Balance — Thailand Country Annex
Effective date: 28 June 2026 Last updated: 28 June 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Thai resident covered by this Annex; the Data Protection Officer ("DPO") for the purposes of Personal Data Protection Act B.E. 2562 (2019) ("PDPA Thailand" — พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562) Section 41 (mandatory DPO appointment for data controllers and data processors whose core activities consist of (a) processing requiring regular and systematic monitoring of personal data or of data subjects by reason of the large scale of personal data as prescribed by the Personal Data Protection Committee — "PDPC" — under the Notification of the Personal Data Protection Committee on the Designation of Data Controllers and Data Processors that are required to appoint a Data Protection Officer B.E. 2565 (2022) of 14 December 2022, in operation from 13 June 2023, the "PDPC DPO Notification 2022"; or (b) processing of sensitive personal data under Section 26; Balance is engaged on Section 41(b) on the most-protective reading because the PDPC DPO Notification 2022 explicitly references processing of personal data of children as a category warranting DPO designation — § 18 versioning protocol covers any further DPO threshold revisions), with business contact published as the publicly-accessible DPO contact required by Section 41(4) + the PDPC DPO Notification 2022 § 5; the designated contact point for the Personal Data Protection Committee (the "PDPC"), the Office of the Personal Data Protection Committee (Thai: สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล, the "PDPC Office"), the Ministry of Digital Economy and Society (Thai: กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม, the "MDES"), the Royal Thai Police — Thailand Internet Crimes Against Children Task Force (Thai: กองบังคับการปราบปรามการกระทำความผิดเกี่ยวกับการล่วงละเมิดทางเพศต่อเด็กผ่านระบบสื่อสารทางอิเล็กทรอนิกส์, the "TICAC"), the Royal Thai Police — Cybercrime Investigation Bureau (Thai: กองบังคับการปราบปรามการกระทำความผิดเกี่ยวกับอาชญากรรมทางเทคโนโลยี, the "CCIB"), the Department of Children and Youth (Thai: กรมกิจการเด็กและเยาวชน, the "DCY") under the Ministry of Social Development and Human Security (Thai: กระทรวงการพัฒนาสังคมและความมั่นคงของมนุษย์, the "MSDHS"), the Office of the Consumer Protection Board (Thai: สำนักงานคณะกรรมการคุ้มครองผู้บริโภค, the "OCPB") under the Office of the Prime Minister, and the Thailand Computer Emergency Response Team (Thai: ศูนย์ประสานการรักษาความมั่นคงปลอดภัยระบบคอมพิวเตอร์ประเทศไทย, the "ThaiCERT") within the National Cyber Security Agency (Thai: สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ, the "NCSA"), under their respective intake protocols.
Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Personal Data Protection Act B.E. 2562 (2019) ("PDPA Thailand") — the principal substantive provisions of the PDPA Thailand were in force from 1 June 2022 following the deferral of the Royal Decree on the Postponement of the Effective Date of Certain Provisions of the Personal Data Protection Act B.E. 2562 (2019) B.E. 2563 (2020) — and any further amendment thereto including any future Personal Data Protection Act (No. 2) B.E. [year] (the § 18 versioning protocol covers their enactment); (b) any amendment to the Six Personal Data Protection Principles at PDPA Thailand Section 21 + Section 22 + Section 24 + Section 26 + Section 27 + Section 37 — lawful basis at Section 24 (consent under Section 19 / performance of contract / legal obligation / vital interest / public interest / legitimate interest / archival or scientific/historical research or statistical purposes / public health) + sensitive personal data at Section 26 (heightened-lawful-basis regime; Balance does NOT process sensitive personal data) + purpose limitation at Section 21 + data quality at Section 37(3) + storage limitation at Section 37(3) + security at Section 37(1) and (2) + transparency at Section 23 + data subject rights at Sections 30-36 + Section 37(4); (c) any Notification, Subordinate Legislation, Rule, Code of Practice, or Determination issued by the PDPC under PDPA Thailand Section 16(5) — including the Notification of the PDPC on Standards of Security Measures B.E. 2565 (2022) (the "PDPC Security Notification 2022"), the Notification of the PDPC on Designation of Data Controllers and Data Processors that are required to appoint a Data Protection Officer B.E. 2565 (2022) (the "PDPC DPO Notification 2022"), the Notification of the PDPC on Personal Data Breach Notification B.E. 2565 (2022) of 14 December 2022 in operation from 13 June 2023 (the "PDPC Breach Notification 2022"), the Notification of the PDPC on Rules and Methods for Records of Processing Activities of the Data Processor B.E. 2565 (2022) (the "PDPC RoPA Notification 2022"), the Notification of the PDPC on Criteria for Sending or Transferring Personal Data to a Foreign Country pursuant to Section 28 B.E. 2566 (2023) of 12 December 2023 in operation from 24 March 2024 (the "PDPC Cross-Border Notification 2023 — Section 28 Adequacy"), the Notification of the PDPC on Standards of Personal Data Protection for the Sending or Transferring of Personal Data Outside the Kingdom pursuant to Section 29 B.E. 2566 (2023) of 12 December 2023 in operation from 24 March 2024 (the "PDPC Cross-Border Notification 2023 — Section 29 Safeguards"), the Notification of the PDPC on Rules and Methods for the Exercise of Data Subject's Rights B.E. 2566 (2023), the Notification of the PDPC on Records of Processing Activities of the Data Controller B.E. 2565 (2022), and any further PDPC subordinate legislation; (d) any decision of the Provincial Court (Thai: ศาลจังหวัด), the Civil Court (Thai: ศาลแพ่ง), the Criminal Court (Thai: ศาลอาญา), the Court of Appeal (Thai: ศาลอุทธรณ์), the Supreme Court of Justice (Thai: ศาลฎีกา) — or the Constitutional Court of the Kingdom of Thailand (Thai: ศาลรัฐธรรมนูญ) — bearing on the PDPA Thailand, on Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 read with the constitutional-jurisprudence right to privacy, or on the established privacy doctrines applied by Thai courts; (e) any amendment to the Child Protection Act B.E. 2546 (2003) (Thai: พระราชบัญญัติคุ้มครองเด็ก พ.ศ. 2546) (the principal Thai child-welfare statute, in force from 30 March 2004) including the Child Protection Act (No. 4) B.E. 2562 (2019) extending child-protection criminal liability; (f) any amendment to the Criminal Code (Thai: ประมวลกฎหมายอาญา) — in particular Section 277 (sexual intercourse with a child under 15 — statutory rape; Section 277/1 enhanced penalty), Section 279 (indecent act on a child under 15), Section 280 (aggravated indecent act on a child under 15), Section 282 (procurement of person under 18 for sexual purposes), Section 283 (procurement by force/threat), Section 284 (trafficking for sexual purpose), Section 285 (aggravated procurement when victim under 15 / under 18), Section 287 (obscene articles), Section 287/1 (child pornography possession — added by Criminal Code Amendment Act (No. 24) B.E. 2558 (2015), in force from 8 April 2015), Section 287/2 (child pornography distribution / dissemination / public exhibition — added by the same Amendment Act), and Section 309-310 (false imprisonment); (g) any amendment to the Computer Crime Act B.E. 2550 (2007) (Thai: พระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. 2550) as amended by Computer Crime Act (No. 2) B.E. 2560 (2017) ("CCA"), in particular Section 5 (unauthorised access to computer system), Section 7 (unauthorised access to computer data), Section 8 (unauthorised interception of computer data), Section 9 (modification or interference with computer data), Section 11 (sending data causing nuisance), Section 14 (entering false data / computer-related fraud / computer-related obscenity / national-security computer-related offences), Section 15 (service-provider liability), Section 16 (unauthorised dissemination of personal images causing damage), Section 18 (powers of investigation), Section 19 (production orders), Section 26 (data-retention obligation for service providers — 90 days minimum, extendible to 2 years on competent-officer order — Balance is NOT a service provider within the scope of the CCA for Thai-resident user data because Balance does not provide a Thai-public-facing communication service within the scope and the parental-control service is a closed family system; § 18 versioning protocol covers any change to the service provider classification); (h) any amendment to the Royal Decree on Operation of Digital Platform Service Business B.E. 2565 (2022) (Thai: พระราชกฤษฎีกาว่าด้วยการประกอบธุรกิจบริการแพลตฟอร์มดิจิทัลที่ต้องแจ้งให้ทราบ พ.ศ. 2565) (the "Digital Platform Services Royal Decree" or "DPS Royal Decree") published in the Royal Gazette on 23 December 2022 and in operation from 21 August 2023 under the Electronic Transactions Act B.E. 2544 (2001) — imposes notification obligations on digital platform service businesses with Thai users above prescribed thresholds (default threshold: annual turnover above THB 1.8 million for natural persons / THB 50 million for legal persons, OR monthly Thai active users above 5,000 — see Notification of the ETDA on Notification of Digital Platform Services Business B.E. 2566 (2023); Balance is below the active-user threshold and is not within the DPS Royal Decree threshold-based notification regime at the Effective date — § 18 versioning protocol covers any threshold breach); (i) any amendment to the Electronic Transactions Act B.E. 2544 (2001) as amended by Electronic Transactions Act (No. 2) B.E. 2551 (2008) + Electronic Transactions Act (No. 3) B.E. 2562 (2019) + Electronic Transactions Act (No. 4) B.E. 2562 (2019); (j) any amendment to the Consumer Protection Act B.E. 2522 (1979) (Thai: พระราชบัญญัติคุ้มครองผู้บริโภค พ.ศ. 2522) as amended (most recently by the Consumer Protection Act (No. 4) B.E. 2562 (2019)), the Direct Sales and Direct Marketing Act B.E. 2545 (2002) (Thai: พระราชบัญญัติขายตรงและตลาดแบบตรง พ.ศ. 2545) as amended by Direct Sales and Direct Marketing Act (No. 3) B.E. 2560 (2017), the Unfair Contract Terms Act B.E. 2540 (1997) (Thai: พระราชบัญญัติว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540), the Civil and Commercial Code (Thai: ประมวลกฎหมายแพ่งและพาณิชย์) — in particular Section 19 (age of majority 20 years), Section 20 (capacity to contract — minor's contract requires the legal representative's consent; an act done by a minor without that consent is voidable), Sections 21-29 (minor capacity provisions), Sections 150-152 (juristic acts) — collectively the principal Thai consumer-protection and contract-capacity statutes; (k) any amendment to the Anti-Trafficking in Persons Act B.E. 2551 (2008) (Thai: พระราชบัญญัติป้องกันและปราบปรามการค้ามนุษย์ พ.ศ. 2551) as amended; (l) any amendment to the Cybersecurity Act B.E. 2562 (2019) (Thai: พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์ พ.ศ. 2562) — Balance is NOT designated as Critical Information Infrastructure (CII) under the Act; § 18 versioning protocol covers any designation; (m) any amendment to a sub-processor's Thai data-handling posture under our sub-processor register; (n) the bringing into force of any post-Effective-date Thai regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex); (o) Thailand's accession to (or domestic implementation of) the Council of Europe Convention 108 / Convention 108+ (Thailand is not currently a party) or any change in the status of the Convention on Cybercrime (Budapest Convention) — Thailand acceded to the Budapest Convention on 17 April 2024, in force for Thailand from 1 August 2024 (§ 18 versioning protocol covers any further protocol accession including the Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence opened for signature 12 May 2022); (p) any amendment to the Anti-Money Laundering Act B.E. 2542 (1999) (Thai: พระราชบัญญัติป้องกันและปราบปรามการฟอกเงิน พ.ศ. 2542) insofar as it engages production orders against data controllers; (q) any Royal Gazette notification by the PDPC under PDPA Thailand Section 28 (adequacy designation of foreign jurisdictions) or under Section 29 (cross-border safeguards), or any Royal Decree of the Office of the Prime Minister under PDPA Thailand Section 6; (r) any amendment to the Mutual Assistance in Criminal Matters Act B.E. 2535 (1992) (Thai: พระราชบัญญัติความร่วมมือระหว่างประเทศในเรื่องทางอาญา พ.ศ. 2535).
Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — Thailand row).
- Children's Privacy Notice § 14 (Country annexes — Thailand row).
- Child Safety Standards § 13 (Country annexes — Thailand row).
- Terms of Service § 19 (Thailand consumer-protection carve-out under the Consumer Protection Act B.E. 2522 (1979) + the Direct Sales and Direct Marketing Act B.E. 2545 (2002) + the Unfair Contract Terms Act B.E. 2540 (1997) + the Civil and Commercial Code — and the Civil and Commercial Code Section 19 for parent contracting capacity).
- Subscription Terms § 20 (Thailand consumer-rights overlay — Consumer Protection Act B.E. 2522 + Direct Sales and Direct Marketing Act B.E. 2545 + Unfair Contract Terms Act B.E. 2540 + Civil and Commercial Code; 7-day right of withdrawal under Direct Sales and Direct Marketing Act B.E. 2545 Section 33 for direct-marketing-defined transactions — application uncertain for online subscription supply outside the direct marketing definition; Balance honors a voluntary 14-day no-questions Google Play Billing refund as market-leading consumer-protection overlay that exceeds the 7-day statutory floor where it would otherwise apply).
- Data Retention & Deletion Policy § 14 (Thailand PDPC complaint route).
- our breach-notification runbook § 9 (Thailand mandatory data-breach-notification route under PDPA Thailand Section 37(4) read with the PDPC Breach Notification 2022 — 72 hours from awareness of a personal data breach, with affected-individual notification on the high-risk-to-rights-and-freedoms threshold).
- our international-transfer pack § 6 (PDPA Thailand Section 28 + Section 29 cross-border-transfer mechanism + the PDPC Cross-Border Notification 2023 — Section 29 Safeguards recommended-form contractual clauses).
This Annex is the canonical Thai-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Thai resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Thai resident a right that this Annex does not, the global Policy governs. The two are read together.
This Annex is drafted in English. The national language of the Kingdom of Thailand under Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 51 (state duty to preserve the national language) + Sections 70-71 (state duties on culture and learning) is Thai (Thai: ภาษาไทย). Thai-language translation of this Annex is queued for the Phase-2 locale rollout per our internal compliance tracker. No translation is statutorily required at the Effective date for the English-language privacy notice to a Thai resident (the PDPA Thailand does not mandate Thai-language notification; PDPC interpretive practice accepts notices in English provided the notice is intelligible to the data subject — and PDPC guidance prefers Thai-language notification for materially-affected Thai-resident data subjects, which Balance will deliver via the Phase-2 locale rollout).
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is Thailand — the unitary kingdom comprising 76 changwat (provinces) plus Bangkok Metropolis (Krung Thep Mahanakhon) as a special administrative area, organised into six conventional regions (Northern / Northeastern / Central / Eastern / Western / Southern). There is no provincial-level data-protection sub-layer that derogates from the PDPA Thailand in respect of Balance's commercial processing (the PDPA Thailand at Section 4 excludes certain state agencies and activities — the House of Representatives, the Senate, the Parliament, the judicial branch acting as such, credit-bureau companies under the Credit Information Business Act, certain national-security activities, mass-media activities, certain personal/family-only processing — but Balance is a commercial data controller and the PDPA Thailand applies in full).
We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.
Where any of the three signals identifies Thailand as the country of residence, this Annex applies, even if the other signals are non-Thai. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.
The PDPA Thailand has explicit territorial reach defined at Section 5 of the PDPA Thailand: the PDPA Thailand applies (i) to a data controller or data processor in the Kingdom of Thailand, irrespective of whether such collection, use, or disclosure of personal data occurs in the Kingdom or not; and (ii) to a data controller or data processor outside the Kingdom of Thailand in case where (a) the activity is to offer goods or services to data subjects in the Kingdom, irrespective of whether the payment is made by the data subject; or (b) the activity is to monitor the data subject's behaviour, where the behaviour takes place in the Kingdom. Balance squarely targets Thai residents through Google Play Thailand, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Thai-resident parents and kids; the PDPA Thailand applies in respect of all personal data Balance processes in connection with Thai-resident users via Section 5(2)(a) (offering services to data subjects in Thailand).
2. Statutory framework — what applies
The Thai personal-data-protection regime is dominated by the Personal Data Protection Act B.E. 2562 (2019) ("PDPA Thailand"), published in the Royal Gazette on 27 May 2019 with phased commencement (institutional provisions from 28 May 2019; the principal substantive provisions originally scheduled for 28 May 2020 were twice deferred by the Royal Decree on the Postponement of the Effective Date of Certain Provisions of the Personal Data Protection Act B.E. 2562 (2019) B.E. 2563 (2020) and finally entered into force on 1 June 2022). The PDPA Thailand is supplemented by the body of PDPC Notifications issued from 2022 onward — most directly relevant the PDPC Security Notification 2022, the PDPC DPO Notification 2022, the PDPC Breach Notification 2022, the PDPC RoPA Notification 2022 (both data-controller and data-processor versions), the PDPC Cross-Border Notification 2023 — Section 28 Adequacy, and the PDPC Cross-Border Notification 2023 — Section 29 Safeguards. Adjacent layers: the Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 (right to privacy) + Section 33 (freedom of dwelling) + Section 34 (freedom of expression) + Section 36 (right to private communication); the Child Protection Act B.E. 2546 (2003); the Criminal Code including Section 287/1 + Section 287/2 (child pornography) + Section 277 + Sections 279-285 (sexual offences against children); the Computer Crime Act B.E. 2550 (2007) as amended; the Digital Platform Services Royal Decree B.E. 2565 (2022); the Electronic Transactions Act B.E. 2544 (2001) as amended; the Cybersecurity Act B.E. 2562 (2019); the Consumer Protection Act B.E. 2522 (1979) as amended; the Direct Sales and Direct Marketing Act B.E. 2545 (2002) as amended; the Unfair Contract Terms Act B.E. 2540 (1997); the Civil and Commercial Code; the Anti-Trafficking in Persons Act B.E. 2551 (2008); the Mutual Assistance in Criminal Matters Act B.E. 2535 (1992); the Anti-Money Laundering Act B.E. 2542 (1999).
| Instrument | Short cite | What it does | Balance's posture |
|---|---|---|---|
| Constitution of the Kingdom of Thailand B.E. 2560 (2017) | Constitution — the supreme law of the Kingdom under Section 5. Section 32 "A person shall enjoy the right of privacy, dignity, reputation and family. An act violating or affecting the right of a person under paragraph one or an exploitation of personal information in any manner whatsoever shall not be permitted, except by virtue of a provision of law enacted only to the extent of necessity for public interest" — the constitutional right to privacy and the constitutional foundation of personal-data protection; Section 33 freedom of dwelling; Section 34 freedom of expression; Section 36 right to private communication; Section 50 state duty to protect children; Section 71 state duty to develop children. | The constitutional anchor. The right to privacy in Thailand is constitutional (Section 32) AND statutory (PDPA Thailand + adjacent regimes). | Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below. |
| Personal Data Protection Act B.E. 2562 (2019) | PDPA Thailand — published in the Royal Gazette on 27 May 2019; principal substantive provisions originally scheduled for 28 May 2020 were twice deferred by the Royal Decree on the Postponement of the Effective Date of Certain Provisions of the Personal Data Protection Act B.E. 2562 (2019) B.E. 2563 (2020) and finally entered into force on 1 June 2022. Chapter I General Provisions (Sections 4-5 — application + extraterritorial reach via Section 5(2) offer-of-services-to-Thai-residents limb + monitoring-behaviour-in-Thailand limb); Chapter II Personal Data Protection Committee (Sections 8-18 — PDPC composition + functions including Section 16(5) issuance of subordinate legislation + Section 16(7) hearing complaints); Chapter III Personal Data Protection with Parts on collection (Sections 19-25), use or disclosure (Sections 27-29), sensitive personal data (Section 26), and the data controller's general obligations (Section 37); Section 19 the consent requirement (express + freely given + specific purpose + clear and easily understandable language + separated from other matters + free of misleading or deceptive design) + Section 19(5) right to withdraw consent at any time with consequences clearly notified; Section 21 the purpose-limitation principle; Section 22 the data-minimisation principle; Section 23 the transparency requirement (notice at collection — purpose / categories / disclosure recipients / contact / retention / data subject rights); Section 24 the alternative lawful bases for non-sensitive personal data (without consent): (1) prevention or suppression of danger to life/body/health; (2) performance of contract; (3) performance of public-mission duty; (4) legitimate interest of controller or third party where data subject's rights are not overridden; (5) compliance with legal obligation; Section 26 the sensitive-personal-data heightened regime — sensitive categories: racial/ethnic origin / political opinions / religious or philosophical beliefs / sexual behaviour / criminal records / health data / disability / trade union information / genetic data / biometric data / any other data which similarly affects the data subject in the same manner as prescribed by the PDPC (Balance does NOT process sensitive personal data of Thai residents); Section 27 the use and disclosure rules (limited to the purpose of collection, with carve-outs); Section 28 the transfer of personal data to a foreign country — adequacy-based mechanism (the country of destination must have adequate standards of personal data protection as designated by the PDPC under PDPC subordinate legislation — the PDPC has not designated any country as adequate at the Effective date); Section 29 the transfer of personal data to a foreign country — safeguards-based mechanism (in the absence of Section 28 adequacy, transfer is permissible on safeguards including: (1) compliance with law / court order; (2) consent of data subject with knowledge of inadequate-protection status; (3) necessity for contract performance; (4) compliance with contract concluded for the benefit of the data subject; (5) prevention of danger to life/body/health where consent cannot be obtained; (6) important public-interest mission; (7) Section 29 paragraph 2 group-of-undertakings binding-corporate-rules-equivalent mechanism approved by the PDPC; Section 29 paragraph 3 controller-to-controller / controller-to-processor contractual safeguards that meet PDPC standards — operationalised by the PDPC Cross-Border Notification 2023 — Section 29 Safeguards of 12 December 2023 in operation from 24 March 2024 — recommended-form contractual clauses + APEC CBPR overlay + ASEAN MCC overlay accepted); Chapter III Part 3 Rights of the Data Subject Sections 30-36 + Section 37(4) — Section 30 right of access including right to copy + right to request disclosure of source of personal data not collected from data subject + 30-day response deadline under PDPC interpretive practice; Section 31 right to data portability (the data subject may request transmission of the personal data to another controller in a structured commonly-used machine-readable format); Section 32 right to object (to processing for direct marketing / for legitimate-interest or public-task processing / for archival or research purposes); Section 33 right to deletion / erasure / destruction or anonymisation (where withdrawal of consent / no longer necessary / unlawful processing); Section 34 right to restriction of processing; Section 35 right to rectification (data must be accurate / current / complete / not misleading); Section 36 right not to be subject to certain decisions based solely on automated processing — Balance does not engage Section 36 in respect of Thai residents (no automated individual decision-making of legal-effect / similarly-significant-effect within the scope of Section 36); Section 37(4) right of complaint to the PDPC; Section 37 the data controller's general duties including (1) provide security measures of personal data sufficient to prevent unauthorised loss / access / use / amendment / correction / disclosure (operationalised by the PDPC Security Notification 2022); (2) erase or destroy personal data when retention period ends or upon request of the data subject or upon withdrawal of consent (subject to other lawful basis); (3) notify the PDPC of any personal data breach without undue delay where feasible within 72 hours from awareness (operationalised by the PDPC Breach Notification 2022); (4) prepare and maintain a Record of Processing Activities (operationalised by the PDPC RoPA Notification 2022 — for data controllers) for inspection by PDPC; (5) appoint a Data Protection Officer where required under Section 41; (6) implement Privacy Impact Assessments where required; Section 39 Records of Processing Activities of the Data Processor; Section 40 Data Processing Agreement requirement between data controller and data processor; Section 41 mandatory Data Protection Officer (DPO) appointment where (1) the data controller or data processor is a public authority; (2) the activity of the data controller or data processor in collection / use / disclosure of personal data requires regular monitoring of personal data or data subjects by reason of the large scale of personal data; (3) the core activity of the data controller or data processor is the collection / use / disclosure of sensitive personal data under Section 26; or otherwise as prescribed by PDPC under the PDPC DPO Notification 2022 + Section 41(3) DPO functions + Section 41(4) DPO publicly-accessible contact requirement; Chapter IV Complaint (Sections 65-72 — PDPC complaint procedure + Expert Committee + powers of inspection + administrative remedies); Chapter V Civil Liability (Sections 77-78 — civil action including punitive damages up to twice the actual damage); Chapter VI Penalties — administrative penalties (Sections 82-90 — administrative fines up to THB 5 million depending on the offence) + criminal penalties (Sections 79-81 — imprisonment up to 1 year and/or criminal fine up to THB 1 million) + the principle that legal-person liability may also engage the natural-person director / manager / officer-in-default. | The principal statute. Applies in full to Balance as a data controller established outside Thailand that targets services to Thai residents (Section 5(2)(a) offer-of-services limb). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below. | |
| Notifications of the Personal Data Protection Committee (2022 – 2023 series) | PDPC Notifications — a series of binding subordinate-legislation instruments issued by the PDPC under PDPA Thailand Section 16(5). Most directly relevant: Notification of the PDPC on Standards of Security Measures B.E. 2565 (2022) of 7 June 2022 in operation from 8 June 2022 ("PDPC Security Notification 2022"); Notification of the PDPC on Designation of Data Controllers and Data Processors that are required to appoint a Data Protection Officer B.E. 2565 (2022) of 14 December 2022 in operation from 13 June 2023 ("PDPC DPO Notification 2022"); Notification of the PDPC on Rules and Methods of Personal Data Breach Notification B.E. 2565 (2022) of 14 December 2022 in operation from 13 June 2023 ("PDPC Breach Notification 2022") — operationalises Section 37(4) personal data breach notification — 72 hours from awareness + minimum-content requirements + affected-individual notification on the high-risk threshold; Notification of the PDPC on Criteria for Sending or Transferring Personal Data to a Foreign Country pursuant to Section 28 B.E. 2566 (2023) of 12 December 2023 in operation from 24 March 2024 ("PDPC Cross-Border Notification 2023 — Section 28 Adequacy") — sets out adequacy assessment criteria (no country designated as adequate at the Effective date); Notification of the PDPC on Standards of Personal Data Protection for the Sending or Transferring of Personal Data Outside the Kingdom pursuant to Section 29 B.E. 2566 (2023) of 12 December 2023 in operation from 24 March 2024 ("PDPC Cross-Border Notification 2023 — Section 29 Safeguards") — recommended-form contractual clauses + intra-group binding-corporate-rules equivalent; Notification of the PDPC on Rules and Methods for Records of Processing Activities of the Data Processor B.E. 2565 (2022) ("PDPC RoPA Notification 2022 — Processor"); Notification of the PDPC on Records of Processing Activities of the Data Controller B.E. 2565 (2022) ("PDPC RoPA Notification 2022 — Controller"); Notification of the PDPC on Rules and Methods for the Exercise of Data Subject's Rights B.E. 2566 (2023) ("PDPC Rights Notification 2023"); and the body of supplementary PDPC guidance circulars. | Sets the PDPC's binding subordinate-legislation interpretive layer on the PDPA Thailand. Applies in full. | |
| Child Protection Act B.E. 2546 (2003) | Child Protection Act — published in the Royal Gazette on 2 October 2003 + in force 30 March 2004. Substantively amended by Child Protection Act (No. 4) B.E. 2562 (2019). Section 4 definitions — child (Thai: เด็ก) means a person below the age of 18 years and includes a person who has not yet been graduated from compulsory schooling; youth defined; parent + legal guardian defined; Section 7 the principle of best interest of the child as the primary consideration; Section 23-25 state duties to protect children; Section 26 prohibited acts including (1) torture / cruelty / inhumane treatment, (2) abandonment, (3) forcing / inducing / supporting / soliciting child to act in a manner that is detrimental to the child's body or mind, (4) forcing / inducing / supporting / soliciting child to commit immoral / harmful acts, (5) commercial sexual exploitation, (6) employment in places of entertainment / gambling / liquor sales, (7) child labour in violation of labour law, (8) using or making child to do acts dangerous to physical or mental health, (9) disclosure of name / photograph / personal information of child or family that could cause damage to the child; Section 27 mandatory reporting by any person who knows of an act of child abuse or who believes a child to be in danger of abuse + immunity from civil and criminal liability for reporting in good faith; Section 41-46 Provincial Child Protection Committee + Child Protection Officer; Section 60-67 penalties (imprisonment up to 5 years + fine up to THB 100,000 for offences against Section 26). | The principal Thai child-welfare statute. Applies. Treatment in § 5 + § 14 below. | |
| Criminal Code (Thailand) | Criminal Code — the principal general criminal statute, promulgated B.E. 2499 (1956) and amended periodically. Substantive sections relevant to Balance's child-safety + lawful-access posture: Section 277 sexual intercourse with a child under 15 — statutory rape (imprisonment 4-20 years + fine), aggravated penalty if under 13 (imprisonment 7-20 years or life); Section 277/1 enhanced penalty in aggravated circumstances; Section 278 indecent act on a person (imprisonment up to 10 years + fine); Section 279 indecent act on a child under 15 (imprisonment up to 10 years + fine, aggravated if under 13); Section 280 aggravated indecent act on a child under 15 (imprisonment up to 15 years + fine); Section 282 procurement of person under 18 for sexual purposes (imprisonment 5-20 years + fine); Section 283 procurement by force / threat (imprisonment 7-20 years or life); Section 283 bis procurement of person under 18 for departure / for sexual purposes (heightened penalty); Section 284 taking of person under 18 for sexual purposes; Section 285 aggravated procurement when victim under 15 / under 18 (heightened penalty); Section 287 the obscene-articles offence — production / possession / distribution / public exhibition of obscene articles (imprisonment up to 3 years + fine); Section 287/1 the child-pornography possession offence — possession of child pornography for the purpose of sexual gratification of self or others (imprisonment up to 5 years + fine up to THB 100,000) — added by Criminal Code Amendment Act (No. 24) B.E. 2558 (2015) in force 8 April 2015; Section 287/2 the child-pornography distribution offence — distribution / dissemination / public exhibition of child pornography (imprisonment up to 7 years + fine up to THB 140,000) — added by the same Amendment Act; Section 309 false imprisonment; Section 310 false imprisonment for benefit. | Applies. Treatment in § 14 below. | |
| Computer Crime Act B.E. 2550 (2007) as amended by Computer Crime Act (No. 2) B.E. 2560 (2017) | CCA — published in the Royal Gazette on 18 June 2007 + in force 19 July 2007; amended substantively by Computer Crime Act (No. 2) B.E. 2560 (2017) in force 24 May 2017. Section 5 unauthorised access to a computer system; Section 7 unauthorised access to computer data; Section 8 unauthorised interception of computer data; Section 9 modification or interference with computer data without authorisation; Section 10 interference with the functioning of computer systems; Section 11 sending data causing nuisance to the recipient; Section 14 entering false / forged / false-impression / national-security-threatening / obscenity-related computer data + computer-related fraud + computer-related dissemination of obscene material; Section 15 service-provider liability for content visible on service provider's system where service provider has knowledge and fails to remove; Section 16 unauthorised dissemination of personal images that damages reputation or causes shame; Section 17 offences committed outside Thailand may be punishable; Section 18 powers of the competent officer to issue summons / examine / search / seize / order disclosure / order production of computer data; Section 19 procedure for production orders requiring court approval; Section 20 order to block / remove computer data on court order; Section 26 mandatory data retention for service providers — 90 days minimum, extendible to 2 years on competent-officer order — defining service provider by reference to the Ministry of Information and Communication Technology Notification on Categories of Service Providers (now under the Ministry of Digital Economy and Society). Balance is NOT a service provider within the scope of Section 26 for Thai-resident user data because Balance does not provide a Thai-public-facing communication service within the scope and the parental-control service is a closed family system not within the service provider categories prescribed by the MDES Notification — § 18 versioning protocol covers any change to the categorisation. | The principal Thai cybercrime statute. Applies. Treatment in § 13 below. | |
| Royal Decree on Operation of Digital Platform Service Business B.E. 2565 (2022) | Digital Platform Services Royal Decree (DPS Royal Decree) — published in the Royal Gazette on 23 December 2022 and in operation from 21 August 2023 under the Electronic Transactions Act B.E. 2544 (2001) Section 32. The DPS Royal Decree imposes (a) a notification obligation on every digital platform service business before commencement of services to Thai users; (b) heightened obligations on digital platform services with significant impact (categorised by user numbers / turnover thresholds / risk indicators); (c) child-safety and consumer-protection obligations on platforms. The DPS Royal Decree is administered by the Electronic Transactions Development Agency (Thai: สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์, the "ETDA") under the Notification of the ETDA on Notification of Digital Platform Services Business B.E. 2566 (2023) of 16 August 2023. Default threshold for notification: annual turnover above THB 1.8 million (natural persons) / THB 50 million (legal persons), OR monthly Thai active users above 5,000. Balance is below the active-user threshold and is not within the DPS Royal Decree threshold-based notification regime at the Effective date — § 18 versioning protocol covers any threshold breach. The DPS Royal Decree's child-safety standards are voluntarily honoured by Balance's substantive product posture (no advertising directed at children + no behavioural-advertising profile + no content-recommendation surface + Verifiable Parental Consent regardless of age + end-to-end-encrypted proof-media payload). | Applies as a context-setting fact (Balance below notification threshold). Treatment in § 12 + § 13 below. | |
| Electronic Transactions Act B.E. 2544 (2001) as amended | ETA — published in the Royal Gazette on 4 December 2001 + in force 3 April 2002; amended by Electronic Transactions Act (No. 2) B.E. 2551 (2008) + Electronic Transactions Act (No. 3) B.E. 2562 (2019) + Electronic Transactions Act (No. 4) B.E. 2562 (2019). Section 8-13 legal recognition of electronic transactions and electronic signatures; Section 32 Royal Decree powers (basis for the Digital Platform Services Royal Decree B.E. 2565 (2022) and other Royal Decrees on specific electronic-transaction regulation); Section 35 information security in electronic transactions. | The principal Thai electronic-transactions statute. Applies. Treatment in § 16 below. | |
| Cybersecurity Act B.E. 2562 (2019) | Cybersecurity Act — published in the Royal Gazette on 27 May 2019 + in force 28 May 2019. Establishes the National Cyber Security Committee + the National Cyber Security Agency (NCSA) + the Critical Information Infrastructure (CII) regime applicable to designated CII operators. Cybersecurity-incident notification obligations on CII operators. Balance is NOT designated as Critical Information Infrastructure under the Act; § 18 versioning protocol covers any designation. Voluntary cooperation with ThaiCERT (the national CERT within NCSA) is honoured as a best-effort security overlay. | Applies as a context-setting fact (Balance not designated as CII). Treatment in § 13 below. | |
| Consumer Protection Act B.E. 2522 (1979) as amended | CPA Thailand — published in the Royal Gazette on 4 May 1979 + in force 5 May 1979. Substantively amended by Consumer Protection Act (No. 2) B.E. 2541 (1998) + Consumer Protection Act (No. 3) B.E. 2556 (2013) + Consumer Protection Act (No. 4) B.E. 2562 (2019). Chapter I General Provisions + definition of consumer (Section 3) + definition of business operator; Chapter II Consumer Protection Committee (Sections 9-15); Chapter III Consumer Protection in Advertising (Sections 22-29 — prohibition on misleading or unfair advertising); Chapter III/1 Consumer Protection on Labelling; Chapter III/2 Consumer Protection on Contracts — Controlled Contract Business + Controlled List of Terms + mandatory contract-content rules + prohibition on unfair terms (Sections 35 bis - 35 nawa); Chapter IV complaint and remedy procedure including the Office of the Consumer Protection Board (OCPB) administrative-action route; Chapter V Class Action (introduced by amendment) + collective remedies; Chapter VI Penalties. Enforced by the Office of the Consumer Protection Board (OCPB) under the Office of the Prime Minister + the Consumer Protection Committee. | The principal Thai consumer-protection statute. Applies in full. Treatment in § 16 below. | |
| Direct Sales and Direct Marketing Act B.E. 2545 (2002) as amended | DSDMA — published in the Royal Gazette on 30 April 2002 + in force 31 August 2002. Amended by Direct Sales and Direct Marketing Act (No. 3) B.E. 2560 (2017). Section 3 definitions — direct marketing means an act of marketing goods or services in a manner that uses any media of communication to communicate with consumers directly so that the consumer responds in order to purchase the goods or services from the business operator; direct sales defined separately; Section 27 registration requirements for direct-sales operators; Section 28 registration requirements for direct-marketing operators (with carve-outs for de-minimis activities); Section 33 the seven-day right of withdrawal — a consumer who purchases goods or services from a direct sales or direct marketing operator has the right to terminate the contract by giving written notice to the business operator within 7 days from the date of receiving the goods or the date of agreeing to receive the services (the "7-Day Right"); Section 34 the manner of exercise + refund obligations + return obligations. The DSDMA's application to online subscription supply outside the direct marketing definition is uncertain — the direct marketing concept turns on the active-outbound-solicitation element. Where the consumer affirmatively initiates the transaction via the Google Play Store listing (as for Balance), the DSDMA application is contested in Thai legal commentary. Balance honors a voluntary 14-day no-questions Google Play Billing refund as market-leading consumer-protection overlay that exceeds the 7-Day Right where it would otherwise apply. | Applies (uncertain scope for online subscription supply outside direct marketing definition; Balance's voluntary 14-day refund exceeds the 7-Day Right). Treatment in § 16 below. | |
| Unfair Contract Terms Act B.E. 2540 (1997) | UCTA Thailand — published in the Royal Gazette on 15 November 1997 + in force 15 May 1998. Section 4 unfair-terms screen for standard-form / consumer / employment / lease / installment / loan / security contracts — a term that imposes an excessive burden on a party against the other, contrary to good faith / good conscience / fairness, is unenforceable to the extent of the excessive burden, with court power to determine the appropriate scope. Section 5 exclusion / limitation of liability for personal-injury or willful / gross-negligence harm is unenforceable. Section 6 specific examples of unfair terms in standard-form contracts. Section 7 evidentiary unfair terms. Section 8 liability exclusion for goods or services not directly known to the relevant party. Section 9 factors for the unfair-terms assessment (bargaining power / extent of negotiation / knowledge / nature of supply / market alternative / good faith / good conscience). Section 10 other relevant matters. | The principal Thai unfair-contract-terms statute. Applies in full. Treatment in § 16 below. | |
| Civil and Commercial Code | CCC — the principal Thai civil and commercial statute, promulgated B.E. 2466-2477 (1923-1934) with frequent amendment. Section 19 age of majority — 20 years (a person attains majority on completion of 20 years of age) — but a minor of any age becomes sui juris on marriage validly concluded after attaining 17 years (Section 20); Section 21 capacity to contract — a juristic act done by a minor must obtain consent of the legal representative (parent / guardian); a juristic act done without such consent is voidable, except for acts that are merely beneficial to the minor / suitable to the minor's condition / appropriate to ordinary household life of the minor — applied to minor's contracts in Decisions of the Supreme Court of Justice (Dika Court) Nos. 1287/2493, 2168/2515, et seq.; Sections 22-28 further minor-capacity rules; Section 29 ratification by minor on attaining majority; Sections 145-152 juristic acts; Section 154 invalidating elements; Sections 1546-1567 parental power (Thai: อำนาจปกครอง) — the parent's general authority over the minor child; Sections 1568-1571 specific powers of legal representation; Section 1574 restriction on certain acts (sale/exchange/mortgage/lease of real property / business; gift; renunciation) without court approval. | Applies. Treatment in § 16 below. | |
| Anti-Trafficking in Persons Act B.E. 2551 (2008) as amended | Anti-Trafficking in Persons Act — published in the Royal Gazette on 6 February 2008 + in force 5 June 2008. Amended by Anti-Trafficking in Persons Act (No. 2) B.E. 2558 (2015) + Anti-Trafficking in Persons Act (No. 3) B.E. 2560 (2017). Section 4 definitions — trafficking in persons + exploitation including child labour exploitation + sexual exploitation; child means a person below 18 years for the purposes of this Act. Section 6 the principal trafficking offence (imprisonment 6-12 years + fine; heightened penalty for child victim — imprisonment 8-15 years or 10-20 years or life depending on aggravating factors). Section 11 assisting / aiding trafficking. Section 13-14 corporate liability. Section 27 the multi-disciplinary team approach to victim assistance. Enforced by the Department of Special Investigation (DSI) under the Ministry of Justice + the Anti-Trafficking in Persons Division of the Royal Thai Police + the Ministry of Social Development and Human Security (MSDHS). | Applies. Treatment in § 14 below. | |
| Mutual Assistance in Criminal Matters Act B.E. 2535 (1992) | MACMA Thailand — the principal Thai foreign-state-cooperation statute in criminal matters. Channelled through the Central Authority at the Office of the Attorney General (Thai: สำนักงานอัยการสูงสุด). Bilateral mutual legal assistance treaties with the United States (signed 19 March 1986, in force 10 June 1993), Australia, Canada, France, Germany, Republic of Korea, the United Kingdom, and other states. | Applies. Treatment in § 13 below. | |
| Anti-Money Laundering Act B.E. 2542 (1999) as amended | AMLA Thailand — published in the Royal Gazette on 19 April 1999 + in force 19 August 1999. Amended substantively by Anti-Money Laundering Act (No. 5) B.E. 2558 (2015). The principal Thai anti-money-laundering statute. Enforced by the Anti-Money Laundering Office (Thai: สำนักงานป้องกันและปราบปรามการฟอกเงิน, the "AMLO"). Relevant insofar as it engages production orders against data controllers. | Applies. Treatment in § 13 below. | |
| EU adequacy | None. Thailand does not hold an EU adequacy decision under GDPR Article 45 at the Effective date. EU/EEA → Thailand transfers are governed by EU SCCs + Transfer Impact Assessment. | Cross-reference in EU / EEA annex § 8. | The absence of EU adequacy does not affect Balance's posture because Balance has no Thai data residency (the backend is in the US — see § 9 below). |
| Convention 108 / Convention 108+ | Not applicable. Thailand is not a party to the Council of Europe Convention 108 or Convention 108+. | Applies as a context-setting fact. Treatment in § 8 below. | |
| APEC Cross-Border Privacy Rules (CBPR) | Thailand is an APEC participating economy since the founding of APEC in 1989. Thailand is not currently an APEC CBPR participating economy at the Effective date (Thailand has indicated interest but has not formally joined the operational CBPR system) — § 18 versioning protocol covers any change. | Applies as a context-setting fact. The Balance principal operational mechanism for Thailand-to-third-country transfers remains the PDPA Thailand Section 29 paragraph 3 contractual-safeguards framework + the PDPC Cross-Border Notification 2023 — Section 29 Safeguards. | |
| ASEAN Framework on Personal Data Protection (2016) | The ASEAN Framework on Personal Data Protection adopted by the ASEAN Telecommunications and IT Ministers in November 2016 + the ASEAN Data Management Framework + the ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021). Thailand is a signatory and supportive member. | Applies as a context-setting fact. The ASEAN Model Contractual Clauses provide an alternative contractual-protection overlay route used in this Annex's transfer pack at § 8 below. | |
| Budapest Convention on Cybercrime | Applicable. Thailand acceded to the Convention on Cybercrime (Budapest Convention) on 17 April 2024 and the Convention entered into force for Thailand on 1 August 2024. The Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence (opened for signature 12 May 2022) — Thailand's accession to the Second Additional Protocol is pending; § 18 versioning protocol covers any change. | Applies as a context-setting fact. Cross-border lawful-access for Thailand is now via the Budapest Convention 24/7 point of contact + Article 25 + Article 27 spontaneous-information-sharing channels, in addition to the Mutual Assistance in Criminal Matters Act B.E. 2535 (1992) + bilateral MLATs. |
(Any prospective Thai regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date PDPC Notification in that area, the Thailand AI Ethics Guidelines (issued by the Ministry of Digital Economy and Society in March 2022, voluntary best-practice guidance only), the National AI Strategy and Action Plan 2022–2027, the Royal Decree on Artificial Intelligence Systems (draft before the Council of State; not enacted at the Effective date), any future Thai primary legislation on artificial intelligence before the House of Representatives / Senate, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Thai regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)
3. Supervisory authorities
3.1 PDPC — Personal Data Protection Committee + PDPC Office
The principal supervisory authority is the Personal Data Protection Committee (Thai: คณะกรรมการคุ้มครองข้อมูลส่วนบุคคล, the "PDPC"), the regulatory committee established under PDPA Thailand Section 8 with the Office of the Personal Data Protection Committee (Thai: สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล, the "PDPC Office") as its operational arm. The PDPC sits within the Ministry of Digital Economy and Society (Thai: กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม, the "MDES"). The PDPC's composition under Section 8 includes the Chairperson selected by a Selection Committee, plus ex-officio members and qualified members. The PDPC has investigative + enforcement + regulatory + recommendatory powers under PDPA Thailand Sections 14-18 + Sections 65-72. The PDPC's decisions are appealable to the Administrative Court of Thailand (Thai: ศาลปกครอง) under the Establishment of Administrative Courts and Administrative Court Procedure Act B.E. 2542 (1999).
| Field | Value |
|---|---|
| Name | Office of the Personal Data Protection Committee (Thai: สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล) |
| Parent ministry | Ministry of Digital Economy and Society (กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม, MDES) |
| Headquarters | 120 Mueang Thong Thani, Chaengwattana Road, Pak Kret District, Nonthaburi 11120, Thailand |
| Website | https://www.pdpc.or.th/ (Thai) — English landing page available |
| Complaint channel | PDPC Office online complaint portal accessible from https://www.pdpc.or.th/ (complaint form via the e-Service portal); email pdpc@pdpc.or.th |
| Phone | +66 2 142 1033 |
| Data-Breach-Notification channel | PDPC Office online Personal Data Breach Notification portal per PDPA Thailand Section 37(4) + the PDPC Breach Notification 2022 — 72-hour notification from awareness of personal data breach. |
| PDPC Chairperson | At the Effective date — published at https://www.pdpc.or.th/ |
The PDPC is the first-line forum for any PDPA-Thailand-grounded complaint from any Thai resident. A Thai resident may petition the PDPC after first raising the matter with Balance (the PDPC's published procedure recommends raising the matter with the data controller first, but the PDPC also accepts direct complaints). We accept all data subject access / privacy enquiries at (named individual: , in his capacity as the DPO under PDPA Thailand Section 41 + the PDPC DPO Notification 2022) and respond within the PDPA Thailand timelines (see § 6 below).
A Thai resident may also pursue private remedies via (i) the PDPA Thailand Chapter V civil liability under Sections 77-78 (including punitive damages up to twice the actual damage); (ii) Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 constitutional-rights cause of action read with constitutional-court jurisprudence on the right to privacy + Section 213 individual constitutional complaint to the Constitutional Court (in connection with state action); (iii) common-law-equivalent privacy doctrine as recognised by Thai courts including the line of Dika Court (Supreme Court) decisions on tort-based privacy remedies under CCC Sections 420 + 421 + 423; (iv) the PDPA Thailand Chapter VI penalty regime which may be the subject of criminal complaint to the Royal Thai Police + the Public Prosecutor.
3.2 Ministry of Digital Economy and Society — PDPC Office parent ministry
The Ministry of Digital Economy and Society (Thai: กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม, the "MDES") is the parent ministry of the PDPC Office. The Minister of Digital Economy and Society is the responsible minister for the PDPA Thailand and for the issuance of Royal Decrees and Ministerial Regulations under the PDPA Thailand.
| Field | Value |
|---|---|
| Name | Ministry of Digital Economy and Society (กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม, MDES) |
| Headquarters | The Government Complex Commemorating His Majesty the King's 80th Birthday Anniversary 5th December B.E. 2550 (2007), Building B, 6th-9th Floor, Chaengwattana Road, Thung Song Hong, Lak Si, Bangkok 10210, Thailand |
| Website | https://www.mdes.go.th/ |
| Phone | +66 2 141 6747 |
3.3 Other regulatory bodies
| Body | Subject matter | URL |
|---|---|---|
| Electronic Transactions Development Agency (ETDA) — สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์ | Electronic Transactions Act + Digital Platform Services Royal Decree B.E. 2565 (2022) administration | https://www.etda.or.th/ — +66 2 123 1234 |
| National Cyber Security Agency (NCSA) / ThaiCERT — สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ | Cybersecurity Act administration + national CERT | https://www.ncsa.or.th/ — ThaiCERT at https://www.thaicert.or.th/ |
| Royal Thai Police (RTP) — Thailand Internet Crimes Against Children Task Force (TICAC) | CSAE investigation including online grooming + child pornography | via RTP https://www.royalthaipolice.go.th/ — Emergency 191 |
| Royal Thai Police — Cybercrime Investigation Bureau (CCIB) | Cybercrime investigation including online CSAE | https://www.tcsd.go.th/ — Emergency 191 |
| Royal Thai Police — Anti-Trafficking in Persons Division (ATPD) | Anti-Trafficking in Persons Act B.E. 2551 (2008) | via RTP https://www.royalthaipolice.go.th/ |
| Department of Special Investigation (DSI) — กรมสอบสวนคดีพิเศษ | Special-case investigation including transnational CSAE | https://www.dsi.go.th/ |
| Department of Children and Youth (DCY) — กรมกิจการเด็กและเยาวชน | Child Protection Act 2546 (2003) — child-welfare lead agency | https://www.dcy.go.th/ |
| Ministry of Social Development and Human Security (MSDHS) — กระทรวงการพัฒนาสังคมและความมั่นคงของมนุษย์ | DCY parent ministry; Hotline 1300 national social-welfare hotline | https://www.msociety.go.th/ — Hotline 1300 |
| Office of the Consumer Protection Board (OCPB) — สำนักงานคณะกรรมการคุ้มครองผู้บริโภค | Consumer Protection Act 1979 + Direct Sales and Direct Marketing Act 2545 (2002) | https://www.ocpb.go.th/ — Hotline 1166 |
| Office of the Attorney General (OAG) — สำนักงานอัยการสูงสุด | Public prosecution; Central Authority for Mutual Assistance in Criminal Matters | https://www.ago.go.th/ |
| Administrative Court of Thailand — ศาลปกครอง | Administrative review of PDPC decisions | https://www.admincourt.go.th/ |
| Constitutional Court of the Kingdom of Thailand — ศาลรัฐธรรมนูญ | Constitutional review under Section 213 | https://www.constitutionalcourt.or.th/ |
| National Human Rights Commission of Thailand (NHRCT) — คณะกรรมการสิทธิมนุษยชนแห่งชาติ | Independent human-rights commission | https://www.nhrc.or.th/ |
| Office of the Ombudsman of Thailand — สำนักงานผู้ตรวจการแผ่นดิน | Ombudsman investigation of state-agency action | https://www.ombudsman.go.th/ |
| Thai Hotline (Internet Foundation for the Development of Thailand) | INHOPE-member CSAM hotline | https://www.thaihotline.org/ |
| ChildLine Thailand Foundation — มูลนิธิสายเด็ก | Children's helpline NGO | https://www.childlinethailand.org/ — Hotline 1387 |
| ECPAT Foundation Thailand — มูลนิธิเอกพัตร | CSAE prevention NGO | https://www.ecpat-thailand.org/ |
| Hug Project Thailand | CSAE survivor support + prevention | https://www.hugproject.org/ |
| Samaritans of Thailand | Emotional support hotline | https://www.samaritansthai.com/ — Hotline +66 2 713 6793 (English/Thai) |
| Childline 1387 | Toll-free 24/7 children's helpline operated by ChildLine Thailand Foundation | dial 1387 (toll-free within Thailand) |
| MSDHS Hotline 1300 | 24/7 social-welfare hotline (children + women + family-violence) operated by MSDHS | dial 1300 (toll-free within Thailand) |
| OCPB Hotline 1166 | 24/7 consumer-protection hotline operated by OCPB | dial 1166 (toll-free within Thailand) |
3.4 The DPO
PDPA Thailand Section 41 (in force from 1 June 2022) + the PDPC DPO Notification 2022 of 14 December 2022 in operation from 13 June 2023 require every data controller and data processor falling within the Section 41 criteria to appoint a Data Protection Officer (DPO). The criteria include (3) the core activity of the data controller or data processor is the collection / use / disclosure of sensitive personal data under Section 26 — although Balance does NOT process sensitive personal data of Thai residents, the PDPC DPO Notification 2022 explicitly references processing of personal data of children as a category warranting DPO designation on the most-protective reading; Balance's processing of children's personal data of Thai-resident kids accordingly engages the DPO mandate on the most-protective reading and Balance appoints a DPO. The DPO must be readily accessible, must be reachable by data subjects and by the PDPC, and the DPO's contact details must be publicly available under Section 41(4).
The Balance DPO is:
- , Director, BabaYaga Program, TOO —
.
The DPO's business contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying PDPA Thailand Section 41(4) + the PDPC DPO Notification 2022. The DPO is the contact point for the PDPC on any regulatory matter and for data subjects on rights-exercise matters. The DPO need not be a Thai citizen or resident but must be readily accessible during Thai business hours per the PDPC DPO Notification 2022.
4. Lawful bases — PDPA Thailand Section 19 (consent) + Section 24 (alternative bases) + Section 26 (sensitive-data carve-out)
The PDPA Thailand is a consent-and-purpose-limitation regime modulated by the Section 24 alternative-bases catalogue (performance of contract / legal obligation / vital interest / public-task / legitimate interest). Balance processes personal data of Thai residents on the following PDPA Thailand mapping:
| Processing purpose | PDPA Thailand basis | Cross-reference |
|---|---|---|
| Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) | Section 19 parent's consent given for the specific and lawful purpose + Section 24(3) performance-of-contract necessity + Section 23 transparency notice + Section 21 purpose limitation + Section 22 data minimisation + Section 37(1)/(2) security | H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex |
| Process the kid's personal data | Section 19 parent's consent given on behalf of the kid under CCC Section 21 minor-capacity doctrine + Section 1566 parental power + CCC Section 1571 specific legal representation + the PDPC Notification on Children's Data (forthcoming subordinate legislation queued under PDPA Thailand Section 20 — § 18 versioning protocol) + Section 23 + Section 24(3) | § 7 of this Annex; our Data Protection Impact Assessment § 6 |
| Deliver operational alerts | Section 19 + Section 23 (primary purpose) | H1 § 4; H7 PA-09; M3 |
| Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access | Section 37(1) security obligation + PDPC Security Notification 2022 + Section 24(2) (legitimate interest of controller) + Section 24(4) (compliance with legal obligation) + Section 24(1) (vital interest of data subject) | H7 PA-15; § 13 below |
| Comply with legal, regulatory, and supervisory obligations | Section 24(4) (necessary for compliance with any legal obligation to which the controller is the subject) | § 13 below; M1; § 14 below |
| Process Verifiable Parental Consent for the kid's data | Section 19 + Section 23 — collection of the parent's personal data for the primary purpose of obtaining VPC | § 7 of this Annex; A-US § 5 |
| Process the parent's billing / subscription data | Section 24(3) performance-of-contract necessity; CPA Thailand + DSDMA + UCTA + CCC consumer-protection overlay in § 16 below | H4; § 16 below |
Balance does not process sensitive personal data under PDPA Thailand Section 26 (categories: racial or ethnic origin / political opinions / religious or philosophical beliefs / sexual behaviour / criminal records / health data / disability / trade-union information / genetic data / biometric data / other data which similarly affects the data subject in the same manner as prescribed by the PDPC) in respect of any Thai resident.
Balance does not collect any Thai national or government-issued identification number — neither the Thai national ID number (13-digit number issued under the Civil Registration Act B.E. 2534 (1991)) nor the passport number (issued under the Royal Thai Police Passport Regulations) nor the driver's licence number (issued under the Land Traffic Act B.E. 2522 (1979)). PDPC interpretive practice on collection of the Thai national ID number imposes strict purpose-limitation; Balance's posture aligns: none collected.
5. Children's rights overlay
Thailand does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the PDPA Thailand + the PDPC Notification on Children's Data (subordinate legislation queued under Section 20 — § 18 versioning protocol covers issuance); (ii) the Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 right to privacy + Section 50 state duty to protect children + Section 71 state duty to develop children; (iii) the Child Protection Act B.E. 2546 (2003); (iv) the Criminal Code child-sexual-offences chapter at Sections 277-285 + Section 287/1 + Section 287/2; (v) the Civil and Commercial Code Section 19 age of majority 20 + Section 21 minor-incapacity doctrine + Sections 1546-1574 parental power; (vi) the UN Convention on the Rights of the Child (Thailand acceded on 27 March 1992, with limited declarations subsequently withdrawn or modified) + the Optional Protocol on the Sale of Children, Child Prostitution and Child Pornography (Thailand acceded on 11 January 2006).
5.1 Definitions
For the purposes of this Annex:
- Child (under Child Protection Act B.E. 2546 (2003)): a person below the age of 18 years (Child Protection Act Section 4).
- Child for the purposes of the Criminal Code child-pornography offences (Sections 287/1 + 287/2): a person below the age of 18 years.
- Minor (under CCC Section 19): a person who has not attained the age of 20 years (a person attains majority at the completion of 20 years of age; subject to Section 20 marriage-on-attaining-17-years majority).
- Age of sexual consent (per Criminal Code Section 277): 15 years (statutory-rape elements engage for sexual intercourse with a person under 15 regardless of consent; under 13 attracts heightened penalty).
- Age of digital consent under PDPA Thailand: the PDPA Thailand at the Effective date does not set a single numerical age of digital consent; the PDPC Notification on Children's Data (forthcoming subordinate legislation queued under Section 20) is expected to operationalise the children's-data regime. PDPC interpretive practice treats persons below 20 (the CCC age of majority) as requiring parental consent for the processing of personal data for online services directed at minors, subject to maturity-based exceptions for older adolescents. Balance applies the most-protective reading and obtains parental consent regardless of the child's age.
5.2 Verifiable Parental Consent (VPC) for Thai kids
Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Thai kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Thai residents itemises the categories of personal data being processed, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the PDPA Thailand + Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 + the established Thai privacy doctrine.
5.3 No kid-self-serve consent path
Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of the PDPA Thailand + the forthcoming PDPC Notification on Children's Data + the CCC Section 21 minor-incapacity doctrine + the Child Protection Act B.E. 2546 (2003).
5.4 No advertising directed at children
Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising data file of any user. This is consistent with: (i) the PDPA Thailand Section 32 right to object to direct-marketing processing; (ii) the Direct Sales and Direct Marketing Act B.E. 2545 (2002); (iii) the Consumer Protection Act B.E. 2522 (1979) Chapter III prohibition on misleading advertising — including Section 22 prohibition on advertising that is unfair to consumers + Section 23 prohibition on advertising that may cause harm to the consumer + Section 27 prohibition on advertising directed at children that exploits children's lack of experience; (iv) the Child Protection Act B.E. 2546 (2003) Section 26(4) prohibition on inducing children to act in a manner detrimental to body or mind. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.
5.5 Cooperation routes
The principal Thai child-protection bodies are: (i) the Department of Children and Youth (DCY) within the MSDHS — the principal child-welfare lead agency under Child Protection Act B.E. 2546 (2003); (ii) MSDHS Hotline 1300 24/7 national social-welfare hotline; (iii) the Royal Thai Police TICAC + the Royal Thai Police CCIB + the Royal Thai Police Anti-Trafficking in Persons Division; (iv) the Department of Special Investigation (DSI) for transnational CSAE; (v) the ChildLine Thailand Foundation — Hotline 1387 24/7 children's helpline; (vi) the Thai Hotline (Internet Foundation for the Development of Thailand) — INHOPE-member CSAM hotline; (vii) the ECPAT Foundation Thailand — CSAE prevention NGO; (viii) the Hug Project Thailand — CSAE survivor support; (ix) the Samaritans of Thailand — emotional-support hotline; (x) the National Human Rights Commission of Thailand (NHRCT). Balance cooperates with each on incidents involving Thai kids — see § 14 below.
6. PDPA Thailand rights catalogue
6.1 The rights catalogue
A Thai resident has the following rights under the PDPA Thailand + the PDPC Rights Notification 2023 as in force at the Effective date.
- PDPA Thailand Section 23 — Right to be informed. Notice at collection — purposes / categories / disclosure recipients / contact / retention / data subject rights. Honored at the privacy notice in this Annex + at
+ in-app at sign-up. - PDPA Thailand Section 30 — Right of access. A data subject may request access to and a copy of the personal data of the data subject that is in the controller's possession and request disclosure of the acquisition of the personal data without the consent of the data subject. Honored in-app at Settings → Family → [kid name] → "Export this kid's data". Format: machine-readable JSON archive, with a plain-language English summary; Thai summary queued for Phase-2 locale rollout. Response window: 30 days under PDPC interpretive practice + the PDPC Rights Notification 2023.
- PDPA Thailand Section 31 — Right to data portability. A data subject may request the controller to send or transfer personal data to another data controller in a structured, commonly used, and machine-readable format, where the controller has automated such personal data and the controller is processing on a Section 24(3) performance-of-contract / Section 19 consent basis. Honored at
+ via the in-app "Export this kid's data" affordance. - PDPA Thailand Section 32 — Right to object. A data subject may object at any time to the processing of personal data including (a) processing for direct marketing purposes, (b) processing on a Section 24(2) legitimate-interest basis or a Section 24(3) public-task basis, (c) processing for archival / scientific or historical research / statistical purposes. Honored at
. - PDPA Thailand Section 33 — Right to deletion / erasure / destruction or anonymisation. A data subject may request the controller to delete / destroy or anonymise the personal data where (a) the personal data is no longer necessary for the purposes for which it was collected / used / disclosed; (b) the data subject withdraws consent and there is no other lawful basis; (c) the data subject objects to the processing and there is no overriding legitimate ground; (d) the processing is unlawful. Honored in-app at Settings → Account → "Delete account" + via
. - PDPA Thailand Section 34 — Right to restriction of processing. A data subject may request the controller to suspend / restrict processing in specified circumstances. Honored at
. - PDPA Thailand Section 35 — Right to rectification. A data subject may request the controller to ensure that personal data is accurate / current / complete / not misleading. Honored at
. - PDPA Thailand Section 36 — Right not to be subject to certain decisions based solely on automated processing. (n/a — Balance does not engage Section 36 in respect of Thai residents.)
- PDPA Thailand Section 19(5) — Right to withdraw consent. Honored in-app at Settings → Account → "Delete account" + via
. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. - PDPA Thailand Section 37(4) — Right of complaint to the PDPC. A data subject may file a complaint with the PDPC at the PDPC Office complaint portal or by email at
pdpc@pdpc.or.th. The PDPC may open an investigation, issue an administrative order, or refer the matter to the Public Prosecutor for criminal action. - PDPA Thailand Chapter V civil liability — Sections 77-78. Civil action including punitive damages up to twice the actual damage. Filed in the Civil Court / Provincial Court of competent jurisdiction.
- Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 constitutional-rights remedy. Section 213 individual constitutional complaint to the Constitutional Court in connection with state action; common-law-equivalent privacy doctrine under CCC Sections 420 + 421 + 423 in tort.
6.2 Timeline
- Section 30 access: 30 days from receipt of the data access request, extendable in PDPC interpretive practice where the request is complex.
- Section 31 data portability: 30 days from receipt of the request.
- Section 32 right to object: the controller must cease processing for the objected purpose unless there is an overriding compelling legitimate ground; response within 30 days.
- Section 33 deletion / erasure: 30 days.
- Section 34 restriction: 30 days.
- Section 35 rectification: 30 days.
- Section 19(5) withdrawal of consent: as soon as practicable, in any event within 30 days.
- PDPC complaint: the PDPC Office's published target is to conduct an initial assessment within 30 days + an in-depth investigation thereafter; complex matters may take longer.
Where the data-access carve-outs at PDPA Thailand Section 30 paragraph 2 + Section 25 apply (national security / prevention or detection of crime / regulatory enforcement / professional confidentialities), Balance may decline to provide access and explain the reasons.
6.3 Identity verification
Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.
6.4 Fees
PDPA Thailand Section 30 paragraph 3 + the PDPC Rights Notification 2023 permit the data controller to charge a reasonable fee for processing a data access request in the circumstances where the request is manifestly unfounded or excessive, in particular because of its repetitive character. Balance does not charge for access in practice.
6.5 Language
A request may be submitted in Thai or English. The PDPC accepts complaints in Thai and English (Thai is preferred for PDPC procedural materials).
7. Children's data — PDPA Thailand + Child Protection Act + Civil and Commercial Code
Balance processes personal data of Thai kids under the following layered framework:
- PDPA Thailand Section 19 + Section 23 + Section 26 sensitive-data heightened regime (Balance does NOT process SPD) read with the PDPC DPO Notification 2022 + the forthcoming PDPC Notification on Children's Data under Section 20 — for any minor under the CCC age of majority (20), the controller should obtain consent from the parent or legal guardian.
- Child Protection Act B.E. 2546 (2003) — child-protection framework including the Section 26 prohibitions and the Section 27 mandatory-reporting regime.
- Criminal Code — sexual offences against minors at Sections 277-285 + the online-grooming-equivalent offence at Section 282 (procurement of person under 18) read with the Computer Crime Act Section 14 (computer-related dissemination of obscene material) + Section 287/1 + Section 287/2 (child pornography).
- Civil and Commercial Code Section 21 — minor-incapacity doctrine; the parent contracts on behalf of the kid.
- Civil and Commercial Code Section 19 — age of majority 20.
- Civil and Commercial Code Sections 1546-1574 — parental power (Thai: อำนาจปกครอง) including specific legal representation under Section 1571.
- UN Convention on the Rights of the Child (Thailand acceded on 27 March 1992; limited declarations subsequently withdrawn or modified) + Optional Protocol on the Sale of Children, Child Prostitution and Child Pornography (Thailand acceded on 11 January 2006) — internalised through Thailand's child-welfare statutes.
For Balance:
- Verifiable Parental Consent. Identical mechanism to A-US § 5. The VPC screen is in English (Thai queued for Phase 2 locale rollout).
- No kid-self-serve consent path. Per § 5.3 above.
A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.
8. International data transfers from Thailand — PDPA Thailand Section 28 + Section 29 + the PDPC Cross-Border Notifications 2023
The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Thai resident's personal data leaves Thailand at the point of being uploaded to the Balance backend.
8.1 The Thailand-to-US transfer mechanism — PDPA Thailand Section 28 (adequacy) + Section 29 (safeguards) + the PDPC Cross-Border Notifications 2023
PDPA Thailand Section 28 sets out the adequacy-based transfer mechanism: a data controller may transfer personal data to a foreign country where the receiving country has adequate standards of personal data protection as designated by the PDPC. The PDPC Cross-Border Notification 2023 — Section 28 Adequacy of 12 December 2023 (in operation from 24 March 2024) sets out the adequacy assessment methodology. At the Effective date, the PDPC has not designated any foreign country as adequate. Accordingly Balance does not rely on Section 28.
PDPA Thailand Section 29 sets out the safeguards-based transfer mechanism in the absence of Section 28 adequacy. Under Section 29 read with the PDPC Cross-Border Notification 2023 — Section 29 Safeguards of 12 December 2023 (in operation from 24 March 2024), a controller may transfer personal data to a foreign country on the following grounds:
- (1) compliance with law / court order;
- (2) consent of the data subject given with knowledge of the inadequate-protection status of the receiving country — belt-and-braces basis used by Balance;
- (3) necessity for the performance of a contract between the data subject and the controller or for pre-contractual steps at the data subject's request — principal basis used by Balance for the subscription contract;
- (4) necessity for the conclusion or performance of a contract between the controller and a third party for the benefit of the data subject;
- (5) prevention of danger to life / body / health of the data subject or another person where the data subject is unable to give consent;
- (6) public-interest mission of substantial public benefit;
- (7) Section 29 paragraph 2 group-of-undertakings binding-corporate-rules-equivalent mechanism approved by the PDPC (n/a for Balance — no intra-group binding corporate rules);
- (8) Section 29 paragraph 3 controller-to-controller / controller-to-processor contractual safeguards that meet PDPC standards — operationalised by the PDPC Cross-Border Notification 2023 — Section 29 Safeguards — recommended-form contractual clauses; principal operational mechanism for Balance's processor-tier transfers.
Balance relies on the following stack to satisfy PDPA Thailand Section 29 + the PDPC Cross-Border Notification 2023 — Section 29 Safeguards:
- Section 29 paragraph 3 written contracts with PDPC-standard safeguards — principal mechanism. Each US sub-processor (Emergent Labs Inc.; Google LLC for GCS, FCM, Sign-In, and Play Billing; Resend, Inc.) is bound by a written processor agreement that includes a binding undertaking to maintain the personal data in accordance with the PDPA Thailand + Section 37(1)/(2) security + Section 26 sensitive-data restrictions (n/a) + Section 21 purpose limitation + Section 22 data minimisation. The clauses incorporate the substance of the EU SCC + UK IDTA + APP-aligned + Quebec-Private-Sector-Act-aligned + ASEAN Model Contractual Clauses substance as substantive overlays. The full transfer pack is in our international-transfer pack § 6.
- Section 29(2) parent's consent overlay — belt-and-braces. The parent's sign-up consent prominently and expressly discloses the cross-border transfer to the United States, expressly states that the United States has not been designated as adequate by the PDPC under Section 28 but that the recipient has given a written undertaking to maintain the personal data in accordance with PDPC standards, identifies the country of destination and the categories of recipients, and informs the parent of any risk arising from the transfer.
- Section 29(3) performance-of-contract necessity. The transfer is also necessary for the performance of the subscription contract between Balance and the parent and for the operation of the parental-control service.
- Supplementary measures — most importantly, the end-to-end encryption of proof media documented in our encryption-posture record. The E2EE is the principal supplementary measure ensuring that even a compelled-production scenario in the US yields only opaque ciphertext, not plaintext media.
- Onward-transfer restrictions — every sub-processor's processor agreement forbids onward transfer of Thai-resident personal data to a third country outside the PDPA Thailand Section 29 framework without the controller's prior written authorisation.
8.2 The Thailand-to-KZ axis (controller administrative access)
The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country and is not designated as adequate by the PDPC under Section 28, the Thailand-KZ axis is covered by the PDPA Thailand Section 29(3) written contracts with PDPC-standard safeguards + Section 29(2) parent's consent overlay + Section 29(3) performance-of-contract necessity — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance + ASEAN Model Contractual Clauses substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.
8.3 PDPA Thailand RoPA registration
PDPA Thailand Section 39 (Records of Processing Activities of the data processor) + Section 37(4) (Records of Processing Activities of the data controller) + the PDPC RoPA Notification 2022 require data controllers and data processors to prepare and maintain a Record of Processing Activities for inspection by the PDPC. There is no public RoPA registration regime under the PDPA Thailand (the RoPA is an internal record available for PDPC inspection on request). Balance maintains the internal RoPA at our Records of Processing Activities (Article 30).
8.4 APEC CBPR overlay (context-setting)
Thailand is not currently an APEC CBPR participating economy at the Effective date (Thailand has indicated interest but has not formally joined the operational CBPR system) — § 18 versioning protocol covers any change. The APEC CBPR system provides a complementary accountability framework for cross-border data transfers within the APEC region (which includes Singapore, the Philippines, the United States, Canada, Japan, the Republic of Korea, Mexico, Taiwan, Australia, and other APEC economies at the Effective date). Balance's principal operational mechanism remains the PDPA Thailand Section 29 paragraph 3 written contracts framework + the PDPC Cross-Border Notification 2023 — Section 29 Safeguards.
8.5 ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021)
Thailand is an ASEAN Member State + a signatory to the ASEAN Framework on Personal Data Protection (2016) + the ASEAN Data Management Framework. The ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021) provide a recommended-form contractual-clauses template usable across ASEAN Member States. Balance's sub-processor agreements incorporate the substance of the ASEAN Model Contractual Clauses as a substantive overlay (see our international-transfer pack § 6).
9. Data residency for Thai residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region. |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Thai resident's personal data held in Thailand? | No. Every Thai resident's personal data is held in the United States. The PDPA Thailand Section 29(3) written contracts + Section 29(2) parent's consent + Section 29(3) performance-of-contract necessity stack in § 8 above is the legal basis for the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements. |
| Is there a Thai establishment? | No. Balance has no permanent establishment in Thailand. The PDPA Thailand's territorial reach (Section 5(2)(a) offer-of-services-to-Thai-residents limb) is the basis for Balance's PDPA Thailand compliance. |
| Where is the supervisory authority? | Thailand — PDPC + PDPC Office + the regulatory bodies in § 3.3 above. |
The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Thailand does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Bank of Thailand directives on outsourcing by Thai banks — not applicable to Balance; the Securities and Exchange Commission Thailand directives — not applicable to Balance; certain Ministry of Public Health directives on healthcare data localisation under the National Health Act B.E. 2550 (2007) — not applicable to Balance).
10. Sub-processors touching Thai-resident data
| Sub-processor | Role | Location of processing | Thai transfer paperwork |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer | Hosts the FastAPI backend + MongoDB cluster | United States | PDPA Thailand Section 29(3) written processor agreement with PDPC-standard safeguards + Section 29(2) parent's consent on file per our international-transfer pack § 6; E2EE supplementary measure for proof media; ASEAN Model Contractual Clauses substance. |
| Google LLC — Google Cloud Storage (USA) | Stores end-to-end-encrypted proof-media ciphertext | United States (us multi-region) |
PDPA Thailand Section 29(3) written processor agreement (Google Cloud Data Processing Addendum) + Section 29(2) consent; ciphertext-only handling. |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States (us multi-region) |
PDPA Thailand Section 29(3) written processor agreement (Google Cloud Data Processing Addendum) + Section 29(2) consent; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted. |
| Google LLC — Firebase Cloud Messaging | Delivers push notifications to Thai kid + parent devices | United States | PDPA Thailand Section 29(3) + Section 29(2) as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures). |
| Google LLC — Google Sign-In | Authenticates parent Google identity (when used) | United States | PDPA Thailand Section 29(3) + Section 29(2) as above. |
| Google LLC — Google Play Billing | Processes subscription purchases | United States | PDPA Thailand Section 29(3) + Section 29(2) + Google Play Developer Distribution Agreement. |
| Resend, Inc. (San Francisco, CA, USA) | Delivers transactional email to Thai parent users | United States | PDPA Thailand Section 29(3) + Section 29(2). |
Every sub-processor is bound by a written data-processing agreement under PDPA Thailand Section 40 that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + PDPA Thailand Section 37(1)/(2) + the PDPC Security Notification 2022. The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.
11. Breach notification — PDPA Thailand Section 37(4) + PDPC Breach Notification 2022
PDPA Thailand Section 37(4) + the PDPC Breach Notification 2022 of 14 December 2022 (in operation from 13 June 2023) is the principal breach-notification regime. The Thai regime requires PDPC notification without undue delay, where feasible within 72 hours from awareness of a personal data breach:
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| PDPC | A personal data breach has occurred — defined by the PDPC Breach Notification 2022 as a breach of security leading to the unlawful or unauthorised loss / access / use / amendment / correction / disclosure of personal data — that is likely to result in a risk to the rights and freedoms of natural persons (and the PDPC Breach Notification 2022 makes notification voluntary for breaches that are unlikely to result in a risk). | Without undue delay, where feasible within 72 hours from awareness of the personal data breach. Awareness is the time at which the controller has a reasonable degree of certainty that a personal data breach has occurred. Balance internal anchor: as soon as practicable but no later than 72 hours from initial discovery. | PDPC Office online Personal Data Breach Notification portal + by email to pdpc@pdpc.or.th |
| Affected individuals | A personal data breach as above where, on the PDPC Breach Notification 2022 harm-likelihood analysis, the breach is likely to result in a high risk to the rights and freedoms of natural persons (e.g., financial loss / identity theft / reputational damage / loss of confidentiality of personal data protected by professional secrecy / unauthorised reversal of pseudonymisation / any other significant economic or social disadvantage). | As soon as practicable after PDPC notification, with carve-outs in the PDPC Breach Notification 2022 (where the data has been rendered unintelligible — e.g., the E2EE ciphertext case — affected-individual notification may not be warranted; where the controller has taken subsequent measures eliminating the high risk; where direct notification would involve disproportionate effort). | Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English, with a Thai version queued for the Phase-2 locale rollout. |
| CSAE-specific | An incident with a CSAE component. | Per § 14 below + the internal runbook (M1). | TICAC + CCIB + DCY + MSDHS Hotline 1300 + ThaiCERT. |
The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, formal assessment under PDPA Thailand Section 37(4) + the PDPC Breach Notification 2022 completed within 48 hours of discovery for risk-to-rights-and-freedoms escalation, PDPC notification within the 72-hour statutory window, affected-individual notification per the high-risk analysis.
11.1 Minimum content of the PDPC notification (PDPC Breach Notification 2022)
The PDPC notification states:
- the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects concerned, and the categories and approximate number of personal data records concerned;
- the name and contact details of the DPO (, named individual: ) — the contact from whom the PDPC may obtain additional information;
- the likely consequences of the personal data breach;
- the measures taken or proposed to be taken to address the personal data breach (including measures to mitigate possible adverse effects).
The English-language template lives in our breach-notification runbook § 8.1. A Thai version is queued for Phase 2 locale rollout.
11.2 Non-compliance — PDPA Thailand Chapter VI penalties
- Administrative fines under PDPA Thailand Sections 82-90 — up to THB 5 million for the most serious offences (failure to comply with the cross-border transfer rules / failure to comply with the security obligation / failure to notify a personal data breach / failure to appoint a DPO).
- Criminal penalties under PDPA Thailand Sections 79-81 — imprisonment up to 1 year and/or criminal fine up to THB 1 million for offences including unlawful use of sensitive personal data + unlawful disclosure of personal data + obstruction of PDPC inspection.
- Civil liability under PDPA Thailand Sections 77-78 — civil action including punitive damages up to twice the actual damage.
11.3 Concurrent Cybersecurity Act / ThaiCERT notification
For incidents involving cybersecurity attacks on the controller's systems, the Cybersecurity Act B.E. 2562 (2019) notification regime applies only to designated CII operators. Balance is NOT designated as Critical Information Infrastructure under the Act. Voluntary cooperation with ThaiCERT (the national CERT within NCSA) is honoured as a best-effort security overlay.
12. Cookies, spam, and electronic direct marketing
Thailand does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) PDPA Thailand Section 19 + Section 23 + Section 27 for any cookie that processes personal data; (ii) the PDPC's interpretive position on cookies in PDPC guidance and the PDPC Rights Notification 2023; (iii) the Direct Sales and Direct Marketing Act B.E. 2545 (2002) for direct-marketing-defined communications; (iv) PDPA Thailand Section 32 right to object to direct-marketing processing; (v) the Consumer Protection Act B.E. 2522 (1979) Chapter III advertising rules.
12.1 In-app — strictly-necessary storage only
The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.
12.2 Public legal-documents site — no analytics, no advertising, no tracking
The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.
12.3 Electronic direct marketing — not sent
Balance does not send direct-marketing communications within the meaning of the Direct Sales and Direct Marketing Act B.E. 2545 (2002) to Thai residents. The only email Balance sends to Thai parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. The DSDMA's direct marketing definition turns on the active-outbound-solicitation element; transactional messages are outside the definition. If Balance ever introduces a marketing channel, we will comply with the DSDMA registration regime + PDPA Thailand Section 19 prior consent + PDPA Thailand Section 32 right to object + the Consumer Protection Act Chapter III advertising rules including Section 22 fairness and Section 27 protection of children.
12.4 No telemarketing
Balance does not place telemarketing voice calls, SMS, or messaging-app outreach to Thai residents.
13. Lawful-access requests and the encryption posture
Thai authorities may serve a lawful-access request on Balance via:
- A judicial search warrant under the Criminal Procedure Code (Thai: ประมวลกฎหมายวิธีพิจารณาความอาญา) Sections 92-105 — the principal mechanism for compelling production of stored personal data in connection with a criminal investigation.
- A production order under the Computer Crime Act B.E. 2550 (2007) Section 18 + Section 19 — competent-officer powers (with court approval at Section 19 for content data) to summon / examine / search / seize / order disclosure / order production of computer data.
- A judicial interception order under the Criminal Procedure Code + the Special Investigation Act B.E. 2547 (2004) Section 25 intercept regime for special-case investigations administered by DSI.
- A PDPC investigation under PDPA Thailand Sections 65-72 (Expert Committee inspection + administrative remedies).
- An ordinary civil-court production order or subpoena under the Civil Procedure Code.
- A Mutual Assistance in Criminal Matters Act B.E. 2535 (1992) request channelled through the Central Authority at the Office of the Attorney General — for foreign-state cooperation.
- A Budapest Convention on Cybercrime Article 25 + Article 27 + Article 32 + Article 35 24/7 point-of-contact request — Thailand acceded to the Convention on 17 April 2024, in force for Thailand from 1 August 2024. The Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence (opened for signature 12 May 2022) — Thailand's accession is pending.
- The Digital Platform Services Royal Decree B.E. 2565 (2022) notice/take-down provisions (Balance below the active-user threshold and is not a notification-tier platform).
- A prerogative-writ application to the Administrative Court of Thailand for judicial review of administrative action under the Establishment of Administrative Courts and Administrative Court Procedure Act B.E. 2542 (1999).
- A Constitutional Court Section 213 individual constitutional complaint in connection with state action that violates the Section 32 constitutional right to privacy.
The Balance architectural posture interacts with these mechanisms as follows:
- Proof media is end-to-end encrypted. The kid's device generates a fresh per-file file-encryption key, encrypts the proof file with XChaCha20-Poly1305, wraps the file-encryption key to each authorised parent device's X25519 public key, and uploads only the resulting ciphertext + the recipient-wrap envelopes. We do not retain a master key, a backdoor, or any other means by which we could ourselves decrypt the proof media. PDPA Thailand Section 37(1)/(2) security obligation + the PDPC Security Notification 2022 + the Computer Crime Act Section 9 prohibition on unauthorised modification + the Criminal Procedure Code judicial-order requirement for compelled disclosure all reinforce the design choice.
- No assistance with bulk plaintext interception. Balance does not perform bulk plaintext content scanning. Balance does not deploy a server-side content-moderation engine on the proof-media payload. There is no plaintext on our side to be intercepted.
- Response protocol. On receipt of a lawful-access request directed at proof media, we will: 1. acknowledge receipt within one business day; 2. engage Thai counsel to assess the validity of the request and the appropriate response under PDPA Thailand Section 24(4) compliance-with-legal-obligation basis + the relevant lawful-access statute + the Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 proportionality screen; 3. preserve the relevant ciphertext for the period the request requires (subject to our retention rules); 4. inform the requesting authority that the proof media is end-to-end encrypted and that plaintext is not available from us; 5. cooperate in identifying and serving the lawful-process route to the parent — who holds the decryption key — if that is the appropriate channel.
- CSAE-cooperation overlay. Notwithstanding the encryption posture, Balance cooperates fully with the Royal Thai Police TICAC + CCIB + DSI + DCY + MSDHS + ThaiCERT on any CSAE-related referral, via the routes in § 14 below.
- Notification of the data subject. Where the lawful-access request is not accompanied by a non-disclosure obligation, we will inform the affected parent of the request (PDPA Thailand Section 23 transparency + PDPC interpretive practice on transparency in lawful-access matters). Where the request is accompanied by a statutory non-disclosure obligation (e.g., under the Criminal Procedure Code or the Special Investigation Act B.E. 2547 (2004) non-disclosure framework or the Anti-Money Laundering Act B.E. 2542 (1999)), we will comply with the order and inform the parent as soon as the order permits.
The full encryption posture is in our encryption-posture record.
14. CSAE reporting routes — Thailand
A Thai resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day, in English. - Royal Thai Police — emergency 191 (Thai: แจ้งเหตุด่วน 191); Tourist Police 1155 for foreign-language assistance (24/7, English + Thai + multiple other languages).
- Royal Thai Police — TICAC (Thailand Internet Crimes Against Children Task Force) — for online sexual offences against children + CSAE enforcement. Via 191 + via TICAC operational coordination through the Royal Thai Police website at
https://www.royalthaipolice.go.th/. - Royal Thai Police — Cybercrime Investigation Bureau (CCIB) — for online CSAE + cyber-crime investigation. Online reporting at
https://www.tcsd.go.th/+ via Police 191. - Royal Thai Police — Anti-Trafficking in Persons Division (ATPD) — for trafficking-in-persons cases including online recruitment of children for sexual exploitation. Via 191 + via Royal Thai Police channels.
- Department of Special Investigation (DSI) — กรมสอบสวนคดีพิเศษ — for special-case investigation including transnational CSAE. Online at
https://www.dsi.go.th/+ via DSI Hotline 1202. - MSDHS Hotline 1300 — MSDHS 24/7 national social-welfare hotline (children + women + family-violence). Dial 1300 (toll-free).
- ChildLine Thailand Foundation — Hotline 1387 — children's helpline NGO. Dial 1387 (toll-free, 24/7).
- Thai Hotline (Internet Foundation for the Development of Thailand) — INHOPE-member CSAM hotline. Online at
https://www.thaihotline.org/(online intake form). - ECPAT Foundation Thailand — CSAE prevention NGO. Online at
https://www.ecpat-thailand.org/. - Hug Project Thailand — CSAE survivor support + prevention. Online at
https://www.hugproject.org/. - Department of Children and Youth (DCY) — MSDHS — Child Protection Act B.E. 2546 (2003) lead agency. Online at
https://www.dcy.go.th/. - Samaritans of Thailand — emotional-support hotline (English/Thai). Phone +66 2 713 6793 + online at
https://www.samaritansthai.com/. - National Human Rights Commission of Thailand (NHRCT) — independent human-rights commission. Online at
https://www.nhrc.or.th/. - ThaiCERT (within NCSA) — for cyber-incident reporting + CSAE technical incident handling. Online at
https://www.thaicert.or.th/+ emailreport@thaicert.or.th. - ICMEC — International Centre for Missing & Exploited Children —
https://www.icmec.org/. Thailand coordination via INTERPOL Bangkok National Central Bureau. - INHOPE — Thailand is represented in INHOPE through the Thai Hotline (Internet Foundation for the Development of Thailand). Cross-border CSAM reports flow through Thai Hotline + TICAC + CCIB + INTERPOL Bangkok.
The full CSAE Country Routing Table is in Child Safety Standards § 8.6.
15. Complaint routes (summary)
A Thai resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:
| Authority | Subject matter | Address / URL |
|---|---|---|
| Office of the Personal Data Protection Committee (PDPC Office) | PDPA Thailand | 120 Mueang Thong Thani, Chaengwattana Road, Pak Kret District, Nonthaburi 11120; https://www.pdpc.or.th/; +66 2 142 1033; pdpc@pdpc.or.th |
| Ministry of Digital Economy and Society (MDES) | PDPC Office parent ministry | The Government Complex, Building B, 6th-9th Floor, Chaengwattana Road, Thung Song Hong, Lak Si, Bangkok 10210; https://www.mdes.go.th/; +66 2 141 6747 |
| Administrative Court of Thailand | Administrative review of PDPC decisions | https://www.admincourt.go.th/ |
| Constitutional Court of the Kingdom of Thailand | Constitutional review under Section 213 (state action) | https://www.constitutionalcourt.or.th/ |
| Electronic Transactions Development Agency (ETDA) | Digital Platform Services Royal Decree B.E. 2565 (2022) administration | https://www.etda.or.th/; +66 2 123 1234 |
| National Cyber Security Agency (NCSA) / ThaiCERT | Cybersecurity Act administration; national CERT | https://www.ncsa.or.th/; https://www.thaicert.or.th/ |
| Royal Thai Police — TICAC + CCIB | CSAE + cybercrime | https://www.royalthaipolice.go.th/; emergency 191; Tourist Police 1155 |
| Department of Special Investigation (DSI) | Special-case investigation including transnational CSAE | https://www.dsi.go.th/; Hotline 1202 |
| Ministry of Social Development and Human Security (MSDHS) | Child Protection Act B.E. 2546 (2003) lead ministry; Hotline 1300 | https://www.msociety.go.th/; Hotline 1300 |
| Department of Children and Youth (DCY) | Child Protection Act 2003 child-welfare lead agency | https://www.dcy.go.th/ |
| Office of the Consumer Protection Board (OCPB) | Consumer Protection Act 1979 + Direct Sales and Direct Marketing Act 2545 (2002) | https://www.ocpb.go.th/; Hotline 1166 |
| National Human Rights Commission of Thailand (NHRCT) | Independent human-rights commission | https://www.nhrc.or.th/ |
| Office of the Ombudsman of Thailand | Ombudsman investigation of state-agency action | https://www.ombudsman.go.th/ |
| Provincial Court / Civil Court / Criminal Court | PDPA Thailand Chapter V civil liability + Chapter VI criminal complaints; Child Protection Act + Criminal Code prosecutions | via https://www.coj.go.th/ |
| Court of Appeal | Appellate review | via https://www.coj.go.th/ |
| Supreme Court of Justice (Dika Court) | Final appellate review on points of law | https://www.supremecourt.or.th/ |
A Thai resident may always first raise the matter with us at (data access; named individual: , in his capacity as the DPO under PDPA Thailand Section 41 + the PDPC DPO Notification 2022). We will respond within the PDPA Thailand timelines. The PDPC's published policy recommends raising the matter with the data controller first but the PDPC also accepts direct complaints where the data subject demonstrates that internal-remedy exhaustion is impracticable or where the complaint involves a serious matter warranting immediate PDPC action.
16. Consumer rights — the CPA Thailand + DSDMA + UCTA + CCC overlay
The Consumer Protection Act B.E. 2522 (1979) as amended (the "CPA Thailand"), the Direct Sales and Direct Marketing Act B.E. 2545 (2002) as amended (the "DSDMA"), the Unfair Contract Terms Act B.E. 2540 (1997) (the "UCTA Thailand"), and the Civil and Commercial Code apply to Balance's subscription flow as a consumer transaction (the parent is a consumer within the CPA Thailand Section 3 definition — a person who buys or obtains the services of a business operator including a person who is invited or proposed by the business operator to purchase or obtain services). Treatment is implemented in Subscription Terms § 20.
16.1 CPA Thailand Chapter III — consumer protection in advertising + Chapter III/2 — controlled contracts
CPA Thailand Section 22 prohibits advertising that is unfair to consumers — including false statements, exaggerated statements, statements that may cause misunderstanding, statements that are obscene or against good morals, statements that are misleading, or statements that may cause damage to society or the economy. CPA Thailand Section 23 prohibits advertising that may cause harm to mental or physical health. CPA Thailand Section 27 prohibits advertising directed at children that exploits children's lack of experience. The Balance Terms of Service (Terms of Service) and the in-app subscription flow are drafted to avoid each Section 22 / 23 / 27 risk.
CPA Thailand Chapter III/2 (Sections 35 bis to 35 nawa) is the Controlled Contracts regime — certain categories of contract designated by the Consumer Protection Committee on Contracts are subject to mandatory-content rules + prohibitions on unfair terms. Online subscription supply for parental-control services is not currently a Controlled Contract Business (the categories presently designated include leasing of residential buildings, leasing of office space, credit cards, certain installment-sale contracts, certain education contracts, fitness club memberships, mobile-phone-service contracts, internet-service contracts, life-insurance contracts, motor vehicle leases, and condominium agreements). § 18 versioning protocol covers any future designation that captures Balance's subscription flow.
16.2 UCTA Thailand — unfair contract terms screen
UCTA Thailand Section 4 is the unfair-terms screen for standard-form / consumer / employment / lease / installment / loan / security contracts — a term that imposes an excessive burden on a party against the other, contrary to good faith / good conscience / fairness, is unenforceable to the extent of the excessive burden, with court power to determine the appropriate scope. UCTA Thailand Section 5 invalidates exclusion / limitation of liability for personal-injury or willful / gross-negligence harm. UCTA Thailand Section 6 lists specific examples of unfair terms in standard-form contracts. UCTA Thailand Section 9 lists the factors for the unfair-terms assessment (bargaining power / extent of negotiation / knowledge / nature of supply / market alternative / good faith / good conscience).
Balance's Terms of Service and Subscription Terms are drafted to comply with UCTA Thailand. Choice-of-law clauses or jurisdiction clauses that would deprive the Thai consumer of mandatory protection are subject to UCTA Thailand Section 4 + Section 6 + the public policy doctrine in Dika Court (Supreme Court) decisions on the unenforceability of foreign-jurisdiction clauses in consumer cases.
16.3 Direct Sales and Direct Marketing Act B.E. 2545 (2002) — 7-Day Right under Section 33
The DSDMA Section 33 grants a consumer who purchases goods or services from a direct sales or direct marketing operator the right to terminate the contract by giving written notice to the business operator within 7 days from the date of receiving the goods or the date of agreeing to receive the services. Section 34 sets out the manner of exercise + refund obligations + return obligations.
The DSDMA's application to online subscription supply outside the direct marketing definition is uncertain. The direct marketing concept turns on the active-outbound-solicitation element. Where the consumer affirmatively initiates the transaction via the Google Play Store listing (as for Balance), Thai legal commentary is divided on whether the DSDMA captures the transaction. The conservative position — adopted by Balance — is to assume DSDMA application where the consumer is in Thailand and to honour the 7-Day Right + manner-of-exercise rules.
16.4 Voluntary 14-day no-questions refund — exceeds DSDMA 7-Day Right
Balance honours a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the DSDMA 7-Day Right by 7 days. The 14-day refund window is documented at Subscription Terms § 20.
16.5 CCC — capacity-of-minors framework + Age of Majority
Under CCC Section 21 + CCC Section 19, a kid (under 20) cannot enter into a binding contract without the consent of the legal representative; a contract made by a minor without that consent is voidable (subject to Section 22 carve-outs for acts that are merely beneficial to the minor / suitable to the minor's condition / appropriate to ordinary household life of the minor). The subscription contract is between Balance and the parent (who is 20+ — the CCC age of majority). The kid is a beneficiary of the service supplied to the parent. Balance does not contract directly with kids.
16.6 CCC tort framework — privacy and personality rights
CCC Section 420 is the general tort provision — a person who wilfully or negligently and unlawfully injures the life / body / health / liberty / property / right of another shall be liable to make compensation. CCC Section 421 addresses intentional injury (a person who wilfully causes damage to another in a manner contrary to good morals shall be liable to make compensation). CCC Section 423 addresses defamation. The Dika Court (Supreme Court of Justice) has applied Sections 420 + 421 + 423 to privacy violations including unauthorised disclosure of personal data + unauthorised publication of personal images + invasion of communicational privacy.
16.7 Consumer Class Action mechanism
CPA Thailand (as amended) + the Civil Procedure Code Sections 222/1-222/49 establish the consumer class action mechanism — a representative consumer may file a class action on behalf of similarly-situated consumers; certified by the Civil Court Class Action Division. Applicable to PDPA Thailand civil-liability claims under Sections 77-78 (although the more specific PDPA Thailand civil-liability framework controls; class-action mechanism remains available where consumer-protection grounds are also engaged).
16.8 Forum and choice of law
The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace CPA Thailand / DSDMA / UCTA Thailand / PDPA Thailand to the prejudice of the Thai consumer are subject to UCTA Thailand Section 4 + the Conflict of Laws Act B.E. 2481 (1938) Section 13 (public-policy reservation) + the public policy doctrine recognised by Thai courts.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — PDPA Thailand Section 29(3) written processor agreements with PDPC-standard safeguards + Section 29(2) parent's consent + ASEAN Model Contractual Clauses substance on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- Play Console Permission Declarations: the Play Console permission declarations (M4).
- Play Console Data Safety: the Play Console Data Safety form (M5).
- Play Console Child Safety Standards Declaration: the Play Console Child Safety Standards declaration (M6).
- Play Console Target Audience + IARC: the Play Console Target Audience form (M7).
- US Country Annex: United States annex (A-US).
- UK Country Annex: United Kingdom annex (A-UK).
- EU/EEA Country Annex: EU / EEA annex (A-EU-EEA).
- Argentina Country Annex: Argentina annex (A-AR).
- Chile Country Annex: Chile annex (A-CL).
- Colombia Country Annex: Colombia annex (A-CO).
- Peru Country Annex: Peru annex (A-PE).
- Uruguay Country Annex: Uruguay annex (A-UY).
- Canada Country Annex: Canada annex (A-CA).
- Australia Country Annex: Australia annex (A-AU).
- New Zealand Country Annex: New Zealand annex (A-NZ).
- Singapore Country Annex: Singapore annex (A-SG).
- Philippines Country Annex: Philippines annex (A-PH).
- Israel Country Annex: Israel annex (A-IL).
- Hong Kong Country Annex: Hong Kong annex (A-HK).
- Malaysia Country Annex: Malaysia annex (A-MY).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Android Permissions Register: our permissions register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Phase-2 Placeholder Tracker: our internal compliance tracker.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:
- Every change to a substantive row in §§ 2–16 bumps the Last updated date at the top of this file and triggers a re-publication at Privacy Policy and Children's Privacy Notice.
- A material amendment to the PDPA Thailand B.E. 2562 (2019) — including the enactment of any Personal Data Protection Act (No. 2) B.E. [year] or successor amendment — triggers an off-cycle rewrite of §§ 2, 4, 6, 8, and 11.
- A new or amended PDPC Notification, Subordinate Legislation, Rule, Code of Practice, or Determination — including any revision to the PDPC Security Notification 2022, the PDPC DPO Notification 2022, the PDPC Breach Notification 2022, the PDPC RoPA Notification 2022, the PDPC Cross-Border Notification 2023 — Section 28 Adequacy, the PDPC Cross-Border Notification 2023 — Section 29 Safeguards, the PDPC Rights Notification 2023, or the issuance of any new PDPC Notification on Children's Data under PDPA Thailand Section 20 — triggers an off-cycle update.
- A material amendment to the Child Protection Act B.E. 2546 (2003), the Criminal Code (in particular Sections 277-285 + Section 287/1 + Section 287/2), the Anti-Trafficking in Persons Act B.E. 2551 (2008), or the Promotion and Development of Children and Young Persons Act B.E. 2550 (2007), triggers an off-cycle update to §§ 5, 13, 14.
- A material amendment to the Computer Crime Act B.E. 2550 (2007) (and any future Computer Crime Act amendment), the Digital Platform Services Royal Decree B.E. 2565 (2022) + the Notification of the ETDA on Notification of Digital Platform Services Business B.E. 2566 (2023), the Cybersecurity Act B.E. 2562 (2019), the Special Investigation Act B.E. 2547 (2004), the Anti-Money Laundering Act B.E. 2542 (1999), the Mutual Assistance in Criminal Matters Act B.E. 2535 (1992), the Criminal Procedure Code, or any future Thai primary or subordinate legislation on data localisation or content moderation, triggers an off-cycle update to § 13.
- A material amendment to the Consumer Protection Act B.E. 2522 (1979), the Direct Sales and Direct Marketing Act B.E. 2545 (2002), the Unfair Contract Terms Act B.E. 2540 (1997), the Civil and Commercial Code, or any future Thai primary or subordinate consumer-protection legislation triggers an off-cycle update to § 16 + Subscription Terms.
- A material amendment to the Electronic Transactions Act B.E. 2544 (2001) triggers an off-cycle update to § 16 + § 12.
- A material decision of the PDPC, of the Provincial Court / Civil Court / Criminal Court / Court of Appeal / Supreme Court of Justice (Dika Court) bearing on the PDPA Thailand, on Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32, or on the established Thai privacy doctrine, triggers an off-cycle update.
- Thailand's accession to (or domestic implementation of) the Council of Europe Convention 108 / 108+ triggers an off-cycle update to § 2 + § 8 + § 13.
- Thailand's accession to the Second Additional Protocol to the Convention on Cybercrime (Budapest Convention) on enhanced co-operation and disclosure of electronic evidence (opened for signature 12 May 2022) triggers an off-cycle update to § 2 + § 13.
- A new EU adequacy decision for Thailand (currently none at the Effective date) triggers an off-cycle update to § 8 + § 9.
- A change to Thailand's APEC CBPR participation status (currently not a participating economy at the Effective date) triggers an off-cycle update to § 8.
- The Digital Platform Services Royal Decree B.E. 2565 (2022) threshold breach by Balance (currently below the 5,000 monthly Thai active users threshold and below the turnover thresholds) triggers an off-cycle update to § 2 + § 13.
- A material change to a sub-processor's PDPC-standard-safeguards status triggers an off-cycle update to § 8 + § 10 + our sub-processor register.
- The annual review is by 9 June. The DPO signs the review off; the Designated Child Safety Officer co-signs any change to § 3 (supervisory authorities), § 5 (children's rights), § 11 (breach), § 13 (lawful-access), or § 14 (CSAE routes).
- This Annex is republished alongside H1 and H2 at the public legal-documents site (Privacy Policy and Children's Privacy Notice) and is incorporated by reference. The Thai translation is queued for the Phase-2 locale rollout per our internal compliance tracker.
End of Thailand Country Annex.