Skip to main content

humanit managed services

BLOG

Is Your IT Ready for PDPA and AI Governance? A Practical Guide for Thai Businesses

Is Your IT Ready for PDPA and AI Governance? A Practical Guide for Thai Businesses

Every Thai business now handles personal data, and more are adding AI tools to the mix, often faster than their systems can safely support. That raises a question many organisations have not fully answered: is your IT actually ready to keep you compliant? When our team recently attended the AustCham Thailand Eastern Seaboard (ESB) Members Briefing on PDPA and AI governance, hosted with BDO, one message stood out: data protection and AI governance are no longer just legal or policy exercises. They are solved or lost within your infrastructure. Here is what that means for Thai businesses, and a practical checklist to get your IT PDPA- and AI-governance-ready.

Why PDPA and AI governance are now an IT problem

Thailand’s Personal Data Protection Act (PDPA) has applied to businesses for years, requiring you to protect personal data with appropriate security measures. AI raises the stakes. The briefing’s sharpest insight was that AI is a “flaw multiplier”; it does not remove the weaknesses in your controls; it magnifies them. Point an AI tool at poorly organised data, loose access permissions, or unreliable backups, and you don’t get efficiency; you scale your exposure. For anyone responsible for IT, that reframes AI governance as an extension of the security and data management work you already do, not as a separate future project.

The IT foundations of PDPA and AI governance readiness

Before any policy or privacy notice, five IT foundations decide whether you can actually comply. Get these right, and the rest becomes manageable.

1. Know where your personal data lives

You cannot protect or account for data you cannot see. Mapping which systems hold personal data and which AI tools touch it is the groundwork for your Records of Processing Activities (ROPA) and every risk assessment that follows. This is where strategic IT planning and a proper asset inventory pay off.

2. Control and monitor access

PDPA expects appropriate access controls. In practice, that means least-privilege permissions, monitored access, and the ability to see who touched what and when. Managed risk and security, together with remote monitoring, turn that expectation into something you can evidence to an auditor or a regulator.

3. Protect the web and network layer

A great deal of personal data moves through browsers, email and web applications. Web protection and filtering reduce the risk of leaks and malware that can turn a minor gap into a reportable breach and keep AI tools from becoming an uncontrolled data exit.

4. Back up with retention and recovery in mind

PDPA involves retention periods and the ability to restore data, while AI governance adds the need to decommission systems cleanly at end of life. Reliable backup and disaster recovery cover both, so you can prove data is kept only as long as needed and recovered when it matters.

5. Keep the security baseline current

Unpatched systems and outdated antivirus software are the very flaws that AI multiplies. Managed antivirus and patch management keep the baseline solid, closing the everyday gaps that attackers — and careless AI integrations exploit first.

Standards give you a head start: ISO 27001, ISO/IEC 42001 and NIST AI RMF.

A recurring theme at the briefing was “standards first, regulation follows”; there is no need to wait for Thailand’s draft AI law to be finalised before acting. Aligning to established standards now puts you ahead: ISO/IEC 27001 for information security management, ISO/IEC 42001 as a certifiable AI management system, and the NIST AI Risk Management Framework for identifying and mitigating AI risks, with the OECD AI Principles and the EU AI Act as reference points. For Thai businesses, especially factories and exporters working with international partners, these standards are increasingly a condition of doing business rather than just a badge.

Your IT readiness checklist, adapted from the briefing's governance tools

The seminar shared four practical governance tools. Here is what each one actually requires from your IT.

1. Privacy notices that reflect AI

Your systems must be able to show when AI processes customer data, disclose any automated decision-making, and support requests for human review of AI outputs. That is a data-flow and logging capability, not just a wording change.

2. An intake gate for new AI projects

Before an AI tool goes live, run an IT security and data review: what data does it use, where does that data go, is it used to train the provider’s models, and is it transferred overseas? A simple gate stops risky integrations before they reach production.

3. AI systems recorded in your ROPA

Recording AI systems in your Records of Processing Activities depends on an accurate, maintained inventory of systems and data flows, squarely an IT responsibility. If your asset register is out of date, your ROPA will be too.

4. Controls across the AI lifecycle

From design and storage through use, monitoring and retirement, each stage needs IT controls: access management, activity logging, encryption, backup, and secure decommissioning when a system is retired. Governance on paper only works if the controls exist in the infrastructure.

What Thai businesses should do now?

You do not need to wait for the final AI law to make progress. Start by getting the IT foundations right: data visibility, access control, backup and a current security baseline, and adopt recognised standards as your roadmap. That is exactly where HumanIT helps. From managed risk and security to backup and disaster recovery and our PDPA and ISO compliance pack, we help businesses across Pattaya, Chonburi and the Eastern Seaboard build IT that stands up to PDPA and AI governance, before regulation forces the issue.

Frequently asked questions

Not sure where your IT stands? Book a free IT assessment, and we’ll help you find the gaps.

Call 033 005 920
humanit.asia/contact-us

Is PDPA compliance an IT responsibility or a legal one?

Both. Legal defines the obligations; IT provides the controls access management, encryption, backup, monitoring and breach response that make compliance real day to day.

What IT controls does PDPA expect?

Appropriate security measures: access control, data encryption, secure backups, activity monitoring, and a tested plan to detect and respond to data breaches.

Does using AI change our PDPA obligations?

Yes. You must disclose AI use in your privacy notices, record AI systems in your ROPA, assess the impact through a DPIA, and ensure a human can review automated decisions.

How do ISO 27001 and ISO/IEC 42001 help?

ISO 27001 structures your information security; ISO/IEC 42001 does the same for AI management. Together they give auditors, partners and regulators confidence that you take data and AI seriously.