Skip to content

Cold Email Laws in Thailand: PDPA Legitimate Interest, a THB 200,000 Per-Email Spam Fine and a Regulator Now Fining

September 28, 2026. Thailand is one of the few markets where cold email is governed by two statutes with different logics, and a sender has to clear both. The Personal Data Protection Act B.E. 2562, the PDPA, became law on May 28, 2019 and came into full force on June 1, 2022 after two Royal Decree postponements; it is a GDPR-shaped privacy law with a legitimate-interest basis, an express right to object to direct marketing and administrative fines up to THB 5 million, and according to DLA Piper's country guide (updated February 14, 2026) the Personal Data Protection Committee has now imposed administrative fines in six cases, one in 2024 and five in 2025. The second statute is older and blunter: Section 11 of the Computer Crime Act, as amended in 2017, makes it an offence to send email that disturbs the recipient without an unsubscribe route, and a Ministerial Notification sets out the safe harbour. For commercial email to someone who is not a customer, the safe harbour requires consent, and the fine is up to THB 200,000 per email.

Cold email laws in Thailand: PDPA legitimate interest, the Computer Crime Act's THB 200,000 per-email fine and the PDPC's fines to date

Key numbers

ItemNumber
PDPA became lawMay 28, 2019
PDPA in full force (after two Royal Decree postponements)June 1, 2022
PDPA maximum administrative fine (per case, graded by intent, business size and damage)THB 5,000,000
Punitive damages a court may addup to 2x actual compensation
PDPC administrative fine cases to date (one in 2024, five in 2025, per DLA Piper)6
Largest single PDPC fines (the August 2024 first case and the IT retailer in the August 2025 wave)THB 7,000,000
Total PDPC fines imposed to date (about USD 654,690, per Tilleke and Gibbins)about THB 21.5 million
Computer Crime Act Section 11 fineup to THB 200,000 per email
Stop window after an unsubscribe request (MDES Notification safe harbour)immediately, or within 7 days

DLA Piper's Thailand guide (updated 14 February 2026), DLA Piper Privacy Matters (27 August 2024), Tilleke and Gibbins' summary of the 1 August 2025 PDPC announcement and CPO Magazine's summary of the MDES Notification, all read on 28 September 2026.

The PDPA layer

  1. Lawful basis. Collection, use or disclosure of personal data requires consent unless another basis applies, and the PDPA lists contract, legal obligation and the data controller's legitimate interest among them, per DLA Piper's collection and processing note. A B2B sender will usually document legitimate interest.
  2. If you use consent, it has a form. A consent request must be explicit, in writing or electronic, clearly separated from other messages, easily accessible and in plain language, and not misleading; it must be freely given and not a condition of a contract. The regulator's consent guideline requires a clear affirmative action such as ticking a box, and consent can be refused or withdrawn at any time.
  3. Notice regardless of basis. A privacy notice stating the purpose and the categories of recipients must be given before or at collection whether or not consent is the basis; the regulator's guideline allows it by URL or QR code.
  4. The direct-marketing objection. Data subjects have the right to object to direct marketing, electronic or not, so DLA Piper's marketing note concludes that an opt-out function must be available throughout the entire processing period.
  5. Penalties and who pays. Civil, criminal and administrative penalties; the maximum administrative fine is THB 5,000,000; courts may award punitive damages up to twice actual compensation; and where the offender is a company, the director, manager or responsible person can be criminally liable if the offence resulted from their order, action or omission. A 2022 notification, as amended, grades fines by intent or gross negligence, the size of the business and the damage caused.
Bar chart of the eight administrative fines Thailand's PDPC announced on 1 August 2025, from THB 16,940 to THB 7,000,000
Amounts as reported by Tilleke and Gibbins from the PDPC announcement of 1 August 2025. Source: tilleke.com, read September 2026.

What the PDPC has actually fined

None of the six cases is a marketing case, which tells a sender what the regulator's checklist looks like. The first fine came on August 21, 2024: the maximum THB 7 million on a company selling online, after personal data from more than 100,000 customers leaked to call-centre gangs, with no data protection officer appointed and the breach reported late, as DLA Piper recorded at the time. Tilleke and Gibbins' summary of the PDPC's August 1, 2025 announcement lists eight further fines in five cases and puts the total imposed to date at about THB 21.5 million: a computer and accessories retailer fined THB 7,000,000 after more than 100 complaints about a call-centre scam, with no DPO, no breach report and its revenue and size weighed in the amount; the data processor running a collectible toy retailer's reservation system fined THB 3,000,000 and the retailer THB 500,000 after about 200,000 records were altered in a ten-minute intrusion; a cosmetics company fined THB 2,500,000 for a leak to a call-centre gang and no breach notification; a private hospital fined THB 1,210,000 after a contractor used patient records to wrap sweets, and the contractor THB 16,940; and a state agency and its software developer THB 153,120 each after 200,000 data subjects' records reached the dark web. Every order turned on security measures, breach reporting and, where required, a DPO. A marketing complaint will be judged against the same list, plus the consent and objection rules above.

The Computer Crime Act layer

The original Section 11 caught emails with concealed or falsified origins; the 2017 amendment extended it to email or electronic data that disturbs the recipient and does not allow them to unsubscribe, and the Ministry of Digital Economy and Society issued a Notification on the characteristics and methods of sending data deemed not to cause a disturbance, described by Tilleke and Gibbins' Athistha Chitranukroh in CPO Magazine. The safe harbour treats as non-disturbing data sent as evidence of an agreed transaction, for legal compliance, to express an existing relationship, and non-commercial data from government, educational or charitable bodies. Commercial email outside those categories is permissible only with the recipient's consent, and every message must carry a visible, quick, unconditional opt-out that does not divert the recipient to another commercial channel. On request the sender must stop immediately or, in certain circumstances, within seven days; a second written request after continued sending fixes the offence. The fine is up to THB 200,000 levied against each single spam email, and the notification leaves the Ministry's permanent secretary to interpret disputes, including whether implied consent is enough.

Why the two layers do not agree

The PDPA lets a sender rely on legitimate interest and honour an objection; the Computer Crime Act's safe harbour asks for consent for commercial email to anyone who is not already a customer or counterparty. A sender that satisfies the PDPA can still be outside the safe harbour, and the per-email fine is the one a disgruntled recipient can trigger with a second written request. At the maximum, twenty-five ignored emails already equal the PDPA's THB 5 million ceiling. On the notification's own categories, a B2B email that expresses an existing business relationship and carries a compliant opt-out sits inside the safe harbour, a purchased-list blast to strangers sits outside it, and the seven-day stop clock starts on the first unsubscribe.

What it means for operators

Thailand is workable for relationship-led outbound and hostile to volume. Segment to recipients with a demonstrable business connection, put the privacy notice link and a one-click unsubscribe in every message, honour opt-outs on the day rather than in seven, keep the legitimate-interest assessment and the objection log with the campaign, and never route an unsubscribe through a sales page. Because the PDPC has moved from zero fines to six cases in eighteen months, has weighed company size in setting the largest of them, and publishes little about the cases beyond the categories of failure, assume the next one could be a marketing complaint. The suppression and consent-record discipline this requires is the reason we build email infrastructure to store the basis and the objection for every address, not just the send. For the region, our Vietnam and Indonesia guides cover the two neighbours with the largest search demand, our country-by-country comparison table puts every regime side by side, and the opt-in vs opt-out map shows where each sits. A Thai lead generation programme is built on the relationship category, not the list.

Want a Thailand sequence that clears both statutes?

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

Under the PDPA a B2B sender can rely on legitimate interest with a privacy notice and an opt-out, but the Computer Crime Act's safe harbour treats commercial email to non-customers as permissible only with consent and fines up to THB 200,000 per email once a recipient's unsubscribe is ignored. Relationship-based outbound with a compliant opt-out is defensible; purchased-list blasts are not.

The maximum administrative fine is THB 5,000,000, alongside civil liability with punitive damages up to twice actual compensation and criminal liability that can reach a company's directors or responsible managers. DLA Piper records six administrative fine cases since June 2022, one in 2024 and five in 2025, and the largest single fines so far have been THB 7 million.

Yes, on both statutes. The PDPA gives data subjects the right to object to direct marketing so an opt-out must exist throughout processing, and the Computer Crime Act safe harbour requires a visible, quick, unconditional unsubscribe that does not divert the recipient to another commercial channel, honoured immediately or within seven days.

Under the PDPA, yes: the data controller's legitimate interest is a recognised lawful basis, subject to notice and the right to object. It does not by itself satisfy the Computer Crime Act safe harbour, which asks for consent or an existing relationship for commercial email.

Security and breach-reporting failures, not marketing. The first fine, THB 7 million in August 2024, went to an online seller with no DPO whose customer data leaked to call-centre gangs; the PDPC's August 1, 2025 announcement added eight fines in five cases, from THB 16,940 on a hospital contractor to THB 7,000,000 on an IT retailer, taking the total imposed to about THB 21.5 million according to Tilleke and Gibbins.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us