
If you run a website in Thailand and use Google Analytics, Facebook Pixel, or even a login system — you are processing the personal data of your visitors. That activity falls under the Personal Data Protection Act B.E. 2562, known as PDPA. This article explains from start to finish what PDPA is, what your website needs to do, and how AsiaGB handles it all.
What Is PDPA?
PDPA stands for Personal Data Protection Act. It is Thailand's personal data protection law, published in the Royal Gazette on 27 May 2019 and fully effective since 1 June 2022.
Its primary inspiration is the EU's GDPR (General Data Protection Regulation), the world's most stringent data protection law. Thailand's PDPA follows the same principles but is adapted to the Thai context.
Personal data means any information that can identify a natural person — directly or indirectly — such as a name, email address, phone number, IP address, browsing behaviour, or cookies that can be linked to an identity.
Who Must Comply With PDPA?
PDPA applies to every organisation and individual that collects, uses, or discloses personal data of natural persons located in Thailand — regardless of whether the organisation itself is based in Thailand. If your website has Thai users, you fall under this law.
- Business website owners — collecting member, customer, or prospect data
- Online shops — collecting order information and delivery addresses
- Blogs and online media — using Analytics to track visitors
- Mobile and web applications — collecting user data
- Organisations and government agencies — collecting citizen data
What Are Cookies and What Types Exist?
A cookie is a small text file that a website stores in the user's browser to remember certain information — such as login status, user preferences, or browsing behaviour.
| Type | Purpose | Consent Required? |
|---|---|---|
| Strictly Necessary | Session login, CSRF tokens, shopping cart — the website cannot function without them | No |
| Analytics | Google Analytics, visitor statistics, page speed measurement | Yes |
| Marketing | Facebook Pixel, Google Ads, Remarketing, targeted advertising | Yes |
| Preferences | Language, theme, or font size chosen by the user | Recommended |
PDPA and Cookies — What Does Your Website Need to Do?
Section 19 of PDPA states that collecting personal data requires prior consent from the data subject. Section 24 permits processing without consent in specific situations — such as fulfilling a contract or pursuing a legitimate interest.
Section 19 PDPA: "The data controller must obtain consent from the data subject prior to or at the time of collection, unless sections 24 or 26 provide otherwise."
What a Legally Compliant Cookie Consent System Must Include
- Notify users before cookies are activated — not after the page has already loaded
- Clearly explain what data is collected and why
- Make it as easy to decline as it is to accept
- Allow users to withdraw consent at any time
- Keep a Consent Log as evidence for audits
- Provide a link to a complete Privacy Policy
- Do not use pre-checked boxes or dark patterns to force acceptance
- Do not load Analytics cookies before obtaining consent
How AsiaGB Handles PDPA
AsiaGB chose to build its own Cookie Consent system rather than depend on a foreign third-party vendor. The two main reasons: full control over data and native Thai-language support from day one.
The System Meets Every Legal Requirement
🛡️ Blocked Before Consent
Google Consent Mode v2 sets analytics_storage=denied by default. GA4 records nothing until the user clicks "Accept."
🌐 2 Languages, Automatic
The banner displays Thai on TH pages and English on EN pages — detected automatically from the HTML lang attribute with no extra configuration needed.
📋 Complete Consent Log
Every action is written to MySQL with UTC timestamp, choice, policy version, language, page URL, anonymised IP, and UA hash.
↩️ Withdrawal at Any Time
A "Manage Cookies" link in the footer of every page lets users change their mind. The system logs "withdraw" and "re-accept" events separately from the initial consent.
📅 Stored for 1 Year
Consent logs are retained for 365 days so AsiaGB can produce evidence if the PDPC receives a complaint or conducts an inspection.
🏢 Covers All Domains
The same system works across both asiagb.com and billing.in.th (WHMCS). All logs feed into a single database with a referrer column for per-site reporting.
Data Stored per Consent Event
| Field | Data | Reason |
|---|---|---|
ts | UTC timestamp of consent | Legal evidence |
choice | accept / decline / withdraw / re-accept | Unambiguous consent state |
version | Consent form version | Track form changes |
policy_ver | Privacy Policy version | Know which policy the user saw |
lang | Language shown on banner | Confirm the user understood the text |
page | URL of the page where consent was given | Context of consent |
categories | Cookie categories consented to | Define the scope of consent |
ip_anon | IP /24 prefix only (e.g. 171.6.129.0) | Not personally identifiable, but confirms device |
ua_hash | User-Agent SHA-256 hash | Confirms real browser, not a bot |
referrer | Referring domain only (e.g. billing.in.th) | Per-site breakdown in reports |
AsiaGB's Privacy Policy
Beyond the consent system, AsiaGB maintains a Privacy Policy written to full PDPA standards, covering every topic the law requires:
- Data Controller — clearly identified as Injan Network, operator of asiagb.com and billing.in.th
- Data Collected — separated into data provided directly (registration) and data collected automatically (Analytics)
- Purpose and Legal Basis — each processing activity is mapped to a Legal Basis under PDPA Section 24
- Retention Period — customer accounts: 7 years after contract end; Analytics: 90 days
- Data Subject Rights — all 8 rights under PDPA including the right to erasure
- Complaint Channel — email, Line, and support ticket with a 30-day response commitment
A Checklist for Thai Website Owners
If you run a website and have not yet dealt with PDPA compliance, here is the minimum checklist to work through:
- Identify which cookies your site uses (DevTools → Application → Cookies)
- If you use Google Analytics → you need a consent system before it loads
- Use Google Consent Mode v2 so GA4 starts in denied mode
- Show a banner before any analytics cookies fire
- Make "Decline" as easy to click as "Accept"
- Store a Consent Log as evidence
- Add a "Withdraw Consent / Manage Cookies" link on every page
- Write a Privacy Policy that is comprehensive and easy to find
- If you use Facebook Pixel or Google Ads → you also need Marketing consent
- If you collect data from minors (under 20 in Thailand) → parental consent is required
Penalties for Non-Compliance With PDPA
PDPA provides for civil, criminal, and administrative penalties. In summary:
- Administrative fine — up to 5,000,000 THB per violation
- Criminal penalty — for certain types of breach: up to 1 year imprisonment and/or a fine of up to 1,000,000 THB
- Civil liability — compensation to the data subject plus punitive damages of up to 2× the actual loss
Note: While the penalties are significant, active enforcement is still relatively limited. That said, starting compliance today is a worthwhile investment — both for customer trust and as insurance against future risk.
Summary
PDPA is not something to fear — it is something to prepare for. Any website using Analytics needs a correct consent system, a complete Privacy Policy, and a Consent Log ready to show regulators. AsiaGB has completed all of these steps and is ready to serve customers who take their users' privacy seriously.
Great Websites Start With Great Hosting
AsiaGB provides web hosting in Thailand with a support team that understands Thai law and speaks Thai.
View Hosting Plans