Latest News & Insights

Athentic Consulting’s team of experienced experts bring you the
latest news and insights in law and regulations.

Data-Center-for-PDPA

Data Centers: Privacy Challenges and Cross-Border Legal Complexities in the Digital Era

In an era where data has become a primary driver of the economy, technological infrastructure has become the backbone of operations across every sector. Whether it is scanning to pay through PromptPay, backing up photos to the cloud, or artificial intelligence (AI) processing information in a split second, all of these depend on Data Centers, which handle streaming, data backup, processing, and signal distribution around the clock. Digital transformation has caused both the public and private sectors in Thailand to rely significantly on Data Center providers, both domestic and international.

From an information technology standpoint, a Data Center refers to a facility, location, or room used to house computer servers and various network systems in order to centralize the storage, collection, and management of information technology equipment such as servers, storage systems, and network devices in one organized place. This supports the processing and delivery of large volumes of data to various systems or applications. A Data Center functions as a central hub for storing data, processing information, and distributing digital data so that users can access and share it efficiently from a central location.

However, when the data stored or processed in a Data Center qualifies as "personal data" under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), the technological relationship immediately becomes a legal relationship as well. The main challenge lies in determining the legal status of the Data Center provider: whether it functions merely as a storage provider, as a data processor, or whether it carries additional duties and liabilities under the law.


Legal Obligations under the PDPA for Data Centers

Under personal data protection law, a Data Controller means a person or juristic entity that determines the purposes and methods of processing personal data, such as a company using employee personal data it has collected to process payroll. A Data Processor means a person or juristic entity that processes data according to the instructions of the Data Controller, without authority to decide the purposes of using the data, such as an outsourced payroll company that must calculate and disburse employee salaries based on the data and instructions sent by the hiring company.

From these examples, it becomes clear that determining the correct status does not depend solely on the labels agreed upon in a document, but is instead determined by who, in practice, actually holds authority over the processing of the data. Applying this to the context of Data Centers makes the picture even clearer.

Generally, when an organization (the Data Controller) hires a Data Center provider (the Data Processor) to host its database, the provider's role is limited to facilitating the infrastructure according to instructions, without any right to use the data for other purposes on its own.

Therefore, when we define the hiring organization as the Data Controller and it places data in the care of a hired provider that holds the status of Data Processor, the hiring organization, in its capacity as Data Controller, has three legal duties as follows.

1. Executing a Data Processing Agreement (DPA)

Even when an organization moves its data to a Data Center, legal responsibility still remains with the organization. Under Section 40 of the PDPA, the Data Controller must arrange for an agreement or contract, commonly called a Data Processing Agreement (DPA), to govern the Data Center's processing of data so that it acts only according to the instructions given to it.

At minimum, a DPA prepared under the requirements of the PDPA must address the following essential matters:

  • The structure and scope of the legal relationship, such as requiring the Data Processor to collect, use, or disclose personal data only according to instructions received from the Data Controller.
  • Security and oversight measures, such as requiring the Data Processor to implement appropriate security measures to prevent the loss of, unauthorized or unlawful access to, use of, alteration of, correction of, or disclosure of personal data.
  • Risk management, such as requiring the Data Processor to notify the Data Controller of a personal data breach without delay, and within 72 hours from the time the Data Processor becomes aware of the incident, to the extent practicable.
  • A requirement that the Data Processor maintain a record of personal data processing activities.

In addition, the DPA serves as a legal safeguard demonstrating the organization's due care, and it also serves as important evidence for pursuing claims for damages if a data breach occurs on the Data Center's side.

2. Implementing Security Measures

Throughout the delivery of data and the entire data processing cycle, Section 37(1) and Section 40(2) of the PDPA, together with Clause 6 of the Notification of the Personal Data Protection Committee on Security Measures for Data Controllers B.E. 2565 (2022), do not treat this as the duty of only one party. Rather, both the Data Controller and the Data Processor share the legal duty to arrange appropriate security measures. The Data Controller must specify in the agreement that the Processor maintain measures equivalent to the minimum security standard, in order to preserve the confidentiality, integrity, and availability of the organization's personal data. These measures must cover three main dimensions:

2.1 Organizational Measures: such as establishing policies and practices for personal data protection, defining roles and access rights based on the need to know and least privilege principles, entering into confidentiality agreements with personnel, conducting awareness training, and preparing a data breach response plan.

2.2 Technical Measures: such as data encryption and cybersecurity systems to prevent hacking or interception of data during storage and transmission.

2.3 Physical Measures: such as access control systems for server rooms to prevent loss, unauthorized access, alteration, correction, or disclosure of data, in order to keep unauthorized individuals from reaching the servers.

These measures should be reviewed and improved according to the organization's policy, whenever necessary, when there is a change in technology, or immediately upon the occurrence of a personal data breach.

3. Assessing and Overseeing Cross Border Data Transfers

When an organization decides to store or process data at a Data Center or cloud service whose main or backup servers are located abroad, the law does not treat this in every case as a cross border transfer of data. This is because, under the Notification of the Personal Data Protection Committee on Criteria for the Protection of Personal Data Sent or Transferred Abroad B.E. 2566 (2023), if the service is limited to data storage or data transit, and no person other than the Data Controller and the Data Processor is able to access the personal data (for example, the organization encrypts the data using robust techniques and alone holds the encryption key, such that the cloud provider or any third party cannot decrypt or view the content), such an arrangement will not be considered a sending or transfer of personal data abroad under Section 28.

However, if the overseas Data Center or cloud provider, or any third party, has the right or ability to access the content of the personal data, such an arrangement will be treated as a transfer of data abroad. In that case, the Data Controller has a duty to assess whether the destination country maintains an adequate standard of personal data protection, or to put in place appropriate protective measures, such as entering into a contract based on Standard Contractual Clauses (SCCs), to ensure that the personal data continues to receive protection consistent with legal standards. If the destination country does not have an adequate standard and no appropriate protective measures are in place, the transfer of data may proceed only if it falls within a legal exception under Section 28, such as:

  • Being necessary to comply with the law.
  • Being based on the consent of the data subject, after the data subject has been informed of the destination country's inadequate protection standard.
  • Being necessary for the performance of a contract to which the data subject is a party, or to take steps requested by the data subject prior to entering into such a contract.


Case Study: The Illusion of Data Localization and Legal Complexity

In theory, many organizations put measures in place to oversee Data Center providers through three key mechanisms: executing a DPA, arranging security measures, and overseeing cross border data transfers. In practice, however, enforcing all three mechanisms still involves unexpected challenges and gaps. Many organizations believe that storing data in a Data Center located within Thailand is the best answer for security. In reality, however, physical location is only one dimension of the issue, because in the digital world, hidden risks can still arise even when the data an organization has stored has never left the country and has never been transferred across any border. The first risk is remote access by individuals located abroad, and the next risk is the nationality obligations of the provider, which may cause a Data Center in Thailand to become subject to enforcement under foreign law, potentially conflicting with Thai law. This can be explained through the following points.

1. The Myth of Data Localization and Remote Access

People commonly hold a mistaken belief that choosing a Data Center located in Thailand (a local Data Center) means the data will remain stored within the Kingdom and can never raise the issue of cross border data transfer. In reality, however, important information systems, such as core banking systems, even when their servers are located in Thailand, are often managed under a follow the sun model, which relies on IT support teams from abroad accessing the systems remotely to resolve issues around the clock.

Legally, the essential principle under Section 28 of the PDPA and international guidance (such as EDPB Guidelines 05/2021, Example 8.1) focuses primarily on the granting of access to data rather than the physical location of the server. Therefore, allowing a person abroad to access personal data remotely, even without downloading any file, may still raise issues concerning processing and cross border data transfer. This must be considered together with the status of the person accessing the data and the nature of that access.

1.1 Key considerations depend on the legal status of the person accessing the data:

  • Where the IT support team is a third party or a separate entity: If the remote party is a vendor hired to maintain the system, or an affiliated company separately registered as a juristic entity abroad, such remote access will be considered a transfer of personal data abroad under Section 28, because it opens access to a third party. As a result, the organization must assess the standards of the destination country and also arrange a DPA.
  • Where the IT support team consists of personnel of the same juristic entity: If the remote party is an employee of the same organization stationed at an overseas branch, the access to data will be interpreted as merely a conduit for the transit of data, because the data remains within the material scope of responsibility and legal protection of the same juristic entity, with no third party involved.
2. Conflicts among Cross Border Laws and Access to Data by Foreign States (Extraterritorial Jurisdiction)

A policy level challenge arises when a Data Center is located in Thailand but operates as a branch or subsidiary of a company not registered as a juristic entity in Thailand, such as a provider subject to the jurisdiction of the United States, which may fall under U.S. law such as the U.S. CLOUD Act (2018).

  • U.S. CLOUD Act: Empowers the U.S. government to order American companies to hand over data within their custody, regardless of where the server holding that data is located anywhere in the world.
  • PDPA (Thailand): Requires that disclosure of personal data to external agencies or foreign states must be supported by a proper lawful basis under Section 27, Section 24, or Section 26, and must also comply with Sections 28 and 29.

From the example above, it can be seen that a Data Center provider may find itself in a difficult position, forced to choose between following the orders of the government of the country where the company is based, or violating Thailand's PDPA as the country where the data is located. This requires finding practical approaches and technical measures to mitigate this legal risk.


Guidelines for Selecting and Managing a Data Center in Compliance with Personal Data Protection Law

Based on the case studies and legal challenges discussed above, the following practical guidelines can be summarized for organizations selecting and managing a Data Center in compliance with the PDPA:

  • Assess the system and the pattern of data access (Remote Access Analysis): Before choosing a service, analyze whether the Data Center's management follows a follow the sun model, and whether the team accessing the system consists of employees of the same organization or third party vendors, in order to properly assign legal duties from the outset.
  • Review or arrange a Data Processing Agreement (DPA): Review the DPA to ensure it is comprehensive enough to control and oversee the Data Center provider, by clearly defining the scope of instructions, security measures, and the conditions under which the overseas IT support team may remotely access the system, along with establishing a mechanism to provide notice if a request to access data is received from a foreign government agency.
  • Establish both technical and physical security measures: Arrange for data encryption both while data is at rest and while it is in transit, and control physical access to the actual server room, in order to prevent unauthorized access to the data.


Conclusion

Selecting and managing a Data Center in the current era should not focus solely on the physical location of the server cabinet. It is necessary to consider the matter comprehensively, including the type of system, the rights to access data, and the legal structure of the provider, so that the use of the Data Center complies with the PDPA. Organizations should assess and manage risk across multiple dimensions at the same time, whether it is the conditions surrounding remote access by overseas teams that may amount to a cross border data transfer, preparing an approach to deal with foreign laws that may affect the privacy of data, or applying advanced technical measures such as data encryption to limit access rights. Taking these steps not only helps an organization comply with the law correctly, but also plays a key role in protecting the rights and freedoms of data subjects effectively and sustainably, while raising the organization's overall standard of privacy protection.


Punsuree Kanjanapong
Lead - Legal Technology Counselor
Pattarin Tamano
Legal Technology Counselor
Nanthachaporn Chuatanabadee
Legal Technology Counselor
About ATHENTIC News & Insights Our Services Contact us Career