Compliance

GDPR and PDPA are in force. The clock is 72 hours.

Thailand's Personal Data Protection Act has been fully in force since 1 June 2022, and the GDPR since 2018. Both give you 72 hours from becoming aware of a personal data breach to report it. That deadline is what turns detection speed from an IT preference into a legal obligation, and it is where security technology earns its place in a compliance programme.

  • 1 June 2022

    The date Thailand's PDPA came into full force, after the Personal Data Protection Committee was formed

  • 72 hours

    To notify the regulator of a personal data breach, under the PDPA and the GDPR alike

0 June 2022PDPA in full forceThailand's Personal Data Protection Act, after multiple extensions and the formation of the Personal Data Protection Committee
0 hoursTo report a breachPDPA: notify the Office of the PDPC within 72 hours of becoming aware. GDPR Article 33: the same 72 hours to the supervisory authority
0,000,000Baht, maximum administrative fineThe ceiling for an administrative fine under the PDPA. Criminal liability is separate and narrower - see the comparison below
0%Or 20 million euro, GDPRGDPR Article 83(5): up to 20 million euro or 4 percent of total worldwide annual turnover, whichever is higher

Side by side

GDPR and PDPA, compared on the points that change what you have to build

Thailand's PDPA was drafted closely on the GDPR, so the obligations rhyme. Where they differ, they differ in ways that matter to a security programme. Search the table or open a row for the detail.

9 obligations compared

GDPR and PDPA, compared on the points that change what you have to build
ObligationGDPREuropean UnionPDPAThailand
1Status and reach3 obligationsWho each law binds, and since when.
25 May 20181 June 2022
National supervisory authorityPDPC
Included in GDPRIncluded in PDPA
2When something goes wrong3 obligationsThe part of the law that a security product can actually help you meet.
72 hours72 hours
Included in GDPRIncluded in PDPA
Included in GDPRIncluded in PDPA
3What non-compliance costs3 obligationsStated with their scope, because the headline numbers get quoted out of context.
EUR 20m or 4%THB 5,000,000
Set by member stateUp to 1 year, sensitive data
Included in GDPRIncluded in PDPA

Three jobs

Where security technology actually meets the obligation

Most of a data protection programme is legal and organisational work that no software can do for you. Three parts of it are technical, and those are the three this page is about.

01 / 03

Data that leaves the building

A laptop in a taxi is the oldest breach there is, and the easiest to render harmless.

  • Full disk encryption on Windows and macOS endpoints
  • An encrypted, unrecoverable drive is not the same event as a readable one
  • Recovery keys and encryption status reportable from one console

02 / 03

Data taken by an attacker

Targeted attacks, ransomware and living-off-the-land techniques aimed at the data you hold.

  • Prevention before execution, not just detection after it
  • Unknown and file-less threats stopped without a signature
  • Application control to shrink what can run at all

03 / 03

Knowing it happened

Both laws start the 72-hour clock when you become aware. Awareness is a control you can buy.

  • Detections correlated across the estate, not one alert per machine
  • An incident timeline you can hand to a regulator
  • Evidence of what was reached, and what was not

Lost and stolen devices

Encryption turns a lost laptop into a non-event

The cheapest breach to prevent is the one where the device simply leaves. GravityZone Full Disk Encryption is managed from the same console as the rest of your endpoint security.

GravityZone encryption policy showing native BitLocker and FileVault encryption managed centrally

Native encryption, centrally managed

It drives the encryption already built into the operating system - BitLocker on Windows, FileVault on macOS - rather than installing a second cryptographic stack. There is no separate key server to stand up and no performance penalty from a third-party driver, and the whole estate is managed from the GravityZone console you already use.

  • BitLocker and FileVault driven from one policy
  • No extra agent, no key management server
  • Encryption status visible per device
Pre-boot authentication prompt requiring credentials before the operating system starts

Pre-boot authentication

The machine demands credentials before the operating system loads, so a drive pulled out and mounted elsewhere gives up nothing. This is the control that makes the difference between reporting a lost asset and reporting a personal data breach.

GravityZone encryption report listing devices with their encryption status and recovery key availability

Reporting you can show someone

Encryption status and recovery key custody, per device, as a report. When a device goes missing, the question is whether it was encrypted at the time - and a report that answers it is worth considerably more than a recollection.

Attack prevention

Stopping the attack that would have taken the data

A breach you prevent is a breach you never have to notify. These are the layers that work before anything executes, and the ones that contain what does.

HyperDetect - tunable machine learning before execution

Blocks what has no signature yet

Machine learning models and advanced heuristics inspect a file and its behaviour before it is allowed to run, which is what catches threats that have no signature yet: file-less attacks, malicious PowerShell, unknown ransomware families.

Blocks at the pre-execution stage
The payload never touches the data it was written to take.
Aggressiveness configurable per policy
Run it hard on the finance team and gentler on developers, instead of one setting for everyone.
Reports what it suspected and why
A blocked item comes with a reason, so a false positive is a five-minute conversation.

The 72-hour clock

Detection speed is a compliance control, not an IT preference

Both laws start counting from the moment you become aware. That single drafting choice is why visibility belongs in a compliance budget: an intrusion nobody has noticed is not a clock that has been paused, it is a clock that has not started - and a regulator asking why will want to know what you had in place to notice.

You cannot report what you have not detected

The obligation is to notify within 72 hours of awareness. An organisation with no detection capability does not thereby escape the deadline; it arrives at it late, and with nothing to say about scope. Endpoint detection and response exists to make awareness early and specific.

The regulator asks what was reached, not just what happened

A notification has to describe the nature of the breach and the likely consequences. Correlated detections and an incident timeline let you answer with evidence about which systems and which data were actually touched, rather than with the worst case you cannot rule out.

Evidence beats recollection

Encryption status at the time of loss, which controls were enabled, what the agent blocked and when. These are reportable facts from the console. Reconstructing them after an incident, from memory and email, is where compliance programmes come apart.

Where to start

Two honest routes, depending on what you already know

The legally correct order is to understand your data first. In practice most organisations discover they need to do both at once, and pretending otherwise leaves them unprotected while the mapping runs. Pick the route that matches where you actually are.

The correct order

You have not mapped your data yet

  1. 1Inventory the personal data you hold: what it is, where it lives, who can reach it, why you have it and how long you keep it.
  2. 2Classify it - ordinary personal data, or the sensitive categories the PDPA treats separately under section 26 and the GDPR under Article 9. The sensitive set carries the heavier penalties.
  3. 3Assess the risk to each store: what would have to go wrong for it to be exposed, and what the consequence would be for the people in it.
  4. 4Choose technical and organisational controls against that risk register, then deploy them where the register says they matter.
Most common in practice

You need cover while you map

  1. 1Encrypt the endpoints now. Device loss is the breach that needs no attacker, and encryption is the one control that does not require knowing what is on the disk.
  2. 2Turn on prevention across the estate - pre-execution blocking, anti-exploit, application control where machines have a fixed job.
  3. 3Get detection and response reporting into one console, so the 72-hour clock starts on a detection rather than on a phone call from someone else.
  4. 4Run the data mapping in parallel, and use what the console tells you about where data actually moves to inform it.

Where these controls live

Which GravityZone tier carries which control

The controls on this page are spread across the GravityZone range and its add-ons. Nothing here is a separate compliance product - it is the endpoint security platform, configured against the obligation.

We are a Bitdefender partner in Thailand and the region. Tell us how many endpoints and what you are trying to satisfy, and we will map the tiers and add-ons to it and quote. Prices are for licences only and do not include implementation services.

GDPR and PDPA, answered

Start with the controls, not with the panic

Tell us how many endpoints you have and where your personal data actually sits, and we will map the technical controls to the obligations you are working to and quote them. If you would rather see it first, start a free trial of GravityZone and encrypt a handful of real laptops. This page is a description of technology and law as we understand it, not legal advice - take advice on your own obligations.