ISO 27001 · Thailand

ISO 27001 in Thailand: what it takes

The short answer

Two laws matter in Thailand, both from 2019: the PDPA (B.E. 2562), fully in force since June 2022, requiring ‘appropriate security measures’ and breach reports to the PDPC within 72 hours where feasible, and the Cybersecurity Act, which puts critical information infrastructure under the NCSA. Neither mandates a certificate. An ISO 27001 ISMS evidences both.

Thailand’s twin 2019 laws

Thailand passed its two defining laws in the same year. The Personal Data Protection Act B.E. 2562 (2019) — the PDPA — came fully into force on 1 June 2022 and is enforced by the Personal Data Protection Committee (PDPC) and its Office, under the Ministry of Digital Economy and Society. The Cybersecurity Act B.E. 2562 (2019) established the critical information infrastructure regime under the National Cyber Security Agency (NCSA).

Instrument Regulator What it asks of you
PDPA B.E. 2562 (2019) PDPC and its Office “Appropriate security measures” for personal data, plus risk-tiered breach reporting
PDPC breach notification B.E. 2565 (2022) PDPC Office The criteria and method for reporting personal-data breaches
Cybersecurity Act B.E. 2562 (2019) NCSA Critical information infrastructure duties, where your systems are within the regime

The PDPA’s breach rule is tiered by risk, and the tiers are where the operational work hides:

Assessed risk What the PDPA requires
No risk to rights and freedoms Notification exempt
Risk Notify the PDPC Office without delay and, where feasible, within 72 hours of becoming aware
High risk Notify the affected individuals as well

Every tier starts with the word “assessed”. You don’t get to pick a tier; you have to establish one, with evidence of what happened and what data was involved. The 72-hour figure gets the attention, but the assessment that precedes it is the actual work.

There’s no data-residency rule in the PDPA, and no clause in either law names ISO 27001. “Appropriate security measures” is technology-neutral — which means when the PDPC Office asks what was appropriate for your processing, the answer is yours to construct and prove.

How one ISMS carries both laws

The PDPA and the Cybersecurity Act ask different questions — one about personal data, one about systems staying up and incidents being handled — but a single ISO 27001 ISMS can hold both, because the standard’s risk assessment covers whatever obligations you record as requirements.

Thai obligation Where the ISMS answers it
“Appropriate security measures” (PDPA) Risk assessment across the 93 Annex A controls, with applicability documented in the Statement of Applicability — a written case for what’s appropriate, plus evidence it runs
Risk-tiered breach reporting (PDPC notification) Detection in front of incident management: continuous logging and monitoring, an assessment step that can place a breach in the right tier, and notification that fits the window
CII duties (Cybersecurity Act) Monitoring, incident response and reporting discipline scoped to the systems the regime cares about

The precondition is scoping. The ISMS only carries the Cybersecurity Act if the CII-relevant systems sit inside the certificate boundary and the Act is recorded as a legal requirement alongside the PDPA. Certification against a scope that quietly excludes your most regulated systems evidences very little.

Certification in Thailand: NAC, TISI and scope

The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by a certification body accredited through Thailand’s National Accreditation Council, via the Thai Industrial Standards Institute (TISI) under the Ministry of Industry. Never by Secure60. Audit fees are set by the certification body and vary with the size and scope of what’s certified; annual surveillance and three-yearly recertification follow.

Thai operations frequently sit inside regional groups, and one ISMS with a multi-country scope is usually the cheaper, more consistent answer than a standalone Thai certificate. Secure60 has delivery infrastructure in Thailand via Rackcorp, with 2 datacentres, so log collection and monitoring can run in-country on our security platform where that’s the expectation.

What most people get wrong

PDPA compliance gets treated as covering the Cybersecurity Act. They share a year of birth and the word “security”, so a privacy program gets built for the PDPC and everyone assumes Thailand is done.

They’re different laws with different regulators. The PDPA is about personal data and answers to the PDPC; the Cybersecurity Act is about critical information infrastructure and answers to the NCSA. A privacy program says little about whether your infrastructure meets the CII regime’s expectations. If your systems are within that regime, the monitoring and incident duties exist regardless of how polished the privacy notices are — and the time to find out is before designation conversations start, not during them. One ISMS can cover both, but only if it was scoped to.

How Secure60 handles this

We build the ISMS against both Thai laws — the PDPA recorded alongside the Cybersecurity Act as legal requirements — then run the operations underneath: logging, monitoring, incident response with the assessment step the PDPC’s risk tiers demand, on Rackcorp infrastructure in Thailand where residency is expected. The certification audit belongs to a certification body accredited through the NAC and TISI; our job is making everything it samples real. We hold ISO 27001:2022 certification ourselves and run our own operations on the same platform.

Frequently asked questions

Is ISO 27001 legally mandatory in Thailand?

No. The PDPA requires ‘appropriate security measures’ without naming a standard, and the Cybersecurity Act sets duties for critical information infrastructure rather than certificates. A certified ISMS is the practical way to evidence both to a regulator or a customer.

What does the Thai PDPA require after a breach?

It depends on the risk. Where there’s no risk to rights and freedoms, notification is exempt. Where there’s risk, notify the PDPC Office without delay and, where feasible, within 72 hours of becoming aware. Where the risk is high, notify the affected individuals as well. The detail sits in the PDPC’s breach-reporting notification of B.E. 2565 (2022).

What is the Cybersecurity Act and does it apply to us?

The Cybersecurity Act B.E. 2562 (2019) establishes Thailand’s critical information infrastructure regime under the National Cyber Security Agency (NCSA). It applies where your systems fall within the CII regime — a separate question from PDPA compliance, with a different regulator.

Who performs the ISO 27001 certification audit in Thailand?

A certification body accredited through Thailand’s National Accreditation Council, via the Thai Industrial Standards Institute (TISI) under the Ministry of Industry — not Secure60. Audit fees are set by the certification body and vary with scope.

Can Secure60 deliver in Thailand?

Yes — we have delivery infrastructure in Thailand via Rackcorp, with 2 datacentres, so log collection and monitoring can run in-country. We don’t have local offices, and we never perform the certification audit.

Processing Thai personal data or running infrastructure in Thailand?

Book a readiness call. We'll map the PDPA and the Cybersecurity Act against your systems and tell you what an ISMS engagement covers.

Book a readiness call Run a pilot