LexVibe
Thailand
In force since 1 June 2022

PDPA compliance for a newsletter

Personal Data Protection Act B.E. 2562 (Thailand). This page applies it to one kind of product (newsletter), so you get the obligations that are actually yours instead of a summary of the whole statute.

Does it apply to you?

Processing of personal data of people in Thailand, including from abroad.

What a newsletter typically processes

  • email addresses collected through a signup form
  • open and click tracking
  • list data held by an email service provider

Each of these is processing you have to disclose. Adding an SDK later adds to this list — which is why a policy written once goes stale.

Documents you need

The intersection of what PDPA requires and what a newsletter actually does:

  • Privacy policy

Rights you must honour

PDPA gives people in Thailand the right to:

  • Access a copy of their data
  • Correct inaccurate data
  • Have their data deleted
  • Receive their data in a portable format
  • Object to certain processing
  • Withdraw consent at any time

Cookies and trackers

Nothing non-essential may load before the visitor agrees. Analytics and marketing scripts must be blocked until then — a banner that only informs is not enough.

See what your site is actually missing

Paste your URL. We fetch the live page, detect the trackers, payments and AI calls that really ship to visitors, and tell you which documents and consent you need. No signup.

No signup · result in seconds

Primary sources

  • PDPAPersonal Data Protection Act B.E. 2562 (Thailand) · PDPC Thailand

Everything we track about PDPA

PDPA for other kinds of product

Other frameworks for a newsletter

This page is an engineering summary of publicly available regulatory requirements, generated from LexVibe's framework registry — not legal advice. Every framework links to its official text so you can check it yourself. For decisions about your own compliance posture, consult the primary sources and a lawyer qualified in the relevant jurisdiction.