PDPA For SMEs: The Complete Marketing Compliance Guide
PDPA for SME marketing in Thailand is no longer optional — it is the baseline standard for any business that collects a customer’s name…
PDPA For SMEs: The Complete Marketing Compliance Guide

PDPA for SME marketing in Thailand is no longer optional — it is the baseline standard for any business that collects a customer’s name, phone number, or digital footprint. Whether you run a café loyalty programme, a clinic booking form, or a Facebook Ads funnel, Thai law holds you accountable for every piece of personal data you touch. This guide translates complex legal obligations into a practical, plain-English playbook so you can protect your brand, avoid six-figure fines, and turn privacy compliance into a genuine competitive advantage.
📋 Table of Contents
- 🕵️ Have You Ever Felt “Spooked” by a Brand?
- 🛡️ What Is Data Protection and PDPA? The SME Essentials
- ⚖️ Why Thai SMEs Must Comply with PDPA (Not Just to Avoid Fines)
- 📣 Permission Marketing: The Strategic Shift from Interruption to Invitation
- 📚 Case Study: Costly Lessons from a Beauty Clinic’s PDPA Breach
- ✅ Survival Checklist: 6 Actions Every SME Owner Must Take Now
- 🏆 Conclusion: Data Protection as a Golden Business Opportunity
- ❓ Frequently Asked Questions (FAQ)
🕵️ Have You Ever Felt “Spooked” by a Brand?
Picture this: you stop at your favourite coffee shop, give your phone number at the counter to collect reward points — and two days later, an unsolicited loan SMS arrives. Then a life-insurance call. Then another.
Annoying? Almost certainly. Alarming? Possibly. Because the first question that crosses your mind is: where did they get my number?
As a business owner, if your customers ever ask that question about your brand, you are already in crisis territory. Personal data travels faster than any viral post in the digital age — and when it ends up in the wrong hands, or is used without explicit permission, the damage is not limited to a regulatory fine. What collapses in an instant is Trust — the single most durable currency in business.
Today, I want to walk Thai SME owners through PDPA for SME — not as a dry legal lecture, but as a “survival strategy” that can transform you from a transactional merchant into a brand your customers genuinely love and trust.
🛡️ What Is Data Protection and PDPA? The Fundamentals Every Thai SME Must Know
Think of it like a bank account. When you deposit money, you trust the bank to keep it in a vault — not to hand it to a stranger, or invest it recklessly without telling you. Customer data works the same way. The moment a customer shares their name, phone number, or browsing behaviour with your business, you become their data custodian. Three core obligations follow:
Your obligations as a data custodian are:
- Keep it secure: Prevent unauthorised access or theft — this is your Security obligation under PDPA Section 37.
- Use it for the stated purpose only: If you collected a phone number to arrange delivery, use it for delivery — not to sell insurance. This is the Purpose Limitation principle.
- Be transparent: Tell customers clearly what data you collect, why, and how. This is Transparency — and it is non-negotiable.
How Thai Law Defines “Personal Data” in a Business Context
Personal data under Thailand’s PDPA (Personal Data Protection Act B.E. 2562 / 2019) extends well beyond a name and national ID. In a typical SME marketing context, it includes:
- Mobile phone numbers and Line IDs — the lifeblood of Thai CRM systems
- Purchase history and transaction records, however informally stored
- Website browsing behaviour captured via Cookies, Facebook Pixel, or Google Analytics
- IP addresses, GPS coordinates, and any other device-level identifiers
⚖️ Why Thai SMEs Must Comply with PDPA (It Goes Far Beyond Avoiding Fines)
A common misconception among Thai SME operators is that PDPA is enforcement machinery aimed exclusively at large corporations. That is incorrect. While the law does offer a limited exemption from maintaining a formal Record of Processing Activities (RoPA) for businesses with annual revenue below ฿300 million, it does not exempt smaller operators from security obligations or the requirement to obtain valid consent. This position is confirmed by Tilleke & Gibbins’ analysis of Thailand’s data privacy landscape in 2025.
Trust Is the Key to Sustainable Revenue
Thai consumers are becoming increasingly sophisticated about their data rights. Once they discover that a brand has shared or sold their contact details without permission, they disengage permanently — and they tell others. The business case for privacy is no longer theoretical. According to the Usercentrics Data Privacy Statistics Report 2025, every ฿1 invested in privacy infrastructure generates a return of up to ฿42 — a 4,200% ROI — because customers who trust a brand are willing to share richer, more accurate data that enables genuinely personalised marketing.
Regulatory Penalties Are Real — and Already Being Imposed
PDPA is not aspirational guidance. As of August 2025, Thailand’s Personal Data Protection Committee (PDPC) has issued confirmed administrative fines totalling over ฿21.5 million across just eight enforcement actions. The most significant single penalty reached ฿7,000,000 — imposed on an IT product distributor that lacked adequate security controls and had failed to appoint a Data Protection Officer (DPO) as required by law. Reference: Bangkok Post — PDPC Levies Fines in Data Breach Cases.
- Maximum administrative fine: ฿5,000,000 per offence (PDPA Section 82–90)
- Civil liability: Up to 2× actual damages (punitive damages) if a data breach causes proven harm
- Criminal exposure: Up to 1 year imprisonment for the most serious intentional violations
📣 Permission Marketing: The Strategic Shift from Interruption to Invitation
The era of Interruption Marketing — blasting promotions at anyone who happens to scroll past — is over. The strategic framework that replaces it is Permission Marketing: a discipline built on the simple premise that earned attention converts at a dramatically higher rate than purchased attention.
**“Turn strangers into friends, and friends into customers — through respect.”***
- Seth Godin*
The 3 Iron Rules: Opt-In, Double Opt-In, and Easy Opt-Out
- Always request consent (Opt-In): Never assume that a customer who provides their contact details during a transaction has consented to receive marketing communications. You must present an active, unticked checkbox — “I agree to receive news and promotions” — for the customer to select voluntarily. Pre-ticked consent boxes are strictly prohibited under PDPA Section 19.
- Verify identity (Double Opt-In): When a customer submits an email address, send a confirmation link before adding them to any marketing list. This confirms the address is genuine, protects you from third-party abuse, and strengthens the legal basis of the consent record.
- Make withdrawal effortless (Easy Opt-Out): An Unsubscribe link or “Stop messages” option must be visible, functional, and honoured immediately. Burying opt-out mechanisms is both a legal risk and a brand-destroying practice.
📚 Case Study: Costly Lessons from a Beauty Clinic’s PDPA Breach
To illustrate the real-world consequences, consider the “Kind Beauty Clinic” (fictitious name) — a composite drawn from documented enforcement cases in Thailand in 2025.
The Situation: The clinic ran Facebook Ads offering a free facial trial, collecting names and phone numbers through a landing-page form. There was no Privacy Notice on the form. An administrator extracted the leads and added them to a LINE group for repeated promotional broadcasts. Patient consultation records were stored on paper and disposed of through a general waste contractor — without any data destruction protocol.
Real Enforcement Precedents from 2025 (Source: DLA Piper Global Data Protection Overview):
- Data Breach Case: A cosmetics company was fined ฿2,500,000 after inadequate security controls allowed customer data to reach a call-centre fraud operation, resulting in direct financial harm to customers.
- Improper Disposal Case: A private hospital was fined ฿1,210,000 after outsourcing medical record destruction to a contractor who instead sold the paper documents as scrap — which subsequently appeared as food packaging bags sold near a local school.
Business Impact: Beyond the seven-figure fines, these organisations suffered immediate and lasting reputational damage. Customer relationships built over years evaporated overnight. For an SME operating on tighter margins, the reputational cost alone — compounded by lost customer lifetime value — can be existential. This is precisely the risk that every Thai SME must take seriously.
✅ Survival Checklist: 6 Actions Every SME Owner Must Take Immediately
The following framework is Kooru’s recommended baseline for any Thai SME that collects customer data — regardless of size or sector. For a deeper dive into PDPA Compliance Audits for Thai businesses, see our dedicated resource.
Audit Your Website and Data Collection Points
- [ ] Website Audit: Does your homepage display a Cookie Consent Banner? Is the “Reject All” button genuinely functional — or just decorative? Under PDPA, both acceptance and rejection must be equally accessible.
- [ ] Consent Forms: At every touchpoint where you collect names or phone numbers — online and offline — is there a separate, unticked checkbox for marketing consent? The checkbox must be independent from the service-agreement tick box.
- [ ] Update Your Privacy Policy: Is your Privacy Notice written in plain, readable Thai — or is it a copy-pasted legal template that no ordinary person would understand? A valid Privacy Notice must state what data you collect, why, how long you keep it, and who you share it with.
- [ ] Staff Training: Do your sales team and chat administrators understand their PDPA obligations? Screenshotting customer data and sharing it via personal LINE chats is a data security violation — full stop.
- [ ] Revocation System: If a customer requests removal from your marketing list, do you have an operational process to action that request immediately — and document it?
- [ ] Access Control: Who in your organisation can view the full customer database? Limit access strictly to those with a business need. Not everyone on the payroll should have access to every customer record.
🏆 Conclusion: Turn Data Protection into a Golden Business Opportunity
“Data Protection is not a burden — it is a golden opportunity.”
While your competitors continue spamming inboxes and ignoring data security, you have a strategic window to differentiate. Declare your position: “We treat your data the way we treat family.” That single commitment, backed by genuine compliance, will earn you a level of customer loyalty that no advertising budget can buy.
If your internal audit today returns the verdict “at risk” — act now. The PDPC does not send warning letters before enforcement. The fine comes first.
Ready for a professional PDPA Compliance Audit or a bespoke Privacy Policy for your business? The Kooru team specialises in PDPA Compliance Audits tailored specifically for Thai SMEs. [Contact us today for an initial consultation] — and protect your business before the regulator reaches your door.
By: Khun Phuwara Krobtaku — Senior Advisor, Business Strategy & Legal-Tech, The Kooru Data Tech & Law (Thailand)
Primary Keyword: PDPA for SME Secondary Keywords: personal data protection Thailand, permission marketing PDPA, PDPA consent management, PDPA fine penalty Thailand, customer data protection
Originally published at https://kooru.com on May 7, 2026.
메타데이터
- post_id
- 1cf83ef3fd9c
- slug
- pdpa-for-smes-the-complete-marketing-compliance-guide-1cf83ef3fd9c
- url
- https://medium.com/@thekoorudatatechandlaw/pdpa-for-smes-the-complete-marketing-compliance-guide-1cf83ef3fd9c
- canonical_url
- https://medium.com/@thekoorudatatechandlaw/pdpa-for-smes-the-complete-marketing-compliance-guide-1cf83ef3fd9c
- author_url
- https://medium.com/@thekoorudatatechandlaw
- status
- ok
- fetched_at
- 2026-06-22 05:41:33