This site contains affiliate links — we may earn a commission if you sign up through them. Details

PDPA and Choosing Hosting in 2026

PDPA guide for website owners — lawful data collection, choosing a host, server location and compliance checklist

PDPA and Choosing Hosting in 2026

What is PDPA and how it affects websites

PDPA is Thailand’s Personal Data Protection Act B.E. 2562, fully enforced since June 2022. It requires a lawful basis for collecting, using or disclosing personal data and that the data be kept secure. Any website collecting names, emails, phone numbers or cookies falls under it.

Data controller vs data processor

PDPA separates the data controller, who decides what data to collect and why, from the data processor, who processes it on their behalf. A website owner is usually the controller while the hosting provider is typically a processor — so an agreement between them is needed.

Personal data websites commonly collect

Before achieving PDPA compliance you must know what your site collects. Many sites gather more than they realise — from forms, comments and membership systems to tracking cookies and server logs.

How to choose PDPA-aligned hosting

Hosting is where personal data actually lives, so choosing a host with clear security measures and processes is a key part of PDPA compliance. In our assessment, server location, encryption, backups and access control are the factors to examine.

Does server location matter for PDPA?

PDPA has rules on cross-border data transfers. Keeping data on servers in Thailand reduces the complexity of international transfers and, at the same time, usually makes the site faster for local visitors.

RecommendedAsiaGB.com — the hosting & VPS we use and recommend: servers in Thailand and Singapore, SSD storage, managed through DirectAdmin, with 24-hour Thai support and 99% uptime.

Editor's pick from our hands-on testing.

Visit AsiaGB →

Measures to implement on your website

Beyond choosing a good host, owners must do their part: a privacy policy, a cookie banner, consent collection, and a channel for data subjects to exercise rights such as accessing or deleting their data.

When a data breach happens

PDPA requires notifying the Personal Data Protection Committee’s office of a personal data breach without delay — generally within 72 hours of becoming aware. Good backups and logging make it possible to respond and investigate after the fact.

A checklist to get your site PDPA-ready

Here is an actionable summary. PDPA compliance is not a one-off task but an ongoing process — start with these basics and review them periodically.

Frequently Asked Questions

Does a small personal site need to follow PDPA?
If the site collects personal data for business purposes it falls under PDPA, even if small. Purely personal or household use may be exempt, but any site with a contact form or shop should comply to be safe.
Do I have to use servers in Thailand?
Not strictly, but storing data on Thai servers reduces cross-border transfer complexity and makes data residency easier to explain. Using a foreign cloud requires appropriate safeguards.
How much does hosting help with PDPA?
A host helps with infrastructure security — SSL, backups, firewall and access control — but policies, consent and handling data-subject rights remain the website owner’s responsibility.
Must every organisation appoint a DPO?
Not every one. PDPA requires a Data Protection Officer only in certain cases, such as large-scale processing or sensitive data as a core activity. Small businesses may not need one but should still have a clear person responsible for data.