Siam Thanat Hack Co., Ltd.

Personal Data Protection Act B.E. 2562 (2019) and Penetration Testing

Section 37 requires data controllers to provide appropriate security measures. Penetration Testing is one way to validate the effectiveness of technical controls.

Testing in support of PDPA security measures

Section 37 requires controllers to apply appropriate measures. Testing helps demonstrate control effectiveness, but it is not the sole evidence of PDPA compliance.

Thai infographic explaining: Testing in support of PDPA security measures
Visual summary: Testing in support of PDPA security measures
  • Link tested systems to the data inventory, processing purpose, and personal-data risk so scope reflects actual impact.
  • Examine authentication, authorisation, data protection in transit and at rest, and the handling of sessions, APIs, and administrative functions.
  • Control test data, minimise real personal data, redact evidence, and define retention or deletion for testing artefacts.
  • Review measures when risk, technology, or processing changes. One pentest does not establish complete compliance on its own.

PERSONAL DATA PROTECTION

Section 37 requires data controllers to provide appropriate security measures. Penetration Testing is one way to validate the effectiveness of technical controls.

หน้าที่ตามมาตรา 37

  • ผู้ควบคุมข้อมูลส่วนบุคคลต้องมีมาตรการที่เหมาะสม เพื่อป้องกันการสูญหาย เข้าถึง ใช้ เปลี่ยนแปลง แก้ไข หรือเปิดเผยโดยปราศจากอำนาจหรือโดยมิชอบ
  • มาตรการขั้นต่ำต้องมีมาตรการเชิงองค์กรและเชิงเทคนิค และอาจรวมมาตรการทางกายภาพเมื่อจำเป็นตามระดับความเสี่ยง โดยต้องทบทวนเมื่อจำเป็นหรือเมื่อเทคโนโลยีเปลี่ยนแปลง

บทบาทของ Penetration Testing

  • ใช้ทดสอบว่าการควบคุมทางเทคนิคของ Web, Mobile, API, Network และ Cloud สามารถป้องกันการเข้าถึงหรือเปิดเผยข้อมูลโดยมิชอบได้จริงหรือไม่
  • การทดสอบต้องได้รับอนุญาต กำหนดขอบเขตตามความเสี่ยง ลดการเก็บข้อมูลส่วนบุคคลที่ไม่จำเป็น ปกปิดหลักฐาน และกำหนดการเก็บรักษาและลบที่ชัดเจน
ไม่ใช่หลักฐานทั้งหมดของ compliance

มาตรา 37 และประกาศมาตรการรักษาความมั่นคงปลอดภัยไม่ได้กำหนดให้ทำ Penetration Testing ปีละ 1 ครั้ง และผลทดสอบเพียงอย่างเดียวไม่ใช่หลักฐานว่าปฏิบัติตาม PDPA ครบถ้วน

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofPersonal Data Protection Act B.E. 2562 (2019)

Personal Data Protection Act B.E. 2562 (2019)

By Royal Thai Government Gazette

Open document (PDF) Source