Share
When a personal data breach occurs, many organizations assume that notification to the Personal Data Protection Committee (PDPC) is mandatory in every case. In practice, the law does not require notification for every incident. PDPC Consultation No. 17/2567 provides clear guidance on when notification is and is not required.
1. When Notification Is Not Required
If the organization assesses the incident and determines that the breach does not pose a risk to the rights and freedoms of data subjects, notification to the PDPC is not required. However, the organization should document the incident and retain evidence of the assessment in the event of a subsequent review by the PDPC.
2. When Notification Is Required Within 72 Hours
If investigation confirms reasonable belief that a breach has occurred and poses a risk to data subjects' rights and freedoms, the organization must notify the PDPC within 72 hours from the point of confirmation. This is assessed on a case-by-case basis.
3. When the 72-Hour Deadline Cannot Be Met
If there are justifiable reasons preventing notification within the prescribed timeframe, the organization must notify the PDPC as soon as possible, no later than 15 days, accompanied by an explanation for the delay.
How to Notify the PDPC
What Every Organization Should Have in Place
Read the full consultation: pdpc.or.th/wp-content/uploads/2024/11/PDPC-consultation-46.pdf
This article is part of the LAS Legal Knowledge Hub - Learn more at kelomn.com
Thundthornthep Yamoutai
Legal Advance Solution / LAS
[email protected]