Orange textured background

Thailand regulation

Thailand PDPA and browser fingerprinting

How the Personal Data Protection Act B.E. 2562 (2019) regulates device fingerprinting, why its written-form consent requirement is stricter than GDPR, and what the PDPC's 2024 enforcement campaign means for online tracking.

Reviewed

RegionKingdom of Thailand
RegulatorPersonal Data Protection Committee Office (PDPC, under the Ministry of Digital Economy and Society)
Effective1 June 2022 (fully in force after COVID-era postponements)
Max penaltyTHB 5 million administrative fine per violation + up to 1 year imprisonment and THB 1 million criminal fine for serious violations
Status in-force

What the Thai PDPA says about fingerprinting

The Personal Data Protection Act B.E. 2562 (2019) is Thailand's first comprehensive data protection statute. It was enacted in May 2019 but faced repeated implementation delays during the COVID-19 pandemic. Full enforcement began on 1 June 2022. The law is deliberately modelled on the EU General Data Protection Regulation, borrowing its six lawful bases, its sensitive-data categories, and its cross-border transfer architecture, while adding locally specific requirements that in several places are more demanding than their GDPR equivalents.

The statute does not use the word 'fingerprinting'. Its definition of 'personal data' in section 3 captures 'any information relating to a person, which enables the identification of such person, whether directly or indirectly'. A browser fingerprint, the composite hash derived from a device's screen resolution, installed fonts, canvas rendering, GPU characteristics, audio context, time zone and related signals, falls within that definition the moment it is used to recognise the same visitor across sessions. As with GDPR, the hash does not need to resolve to a name or national ID number; the ability to distinguish and track an individual across interactions is sufficient.

Where Thai PDPA departs from the GDPR template most sharply is in the form of consent required before data collection begins. Section 19 of the Thai PDPA sets a higher formal bar than GDPR Article 4(11), and that difference has direct operational consequences for any fingerprinting deployment targeting Thai users.

Section 19 written-form consent: stricter than GDPR

Section 19 of the Thai PDPA is the statute's most operationally demanding provision for digital products. It requires that consent be obtained in writing or by electronic means. The PDPC's guidance clarifies that 'electronic means' in this context means a recorded affirmative action that constitutes an electronic written record, not a passive click-through or an implicit acceptance inferred from continued browsing.

Three consent mechanisms explicitly fail section 19: pre-checked boxes, where the user is opted in by default; bundled 'agree to our terms and privacy policy' flows, where fingerprinting consent is embedded in a broader acceptance; and 'soft opt-in' banners that treat closing the banner or scrolling past it as consent.

A consent mechanism that satisfies section 19 for a fingerprinting deployment typically has four components: a clear statement naming device fingerprinting as a specific processing activity; a named purpose or purposes; an affirmative action by the user, such as tapping or clicking an 'I consent' button that is visually distinct from a close or dismiss control; and a logged timestamp and version identifier stored by the controller. The GDPR 'freely given, specific, informed, unambiguous' standard covers the substance of consent. Section 19 additionally mandates the written form, which is a procedural requirement that GDPR does not impose.

The PDPC's 2024 guidance on online tracking technologies specifically addressed consent collection for tracking identifiers. It confirmed that fingerprinting signals collected before the user has completed the consent interaction are unlawful, regardless of the ultimate consent outcome, and that a fingerprint collected under a bundled-consent mechanism cannot be retroactively cured by a subsequent granular consent request.

Lawful bases: section 19 (consent) plus section 24 (non-consent grounds)

Thai PDPA splits the lawful-basis framework across two sections, an important structural difference from GDPR Article 6. Section 19 governs consent: it sets the formal requirements (written or electronic-written, specific, separate from other terms, freely withdrawable) and operates as the default basis. Section 24 enumerates the non-consent grounds on which a controller may collect personal data without seeking consent. Conflating the two, or citing 'consent under section 24', is a common drafting error that surfaces in privacy notices and DPIAs.

Section 24's non-consent grounds cover historical or statistical research and archiving, the protection of vital interests of the data subject, the performance of a contract requested by the data subject or pre-contractual steps, public-interest tasks or the exercise of official authority, the controller's legitimate interest balanced against the data subject's rights, and compliance with a legal obligation. For a commercial fingerprinting deployment, consent under section 19 is by far the most common basis. Legitimate interest is available for narrowly scoped anti-fraud and security purposes, subject to a documented balancing test.

Section 26 imposes a separate, stricter regime for sensitive personal data. Biometric data is explicitly listed as a sensitive category in section 26. A fingerprint that is derived from or used to generate a biometric identifier, for example a fingerprint combined with facial recognition or used to reconstruct a biometric template, falls under section 26 and requires explicit consent in addition to satisfying the written-form requirement of section 19. Health data, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal records, and trade union membership are also listed as sensitive categories. Any fingerprinting system that infers or correlates to these categories triggers the section 26 regime.

Thai PDPA lawful bases and their practical status for fingerprinting

  • Consent (s 19): the default and most widely applicable basis for commercial fingerprinting. Must be written or electronic-written, specific to fingerprinting as a named purpose, separate from other terms, and easy to withdraw. Withdrawal must not degrade the service in a way that penalises the user.
  • Vital interest (s 24, vital-interest ground): narrow; covers emergency medical and safety contexts. Not applicable to commercial fingerprinting.
  • Contract necessity (s 24, contract ground): applies where processing is strictly necessary to perform a contract requested by the data subject. Almost never applicable to fingerprinting alone, because a user does not contract to be fingerprinted.
  • Public interest or official authority (s 24, public-task ground): applies to government bodies and public-interest research. Does not apply to private-sector fingerprinting deployments.
  • Legitimate interest (s 24, legitimate-interest ground): workable for narrowly scoped anti-fraud and security purposes after a balancing test has been documented. Does not remove the section 19 written-consent requirement when the purpose is not strictly necessary for service delivery.
  • Legal obligation (s 24, legal-obligation ground): available where processing is required by Thai law, for example AML/KYC-driven device binding under the Anti-Money Laundering Act or the Payment Systems Act.

Cross-border transfers under section 28

Section 28 of the Thai PDPA restricts transfers of personal data to destinations outside Thailand. A transfer is permitted if: (a) the destination country has been granted an adequacy decision by the PDPC; (b) the controller has put in place appropriate safeguards, such as binding corporate rules, standard contractual clauses approved by the PDPC, or a certification scheme accepted by the PDPC; or (c) the data subject has given explicit informed consent to the specific transfer.

As of 2026, the PDPC's adequacy whitelist is still being developed. The most current position recognises countries that already hold EU adequacy decisions, including the EEA member states, the United Kingdom, Japan, South Korea, New Zealand, Canada, and Israel, as offering an acceptable level of protection. Countries that are not on the EU adequacy list, including the United States, Singapore, China, India, and most ASEAN nations, are not on the Thai adequacy whitelist and cannot receive fingerprint data under the adequacy route alone.

For transfers to non-whitelist destinations, a controller must rely on approved safeguards. The PDPC has indicated it will accept standard contractual clauses modelled on those approved under GDPR, but the Thai-specific SCC template has not been published as a finalised instrument as of the date of this review. Controllers routing fingerprint hashes to US-based ad-tech vendors, fingerprinting vendors headquartered in Singapore, or cloud infrastructure in non-adequate countries should treat every such transfer as requiring a documented safeguards mechanism.

Common fingerprinting purposes under Thai PDPA

PurposePersonal data under Thai PDPA?Written consent required (s 19)?Sensitive data regime (s 26)?Cross-border transfer concern (s 28)?
Anti-fraud at login or payment checkoutYesLikely not, if scoped as security of service and documented under the s 24 legitimate-interest groundNo, unless biometric inference is involvedYes, if hash is sent to non-adequate-country vendor
Account-takeover and credential-stuffing detectionYesLikely not, with narrow scope and documented LIANoYes, for non-adequate routing
Bot mitigation on a public formYesUsually not, if strictly necessary for service integrityNoYes, for non-adequate routing
Personalisation and A/B testingYesYes, explicit written consent requiredNoYes, for non-adequate routing
Cross-site behavioural advertisingYesYes, explicit written consent required; bundled consent invalidNoYes, for non-adequate routing
First-party product analytics (page views, funnels)YesYes, unless strictly necessary for service deliveryNoYes, for non-adequate routing
Biometric-linked fingerprinting (fingerprint combined with facial recognition or biometric template)YesYes, explicit consent required under both s 19 and s 26Yes, biometric data is a sensitive category under s 26Yes, additional safeguards required for sensitive data transfers
Fingerprinting to infer health, race, or political opinionYesYes, explicit consent under s 26 on top of s 19 written formYesYes
Session continuity within a single authenticated visitYesOften not, when genuinely necessary for contracted serviceNoYes, for non-adequate routing

PDPC enforcement: the 2024 scale-up

The PDPC spent the first two years after the June 2022 full-enforcement date primarily issuing guidance, conducting audits, and resolving complaints through informal resolution. The enforcement posture shifted materially in 2024.

The PDPC issued formal administrative fines against multiple SMEs and one major bank in 2024. The SME cases involved failures in consent collection mechanisms, including use of pre-checked boxes and bundled consent for data collected via mobile applications, which the PDPC characterised as non-compliant with section 19. The bank case involved cross-border data transfers to a vendor in a non-adequate country without documented safeguards under section 28, as well as a failure to appoint a DPO despite the bank's core activities involving large-scale systematic monitoring of customer behaviour. Administrative fines in these cases reached up to THB 3 million per violation.

In parallel with the administrative fine programme, the PDPC issued sector-specific guidance on online tracking technologies. The guidance confirmed that browser fingerprinting, canvas fingerprinting, and device identifier collection are all subject to the section 19 consent requirement when used for purposes beyond strictly necessary service delivery. The guidance also addressed the cross-border routing of tracking data and stated that routing tracking identifiers to vendors in non-adequate countries without section 28 safeguards is an independent violation, separate from any consent failure.

A third enforcement context emerged through sector regulatory cooperation. The PDPC worked with the Bank of Thailand and the Securities and Exchange Commission of Thailand in 2024 to coordinate enforcement of data protection obligations in the financial-services sector, where device fingerprinting is widely used for fraud detection and transaction monitoring. The coordinated approach signals that fingerprinting-related violations in fintech and banking are a priority for the 2025 to 2027 enforcement cycle.

DPO requirements under Thai PDPA

The Thai PDPA requires appointment of a Data Protection Officer in three circumstances: the controller or processor is a public authority; the core activities of the controller or processor require regular and systematic monitoring of personal data on a large scale; or the core activities involve processing sensitive personal data under section 26 on a large scale.

For fingerprinting deployments, the 'regular and systematic monitoring on a large scale' trigger is the most relevant. A platform that processes fingerprint signals from millions of users to power fraud detection, analytics, or advertising is likely conducting exactly the kind of large-scale systematic monitoring that requires a DPO. The PDPC has not published numerical thresholds for 'large scale' as of the date of this review, but has indicated in guidance that the same contextual assessment used under GDPR is appropriate: factors include the number of data subjects, the volume of data, the geographic extent of the processing, and the duration and frequency of the processing.

Children and parental consent

The Thai PDPA draws two age thresholds for personal data processing. For children under 10 years of age, parental or guardian consent is required for all processing. For persons under 20 years of age who are not legally emancipated, the statute requires parental or guardian consent for certain categories of processing, and the PDPC's guidance extends this to online tracking and device fingerprinting where the controller has reason to believe the user may be a minor.

A fingerprinting deployment that cannot distinguish adult from minor users should apply parental-consent requirements by default to any session that appears to originate from a device pattern associated with younger users, or should implement age-gate flows before any fingerprinting signal is collected.

How Benny the Doorman fits into a Thai PDPA-aware deployment

Benny is a fingerprinting SDK and hosted API, not a consent management platform. That separation is deliberate: consent collection and the section 19 written-form interaction must live in the controller's own CMP or consent flow, and the fingerprint call should only be triggered once the CMP records a compliant written consent for the relevant purpose.

For a Thai PDPA-aware deployment, three integration steps are critical. First, defer the call to Benny's fingerprint API until a section 19-compliant written consent has been recorded. The consent interaction must present fingerprinting as a named, specific purpose and capture an explicit affirmative action, not a passive dismissal or pre-checked box. The consent record, including timestamp and version, should be stored by the controller independently of Benny. Second, for purposes that qualify as legitimate interest, such as narrowly scoped anti-fraud and account-takeover detection, document the balancing test before deployment and keep that data flow architecturally separate from any consent-based purposes. Third, if your Benny deployment involves cross-border transfer of fingerprint hashes to Benny's API infrastructure, note that Benny's processing is performed on infrastructure hosted in Chennai, India.

India is not on the Thai PDPC's adequacy whitelist as of 2026. A Thai controller routing fingerprint data from Thai users to Benny's India-hosted infrastructure must either obtain explicit informed consent from each user for that specific cross-border transfer, or put in place section 28 safeguards such as standard contractual clauses. Benny can provide a data processing agreement and supporting contractual documentation on request to assist controllers in meeting their section 28 obligations. Controllers should obtain independent legal advice on whether the available safeguards satisfy current PDPC requirements before relying on them.

Frequently asked questions

Is browser fingerprinting illegal under the Thai PDPA?

No. Browser fingerprinting is not banned by the Thai PDPA. It is regulated as a form of personal data collection. Fingerprinting is lawful when the controller has obtained section 19 written-form consent, or can rely on another lawful basis such as legitimate interest for narrowly scoped security and anti-fraud purposes. Fingerprinting without a compliant lawful basis is what creates legal exposure under the statute.

Does a standard CMP checkbox count as written consent under section 19?

Not automatically. Section 19 of the Thai PDPA requires consent to be in writing or by electronic means that constitutes a recorded affirmative action. A pre-checked checkbox does not satisfy the requirement. A clearly unchecked checkbox that the user explicitly checks, presented alongside a specific and named description of fingerprinting as a purpose, can satisfy section 19 if the controller logs the action with a timestamp and version. A generic 'Accept all cookies' button that bundles fingerprinting with unrelated purposes does not satisfy the 'specific' element regardless of whether it is pre-checked.

Can I route fingerprint data to a non-EU fingerprinting vendor under the Thai PDPA?

Only with an appropriate legal mechanism under section 28. The Thai PDPC's adequacy whitelist as of 2026 covers countries with EU adequacy decisions. Most commercial fingerprinting vendors operate from US, Singapore, or other non-whitelist infrastructure. Routing fingerprint hashes to those vendors requires either the user's explicit informed consent to that specific cross-border transfer, or documented safeguards such as standard contractual clauses. A generic privacy policy reference to third-party processing is not sufficient.

Does Thai PDPA apply to fingerprinting for anti-fraud purposes?

Yes. Anti-fraud fingerprinting falls inside the Thai PDPA when the fingerprint can be linked to an identifiable Thai data subject. However, the section 19 written-consent requirement may be satisfied by the legitimate-interest basis under section 24(6) for narrowly scoped fraud detection, provided the controller has documented a balancing test showing the legitimate interest outweighs the data subject's rights. The cross-border transfer concern under section 28 applies regardless of the lawful basis for collection.

What makes Thai PDPA's consent requirement stricter than GDPR?

GDPR requires consent to be freely given, specific, informed, and unambiguous, which can be satisfied by a clear affirmative action such as clicking an unchecked box. Thai PDPA section 19 additionally requires the consent to be in writing or by electronic means constituting a written record. This written-form requirement means that implicit consent inferred from behaviour, and soft opt-in mechanisms that treat a dismissed banner as acceptance, are invalid under Thai law even where they might survive a GDPR challenge. The PDPC has explicitly confirmed this position in its 2024 online tracking guidance.

When does a Data Protection Officer need to be appointed under Thai PDPA?

A DPO is required when the controller or processor is a public authority, when core activities require regular and systematic monitoring of personal data on a large scale, or when core activities involve large-scale processing of sensitive personal data under section 26. A platform using fingerprinting at scale for fraud detection, advertising, or analytics is likely conducting large-scale systematic monitoring and should assess whether a DPO is required. The PDPC has not published numerical thresholds but applies a contextual assessment similar to GDPR Article 37.

What are the penalties for non-compliant fingerprinting under the Thai PDPA?

Administrative fines reach up to THB 5 million per violation. Serious violations involving intentional or negligent processing of sensitive personal data without a lawful basis can attract criminal penalties of up to 1 year imprisonment and a THB 1 million criminal fine. In the 2024 enforcement wave, fines against SMEs reached up to THB 3 million per violation. Victims of unlawful processing may also claim civil compensation for actual damages plus punitive damages not exceeding twice the actual damages.

Does Thai PDPA apply to companies based outside Thailand?

Yes, when the controller offers goods or services to data subjects in Thailand or monitors the behaviour of persons in Thailand, regardless of where the controller is established. This extraterritorial scope is modelled on GDPR Article 3(2). A company based in Singapore, the US, or elsewhere that fingerprints Thai website visitors is subject to the Thai PDPA for that processing. The PDPC has stated it will pursue complaints involving foreign controllers on a case-by-case basis.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06