PDPA Sec 28 — 6 safeguards
- (1) ปลายทาง adequate (PDPC ประกาศ list — ปัจจุบันยังว่าง)
- (2) BCR (Binding Corporate Rules) intra-group approved
- (3) SCC (Standard Contractual Clauses) — PDPC ยอมรับ EU SCC 2021
- (4) Certification / Code of Conduct approved
- (5) Explicit consent ของ data subject (ต้อง opt-in ใหม่)
- (6) Necessary for contract / public interest / legal claim / vital interest
GDPR → Thailand transfer
EU controller → Thai processor: ใช้ SCC 2021 Module 2 (C2P)
EU controller → Thai controller: SCC 2021 Module 1 (C2C)
Thai processor → Thai sub-processor: SCC 2021 Module 3 (P2P)
TIA บังคับ: ตรวจ Thailand surveillance law (Cyber Security Act 2562, Computer Crime Act 2560, NSC powers)
Supplementary measures ถ้า TIA fail: encryption at rest + in transit + key ใน EU + pseudonymization
TIA (Transfer Impact Assessment) template
- Step 1: Map transfer (data type, volume, sensitivity, frequency, recipient, purpose)
- Step 2: Identify legal basis ปลายทาง (Computer Crime Act Sec 18, NSC, Cyber Security Act Sec 56-60)
- Step 3: Assess government access risk (judicial oversight? proportionality? redress?)
- Step 4: Supplementary measures (technical: encryption / contractual: warranties / organizational: training)
- Step 5: Document conclusion + review 24 เดือน หรือ legal change
Practical playbook สำหรับธุรกิจไทย
Inbound (EU → ไทย): ลง SCC 2021 + ส่ง TIA ให้ EU exporter · NYC Legal draft TIA ประเมินราคาฟรี
Outbound (ไทย → EU): ใช้ adequate (UK, Switzerland, Japan, Korea) หรือ SCC + consent
Outbound (ไทย → US): ต้อง SCC + supplementary measures (US ไม่อยู่ Thai adequate list · EU-US DPF ไม่ผูกพันไทย)
Outbound (ไทย → China): SCC + China PIPL safeguards · CAC security assessment ถ้า ≥ 100K subjects
DPA (Data Processing Agreement) ทุก vendor · ทบทวนปีละครั้ง · audit right + breach notification 72 ชม






