← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — Thailand Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Thai resident covered by this Annex; the Data Protection Officer ("DPO") for the purposes of Personal Data Protection Act B.E. 2562 (2019) ("PDPA Thailand" — พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562) Section 41 (mandatory DPO appointment for data controllers and data processors whose core activities consist of (a) processing requiring regular and systematic monitoring of personal data or of data subjects by reason of the large scale of personal data as prescribed by the Personal Data Protection Committee — "PDPC" — under the Notification of the Personal Data Protection Committee on the Designation of Data Controllers and Data Processors that are required to appoint a Data Protection Officer B.E. 2565 (2022) of 14 December 2022, in operation from 13 June 2023, the "PDPC DPO Notification 2022"; or (b) processing of sensitive personal data under Section 26; Balance is engaged on Section 41(b) on the most-protective reading because the PDPC DPO Notification 2022 explicitly references processing of personal data of children as a category warranting DPO designation — § 18 versioning protocol covers any further DPO threshold revisions), with business contact published as the publicly-accessible DPO contact required by Section 41(4) + the PDPC DPO Notification 2022 § 5; the designated contact point for the Personal Data Protection Committee (the "PDPC"), the Office of the Personal Data Protection Committee (Thai: สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล, the "PDPC Office"), the Ministry of Digital Economy and Society (Thai: กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม, the "MDES"), the Royal Thai Police — Thailand Internet Crimes Against Children Task Force (Thai: กองบังคับการปราบปรามการกระทำความผิดเกี่ยวกับการล่วงละเมิดทางเพศต่อเด็กผ่านระบบสื่อสารทางอิเล็กทรอนิกส์, the "TICAC"), the Royal Thai Police — Cybercrime Investigation Bureau (Thai: กองบังคับการปราบปรามการกระทำความผิดเกี่ยวกับอาชญากรรมทางเทคโนโลยี, the "CCIB"), the Department of Children and Youth (Thai: กรมกิจการเด็กและเยาวชน, the "DCY") under the Ministry of Social Development and Human Security (Thai: กระทรวงการพัฒนาสังคมและความมั่นคงของมนุษย์, the "MSDHS"), the Office of the Consumer Protection Board (Thai: สำนักงานคณะกรรมการคุ้มครองผู้บริโภค, the "OCPB") under the Office of the Prime Minister, and the Thailand Computer Emergency Response Team (Thai: ศูนย์ประสานการรักษาความมั่นคงปลอดภัยระบบคอมพิวเตอร์ประเทศไทย, the "ThaiCERT") within the National Cyber Security Agency (Thai: สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ, the "NCSA"), under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Personal Data Protection Act B.E. 2562 (2019) ("PDPA Thailand") — the principal substantive provisions of the PDPA Thailand were in force from 1 June 2022 following the deferral of the Royal Decree on the Postponement of the Effective Date of Certain Provisions of the Personal Data Protection Act B.E. 2562 (2019) B.E. 2563 (2020) — and any further amendment thereto including any future Personal Data Protection Act (No. 2) B.E. [year] (the § 18 versioning protocol covers their enactment); (b) any amendment to the Six Personal Data Protection Principles at PDPA Thailand Section 21 + Section 22 + Section 24 + Section 26 + Section 27 + Section 37 — lawful basis at Section 24 (consent under Section 19 / performance of contract / legal obligation / vital interest / public interest / legitimate interest / archival or scientific/historical research or statistical purposes / public health) + sensitive personal data at Section 26 (heightened-lawful-basis regime; Balance does NOT process sensitive personal data) + purpose limitation at Section 21 + data quality at Section 37(3) + storage limitation at Section 37(3) + security at Section 37(1) and (2) + transparency at Section 23 + data subject rights at Sections 30-36 + Section 37(4); (c) any Notification, Subordinate Legislation, Rule, Code of Practice, or Determination issued by the PDPC under PDPA Thailand Section 16(5) — including the Notification of the PDPC on Standards of Security Measures B.E. 2565 (2022) (the "PDPC Security Notification 2022"), the Notification of the PDPC on Designation of Data Controllers and Data Processors that are required to appoint a Data Protection Officer B.E. 2565 (2022) (the "PDPC DPO Notification 2022"), the Notification of the PDPC on Personal Data Breach Notification B.E. 2565 (2022) of 14 December 2022 in operation from 13 June 2023 (the "PDPC Breach Notification 2022"), the Notification of the PDPC on Rules and Methods for Records of Processing Activities of the Data Processor B.E. 2565 (2022) (the "PDPC RoPA Notification 2022"), the Notification of the PDPC on Criteria for Sending or Transferring Personal Data to a Foreign Country pursuant to Section 28 B.E. 2566 (2023) of 12 December 2023 in operation from 24 March 2024 (the "PDPC Cross-Border Notification 2023 — Section 28 Adequacy"), the Notification of the PDPC on Standards of Personal Data Protection for the Sending or Transferring of Personal Data Outside the Kingdom pursuant to Section 29 B.E. 2566 (2023) of 12 December 2023 in operation from 24 March 2024 (the "PDPC Cross-Border Notification 2023 — Section 29 Safeguards"), the Notification of the PDPC on Rules and Methods for the Exercise of Data Subject's Rights B.E. 2566 (2023), the Notification of the PDPC on Records of Processing Activities of the Data Controller B.E. 2565 (2022), and any further PDPC subordinate legislation; (d) any decision of the Provincial Court (Thai: ศาลจังหวัด), the Civil Court (Thai: ศาลแพ่ง), the Criminal Court (Thai: ศาลอาญา), the Court of Appeal (Thai: ศาลอุทธรณ์), the Supreme Court of Justice (Thai: ศาลฎีกา) — or the Constitutional Court of the Kingdom of Thailand (Thai: ศาลรัฐธรรมนูญ) — bearing on the PDPA Thailand, on Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 read with the constitutional-jurisprudence right to privacy, or on the established privacy doctrines applied by Thai courts; (e) any amendment to the Child Protection Act B.E. 2546 (2003) (Thai: พระราชบัญญัติคุ้มครองเด็ก พ.ศ. 2546) (the principal Thai child-welfare statute, in force from 30 March 2004) including the Child Protection Act (No. 4) B.E. 2562 (2019) extending child-protection criminal liability; (f) any amendment to the Criminal Code (Thai: ประมวลกฎหมายอาญา) — in particular Section 277 (sexual intercourse with a child under 15 — statutory rape; Section 277/1 enhanced penalty), Section 279 (indecent act on a child under 15), Section 280 (aggravated indecent act on a child under 15), Section 282 (procurement of person under 18 for sexual purposes), Section 283 (procurement by force/threat), Section 284 (trafficking for sexual purpose), Section 285 (aggravated procurement when victim under 15 / under 18), Section 287 (obscene articles), Section 287/1 (child pornography possession — added by Criminal Code Amendment Act (No. 24) B.E. 2558 (2015), in force from 8 April 2015), Section 287/2 (child pornography distribution / dissemination / public exhibition — added by the same Amendment Act), and Section 309-310 (false imprisonment); (g) any amendment to the Computer Crime Act B.E. 2550 (2007) (Thai: พระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. 2550) as amended by Computer Crime Act (No. 2) B.E. 2560 (2017) ("CCA"), in particular Section 5 (unauthorised access to computer system), Section 7 (unauthorised access to computer data), Section 8 (unauthorised interception of computer data), Section 9 (modification or interference with computer data), Section 11 (sending data causing nuisance), Section 14 (entering false data / computer-related fraud / computer-related obscenity / national-security computer-related offences), Section 15 (service-provider liability), Section 16 (unauthorised dissemination of personal images causing damage), Section 18 (powers of investigation), Section 19 (production orders), Section 26 (data-retention obligation for service providers — 90 days minimum, extendible to 2 years on competent-officer order — Balance is NOT a service provider within the scope of the CCA for Thai-resident user data because Balance does not provide a Thai-public-facing communication service within the scope and the parental-control service is a closed family system; § 18 versioning protocol covers any change to the service provider classification); (h) any amendment to the Royal Decree on Operation of Digital Platform Service Business B.E. 2565 (2022) (Thai: พระราชกฤษฎีกาว่าด้วยการประกอบธุรกิจบริการแพลตฟอร์มดิจิทัลที่ต้องแจ้งให้ทราบ พ.ศ. 2565) (the "Digital Platform Services Royal Decree" or "DPS Royal Decree") published in the Royal Gazette on 23 December 2022 and in operation from 21 August 2023 under the Electronic Transactions Act B.E. 2544 (2001) — imposes notification obligations on digital platform service businesses with Thai users above prescribed thresholds (default threshold: annual turnover above THB 1.8 million for natural persons / THB 50 million for legal persons, OR monthly Thai active users above 5,000 — see Notification of the ETDA on Notification of Digital Platform Services Business B.E. 2566 (2023); Balance is below the active-user threshold and is not within the DPS Royal Decree threshold-based notification regime at the Effective date — § 18 versioning protocol covers any threshold breach); (i) any amendment to the Electronic Transactions Act B.E. 2544 (2001) as amended by Electronic Transactions Act (No. 2) B.E. 2551 (2008) + Electronic Transactions Act (No. 3) B.E. 2562 (2019) + Electronic Transactions Act (No. 4) B.E. 2562 (2019); (j) any amendment to the Consumer Protection Act B.E. 2522 (1979) (Thai: พระราชบัญญัติคุ้มครองผู้บริโภค พ.ศ. 2522) as amended (most recently by the Consumer Protection Act (No. 4) B.E. 2562 (2019)), the Direct Sales and Direct Marketing Act B.E. 2545 (2002) (Thai: พระราชบัญญัติขายตรงและตลาดแบบตรง พ.ศ. 2545) as amended by Direct Sales and Direct Marketing Act (No. 3) B.E. 2560 (2017), the Unfair Contract Terms Act B.E. 2540 (1997) (Thai: พระราชบัญญัติว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540), the Civil and Commercial Code (Thai: ประมวลกฎหมายแพ่งและพาณิชย์) — in particular Section 19 (age of majority 20 years), Section 20 (capacity to contract — minor's contract requires the legal representative's consent; an act done by a minor without that consent is voidable), Sections 21-29 (minor capacity provisions), Sections 150-152 (juristic acts) — collectively the principal Thai consumer-protection and contract-capacity statutes; (k) any amendment to the Anti-Trafficking in Persons Act B.E. 2551 (2008) (Thai: พระราชบัญญัติป้องกันและปราบปรามการค้ามนุษย์ พ.ศ. 2551) as amended; (l) any amendment to the Cybersecurity Act B.E. 2562 (2019) (Thai: พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์ พ.ศ. 2562) — Balance is NOT designated as Critical Information Infrastructure (CII) under the Act; § 18 versioning protocol covers any designation; (m) any amendment to a sub-processor's Thai data-handling posture under our sub-processor register; (n) the bringing into force of any post-Effective-date Thai regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex); (o) Thailand's accession to (or domestic implementation of) the Council of Europe Convention 108 / Convention 108+ (Thailand is not currently a party) or any change in the status of the Convention on Cybercrime (Budapest Convention) — Thailand acceded to the Budapest Convention on 17 April 2024, in force for Thailand from 1 August 2024 (§ 18 versioning protocol covers any further protocol accession including the Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence opened for signature 12 May 2022); (p) any amendment to the Anti-Money Laundering Act B.E. 2542 (1999) (Thai: พระราชบัญญัติป้องกันและปราบปรามการฟอกเงิน พ.ศ. 2542) insofar as it engages production orders against data controllers; (q) any Royal Gazette notification by the PDPC under PDPA Thailand Section 28 (adequacy designation of foreign jurisdictions) or under Section 29 (cross-border safeguards), or any Royal Decree of the Office of the Prime Minister under PDPA Thailand Section 6; (r) any amendment to the Mutual Assistance in Criminal Matters Act B.E. 2535 (1992) (Thai: พระราชบัญญัติความร่วมมือระหว่างประเทศในเรื่องทางอาญา พ.ศ. 2535). Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Thai-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Thai resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Thai resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. The national language of the Kingdom of Thailand under Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 51 (state duty to preserve the national language) + Sections 70-71 (state duties on culture and learning) is Thai (Thai: ภาษาไทย). Thai-language translation of this Annex is queued for the Phase-2 locale rollout per our internal compliance tracker. No translation is statutorily required at the Effective date for the English-language privacy notice to a Thai resident (the PDPA Thailand does not mandate Thai-language notification; PDPC interpretive practice accepts notices in English provided the notice is intelligible to the data subject — and PDPC guidance prefers Thai-language notification for materially-affected Thai-resident data subjects, which Balance will deliver via the Phase-2 locale rollout).


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is Thailand — the unitary kingdom comprising 76 changwat (provinces) plus Bangkok Metropolis (Krung Thep Mahanakhon) as a special administrative area, organised into six conventional regions (Northern / Northeastern / Central / Eastern / Western / Southern). There is no provincial-level data-protection sub-layer that derogates from the PDPA Thailand in respect of Balance's commercial processing (the PDPA Thailand at Section 4 excludes certain state agencies and activities — the House of Representatives, the Senate, the Parliament, the judicial branch acting as such, credit-bureau companies under the Credit Information Business Act, certain national-security activities, mass-media activities, certain personal/family-only processing — but Balance is a commercial data controller and the PDPA Thailand applies in full).

We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies Thailand as the country of residence, this Annex applies, even if the other signals are non-Thai. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

The PDPA Thailand has explicit territorial reach defined at Section 5 of the PDPA Thailand: the PDPA Thailand applies (i) to a data controller or data processor in the Kingdom of Thailand, irrespective of whether such collection, use, or disclosure of personal data occurs in the Kingdom or not; and (ii) to a data controller or data processor outside the Kingdom of Thailand in case where (a) the activity is to offer goods or services to data subjects in the Kingdom, irrespective of whether the payment is made by the data subject; or (b) the activity is to monitor the data subject's behaviour, where the behaviour takes place in the Kingdom. Balance squarely targets Thai residents through Google Play Thailand, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Thai-resident parents and kids; the PDPA Thailand applies in respect of all personal data Balance processes in connection with Thai-resident users via Section 5(2)(a) (offering services to data subjects in Thailand).


2. Statutory framework — what applies

The Thai personal-data-protection regime is dominated by the Personal Data Protection Act B.E. 2562 (2019) ("PDPA Thailand"), published in the Royal Gazette on 27 May 2019 with phased commencement (institutional provisions from 28 May 2019; the principal substantive provisions originally scheduled for 28 May 2020 were twice deferred by the Royal Decree on the Postponement of the Effective Date of Certain Provisions of the Personal Data Protection Act B.E. 2562 (2019) B.E. 2563 (2020) and finally entered into force on 1 June 2022). The PDPA Thailand is supplemented by the body of PDPC Notifications issued from 2022 onward — most directly relevant the PDPC Security Notification 2022, the PDPC DPO Notification 2022, the PDPC Breach Notification 2022, the PDPC RoPA Notification 2022 (both data-controller and data-processor versions), the PDPC Cross-Border Notification 2023 — Section 28 Adequacy, and the PDPC Cross-Border Notification 2023 — Section 29 Safeguards. Adjacent layers: the Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 (right to privacy) + Section 33 (freedom of dwelling) + Section 34 (freedom of expression) + Section 36 (right to private communication); the Child Protection Act B.E. 2546 (2003); the Criminal Code including Section 287/1 + Section 287/2 (child pornography) + Section 277 + Sections 279-285 (sexual offences against children); the Computer Crime Act B.E. 2550 (2007) as amended; the Digital Platform Services Royal Decree B.E. 2565 (2022); the Electronic Transactions Act B.E. 2544 (2001) as amended; the Cybersecurity Act B.E. 2562 (2019); the Consumer Protection Act B.E. 2522 (1979) as amended; the Direct Sales and Direct Marketing Act B.E. 2545 (2002) as amended; the Unfair Contract Terms Act B.E. 2540 (1997); the Civil and Commercial Code; the Anti-Trafficking in Persons Act B.E. 2551 (2008); the Mutual Assistance in Criminal Matters Act B.E. 2535 (1992); the Anti-Money Laundering Act B.E. 2542 (1999).

Instrument Short cite What it does Balance's posture
Constitution of the Kingdom of Thailand B.E. 2560 (2017) Constitution — the supreme law of the Kingdom under Section 5. Section 32 "A person shall enjoy the right of privacy, dignity, reputation and family. An act violating or affecting the right of a person under paragraph one or an exploitation of personal information in any manner whatsoever shall not be permitted, except by virtue of a provision of law enacted only to the extent of necessity for public interest" — the constitutional right to privacy and the constitutional foundation of personal-data protection; Section 33 freedom of dwelling; Section 34 freedom of expression; Section 36 right to private communication; Section 50 state duty to protect children; Section 71 state duty to develop children. The constitutional anchor. The right to privacy in Thailand is constitutional (Section 32) AND statutory (PDPA Thailand + adjacent regimes). Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below.
Personal Data Protection Act B.E. 2562 (2019) PDPA Thailand — published in the Royal Gazette on 27 May 2019; principal substantive provisions originally scheduled for 28 May 2020 were twice deferred by the Royal Decree on the Postponement of the Effective Date of Certain Provisions of the Personal Data Protection Act B.E. 2562 (2019) B.E. 2563 (2020) and finally entered into force on 1 June 2022. Chapter I General Provisions (Sections 4-5 — application + extraterritorial reach via Section 5(2) offer-of-services-to-Thai-residents limb + monitoring-behaviour-in-Thailand limb); Chapter II Personal Data Protection Committee (Sections 8-18 — PDPC composition + functions including Section 16(5) issuance of subordinate legislation + Section 16(7) hearing complaints); Chapter III Personal Data Protection with Parts on collection (Sections 19-25), use or disclosure (Sections 27-29), sensitive personal data (Section 26), and the data controller's general obligations (Section 37); Section 19 the consent requirement (express + freely given + specific purpose + clear and easily understandable language + separated from other matters + free of misleading or deceptive design) + Section 19(5) right to withdraw consent at any time with consequences clearly notified; Section 21 the purpose-limitation principle; Section 22 the data-minimisation principle; Section 23 the transparency requirement (notice at collection — purpose / categories / disclosure recipients / contact / retention / data subject rights); Section 24 the alternative lawful bases for non-sensitive personal data (without consent): (1) prevention or suppression of danger to life/body/health; (2) performance of contract; (3) performance of public-mission duty; (4) legitimate interest of controller or third party where data subject's rights are not overridden; (5) compliance with legal obligation; Section 26 the sensitive-personal-data heightened regime — sensitive categories: racial/ethnic origin / political opinions / religious or philosophical beliefs / sexual behaviour / criminal records / health data / disability / trade union information / genetic data / biometric data / any other data which similarly affects the data subject in the same manner as prescribed by the PDPC (Balance does NOT process sensitive personal data of Thai residents); Section 27 the use and disclosure rules (limited to the purpose of collection, with carve-outs); Section 28 the transfer of personal data to a foreign country — adequacy-based mechanism (the country of destination must have adequate standards of personal data protection as designated by the PDPC under PDPC subordinate legislation — the PDPC has not designated any country as adequate at the Effective date); Section 29 the transfer of personal data to a foreign country — safeguards-based mechanism (in the absence of Section 28 adequacy, transfer is permissible on safeguards including: (1) compliance with law / court order; (2) consent of data subject with knowledge of inadequate-protection status; (3) necessity for contract performance; (4) compliance with contract concluded for the benefit of the data subject; (5) prevention of danger to life/body/health where consent cannot be obtained; (6) important public-interest mission; (7) Section 29 paragraph 2 group-of-undertakings binding-corporate-rules-equivalent mechanism approved by the PDPC; Section 29 paragraph 3 controller-to-controller / controller-to-processor contractual safeguards that meet PDPC standards — operationalised by the PDPC Cross-Border Notification 2023 — Section 29 Safeguards of 12 December 2023 in operation from 24 March 2024 — recommended-form contractual clauses + APEC CBPR overlay + ASEAN MCC overlay accepted); Chapter III Part 3 Rights of the Data Subject Sections 30-36 + Section 37(4) — Section 30 right of access including right to copy + right to request disclosure of source of personal data not collected from data subject + 30-day response deadline under PDPC interpretive practice; Section 31 right to data portability (the data subject may request transmission of the personal data to another controller in a structured commonly-used machine-readable format); Section 32 right to object (to processing for direct marketing / for legitimate-interest or public-task processing / for archival or research purposes); Section 33 right to deletion / erasure / destruction or anonymisation (where withdrawal of consent / no longer necessary / unlawful processing); Section 34 right to restriction of processing; Section 35 right to rectification (data must be accurate / current / complete / not misleading); Section 36 right not to be subject to certain decisions based solely on automated processing — Balance does not engage Section 36 in respect of Thai residents (no automated individual decision-making of legal-effect / similarly-significant-effect within the scope of Section 36); Section 37(4) right of complaint to the PDPC; Section 37 the data controller's general duties including (1) provide security measures of personal data sufficient to prevent unauthorised loss / access / use / amendment / correction / disclosure (operationalised by the PDPC Security Notification 2022); (2) erase or destroy personal data when retention period ends or upon request of the data subject or upon withdrawal of consent (subject to other lawful basis); (3) notify the PDPC of any personal data breach without undue delay where feasible within 72 hours from awareness (operationalised by the PDPC Breach Notification 2022); (4) prepare and maintain a Record of Processing Activities (operationalised by the PDPC RoPA Notification 2022 — for data controllers) for inspection by PDPC; (5) appoint a Data Protection Officer where required under Section 41; (6) implement Privacy Impact Assessments where required; Section 39 Records of Processing Activities of the Data Processor; Section 40 Data Processing Agreement requirement between data controller and data processor; Section 41 mandatory Data Protection Officer (DPO) appointment where (1) the data controller or data processor is a public authority; (2) the activity of the data controller or data processor in collection / use / disclosure of personal data requires regular monitoring of personal data or data subjects by reason of the large scale of personal data; (3) the core activity of the data controller or data processor is the collection / use / disclosure of sensitive personal data under Section 26; or otherwise as prescribed by PDPC under the PDPC DPO Notification 2022 + Section 41(3) DPO functions + Section 41(4) DPO publicly-accessible contact requirement; Chapter IV Complaint (Sections 65-72 — PDPC complaint procedure + Expert Committee + powers of inspection + administrative remedies); Chapter V Civil Liability (Sections 77-78 — civil action including punitive damages up to twice the actual damage); Chapter VI Penalties — administrative penalties (Sections 82-90 — administrative fines up to THB 5 million depending on the offence) + criminal penalties (Sections 79-81 — imprisonment up to 1 year and/or criminal fine up to THB 1 million) + the principle that legal-person liability may also engage the natural-person director / manager / officer-in-default. The principal statute. Applies in full to Balance as a data controller established outside Thailand that targets services to Thai residents (Section 5(2)(a) offer-of-services limb). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below.
Notifications of the Personal Data Protection Committee (2022 – 2023 series) PDPC Notifications — a series of binding subordinate-legislation instruments issued by the PDPC under PDPA Thailand Section 16(5). Most directly relevant: Notification of the PDPC on Standards of Security Measures B.E. 2565 (2022) of 7 June 2022 in operation from 8 June 2022 ("PDPC Security Notification 2022"); Notification of the PDPC on Designation of Data Controllers and Data Processors that are required to appoint a Data Protection Officer B.E. 2565 (2022) of 14 December 2022 in operation from 13 June 2023 ("PDPC DPO Notification 2022"); Notification of the PDPC on Rules and Methods of Personal Data Breach Notification B.E. 2565 (2022) of 14 December 2022 in operation from 13 June 2023 ("PDPC Breach Notification 2022") — operationalises Section 37(4) personal data breach notification — 72 hours from awareness + minimum-content requirements + affected-individual notification on the high-risk threshold; Notification of the PDPC on Criteria for Sending or Transferring Personal Data to a Foreign Country pursuant to Section 28 B.E. 2566 (2023) of 12 December 2023 in operation from 24 March 2024 ("PDPC Cross-Border Notification 2023 — Section 28 Adequacy") — sets out adequacy assessment criteria (no country designated as adequate at the Effective date); Notification of the PDPC on Standards of Personal Data Protection for the Sending or Transferring of Personal Data Outside the Kingdom pursuant to Section 29 B.E. 2566 (2023) of 12 December 2023 in operation from 24 March 2024 ("PDPC Cross-Border Notification 2023 — Section 29 Safeguards") — recommended-form contractual clauses + intra-group binding-corporate-rules equivalent; Notification of the PDPC on Rules and Methods for Records of Processing Activities of the Data Processor B.E. 2565 (2022) ("PDPC RoPA Notification 2022 — Processor"); Notification of the PDPC on Records of Processing Activities of the Data Controller B.E. 2565 (2022) ("PDPC RoPA Notification 2022 — Controller"); Notification of the PDPC on Rules and Methods for the Exercise of Data Subject's Rights B.E. 2566 (2023) ("PDPC Rights Notification 2023"); and the body of supplementary PDPC guidance circulars. Sets the PDPC's binding subordinate-legislation interpretive layer on the PDPA Thailand. Applies in full.
Child Protection Act B.E. 2546 (2003) Child Protection Act — published in the Royal Gazette on 2 October 2003 + in force 30 March 2004. Substantively amended by Child Protection Act (No. 4) B.E. 2562 (2019). Section 4 definitionschild (Thai: เด็ก) means a person below the age of 18 years and includes a person who has not yet been graduated from compulsory schooling; youth defined; parent + legal guardian defined; Section 7 the principle of best interest of the child as the primary consideration; Section 23-25 state duties to protect children; Section 26 prohibited acts including (1) torture / cruelty / inhumane treatment, (2) abandonment, (3) forcing / inducing / supporting / soliciting child to act in a manner that is detrimental to the child's body or mind, (4) forcing / inducing / supporting / soliciting child to commit immoral / harmful acts, (5) commercial sexual exploitation, (6) employment in places of entertainment / gambling / liquor sales, (7) child labour in violation of labour law, (8) using or making child to do acts dangerous to physical or mental health, (9) disclosure of name / photograph / personal information of child or family that could cause damage to the child; Section 27 mandatory reporting by any person who knows of an act of child abuse or who believes a child to be in danger of abuse + immunity from civil and criminal liability for reporting in good faith; Section 41-46 Provincial Child Protection Committee + Child Protection Officer; Section 60-67 penalties (imprisonment up to 5 years + fine up to THB 100,000 for offences against Section 26). The principal Thai child-welfare statute. Applies. Treatment in § 5 + § 14 below.
Criminal Code (Thailand) Criminal Code — the principal general criminal statute, promulgated B.E. 2499 (1956) and amended periodically. Substantive sections relevant to Balance's child-safety + lawful-access posture: Section 277 sexual intercourse with a child under 15 — statutory rape (imprisonment 4-20 years + fine), aggravated penalty if under 13 (imprisonment 7-20 years or life); Section 277/1 enhanced penalty in aggravated circumstances; Section 278 indecent act on a person (imprisonment up to 10 years + fine); Section 279 indecent act on a child under 15 (imprisonment up to 10 years + fine, aggravated if under 13); Section 280 aggravated indecent act on a child under 15 (imprisonment up to 15 years + fine); Section 282 procurement of person under 18 for sexual purposes (imprisonment 5-20 years + fine); Section 283 procurement by force / threat (imprisonment 7-20 years or life); Section 283 bis procurement of person under 18 for departure / for sexual purposes (heightened penalty); Section 284 taking of person under 18 for sexual purposes; Section 285 aggravated procurement when victim under 15 / under 18 (heightened penalty); Section 287 the obscene-articles offence — production / possession / distribution / public exhibition of obscene articles (imprisonment up to 3 years + fine); Section 287/1 the child-pornography possession offence — possession of child pornography for the purpose of sexual gratification of self or others (imprisonment up to 5 years + fine up to THB 100,000) — added by Criminal Code Amendment Act (No. 24) B.E. 2558 (2015) in force 8 April 2015; Section 287/2 the child-pornography distribution offence — distribution / dissemination / public exhibition of child pornography (imprisonment up to 7 years + fine up to THB 140,000) — added by the same Amendment Act; Section 309 false imprisonment; Section 310 false imprisonment for benefit. Applies. Treatment in § 14 below.
Computer Crime Act B.E. 2550 (2007) as amended by Computer Crime Act (No. 2) B.E. 2560 (2017) CCA — published in the Royal Gazette on 18 June 2007 + in force 19 July 2007; amended substantively by Computer Crime Act (No. 2) B.E. 2560 (2017) in force 24 May 2017. Section 5 unauthorised access to a computer system; Section 7 unauthorised access to computer data; Section 8 unauthorised interception of computer data; Section 9 modification or interference with computer data without authorisation; Section 10 interference with the functioning of computer systems; Section 11 sending data causing nuisance to the recipient; Section 14 entering false / forged / false-impression / national-security-threatening / obscenity-related computer data + computer-related fraud + computer-related dissemination of obscene material; Section 15 service-provider liability for content visible on service provider's system where service provider has knowledge and fails to remove; Section 16 unauthorised dissemination of personal images that damages reputation or causes shame; Section 17 offences committed outside Thailand may be punishable; Section 18 powers of the competent officer to issue summons / examine / search / seize / order disclosure / order production of computer data; Section 19 procedure for production orders requiring court approval; Section 20 order to block / remove computer data on court order; Section 26 mandatory data retention for service providers — 90 days minimum, extendible to 2 years on competent-officer order — defining service provider by reference to the Ministry of Information and Communication Technology Notification on Categories of Service Providers (now under the Ministry of Digital Economy and Society). Balance is NOT a service provider within the scope of Section 26 for Thai-resident user data because Balance does not provide a Thai-public-facing communication service within the scope and the parental-control service is a closed family system not within the service provider categories prescribed by the MDES Notification — § 18 versioning protocol covers any change to the categorisation. The principal Thai cybercrime statute. Applies. Treatment in § 13 below.
Royal Decree on Operation of Digital Platform Service Business B.E. 2565 (2022) Digital Platform Services Royal Decree (DPS Royal Decree) — published in the Royal Gazette on 23 December 2022 and in operation from 21 August 2023 under the Electronic Transactions Act B.E. 2544 (2001) Section 32. The DPS Royal Decree imposes (a) a notification obligation on every digital platform service business before commencement of services to Thai users; (b) heightened obligations on digital platform services with significant impact (categorised by user numbers / turnover thresholds / risk indicators); (c) child-safety and consumer-protection obligations on platforms. The DPS Royal Decree is administered by the Electronic Transactions Development Agency (Thai: สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์, the "ETDA") under the Notification of the ETDA on Notification of Digital Platform Services Business B.E. 2566 (2023) of 16 August 2023. Default threshold for notification: annual turnover above THB 1.8 million (natural persons) / THB 50 million (legal persons), OR monthly Thai active users above 5,000. Balance is below the active-user threshold and is not within the DPS Royal Decree threshold-based notification regime at the Effective date — § 18 versioning protocol covers any threshold breach. The DPS Royal Decree's child-safety standards are voluntarily honoured by Balance's substantive product posture (no advertising directed at children + no behavioural-advertising profile + no content-recommendation surface + Verifiable Parental Consent regardless of age + end-to-end-encrypted proof-media payload). Applies as a context-setting fact (Balance below notification threshold). Treatment in § 12 + § 13 below.
Electronic Transactions Act B.E. 2544 (2001) as amended ETA — published in the Royal Gazette on 4 December 2001 + in force 3 April 2002; amended by Electronic Transactions Act (No. 2) B.E. 2551 (2008) + Electronic Transactions Act (No. 3) B.E. 2562 (2019) + Electronic Transactions Act (No. 4) B.E. 2562 (2019). Section 8-13 legal recognition of electronic transactions and electronic signatures; Section 32 Royal Decree powers (basis for the Digital Platform Services Royal Decree B.E. 2565 (2022) and other Royal Decrees on specific electronic-transaction regulation); Section 35 information security in electronic transactions. The principal Thai electronic-transactions statute. Applies. Treatment in § 16 below.
Cybersecurity Act B.E. 2562 (2019) Cybersecurity Act — published in the Royal Gazette on 27 May 2019 + in force 28 May 2019. Establishes the National Cyber Security Committee + the National Cyber Security Agency (NCSA) + the Critical Information Infrastructure (CII) regime applicable to designated CII operators. Cybersecurity-incident notification obligations on CII operators. Balance is NOT designated as Critical Information Infrastructure under the Act; § 18 versioning protocol covers any designation. Voluntary cooperation with ThaiCERT (the national CERT within NCSA) is honoured as a best-effort security overlay. Applies as a context-setting fact (Balance not designated as CII). Treatment in § 13 below.
Consumer Protection Act B.E. 2522 (1979) as amended CPA Thailand — published in the Royal Gazette on 4 May 1979 + in force 5 May 1979. Substantively amended by Consumer Protection Act (No. 2) B.E. 2541 (1998) + Consumer Protection Act (No. 3) B.E. 2556 (2013) + Consumer Protection Act (No. 4) B.E. 2562 (2019). Chapter I General Provisions + definition of consumer (Section 3) + definition of business operator; Chapter II Consumer Protection Committee (Sections 9-15); Chapter III Consumer Protection in Advertising (Sections 22-29 — prohibition on misleading or unfair advertising); Chapter III/1 Consumer Protection on Labelling; Chapter III/2 Consumer Protection on ContractsControlled Contract Business + Controlled List of Terms + mandatory contract-content rules + prohibition on unfair terms (Sections 35 bis - 35 nawa); Chapter IV complaint and remedy procedure including the Office of the Consumer Protection Board (OCPB) administrative-action route; Chapter V Class Action (introduced by amendment) + collective remedies; Chapter VI Penalties. Enforced by the Office of the Consumer Protection Board (OCPB) under the Office of the Prime Minister + the Consumer Protection Committee. The principal Thai consumer-protection statute. Applies in full. Treatment in § 16 below.
Direct Sales and Direct Marketing Act B.E. 2545 (2002) as amended DSDMA — published in the Royal Gazette on 30 April 2002 + in force 31 August 2002. Amended by Direct Sales and Direct Marketing Act (No. 3) B.E. 2560 (2017). Section 3 definitionsdirect marketing means an act of marketing goods or services in a manner that uses any media of communication to communicate with consumers directly so that the consumer responds in order to purchase the goods or services from the business operator; direct sales defined separately; Section 27 registration requirements for direct-sales operators; Section 28 registration requirements for direct-marketing operators (with carve-outs for de-minimis activities); Section 33 the seven-day right of withdrawal — a consumer who purchases goods or services from a direct sales or direct marketing operator has the right to terminate the contract by giving written notice to the business operator within 7 days from the date of receiving the goods or the date of agreeing to receive the services (the "7-Day Right"); Section 34 the manner of exercise + refund obligations + return obligations. The DSDMA's application to online subscription supply outside the direct marketing definition is uncertain — the direct marketing concept turns on the active-outbound-solicitation element. Where the consumer affirmatively initiates the transaction via the Google Play Store listing (as for Balance), the DSDMA application is contested in Thai legal commentary. Balance honors a voluntary 14-day no-questions Google Play Billing refund as market-leading consumer-protection overlay that exceeds the 7-Day Right where it would otherwise apply. Applies (uncertain scope for online subscription supply outside direct marketing definition; Balance's voluntary 14-day refund exceeds the 7-Day Right). Treatment in § 16 below.
Unfair Contract Terms Act B.E. 2540 (1997) UCTA Thailand — published in the Royal Gazette on 15 November 1997 + in force 15 May 1998. Section 4 unfair-terms screen for standard-form / consumer / employment / lease / installment / loan / security contracts — a term that imposes an excessive burden on a party against the other, contrary to good faith / good conscience / fairness, is unenforceable to the extent of the excessive burden, with court power to determine the appropriate scope. Section 5 exclusion / limitation of liability for personal-injury or willful / gross-negligence harm is unenforceable. Section 6 specific examples of unfair terms in standard-form contracts. Section 7 evidentiary unfair terms. Section 8 liability exclusion for goods or services not directly known to the relevant party. Section 9 factors for the unfair-terms assessment (bargaining power / extent of negotiation / knowledge / nature of supply / market alternative / good faith / good conscience). Section 10 other relevant matters. The principal Thai unfair-contract-terms statute. Applies in full. Treatment in § 16 below.
Civil and Commercial Code CCC — the principal Thai civil and commercial statute, promulgated B.E. 2466-2477 (1923-1934) with frequent amendment. Section 19 age of majority — 20 years (a person attains majority on completion of 20 years of age) — but a minor of any age becomes sui juris on marriage validly concluded after attaining 17 years (Section 20); Section 21 capacity to contract — a juristic act done by a minor must obtain consent of the legal representative (parent / guardian); a juristic act done without such consent is voidable, except for acts that are merely beneficial to the minor / suitable to the minor's condition / appropriate to ordinary household life of the minor — applied to minor's contracts in Decisions of the Supreme Court of Justice (Dika Court) Nos. 1287/2493, 2168/2515, et seq.; Sections 22-28 further minor-capacity rules; Section 29 ratification by minor on attaining majority; Sections 145-152 juristic acts; Section 154 invalidating elements; Sections 1546-1567 parental power (Thai: อำนาจปกครอง) — the parent's general authority over the minor child; Sections 1568-1571 specific powers of legal representation; Section 1574 restriction on certain acts (sale/exchange/mortgage/lease of real property / business; gift; renunciation) without court approval. Applies. Treatment in § 16 below.
Anti-Trafficking in Persons Act B.E. 2551 (2008) as amended Anti-Trafficking in Persons Act — published in the Royal Gazette on 6 February 2008 + in force 5 June 2008. Amended by Anti-Trafficking in Persons Act (No. 2) B.E. 2558 (2015) + Anti-Trafficking in Persons Act (No. 3) B.E. 2560 (2017). Section 4 definitionstrafficking in persons + exploitation including child labour exploitation + sexual exploitation; child means a person below 18 years for the purposes of this Act. Section 6 the principal trafficking offence (imprisonment 6-12 years + fine; heightened penalty for child victim — imprisonment 8-15 years or 10-20 years or life depending on aggravating factors). Section 11 assisting / aiding trafficking. Section 13-14 corporate liability. Section 27 the multi-disciplinary team approach to victim assistance. Enforced by the Department of Special Investigation (DSI) under the Ministry of Justice + the Anti-Trafficking in Persons Division of the Royal Thai Police + the Ministry of Social Development and Human Security (MSDHS). Applies. Treatment in § 14 below.
Mutual Assistance in Criminal Matters Act B.E. 2535 (1992) MACMA Thailand — the principal Thai foreign-state-cooperation statute in criminal matters. Channelled through the Central Authority at the Office of the Attorney General (Thai: สำนักงานอัยการสูงสุด). Bilateral mutual legal assistance treaties with the United States (signed 19 March 1986, in force 10 June 1993), Australia, Canada, France, Germany, Republic of Korea, the United Kingdom, and other states. Applies. Treatment in § 13 below.
Anti-Money Laundering Act B.E. 2542 (1999) as amended AMLA Thailand — published in the Royal Gazette on 19 April 1999 + in force 19 August 1999. Amended substantively by Anti-Money Laundering Act (No. 5) B.E. 2558 (2015). The principal Thai anti-money-laundering statute. Enforced by the Anti-Money Laundering Office (Thai: สำนักงานป้องกันและปราบปรามการฟอกเงิน, the "AMLO"). Relevant insofar as it engages production orders against data controllers. Applies. Treatment in § 13 below.
EU adequacy None. Thailand does not hold an EU adequacy decision under GDPR Article 45 at the Effective date. EU/EEA → Thailand transfers are governed by EU SCCs + Transfer Impact Assessment. Cross-reference in EU / EEA annex § 8. The absence of EU adequacy does not affect Balance's posture because Balance has no Thai data residency (the backend is in the US — see § 9 below).
Convention 108 / Convention 108+ Not applicable. Thailand is not a party to the Council of Europe Convention 108 or Convention 108+. Applies as a context-setting fact. Treatment in § 8 below.
APEC Cross-Border Privacy Rules (CBPR) Thailand is an APEC participating economy since the founding of APEC in 1989. Thailand is not currently an APEC CBPR participating economy at the Effective date (Thailand has indicated interest but has not formally joined the operational CBPR system) — § 18 versioning protocol covers any change. Applies as a context-setting fact. The Balance principal operational mechanism for Thailand-to-third-country transfers remains the PDPA Thailand Section 29 paragraph 3 contractual-safeguards framework + the PDPC Cross-Border Notification 2023 — Section 29 Safeguards.
ASEAN Framework on Personal Data Protection (2016) The ASEAN Framework on Personal Data Protection adopted by the ASEAN Telecommunications and IT Ministers in November 2016 + the ASEAN Data Management Framework + the ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021). Thailand is a signatory and supportive member. Applies as a context-setting fact. The ASEAN Model Contractual Clauses provide an alternative contractual-protection overlay route used in this Annex's transfer pack at § 8 below.
Budapest Convention on Cybercrime Applicable. Thailand acceded to the Convention on Cybercrime (Budapest Convention) on 17 April 2024 and the Convention entered into force for Thailand on 1 August 2024. The Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence (opened for signature 12 May 2022) — Thailand's accession to the Second Additional Protocol is pending; § 18 versioning protocol covers any change. Applies as a context-setting fact. Cross-border lawful-access for Thailand is now via the Budapest Convention 24/7 point of contact + Article 25 + Article 27 spontaneous-information-sharing channels, in addition to the Mutual Assistance in Criminal Matters Act B.E. 2535 (1992) + bilateral MLATs.

(Any prospective Thai regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date PDPC Notification in that area, the Thailand AI Ethics Guidelines (issued by the Ministry of Digital Economy and Society in March 2022, voluntary best-practice guidance only), the National AI Strategy and Action Plan 2022–2027, the Royal Decree on Artificial Intelligence Systems (draft before the Council of State; not enacted at the Effective date), any future Thai primary legislation on artificial intelligence before the House of Representatives / Senate, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Thai regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. Supervisory authorities

3.1 PDPC — Personal Data Protection Committee + PDPC Office

The principal supervisory authority is the Personal Data Protection Committee (Thai: คณะกรรมการคุ้มครองข้อมูลส่วนบุคคล, the "PDPC"), the regulatory committee established under PDPA Thailand Section 8 with the Office of the Personal Data Protection Committee (Thai: สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล, the "PDPC Office") as its operational arm. The PDPC sits within the Ministry of Digital Economy and Society (Thai: กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม, the "MDES"). The PDPC's composition under Section 8 includes the Chairperson selected by a Selection Committee, plus ex-officio members and qualified members. The PDPC has investigative + enforcement + regulatory + recommendatory powers under PDPA Thailand Sections 14-18 + Sections 65-72. The PDPC's decisions are appealable to the Administrative Court of Thailand (Thai: ศาลปกครอง) under the Establishment of Administrative Courts and Administrative Court Procedure Act B.E. 2542 (1999).

Field Value
Name Office of the Personal Data Protection Committee (Thai: สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล)
Parent ministry Ministry of Digital Economy and Society (กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม, MDES)
Headquarters 120 Mueang Thong Thani, Chaengwattana Road, Pak Kret District, Nonthaburi 11120, Thailand
Website https://www.pdpc.or.th/ (Thai) — English landing page available
Complaint channel PDPC Office online complaint portal accessible from https://www.pdpc.or.th/ (complaint form via the e-Service portal); email pdpc@pdpc.or.th
Phone +66 2 142 1033
Data-Breach-Notification channel PDPC Office online Personal Data Breach Notification portal per PDPA Thailand Section 37(4) + the PDPC Breach Notification 2022 — 72-hour notification from awareness of personal data breach.
PDPC Chairperson At the Effective date — published at https://www.pdpc.or.th/

The PDPC is the first-line forum for any PDPA-Thailand-grounded complaint from any Thai resident. A Thai resident may petition the PDPC after first raising the matter with Balance (the PDPC's published procedure recommends raising the matter with the data controller first, but the PDPC also accepts direct complaints). We accept all data subject access / privacy enquiries at (named individual: , in his capacity as the DPO under PDPA Thailand Section 41 + the PDPC DPO Notification 2022) and respond within the PDPA Thailand timelines (see § 6 below).

A Thai resident may also pursue private remedies via (i) the PDPA Thailand Chapter V civil liability under Sections 77-78 (including punitive damages up to twice the actual damage); (ii) Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 constitutional-rights cause of action read with constitutional-court jurisprudence on the right to privacy + Section 213 individual constitutional complaint to the Constitutional Court (in connection with state action); (iii) common-law-equivalent privacy doctrine as recognised by Thai courts including the line of Dika Court (Supreme Court) decisions on tort-based privacy remedies under CCC Sections 420 + 421 + 423; (iv) the PDPA Thailand Chapter VI penalty regime which may be the subject of criminal complaint to the Royal Thai Police + the Public Prosecutor.

3.2 Ministry of Digital Economy and Society — PDPC Office parent ministry

The Ministry of Digital Economy and Society (Thai: กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม, the "MDES") is the parent ministry of the PDPC Office. The Minister of Digital Economy and Society is the responsible minister for the PDPA Thailand and for the issuance of Royal Decrees and Ministerial Regulations under the PDPA Thailand.

Field Value
Name Ministry of Digital Economy and Society (กระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม, MDES)
Headquarters The Government Complex Commemorating His Majesty the King's 80th Birthday Anniversary 5th December B.E. 2550 (2007), Building B, 6th-9th Floor, Chaengwattana Road, Thung Song Hong, Lak Si, Bangkok 10210, Thailand
Website https://www.mdes.go.th/
Phone +66 2 141 6747

3.3 Other regulatory bodies

Body Subject matter URL
Electronic Transactions Development Agency (ETDA)สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์ Electronic Transactions Act + Digital Platform Services Royal Decree B.E. 2565 (2022) administration https://www.etda.or.th/ — +66 2 123 1234
National Cyber Security Agency (NCSA) / ThaiCERTสำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ Cybersecurity Act administration + national CERT https://www.ncsa.or.th/ — ThaiCERT at https://www.thaicert.or.th/
Royal Thai Police (RTP) — Thailand Internet Crimes Against Children Task Force (TICAC) CSAE investigation including online grooming + child pornography via RTP https://www.royalthaipolice.go.th/ — Emergency 191
Royal Thai Police — Cybercrime Investigation Bureau (CCIB) Cybercrime investigation including online CSAE https://www.tcsd.go.th/ — Emergency 191
Royal Thai Police — Anti-Trafficking in Persons Division (ATPD) Anti-Trafficking in Persons Act B.E. 2551 (2008) via RTP https://www.royalthaipolice.go.th/
Department of Special Investigation (DSI)กรมสอบสวนคดีพิเศษ Special-case investigation including transnational CSAE https://www.dsi.go.th/
Department of Children and Youth (DCY)กรมกิจการเด็กและเยาวชน Child Protection Act 2546 (2003) — child-welfare lead agency https://www.dcy.go.th/
Ministry of Social Development and Human Security (MSDHS)กระทรวงการพัฒนาสังคมและความมั่นคงของมนุษย์ DCY parent ministry; Hotline 1300 national social-welfare hotline https://www.msociety.go.th/ — Hotline 1300
Office of the Consumer Protection Board (OCPB)สำนักงานคณะกรรมการคุ้มครองผู้บริโภค Consumer Protection Act 1979 + Direct Sales and Direct Marketing Act 2545 (2002) https://www.ocpb.go.th/ — Hotline 1166
Office of the Attorney General (OAG)สำนักงานอัยการสูงสุด Public prosecution; Central Authority for Mutual Assistance in Criminal Matters https://www.ago.go.th/
Administrative Court of Thailandศาลปกครอง Administrative review of PDPC decisions https://www.admincourt.go.th/
Constitutional Court of the Kingdom of Thailandศาลรัฐธรรมนูญ Constitutional review under Section 213 https://www.constitutionalcourt.or.th/
National Human Rights Commission of Thailand (NHRCT)คณะกรรมการสิทธิมนุษยชนแห่งชาติ Independent human-rights commission https://www.nhrc.or.th/
Office of the Ombudsman of Thailandสำนักงานผู้ตรวจการแผ่นดิน Ombudsman investigation of state-agency action https://www.ombudsman.go.th/
Thai Hotline (Internet Foundation for the Development of Thailand) INHOPE-member CSAM hotline https://www.thaihotline.org/
ChildLine Thailand Foundationมูลนิธิสายเด็ก Children's helpline NGO https://www.childlinethailand.org/ — Hotline 1387
ECPAT Foundation Thailandมูลนิธิเอกพัตร CSAE prevention NGO https://www.ecpat-thailand.org/
Hug Project Thailand CSAE survivor support + prevention https://www.hugproject.org/
Samaritans of Thailand Emotional support hotline https://www.samaritansthai.com/ — Hotline +66 2 713 6793 (English/Thai)
Childline 1387 Toll-free 24/7 children's helpline operated by ChildLine Thailand Foundation dial 1387 (toll-free within Thailand)
MSDHS Hotline 1300 24/7 social-welfare hotline (children + women + family-violence) operated by MSDHS dial 1300 (toll-free within Thailand)
OCPB Hotline 1166 24/7 consumer-protection hotline operated by OCPB dial 1166 (toll-free within Thailand)

3.4 The DPO

PDPA Thailand Section 41 (in force from 1 June 2022) + the PDPC DPO Notification 2022 of 14 December 2022 in operation from 13 June 2023 require every data controller and data processor falling within the Section 41 criteria to appoint a Data Protection Officer (DPO). The criteria include (3) the core activity of the data controller or data processor is the collection / use / disclosure of sensitive personal data under Section 26 — although Balance does NOT process sensitive personal data of Thai residents, the PDPC DPO Notification 2022 explicitly references processing of personal data of children as a category warranting DPO designation on the most-protective reading; Balance's processing of children's personal data of Thai-resident kids accordingly engages the DPO mandate on the most-protective reading and Balance appoints a DPO. The DPO must be readily accessible, must be reachable by data subjects and by the PDPC, and the DPO's contact details must be publicly available under Section 41(4).

The Balance DPO is:

The DPO's business contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying PDPA Thailand Section 41(4) + the PDPC DPO Notification 2022. The DPO is the contact point for the PDPC on any regulatory matter and for data subjects on rights-exercise matters. The DPO need not be a Thai citizen or resident but must be readily accessible during Thai business hours per the PDPC DPO Notification 2022.


The PDPA Thailand is a consent-and-purpose-limitation regime modulated by the Section 24 alternative-bases catalogue (performance of contract / legal obligation / vital interest / public-task / legitimate interest). Balance processes personal data of Thai residents on the following PDPA Thailand mapping:

Processing purpose PDPA Thailand basis Cross-reference
Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) Section 19 parent's consent given for the specific and lawful purpose + Section 24(3) performance-of-contract necessity + Section 23 transparency notice + Section 21 purpose limitation + Section 22 data minimisation + Section 37(1)/(2) security H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex
Process the kid's personal data Section 19 parent's consent given on behalf of the kid under CCC Section 21 minor-capacity doctrine + Section 1566 parental power + CCC Section 1571 specific legal representation + the PDPC Notification on Children's Data (forthcoming subordinate legislation queued under PDPA Thailand Section 20 — § 18 versioning protocol) + Section 23 + Section 24(3) § 7 of this Annex; our Data Protection Impact Assessment § 6
Deliver operational alerts Section 19 + Section 23 (primary purpose) H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access Section 37(1) security obligation + PDPC Security Notification 2022 + Section 24(2) (legitimate interest of controller) + Section 24(4) (compliance with legal obligation) + Section 24(1) (vital interest of data subject) H7 PA-15; § 13 below
Comply with legal, regulatory, and supervisory obligations Section 24(4) (necessary for compliance with any legal obligation to which the controller is the subject) § 13 below; M1; § 14 below
Process Verifiable Parental Consent for the kid's data Section 19 + Section 23 — collection of the parent's personal data for the primary purpose of obtaining VPC § 7 of this Annex; A-US § 5
Process the parent's billing / subscription data Section 24(3) performance-of-contract necessity; CPA Thailand + DSDMA + UCTA + CCC consumer-protection overlay in § 16 below H4; § 16 below

Balance does not process sensitive personal data under PDPA Thailand Section 26 (categories: racial or ethnic origin / political opinions / religious or philosophical beliefs / sexual behaviour / criminal records / health data / disability / trade-union information / genetic data / biometric data / other data which similarly affects the data subject in the same manner as prescribed by the PDPC) in respect of any Thai resident.

Balance does not collect any Thai national or government-issued identification number — neither the Thai national ID number (13-digit number issued under the Civil Registration Act B.E. 2534 (1991)) nor the passport number (issued under the Royal Thai Police Passport Regulations) nor the driver's licence number (issued under the Land Traffic Act B.E. 2522 (1979)). PDPC interpretive practice on collection of the Thai national ID number imposes strict purpose-limitation; Balance's posture aligns: none collected.


5. Children's rights overlay

Thailand does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the PDPA Thailand + the PDPC Notification on Children's Data (subordinate legislation queued under Section 20 — § 18 versioning protocol covers issuance); (ii) the Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 right to privacy + Section 50 state duty to protect children + Section 71 state duty to develop children; (iii) the Child Protection Act B.E. 2546 (2003); (iv) the Criminal Code child-sexual-offences chapter at Sections 277-285 + Section 287/1 + Section 287/2; (v) the Civil and Commercial Code Section 19 age of majority 20 + Section 21 minor-incapacity doctrine + Sections 1546-1574 parental power; (vi) the UN Convention on the Rights of the Child (Thailand acceded on 27 March 1992, with limited declarations subsequently withdrawn or modified) + the Optional Protocol on the Sale of Children, Child Prostitution and Child Pornography (Thailand acceded on 11 January 2006).

5.1 Definitions

For the purposes of this Annex:

Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Thai kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Thai residents itemises the categories of personal data being processed, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the PDPA Thailand + Constitution of the Kingdom of Thailand B.E. 2560 (2017) Section 32 + the established Thai privacy doctrine.

Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of the PDPA Thailand + the forthcoming PDPC Notification on Children's Data + the CCC Section 21 minor-incapacity doctrine + the Child Protection Act B.E. 2546 (2003).

5.4 No advertising directed at children

Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising data file of any user. This is consistent with: (i) the PDPA Thailand Section 32 right to object to direct-marketing processing; (ii) the Direct Sales and Direct Marketing Act B.E. 2545 (2002); (iii) the Consumer Protection Act B.E. 2522 (1979) Chapter III prohibition on misleading advertising — including Section 22 prohibition on advertising that is unfair to consumers + Section 23 prohibition on advertising that may cause harm to the consumer + Section 27 prohibition on advertising directed at children that exploits children's lack of experience; (iv) the Child Protection Act B.E. 2546 (2003) Section 26(4) prohibition on inducing children to act in a manner detrimental to body or mind. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.5 Cooperation routes

The principal Thai child-protection bodies are: (i) the Department of Children and Youth (DCY) within the MSDHS — the principal child-welfare lead agency under Child Protection Act B.E. 2546 (2003); (ii) MSDHS Hotline 1300 24/7 national social-welfare hotline; (iii) the Royal Thai Police TICAC + the Royal Thai Police CCIB + the Royal Thai Police Anti-Trafficking in Persons Division; (iv) the Department of Special Investigation (DSI) for transnational CSAE; (v) the ChildLine Thailand Foundation — Hotline 1387 24/7 children's helpline; (vi) the Thai Hotline (Internet Foundation for the Development of Thailand) — INHOPE-member CSAM hotline; (vii) the ECPAT Foundation Thailand — CSAE prevention NGO; (viii) the Hug Project Thailand — CSAE survivor support; (ix) the Samaritans of Thailand — emotional-support hotline; (x) the National Human Rights Commission of Thailand (NHRCT). Balance cooperates with each on incidents involving Thai kids — see § 14 below.


6. PDPA Thailand rights catalogue

6.1 The rights catalogue

A Thai resident has the following rights under the PDPA Thailand + the PDPC Rights Notification 2023 as in force at the Effective date.

6.2 Timeline

Where the data-access carve-outs at PDPA Thailand Section 30 paragraph 2 + Section 25 apply (national security / prevention or detection of crime / regulatory enforcement / professional confidentialities), Balance may decline to provide access and explain the reasons.

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.

6.4 Fees

PDPA Thailand Section 30 paragraph 3 + the PDPC Rights Notification 2023 permit the data controller to charge a reasonable fee for processing a data access request in the circumstances where the request is manifestly unfounded or excessive, in particular because of its repetitive character. Balance does not charge for access in practice.

6.5 Language

A request may be submitted in Thai or English. The PDPC accepts complaints in Thai and English (Thai is preferred for PDPC procedural materials).


7. Children's data — PDPA Thailand + Child Protection Act + Civil and Commercial Code

Balance processes personal data of Thai kids under the following layered framework:

For Balance:

A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


8. International data transfers from Thailand — PDPA Thailand Section 28 + Section 29 + the PDPC Cross-Border Notifications 2023

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Thai resident's personal data leaves Thailand at the point of being uploaded to the Balance backend.

8.1 The Thailand-to-US transfer mechanism — PDPA Thailand Section 28 (adequacy) + Section 29 (safeguards) + the PDPC Cross-Border Notifications 2023

PDPA Thailand Section 28 sets out the adequacy-based transfer mechanism: a data controller may transfer personal data to a foreign country where the receiving country has adequate standards of personal data protection as designated by the PDPC. The PDPC Cross-Border Notification 2023 — Section 28 Adequacy of 12 December 2023 (in operation from 24 March 2024) sets out the adequacy assessment methodology. At the Effective date, the PDPC has not designated any foreign country as adequate. Accordingly Balance does not rely on Section 28.

PDPA Thailand Section 29 sets out the safeguards-based transfer mechanism in the absence of Section 28 adequacy. Under Section 29 read with the PDPC Cross-Border Notification 2023 — Section 29 Safeguards of 12 December 2023 (in operation from 24 March 2024), a controller may transfer personal data to a foreign country on the following grounds:

Balance relies on the following stack to satisfy PDPA Thailand Section 29 + the PDPC Cross-Border Notification 2023 — Section 29 Safeguards:

8.2 The Thailand-to-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country and is not designated as adequate by the PDPC under Section 28, the Thailand-KZ axis is covered by the PDPA Thailand Section 29(3) written contracts with PDPC-standard safeguards + Section 29(2) parent's consent overlay + Section 29(3) performance-of-contract necessity — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance + ASEAN Model Contractual Clauses substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.

8.3 PDPA Thailand RoPA registration

PDPA Thailand Section 39 (Records of Processing Activities of the data processor) + Section 37(4) (Records of Processing Activities of the data controller) + the PDPC RoPA Notification 2022 require data controllers and data processors to prepare and maintain a Record of Processing Activities for inspection by the PDPC. There is no public RoPA registration regime under the PDPA Thailand (the RoPA is an internal record available for PDPC inspection on request). Balance maintains the internal RoPA at our Records of Processing Activities (Article 30).

8.4 APEC CBPR overlay (context-setting)

Thailand is not currently an APEC CBPR participating economy at the Effective date (Thailand has indicated interest but has not formally joined the operational CBPR system) — § 18 versioning protocol covers any change. The APEC CBPR system provides a complementary accountability framework for cross-border data transfers within the APEC region (which includes Singapore, the Philippines, the United States, Canada, Japan, the Republic of Korea, Mexico, Taiwan, Australia, and other APEC economies at the Effective date). Balance's principal operational mechanism remains the PDPA Thailand Section 29 paragraph 3 written contracts framework + the PDPC Cross-Border Notification 2023 — Section 29 Safeguards.

8.5 ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021)

Thailand is an ASEAN Member State + a signatory to the ASEAN Framework on Personal Data Protection (2016) + the ASEAN Data Management Framework. The ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021) provide a recommended-form contractual-clauses template usable across ASEAN Member States. Balance's sub-processor agreements incorporate the substance of the ASEAN Model Contractual Clauses as a substantive overlay (see our international-transfer pack § 6).


9. Data residency for Thai residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Thai resident's personal data held in Thailand? No. Every Thai resident's personal data is held in the United States. The PDPA Thailand Section 29(3) written contracts + Section 29(2) parent's consent + Section 29(3) performance-of-contract necessity stack in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements.
Is there a Thai establishment? No. Balance has no permanent establishment in Thailand. The PDPA Thailand's territorial reach (Section 5(2)(a) offer-of-services-to-Thai-residents limb) is the basis for Balance's PDPA Thailand compliance.
Where is the supervisory authority? Thailand — PDPC + PDPC Office + the regulatory bodies in § 3.3 above.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Thailand does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Bank of Thailand directives on outsourcing by Thai banks — not applicable to Balance; the Securities and Exchange Commission Thailand directives — not applicable to Balance; certain Ministry of Public Health directives on healthcare data localisation under the National Health Act B.E. 2550 (2007) — not applicable to Balance).


10. Sub-processors touching Thai-resident data

Sub-processor Role Location of processing Thai transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States PDPA Thailand Section 29(3) written processor agreement with PDPC-standard safeguards + Section 29(2) parent's consent on file per our international-transfer pack § 6; E2EE supplementary measure for proof media; ASEAN Model Contractual Clauses substance.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) PDPA Thailand Section 29(3) written processor agreement (Google Cloud Data Processing Addendum) + Section 29(2) consent; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) PDPA Thailand Section 29(3) written processor agreement (Google Cloud Data Processing Addendum) + Section 29(2) consent; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to Thai kid + parent devices United States PDPA Thailand Section 29(3) + Section 29(2) as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States PDPA Thailand Section 29(3) + Section 29(2) as above.
Google LLC — Google Play Billing Processes subscription purchases United States PDPA Thailand Section 29(3) + Section 29(2) + Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to Thai parent users United States PDPA Thailand Section 29(3) + Section 29(2).

Every sub-processor is bound by a written data-processing agreement under PDPA Thailand Section 40 that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + PDPA Thailand Section 37(1)/(2) + the PDPC Security Notification 2022. The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.


11. Breach notification — PDPA Thailand Section 37(4) + PDPC Breach Notification 2022

PDPA Thailand Section 37(4) + the PDPC Breach Notification 2022 of 14 December 2022 (in operation from 13 June 2023) is the principal breach-notification regime. The Thai regime requires PDPC notification without undue delay, where feasible within 72 hours from awareness of a personal data breach:

Audience Trigger Deadline Channel
PDPC A personal data breach has occurred — defined by the PDPC Breach Notification 2022 as a breach of security leading to the unlawful or unauthorised loss / access / use / amendment / correction / disclosure of personal data — that is likely to result in a risk to the rights and freedoms of natural persons (and the PDPC Breach Notification 2022 makes notification voluntary for breaches that are unlikely to result in a risk). Without undue delay, where feasible within 72 hours from awareness of the personal data breach. Awareness is the time at which the controller has a reasonable degree of certainty that a personal data breach has occurred. Balance internal anchor: as soon as practicable but no later than 72 hours from initial discovery. PDPC Office online Personal Data Breach Notification portal + by email to pdpc@pdpc.or.th
Affected individuals A personal data breach as above where, on the PDPC Breach Notification 2022 harm-likelihood analysis, the breach is likely to result in a high risk to the rights and freedoms of natural persons (e.g., financial loss / identity theft / reputational damage / loss of confidentiality of personal data protected by professional secrecy / unauthorised reversal of pseudonymisation / any other significant economic or social disadvantage). As soon as practicable after PDPC notification, with carve-outs in the PDPC Breach Notification 2022 (where the data has been rendered unintelligible — e.g., the E2EE ciphertext case — affected-individual notification may not be warranted; where the controller has taken subsequent measures eliminating the high risk; where direct notification would involve disproportionate effort). Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English, with a Thai version queued for the Phase-2 locale rollout.
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). TICAC + CCIB + DCY + MSDHS Hotline 1300 + ThaiCERT.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, formal assessment under PDPA Thailand Section 37(4) + the PDPC Breach Notification 2022 completed within 48 hours of discovery for risk-to-rights-and-freedoms escalation, PDPC notification within the 72-hour statutory window, affected-individual notification per the high-risk analysis.

11.1 Minimum content of the PDPC notification (PDPC Breach Notification 2022)

The PDPC notification states: - the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects concerned, and the categories and approximate number of personal data records concerned; - the name and contact details of the DPO (, named individual: ) — the contact from whom the PDPC may obtain additional information; - the likely consequences of the personal data breach; - the measures taken or proposed to be taken to address the personal data breach (including measures to mitigate possible adverse effects).

The English-language template lives in our breach-notification runbook § 8.1. A Thai version is queued for Phase 2 locale rollout.

11.2 Non-compliance — PDPA Thailand Chapter VI penalties

11.3 Concurrent Cybersecurity Act / ThaiCERT notification

For incidents involving cybersecurity attacks on the controller's systems, the Cybersecurity Act B.E. 2562 (2019) notification regime applies only to designated CII operators. Balance is NOT designated as Critical Information Infrastructure under the Act. Voluntary cooperation with ThaiCERT (the national CERT within NCSA) is honoured as a best-effort security overlay.


12. Cookies, spam, and electronic direct marketing

Thailand does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) PDPA Thailand Section 19 + Section 23 + Section 27 for any cookie that processes personal data; (ii) the PDPC's interpretive position on cookies in PDPC guidance and the PDPC Rights Notification 2023; (iii) the Direct Sales and Direct Marketing Act B.E. 2545 (2002) for direct-marketing-defined communications; (iv) PDPA Thailand Section 32 right to object to direct-marketing processing; (v) the Consumer Protection Act B.E. 2522 (1979) Chapter III advertising rules.

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send direct-marketing communications within the meaning of the Direct Sales and Direct Marketing Act B.E. 2545 (2002) to Thai residents. The only email Balance sends to Thai parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. The DSDMA's direct marketing definition turns on the active-outbound-solicitation element; transactional messages are outside the definition. If Balance ever introduces a marketing channel, we will comply with the DSDMA registration regime + PDPA Thailand Section 19 prior consent + PDPA Thailand Section 32 right to object + the Consumer Protection Act Chapter III advertising rules including Section 22 fairness and Section 27 protection of children.

12.4 No telemarketing

Balance does not place telemarketing voice calls, SMS, or messaging-app outreach to Thai residents.


13. Lawful-access requests and the encryption posture

Thai authorities may serve a lawful-access request on Balance via:

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. CSAE reporting routes — Thailand

A Thai resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

A Thai resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Subject matter Address / URL
Office of the Personal Data Protection Committee (PDPC Office) PDPA Thailand 120 Mueang Thong Thani, Chaengwattana Road, Pak Kret District, Nonthaburi 11120; https://www.pdpc.or.th/; +66 2 142 1033; pdpc@pdpc.or.th
Ministry of Digital Economy and Society (MDES) PDPC Office parent ministry The Government Complex, Building B, 6th-9th Floor, Chaengwattana Road, Thung Song Hong, Lak Si, Bangkok 10210; https://www.mdes.go.th/; +66 2 141 6747
Administrative Court of Thailand Administrative review of PDPC decisions https://www.admincourt.go.th/
Constitutional Court of the Kingdom of Thailand Constitutional review under Section 213 (state action) https://www.constitutionalcourt.or.th/
Electronic Transactions Development Agency (ETDA) Digital Platform Services Royal Decree B.E. 2565 (2022) administration https://www.etda.or.th/; +66 2 123 1234
National Cyber Security Agency (NCSA) / ThaiCERT Cybersecurity Act administration; national CERT https://www.ncsa.or.th/; https://www.thaicert.or.th/
Royal Thai Police — TICAC + CCIB CSAE + cybercrime https://www.royalthaipolice.go.th/; emergency 191; Tourist Police 1155
Department of Special Investigation (DSI) Special-case investigation including transnational CSAE https://www.dsi.go.th/; Hotline 1202
Ministry of Social Development and Human Security (MSDHS) Child Protection Act B.E. 2546 (2003) lead ministry; Hotline 1300 https://www.msociety.go.th/; Hotline 1300
Department of Children and Youth (DCY) Child Protection Act 2003 child-welfare lead agency https://www.dcy.go.th/
Office of the Consumer Protection Board (OCPB) Consumer Protection Act 1979 + Direct Sales and Direct Marketing Act 2545 (2002) https://www.ocpb.go.th/; Hotline 1166
National Human Rights Commission of Thailand (NHRCT) Independent human-rights commission https://www.nhrc.or.th/
Office of the Ombudsman of Thailand Ombudsman investigation of state-agency action https://www.ombudsman.go.th/
Provincial Court / Civil Court / Criminal Court PDPA Thailand Chapter V civil liability + Chapter VI criminal complaints; Child Protection Act + Criminal Code prosecutions via https://www.coj.go.th/
Court of Appeal Appellate review via https://www.coj.go.th/
Supreme Court of Justice (Dika Court) Final appellate review on points of law https://www.supremecourt.or.th/

A Thai resident may always first raise the matter with us at (data access; named individual: , in his capacity as the DPO under PDPA Thailand Section 41 + the PDPC DPO Notification 2022). We will respond within the PDPA Thailand timelines. The PDPC's published policy recommends raising the matter with the data controller first but the PDPC also accepts direct complaints where the data subject demonstrates that internal-remedy exhaustion is impracticable or where the complaint involves a serious matter warranting immediate PDPC action.


16. Consumer rights — the CPA Thailand + DSDMA + UCTA + CCC overlay

The Consumer Protection Act B.E. 2522 (1979) as amended (the "CPA Thailand"), the Direct Sales and Direct Marketing Act B.E. 2545 (2002) as amended (the "DSDMA"), the Unfair Contract Terms Act B.E. 2540 (1997) (the "UCTA Thailand"), and the Civil and Commercial Code apply to Balance's subscription flow as a consumer transaction (the parent is a consumer within the CPA Thailand Section 3 definition — a person who buys or obtains the services of a business operator including a person who is invited or proposed by the business operator to purchase or obtain services). Treatment is implemented in Subscription Terms § 20.

16.1 CPA Thailand Chapter III — consumer protection in advertising + Chapter III/2 — controlled contracts

CPA Thailand Section 22 prohibits advertising that is unfair to consumers — including false statements, exaggerated statements, statements that may cause misunderstanding, statements that are obscene or against good morals, statements that are misleading, or statements that may cause damage to society or the economy. CPA Thailand Section 23 prohibits advertising that may cause harm to mental or physical health. CPA Thailand Section 27 prohibits advertising directed at children that exploits children's lack of experience. The Balance Terms of Service (Terms of Service) and the in-app subscription flow are drafted to avoid each Section 22 / 23 / 27 risk.

CPA Thailand Chapter III/2 (Sections 35 bis to 35 nawa) is the Controlled Contracts regime — certain categories of contract designated by the Consumer Protection Committee on Contracts are subject to mandatory-content rules + prohibitions on unfair terms. Online subscription supply for parental-control services is not currently a Controlled Contract Business (the categories presently designated include leasing of residential buildings, leasing of office space, credit cards, certain installment-sale contracts, certain education contracts, fitness club memberships, mobile-phone-service contracts, internet-service contracts, life-insurance contracts, motor vehicle leases, and condominium agreements). § 18 versioning protocol covers any future designation that captures Balance's subscription flow.

16.2 UCTA Thailand — unfair contract terms screen

UCTA Thailand Section 4 is the unfair-terms screen for standard-form / consumer / employment / lease / installment / loan / security contracts — a term that imposes an excessive burden on a party against the other, contrary to good faith / good conscience / fairness, is unenforceable to the extent of the excessive burden, with court power to determine the appropriate scope. UCTA Thailand Section 5 invalidates exclusion / limitation of liability for personal-injury or willful / gross-negligence harm. UCTA Thailand Section 6 lists specific examples of unfair terms in standard-form contracts. UCTA Thailand Section 9 lists the factors for the unfair-terms assessment (bargaining power / extent of negotiation / knowledge / nature of supply / market alternative / good faith / good conscience).

Balance's Terms of Service and Subscription Terms are drafted to comply with UCTA Thailand. Choice-of-law clauses or jurisdiction clauses that would deprive the Thai consumer of mandatory protection are subject to UCTA Thailand Section 4 + Section 6 + the public policy doctrine in Dika Court (Supreme Court) decisions on the unenforceability of foreign-jurisdiction clauses in consumer cases.

16.3 Direct Sales and Direct Marketing Act B.E. 2545 (2002) — 7-Day Right under Section 33

The DSDMA Section 33 grants a consumer who purchases goods or services from a direct sales or direct marketing operator the right to terminate the contract by giving written notice to the business operator within 7 days from the date of receiving the goods or the date of agreeing to receive the services. Section 34 sets out the manner of exercise + refund obligations + return obligations.

The DSDMA's application to online subscription supply outside the direct marketing definition is uncertain. The direct marketing concept turns on the active-outbound-solicitation element. Where the consumer affirmatively initiates the transaction via the Google Play Store listing (as for Balance), Thai legal commentary is divided on whether the DSDMA captures the transaction. The conservative position — adopted by Balance — is to assume DSDMA application where the consumer is in Thailand and to honour the 7-Day Right + manner-of-exercise rules.

16.4 Voluntary 14-day no-questions refund — exceeds DSDMA 7-Day Right

Balance honours a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the DSDMA 7-Day Right by 7 days. The 14-day refund window is documented at Subscription Terms § 20.

16.5 CCC — capacity-of-minors framework + Age of Majority

Under CCC Section 21 + CCC Section 19, a kid (under 20) cannot enter into a binding contract without the consent of the legal representative; a contract made by a minor without that consent is voidable (subject to Section 22 carve-outs for acts that are merely beneficial to the minor / suitable to the minor's condition / appropriate to ordinary household life of the minor). The subscription contract is between Balance and the parent (who is 20+ — the CCC age of majority). The kid is a beneficiary of the service supplied to the parent. Balance does not contract directly with kids.

16.6 CCC tort framework — privacy and personality rights

CCC Section 420 is the general tort provision — a person who wilfully or negligently and unlawfully injures the life / body / health / liberty / property / right of another shall be liable to make compensation. CCC Section 421 addresses intentional injury (a person who wilfully causes damage to another in a manner contrary to good morals shall be liable to make compensation). CCC Section 423 addresses defamation. The Dika Court (Supreme Court of Justice) has applied Sections 420 + 421 + 423 to privacy violations including unauthorised disclosure of personal data + unauthorised publication of personal images + invasion of communicational privacy.

16.7 Consumer Class Action mechanism

CPA Thailand (as amended) + the Civil Procedure Code Sections 222/1-222/49 establish the consumer class action mechanism — a representative consumer may file a class action on behalf of similarly-situated consumers; certified by the Civil Court Class Action Division. Applicable to PDPA Thailand civil-liability claims under Sections 77-78 (although the more specific PDPA Thailand civil-liability framework controls; class-action mechanism remains available where consumer-protection grounds are also engaged).

16.8 Forum and choice of law

The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace CPA Thailand / DSDMA / UCTA Thailand / PDPA Thailand to the prejudice of the Thai consumer are subject to UCTA Thailand Section 4 + the Conflict of Laws Act B.E. 2481 (1938) Section 13 (public-policy reservation) + the public policy doctrine recognised by Thai courts.


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of Thailand Country Annex.

← Back to Privacy Policy · Children's Privacy Notice