Ask a Thai SME owner about PDPA, and you will usually hear about consent forms and privacy policies those matter. But when personal data actually leaks from a small business, the cause is rarely a missing checkbox on a website. It is almost always access: too many people able to see too much data, for too long, with nobody keeping track.
The PDPA has been fully enforced since 2022, and the Personal Data Protection Committee has shown it is willing to act, including against smaller organisations. Four years in, “we didn’t know” carries no weight. What the law expects, in plain terms, is that you know what personal data you hold, you protect it with appropriate security measures, and you can report a serious breach within 72 hours of discovering it.
Here is the uncomfortable part: you cannot do any of those three things without controlling access.
Walk into an average 30-person company in Bangkok, Chonburi or Chiang Mai, and you will reliably find some version of the following.
A shared Google Drive or file server where the HR folder salaries, ID card copies, medical certificates is readable by most of the company, because permissions were set once in 2021 and never revisited. A former accountant whose email login still works, because offboarding meant collecting the laptop and nothing else. One admin password for the accounting system, written in a LINE group, used by four people. A marketing intern with export rights over the entire customer database, because that was easier than setting up proper roles.
None of this feels like a crisis on a normal day. Under the PDPA, each of these is a security-measure failure waiting to be discovered by an auditor, a disgruntled ex-employee, or an attacker who only needs one password.
The PDPA requires “appropriate security measures” proportionate to the data you hold. For personal data and especially sensitive data like health information or ID numbers, regulators and courts read that as covering, at minimum: access limited to people who need it for their work, authentication that identifies individuals (no shared logins), records of who accessed what, and prompt removal of access when someone leaves or changes roles.
Notice that all four are organisational disciplines, not products. You cannot buy a box that does this. Someone has to own the process every week for every joiner, mover, and leaver.
The fix is a user lifecycle: a defined procedure that runs every time someone’s relationship with your company changes.
When someone joins, they get accounts created from a role template; sales sees the CRM, not payroll. When someone changes roles, access is re-derived from the new role rather than stacked on top of the old one. When someone leaves, every account is deactivated the same day, and a checklist proves it. Quarterly, someone reviews the full list and asks one question per line: does this person still need this?
This is unglamorous work, which is exactly why it does not happen in businesses where IT is a side duty. It is also, hour for hour, the highest-value security work an SME can do; it simultaneously reduces breach risk, shrinks PDPA exposure and cuts software licence waste from accounts nobody uses.
There is a simple way to check whether your current setup would withstand a real incident. Imagine you learn on Monday morning that a customer list has appeared somewhere it should not be. The PDPA clock gives you 72 hours from discovery to notify the PDPC if the breach poses a risk to individuals. In that window, you need to answer: what data was exposed, whose data it was, who had access to the system it came from, when it happened, and what you have done to contain it.
If your systems use shared logins and nobody keeps access records, you cannot answer any of those questions, which means you cannot write the notification, scope the damage, or honestly tell affected customers what happened. The businesses that handle breaches well are not the ones that never get breached. They are the ones whose access controls and logs let them answer the five questions quickly, contain the incident, and demonstrate to the regulator that their security measures were reasonable. That posture is built in the months before the incident, not the 72 hours after it.
If your company has more than a handful of staff and no dedicated IT person, lifecycle management is a strong candidate for outsourcing. It is routine, it must never be skipped, and it does not require anyone on site. HumanIT’s Tier 2 package includes user lifecycle management and access controls, along with 24/7 monitoring and tested backups, at THB 2,500 per device per month or THB 2,000 on an annual billing plan. That puts a repeatable, auditable process in place for your PDPA obligations at less than the cost of one day of legal advice after a breach.
The PDPC will not ask whether you meant well. It will ask who had access to the data, and how you know. Make sure you have a good answer.
Want your access controls handled properly?
Call Eve on +66 89 354 9916 or review the Tier 2 package at humanit.asia/pricing-and-plans.