ISO 27001 · Thailand

ISO 27001 in Thailand: PDPA and the CII Regime

The Short Answer

Two 2019 laws apply in Thailand: the PDPA (B.E. 2562), fully in force since June 2022, requiring ‘appropriate security measures’ and breach reports to the PDPC within 72 hours where feasible, and the Cybersecurity Act, which places critical information infrastructure under the NCSA. Neither mandates a certificate, and one ISO 27001 ISMS can evidence both where it is scoped to.

Thailand’s two 2019 laws

Thailand passed both defining laws in the same year. The Personal Data Protection Act B.E. 2562 (2019) came fully into force on 1 June 2022 and is enforced by the Personal Data Protection Committee (PDPC) and its Office, under the Ministry of Digital Economy and Society. The Cybersecurity Act B.E. 2562 (2019) established the critical information infrastructure regime under the National Cyber Security Agency (NCSA).

Instrument Regulator What it requires
PDPA B.E. 2562 (2019) PDPC and its Office “Appropriate security measures” for personal data, plus risk-tiered breach reporting
PDPC breach notification B.E. 2565 (2022) PDPC Office The criteria and method for reporting personal-data breaches
Cybersecurity Act B.E. 2562 (2019) NCSA Critical information infrastructure duties, where your systems fall within the regime

The PDPA’s breach rule is tiered by risk.

Assessed risk What the PDPA requires
No risk to rights and freedoms Notification exempt
Risk Notify the PDPC Office without delay and, where feasible, within 72 hours of becoming aware
High risk Notify the affected individuals as well

Each tier depends on an assessment. The tier is established with evidence of what happened and what data was involved rather than selected, which makes the assessment the substantive work behind the 72-hour figure.

The PDPA contains no data-residency rule, and neither law names ISO 27001. “Appropriate security measures” is technology-neutral, so the position on what was appropriate for your processing is constructed and evidenced by the organisation.

How one ISMS carries both laws

The PDPA governs personal data and the Cybersecurity Act governs system availability and incident handling. A single ISO 27001 ISMS can hold both, because the standard’s risk assessment covers whatever obligations are recorded as requirements.

Thai obligation Where the ISMS answers it
“Appropriate security measures” (PDPA) Risk assessment across the 93 Annex A controls, with applicability documented in the Statement of Applicability — a written case for what is appropriate, plus evidence it runs
Risk-tiered breach reporting (PDPC notification) Detection in front of incident management: continuous logging and monitoring, an assessment step that can place a breach in the right tier, and notification inside the window
CII duties (Cybersecurity Act) Monitoring, incident response and reporting discipline scoped to the systems within the regime

Scoping is the precondition. The ISMS carries the Cybersecurity Act only where the CII-relevant systems sit inside the certificate boundary and the Act is recorded as a legal requirement alongside the PDPA. A certificate scoped to exclude the most regulated systems evidences little about them.

Certification in Thailand: NAC, TISI and scope

The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by a certification body accredited through Thailand’s National Accreditation Council, via the Thai Industrial Standards Institute (TISI) under the Ministry of Industry, and not by Secure60. Audit fees are set by the certification body and vary with the size and scope of what is certified, followed by annual surveillance and three-yearly recertification.

Thai operations frequently sit inside regional groups, where one ISMS with a multi-country scope is cheaper to run and easier to keep consistent than a standalone Thai certificate. Secure60 has delivery infrastructure in Thailand via Rackcorp, with 2 datacentres, so log collection and monitoring can run in-country on our security platform where that is required.

PDPA compliance does not cover the Cybersecurity Act

The two laws share a year and a subject area and have different regulators and different subject matter. The PDPA governs personal data and answers to the PDPC. The Cybersecurity Act governs critical information infrastructure and answers to the NCSA. A privacy program establishes nothing about whether infrastructure meets the CII regime’s requirements.

Where systems fall within that regime, the monitoring and incident duties apply irrespective of the state of the privacy program, and establishing whether they apply is work to complete before designation conversations begin. One ISMS can cover both laws, provided it was scoped for both.

How Secure60 handles this

We build the ISMS against both Thai laws, with the PDPA recorded alongside the Cybersecurity Act as legal requirements, then run the operations underneath: logging, monitoring, and incident response with the assessment step the PDPC’s risk tiers require, on Rackcorp infrastructure in Thailand where residency is required. The certification audit belongs to a certification body accredited through the NAC and TISI, and our work is making sure everything it samples is operating. Secure60 holds ISO 27001:2022 certification and runs its own operations on the same platform.

Frequently Asked Questions

Is ISO 27001 legally mandatory in Thailand?

No. The PDPA requires ‘appropriate security measures’ without naming a standard, and the Cybersecurity Act sets duties for critical information infrastructure rather than certificates. A certified ISMS is the practical way to evidence both to a regulator or a customer.

What does the Thai PDPA require after a breach?

It depends on the assessed risk. Where there is no risk to rights and freedoms, notification is exempt. Where there is risk, notify the PDPC Office without delay and, where feasible, within 72 hours of becoming aware. Where the risk is high, notify the affected individuals as well. The detail sits in the PDPC’s breach-reporting notification of B.E. 2565 (2022).

What is the Cybersecurity Act and does it apply to us?

The Cybersecurity Act B.E. 2562 (2019) establishes Thailand’s critical information infrastructure regime under the National Cyber Security Agency (NCSA). It applies where your systems fall within the CII regime, which is a separate question from PDPA compliance and a different regulator.

Who performs the ISO 27001 certification audit in Thailand?

A certification body accredited through Thailand’s National Accreditation Council, via the Thai Industrial Standards Institute (TISI) under the Ministry of Industry, and not Secure60. Audit fees are set by the certification body and vary with scope.

Can Secure60 deliver in Thailand?

Yes. We have delivery infrastructure in Thailand via Rackcorp, with 2 datacentres, so log collection and monitoring can run in-country. We have no local offices, and we do not perform the certification audit.

Thailand PDPA and CII Regime Readiness

A readiness call maps the PDPA's breach regime and the Cybersecurity Act against the environment and scopes the ISMS engagement.

30 days, every feature switched on. No credit card.