Is your Swiss data protection framework ready for Thailand?
Swiss companies expanding into Thailand often already have well-developed compliance structures under the Swiss Federal Act on Data Protection and, in many cases, the GDPR.
However, GDPR or Swiss FADP compliance does not automatically mean that the company also complies with Thailand’s Personal Data Protection Act (PDPA).
Thailand has its own requirements concerning lawful processing, sensitive personal data, Data Protection Officers, processor agreements, breach notifications and international data transfers. These rules become particularly important when personal data moves between a Thai subsidiary, a Swiss parent company, European affiliates, cloud providers and international support teams.
To help Swiss-headquartered companies identify and manage these risks, Nomadlaw has prepared a new practical guide:
Nomadlaw Practical Guide: PDPA Compliance for Swiss-Headquartered Groups
The guide is designed for Swiss companies operating in Thailand or exchanging personal data with a Thai subsidiary, branch, service provider or business partner.
Rather than repeating general GDPR principles, it focuses on the areas where Thai law requires a separate analysis or a locally adapted compliance measure.
What does the guide cover?
The guide provides practical guidance on:
- the main differences between the Thai PDPA, the GDPR and the Swiss FADP;
- the territorial and extraterritorial scope of the Thai PDPA;
- lawful bases and sensitive personal data under Thai law;
- the assessment of Data Protection Officer requirements for Thai entities;
- the integration of Thai requirements into an existing global privacy programme;
- processor contracts, vendors and intra-group data processing;
- personal data breaches and Thai notification procedures;
- international transfers between Thailand, Switzerland and the EU;
- Standard Contractual Clauses, Thai transfer safeguards and Binding Corporate Rules;
- Transfer Risk Assessments/Transfer Impact Assessments, and
- selected operational topics involving employee data, monitoring systems and international IT platforms.
GDPR compliance does not automatically mean PDPA compliance
The Thai PDPA is strongly influenced by the GDPR, but it is not simply a Thai copy of European data protection law.
A Swiss company may therefore use its existing GDPR or FADP framework as a strong foundation. Nevertheless, it should add a specific Thai compliance layer addressing matters such as:
- Thai lawful bases;
- Section 26 sensitive personal data;
- Thai DPO requirements;
- Thailand-originating data transfers;
- local breach escalation;
- processor and vendor arrangements, and
- Thai privacy notices and documentation.
For most international groups, this targeted approach is more efficient than creating an entirely separate privacy programme for Thailand.
Cross-border data transfers require a separate analysis
One of the most important issues for Swiss-headquartered groups is the direction in which personal data is transferred.
A transfer from Switzerland to Thailand must be assessed under Swiss data protection law and, where relevant, the GDPR. A transfer from Thailand to Switzerland must instead be analysed under the Thai PDPA’s own outbound-transfer rules. This means that existing European or Swiss Standard Contractual Clauses may provide a useful foundation, but they do not automatically resolve every transfer of Thailand-originating personal data.
The guide explains how companies can structure intra-group transfers more effectively by combining existing GDPR or FADP safeguards with an appropriate Thai transfer mechanism.
Does the Thai subsidiary need its own DPO assessment?
The fact that a Swiss or European parent company already has a Data Protection Officer does not automatically determine whether the Thai subsidiary must appoint one.
Each Thai entity should assess its own activities, including:
- whether regular and systematic monitoring forms part of its core business;
- whether it processes personal data on a large scale;
- whether sensitive personal data is central to its activities;
- whether an existing group DPO can effectively support the Thai entity.
A group DPO may be able to cover the Thai subsidiary, but the arrangement must work in practice and meet the requirements of Thai law.
A practical guide for international compliance teams
The guide is intended to help legal, compliance, HR, IT and management teams understand where their existing international privacy framework may need to be adapted.
It is particularly relevant for:
- Swiss companies with a subsidiary or branch in Thailand;
- groups using shared HR, finance, CRM or IT systems;
- companies transferring employee or customer data between Thailand and Switzerland;
- Data Protection Officers responsible for international subsidiaries;
- Swiss businesses preparing to establish operations in Thailand;
- organisations using global cloud providers or regional support centres.
Download the Practical PDPA Guide
Download the Nomadlaw Practical Guide: PDPA Compliance for Swiss-Headquartered Groups here.
The guide is intended as general practical information. The appropriate compliance measures should always be assessed in light of the company’s specific structure, sector, systems, workforce and data flows.
Need support with Thailand–Switzerland data protection?
Nomadlaw supports Swiss companies with the coordination and implementation of cross-border data protection matters, including:
- Thai PDPA compliance reviews;
- data-flow and transfer assessments;
- intra-group transfer agreements;
- processor and vendor contract reviews;
- DPO assessments;
- privacy documentation;
- coordination with legal advisers in Thailand and Switzerland.
One central contact for legal and compliance matters in Switzerland and Thailand

