Than You Think
HR teams touch more personal data than almost any other function in a company. From the moment a candidate submits a CV to the day a former employee’s records are archived, HR processes an enormous range of sensitive information:
- Full names, national ID numbers, dates of birth
- Health records, medical certificates, and sick leave data
- Bank account details, salary, and financial history
- Performance reviews, disciplinary records, and promotion history
- Family information, emergency contacts, and insurance beneficiaries
Under Thailand’s PDPA, all of this qualifies as “personal data.” Much of it — particularly health information — is classified as “sensitive data,” which carries even stricter requirements for consent and security.
The stakes are real: administrative fines can reach ฿5 million per violation, and there are criminal penalties for intentional breaches. Beyond the financial risk, a data incident can permanently damage employee trust and your company’s reputation.
7 Things HR Must Do Before a PDPA Audit
1. Complete a Data Mapping Exercise
Before you can protect data, you need to know what you have. Data mapping — formally called a Record of Processing Activities (ROPA) — is your starting point. Document:
- What personal data you collect (categories and data types)
- The lawful basis for each processing activity
- Where data is stored (systems, files, cloud platforms)
- Who has access — internally and externally
- Retention periods for each data type
- Any third-party transfers (insurers, payroll processors, banks)
Tools like Sprout Keeper provide a secure digital document vault for employee records with role-based access controls, making it far easier to maintain audit-ready documentation.
2. Establish a Clear Lawful Basis for Every HR Activity
Every time HR collects or processes personal data, there must be a valid legal basis. The four most relevant for HR in Thailand are:
- Consent — for non-essential activities like using an employee’s photo for marketing materials
- Contractual Necessity — for data essential to the employment relationship (salary, bank details)
- Legal Obligation — for data required by Thai law, such as Social Security (ประกันสังคม) and Revenue Department reporting
- Legitimate Interest — use with caution; requires a documented balancing test
Avoid over-relying on consent in employment relationships — in practice, employees may not feel free to refuse, which can make that consent legally questionable.
3. Update All HR Forms and Documentation
Your existing HR documents likely pre-date PDPA and need a compliance review. Priority items:
- Job application forms — must include a Privacy Notice explaining what data is collected, why, and for how long. Add a clear consent checkbox for non-essential data.
- Employment contracts — add a data protection clause referencing the company’s Privacy Policy
- Privacy Notice for employees — deliver this from day one, clearly explaining all processing activities
- Medical certificate and leave request forms — health data is sensitive under PDPA; make the legal basis explicit
The Sprout Leave Application manages leave requests digitally, with employee health data stored securely rather than circulating in shared spreadsheets or email threads.
4. Train HR Teams and Line Managers
Most PDPA compliance failures aren’t policy failures — they’re people failures. Training priorities include:
- What counts as personal data versus sensitive personal data
- How to handle Data Subject Requests (DSRs) within the 30-day deadline
- How to identify and report a data breach within 72 hours
- Prohibited behaviors: sharing employee data via personal Line, forwarding HR records to unauthorized parties
- Secure data handling when working remotely
Managers who handle performance reviews, disciplinary processes, or attendance data need specific training — not just the HR team.
5. Build a Data Subject Rights Process
Under PDPA, every employee (and job applicant) has rights you must respect:
- Right to be informed — know what data is held about them
- Right of access — receive a copy of their personal data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion (subject to legal retention requirements)
- Right to restrict processing — pause certain uses of their data
- Right to data portability — transfer data to another controller
- Right to object — challenge processing based on legitimate interest
You need a defined process to receive, verify, and respond to DSRs within 30 days. Do you have one documented?
6. Review All Third-Party Vendor Contracts
HR regularly shares employee data with external parties — group health insurers, payroll outsourcing firms, background check providers, recruitment platforms like Manatal. Each relationship requires a signed Data Processing Agreement (DPA).
Before renewing or signing any vendor contract, confirm they have adequate data security measures, only process the minimum data necessary, and commit to your required data retention and deletion timelines.
7. Prepare a Data Breach Response Plan
PDPA requires notification to the PDPC within 72 hours of discovering a breach that poses a risk to individuals. Your response plan should include:
- A designated response team and escalation path
- Detection and risk-assessment procedures
- PDPC notification templates
- Employee notification templates for high-risk breaches
- An incident log — even for breaches that don’t require formal notification
The Sprout Attendance Application stores time and attendance data in a secure cloud environment, reducing the risk of data exposure from locally-stored spreadsheets.
Practical Tips From HR Teams That Have Passed Audits
- Run a self-audit every six months — don’t wait for an external review to find gaps
- Document every consent — digital records in your HR system are far more defensible than paper forms in a filing cabinet
- Apply data minimization actively — if you don’t need it, don’t collect it. If you collected it and no longer need it, delete it per your retention schedule
- Test your access controls quarterly — who can actually access what? Run a spot check and you may be surprised
- Use systems built for compliance — manual processes create compliance blind spots. Sprout’s HR platform is designed with Thai data privacy standards in mind, helping you reduce human error across payroll, attendance, and document management
Why Sprout for PDPA HR Compliance in Thailand
Sprout is built specifically for HR teams in Thailand, with compliance-ready features across the full employee lifecycle:
- Sprout Keeper — A secure digital vault for all employee documents, with granular role-based access controls, audit trails, and PDPA-aligned document lifecycle management
- Payroll Application — Automates salary calculation, tax filing, and payslip generation, minimising manual handling of sensitive financial data
- Leave Application — Digitises leave requests and approvals, keeping employee health data secure and auditable
- Attendance Application — Cloud-based time tracking with GPS and facial recognition options, eliminating the data risks of spreadsheet-based records
Ready to see how Sprout can make your HR team audit-ready? Book a free consultation with our team today.
Frequently Asked Questions
What is PDPA and why does it matter for HR teams in Thailand?
Thailand’s Personal Data Protection Act (PDPA), fully enforced since 2022, regulates how organizations collect, use, and store personal data. HR teams are among the highest-risk functions because they process everything from national ID numbers to health records. PDPA HR compliance is not optional — it applies to every company operating in Thailand, regardless of size.
What are the penalties for PDPA non-compliance in Thailand?
Administrative fines can reach ฿5 million per violation, with criminal penalties — including imprisonment — for intentional breaches such as unauthorized disclosure of sensitive data. Reputational damage and loss of employee trust are additional costs that are harder to quantify.
Where should an HR team start with PDPA compliance?
Start with a Data Mapping exercise (ROPA). You need to know exactly what personal data your HR function holds, where it sits, who can access it, and what the legal basis is for each processing activity. Once you have that foundation, everything else — updating forms, training teams, building DSR processes — follows naturally.
What counts as sensitive personal data under Thailand’s PDPA?
Sensitive data includes racial or ethnic origin, political opinions, religious beliefs, sexual behaviour, criminal records, health data, trade union membership, and genetic or biometric data. Health information — such as medical certificates and sick leave records — is particularly relevant for HR and requires explicit consent and heightened security measures.
How does the consent requirement work for employee data?
Consent under PDPA must be freely given, specific, informed, and unambiguous. In employment contexts, be cautious — employees may not feel truly free to refuse. Wherever possible, use a more appropriate legal basis (contractual necessity or legal obligation) and reserve consent for genuinely optional data uses.
How quickly must a company respond to a Data Subject Request (DSR)?
You must respond within 30 days of receiving a DSR. Extensions are possible in complex cases, but you must notify the individual. Having a documented DSR process — including an intake form, identity verification step, and response template — is essential before an audit.
Does PDPA apply to small and medium-sized businesses in Thailand?
Yes. PDPA applies to all organizations that collect or process personal data in Thailand, with very limited exceptions. SMEs that handle employee data — which is every employer — must comply. The good news is that PDPA compliance is scalable: start with the basics (data mapping, updated forms, training) and build from there.
How can HR software help with PDPA compliance?
A well-designed HR system enforces access controls automatically, maintains audit logs of who accessed what and when, applies data retention rules consistently, and eliminates the high-risk practice of storing employee data in unprotected spreadsheets. Sprout Keeper and the full Sprout HR platform are built with these compliance requirements in mind.
Final Thoughts: Get Compliant Before the Audit Finds You
PDPA HR compliance in Thailand isn’t a one-time exercise — it’s an ongoing commitment to handling your employees’ personal data with the care it deserves. The good news is that getting structured about it now pays dividends well beyond audit preparation: better data hygiene, more employee trust, and reduced operational risk.
Your action checklist: complete a Data Mapping exercise → audit your legal bases → update HR forms and Privacy Notices → train your teams → build a DSR response process → sign DPAs with every vendor → prepare your Data Breach Response Plan.
Don’t wait for the audit letter.
Book a free consultation with Sprout today and see how our HR platform helps Thai businesses stay compliant, efficient, and audit-ready.
Follow Sprout for more HR compliance insights:
Get More Content Like This In Your Inbox!
Table of Contents

Jarinee Yung Punpeang
Product Manager - Totem
With over 11 years of experience in software, Jarinee has worked as both a QA and Product Manager, bringing a deep understanding of leave and payroll compliance. She is passionate about reviewing and refining products to ensure top-notch quality and a seamless experience for users.
Get More Content like this in your Inbox!
Related Solutions
Check out what’s new with Sprout’s innovations and partner products!
Totem Payroll
The Online Payroll Management Software for Businesses of All Sizes
Sprout Keeper
Your reliable partner for Time & Billing
Recruitment
Hire at the Speed of Your Growth















