Siam Thanat Hack Co., Ltd.

Personal Data Protection Act B.E. 2562 (2019) and Penetration Testing

Section 37 requires data controllers to provide appropriate security measures. Penetration Testing is one way to validate the effectiveness of technical controls.

Executive Summary and Mandate Overview
Target Audience Data Controllers and Data Processors handling Personal Identifiable Information (PII)
Mandatory Frequency Review measures when necessary or when technology changes (Sec 37(1)); no statutory annual pentest cadence
Required Scope Customer Databases, Web Portals, APIs handling PII, Cloud Infrastructure
Non-Compliance Risk Administrative fines up to 5,000,000 THB (Sec 82 to 84) and civil and criminal liability

Testing in support of PDPA security measures

Section 37 requires controllers to apply appropriate measures. Testing helps demonstrate control effectiveness, but it is not the sole evidence of PDPA compliance.

Thai infographic explaining: Testing in support of PDPA security measures
Visual summary: Testing in support of PDPA security measures
  • Link tested systems to the data inventory, processing purpose, and personal-data risk so scope reflects actual impact.
  • Examine authentication, authorisation, data protection in transit and at rest, and the handling of sessions, APIs, and administrative functions.
  • Control test data, minimise real personal data, redact evidence, and define retention or deletion for testing artefacts.
  • Review measures when risk, technology, or processing changes. One pentest does not establish complete compliance on its own.

PERSONAL DATA PROTECTION

Section 37 requires data controllers to provide appropriate security measures. Penetration Testing is one way to validate the effectiveness of technical controls.

Section 37 duty

  • A data controller must provide appropriate security measures to prevent unauthorized or unlawful loss, access, use, alteration, correction, or disclosure of personal data.
  • Minimum safeguards must include organizational and technical measures and may include physical measures where necessary according to risk. They must be reviewed when necessary or when technology changes.

Role of Penetration Testing

  • Testing can validate whether technical controls across web, mobile, API, network, and cloud environments resist unauthorized access or disclosure in practice.
  • Assessments must be authorized and risk-based, minimize unnecessary personal-data collection, redact evidence, and define secure retention and deletion.
Not complete compliance evidence

The PDPA does not mandate annual Penetration Testing. Section 37 and the security-measures notification require appropriate measures, while testing is one way to validate technical controls; a test report alone is not evidence of complete PDPA compliance.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
Section 37(1) Appropriate Technical and Organizational Safeguards PII Databases, Web Portals, Cloud Workloads When necessary or when technology changes
PDPC Directive Technical Security and Penetration Verification Personal Data Processing Infrastructure Post-update and annual

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview of Personal Data Protection Act B.E. 2562 (2019)

Personal Data Protection Act B.E. 2562 (2019)

By Royal Thai Government Gazette

Open document (PDF) Download Source