PDPA and Choosing Hosting in 2026
PDPA guide for website owners — lawful data collection, choosing a host, server location and compliance checklist
Contents
What is PDPA and how it affects websites
PDPA is Thailand’s Personal Data Protection Act B.E. 2562, fully enforced since June 2022. It requires a lawful basis for collecting, using or disclosing personal data and that the data be kept secure. Any website collecting names, emails, phone numbers or cookies falls under it.
- Fully enforced since June 2022
- Covers data identifying a person: name, email, phone, IP
- Requires a lawful basis to collect, such as consent
- Violations carry civil, criminal and administrative penalties
- Applies to companies and individuals processing data commercially
Data controller vs data processor
PDPA separates the data controller, who decides what data to collect and why, from the data processor, who processes it on their behalf. A website owner is usually the controller while the hosting provider is typically a processor — so an agreement between them is needed.
- Data controller: the site owner/business deciding on data
- Data processor: hosts, clouds and services processing on their behalf
- You should have a Data Processing Agreement (DPA) with providers
- Controllers must ensure processors have adequate security
- Some organisations must appoint a DPO (data protection officer)
Personal data websites commonly collect
Before achieving PDPA compliance you must know what your site collects. Many sites gather more than they realise — from forms, comments and membership systems to tracking cookies and server logs.
- Contact/signup forms: name, email, phone, address
- Membership and carts: accounts and order history
- Cookies and analytics: behaviour and IP
- Server logs: IP addresses and access times
- Payment data (usually via a gateway, not stored yourself)
How to choose PDPA-aligned hosting
Hosting is where personal data actually lives, so choosing a host with clear security measures and processes is a key part of PDPA compliance. In our assessment, server location, encryption, backups and access control are the factors to examine.
- Security measures: free SSL, firewall, malware scanning
- Regular, restorable backups
- Access control and access logging
- Willingness to sign a Data Processing Agreement (DPA)
- Support that can genuinely answer security questions
Does server location matter for PDPA?
PDPA has rules on cross-border data transfers. Keeping data on servers in Thailand reduces the complexity of international transfers and, at the same time, usually makes the site faster for local visitors.
- Sending data abroad has extra conditions
- Servers in Thailand reduce cross-border transfer issues
- Local data residency is easier to explain to users and auditors
- Speed for Thai visitors is a bonus
- Foreign clouds require appropriate safeguards in place
Measures to implement on your website
Beyond choosing a good host, owners must do their part: a privacy policy, a cookie banner, consent collection, and a channel for data subjects to exercise rights such as accessing or deleting their data.
- Publish a clear privacy policy
- A cookie banner and consent before tracking
- A channel for users to access/correct/delete their data
- Collect only what is necessary (data minimisation)
- Encrypt data in transit with HTTPS on every page
When a data breach happens
PDPA requires notifying the Personal Data Protection Committee’s office of a personal data breach without delay — generally within 72 hours of becoming aware. Good backups and logging make it possible to respond and investigate after the fact.
- Report breaches without delay (the ~72-hour guideline)
- If high risk to rights, notify the data subjects too
- Backups enable recovery after an attack
- Access logs help trace the cause
- Have an incident-response plan prepared in advance
A checklist to get your site PDPA-ready
Here is an actionable summary. PDPA compliance is not a one-off task but an ongoing process — start with these basics and review them periodically.
- Pick a host with free SSL, backups and DPA readiness
- Enable HTTPS on every page with forced redirects
- Create a privacy policy and cookie banner
- Collect only necessary data with defined retention
- Provide a data-subject rights channel and an incident plan