On 29 June 2026, the Royal Decree on the Data Sharing of Personal Information under the Control of a Government Agency to Another Government Agency B.E. 2569 (2026) was published in the Government Gazette and entered into force on 30 June 2026.
This Royal Decree marks a significant step forward in inter-agency information Data Sharing, enabling government agencies to connect and exchange data with one another. It strengthens transparency, improves the efficiency of law enforcement, supports the development of Digital Government, and elevates public service delivery through electronic systems.
What Is Inter-Agency Data Sharing of Personal Information?
The core substance of this Royal Decree is to establish criteria enabling government agencies to disclose information to one another. Under the Decree, a government agency is required to disclose information to another government agency upon request, for the purpose of carrying out or providing public services to the public through electronic systems. The objective is to promote data integration for analytical purposes, and to enhance the efficiency of law enforcement and public service provision.
The benefits of inter-agency information Data Sharing extend beyond reducing duplication in data collection. Agencies can cross-verify information with one another, assistance and welfare programs can be delivered more precisely to their intended target groups, and government agencies can use the data to formulate more effective policies. It also increases transparency in public administration and supports law enforcement efforts, such as preventing corruption, human trafficking, and online fraud.
What Conditions Apply to Inter-Agency Data Sharing?
Although the law requires a government agency to disclose information to another government agency upon request, this Data Sharing is not unlimited. The following key principles apply:
What Are the Duties of the Receiving Government Agency in Inter-Agency Data Sharing?
A government agency that receives information through inter-agency Data Sharing is under a duty to safeguard that information and is prohibited from disclosing it to any external party, whether another government agency, a private entity, or any unrelated individual. Importantly, the receiving government agency must maintain the information in accordance with the criteria prescribed by the Committee, which must be consistent with cybersecurity standards.
As the Official Information Committee has not yet issued the criteria and conditions for data maintenance, the current practice is to apply data protection measures consistent with cybersecurity standards. In doing so, government agencies should refer to relevant laws and standards, including the Cybersecurity Act B.E. 2562 (2019), the Personal Data Protection Act B.E. 2562 (2019), and the Notification of the Personal Data Protection Committee Re: Security Measures of the Data Controller B.E. 2565 (2022). These instruments cover key measures across policy, technical, and physical dimensions, such as access control, authentication, encryption, backup, and incident response.
Inter-Agency Data Sharing and Practical Challenges
Inter-agency information Data Sharing represents a significant step forward in Thailand's development of Government Data Sharing and Digital Government. In practice, however, each agency's readiness in data management is a critical starting point for enabling Data Sharing between agencies. When data is of high quality and protected by appropriate safeguards, it builds public trust while simultaneously enhancing the efficiency of government service delivery. The foundational data management practices that government agencies need to undertake include: