Skip to Content

How Odoo Supports PDPA Compliance in Thailand

July 7, 2026 by
Elevanta Marketing

PDPA compliance in Thailand isn't optional anymore; it's actively enforced with real financial penalties. As of early 2026, the PDPC has recorded 2,672 complaints and issued THB 21.5 million in fines. The grace period is gone. And Odoo has the built-in tools to protect your business before the next inspection.

This is for business owners, HR managers, and ops teams in Bangkok, Si Racha, and those who store customer or employee data, and want to know exactly how Odoo helps.

What Is Thailand's PDPA?

Thailand's Personal Data Protection Act was passed in 2019 and has been fully enforced since June 2022. It covers every business collecting, using, or disclosing personal data of anyone, locally and internationally.

What Counts as Personal Data?

More than most businesses realize. Names, email addresses, phone numbers, IP addresses, salary records, customer order history, and cookie identifiers are all personal data under PDPA. If it identifies a person, it's covered.

Who Must Comply?

No size exemption exists. A small clinic and a large retailer face the same obligations. If your business collects customer data or employs staff, PDPA applies to you.

Does your business collect customer names, emails, or order history? Then PDPA applies. Full stop.

What Does PDPA Compliance Mean for Your Business?

Compliance comes down to four core obligations every business must meet.

4 Core PDPA Obligations

  • Get valid consent before collecting personal data, explicit, not implied

  • Tell people why you're collecting their data; the purpose must be stated clearly

  • Let them access, correct, or delete their data when they request it

  • Report data breaches within 72 hours of discovery

Do You Need a DPO?

The October 2025 Royal Gazette made a Data Protection Officer mandatory for state agencies and required for private businesses processing personal data at large scale. Many local SMEs now need a designated DPO or compliance officer responsible for PDPA compliance in Thailand internally. Up to THB 5,000,000 administrative fine. Up to THB 1,000,000 criminal fine. Imprisonment is possible for individuals who directed violations.

Why the 2026 PDPA Update Matters

This is where most businesses underestimate the risk.

Enforcement Is Now Real

THB 21.5 million in fines issued in August 2025. 2672 complaints filed by January 2026. The PDPC Eagle Eye unit now actively monitors the dark web and social media platforms for data leaks and initiates investigations proactively. Businesses aren't just being reported by customers anymore. Fines and penalties are happening without any complaint being filed.

Priority Sectors Being Watched

The PDPC's 2026 focus areas: Odoo e-commerce integration, healthcare, telecommunications, and public services. If you're in retail, wholesale, or healthcare, you're in the active enforcement zone.

Third-party due diligence is now a legal shield, not an optional best practice. Data Controllers are being held liable for security failures of their vendors. Cross-border data transfer rules under Sections 28–29 are now fully enforceable. This in 2026 means your entire supply chain of data processors needs scrutiny, not just your internal systems.

How Odoo Supports PDPA: Built-In Features

Odoo alone can't guarantee full PDPA compliance; compliance covers your whole organization, not just your software. But Odoo provides the technical foundation that makes Odoo ERP implementation PDPA compliance achievable without a large IT team.

Here's what Odoo covers out of the box:

  • Role-based access control: restrict who sees what personal data

  • Consent checkboxes: via Odoo Studio, capture explicit consent per purpose

  • Full audit trail logging: every user action recorded and timestamped

  • Data export tools: respond to subject access requests quickly

  • Data deletion: process erasure requests within Odoo directly

  • ISO 27001 + GDPR-aligned security: the exact standards PDPA is modelled on

Each of these features gets its own dedicated section below. PDPA compliance for Thai businesses is a technical challenge, but Elevanta has seen Odoo solve every part of it. And Odoo PDPA Thailand setups work across every business type from wholesale distributors in Si Racha to healthcare management providers in Thailand.

Access Control: Who Sees What in Odoo

PDPA says only authorized people should access personal data. If your sales rep can view HR salary records, that's a PDPA violation in the making.

How Odoo Handles It

Group-based access control restricts each department to its own data. HR personnel see HR records. The sales team sees CRM contacts. Finance sees invoices. Nobody crosses into data they don't need for their job.

Set up in Practice

Go to Settings → Users & Companies → Groups.

Assign roles per department. Passwords use industry-standard secure hashing. External login supports OAuth 2.0 and LDAP. Odoo access control configuration done right from day one prevents the most common PDPA data access violations before they happen.

PDPA vs GDPR vs CCP: Quick Comparison

If you've heard of GDPR, PDPA will feel familiar. But there are differences worth knowing before you assume existing compliance covers you here.

Feature

PDPA Thailand

GDPR Europe

CCPA California

Who it covers

Any business with local data subjects

Any business with EU data subjects

Businesses serving California residents

Max admin fine

THB 5,000,000

€20,000,000

USD 7,500 per violation

Consent type

Explicit, purpose-specific

Explicit, purpose-specific

Opt-out right

Data subject rights

Access, correct, delete, port

Access, correct, delete, port, restrict

Know, delete, opt-out

DPO required

Large-scale processing

Large-scale processing

Not required

Breach notification

72 hours to PDPC

72 hours to the authority

ASAP to affected individuals

PDPA is closest to GDPR. Already GDPR-compliant? PDPA won't feel completely foreign. But local nuances, biometric data rules, local enforcement patterns, and the local ERP compliance context still need local expert attention.

Consent Management: Collecting Data the Legal Way

Most businesses still rely on a single "I agree to terms" checkbox, assuming it covers every type of data collection. Under PDPA, that isn't enough. Consent must be explicit, purpose-specific, and properly recorded. Marketing emails, website analytics, and order processing each require separate consent, and combining them into one checkbox can put your business at risk of non-compliance.

With Odoo Studio, businesses can easily create separate consent checkboxes for each purpose without custom development. Whether it's a website contact form, CRM lead capture page, or email marketing signup, Odoo records and stores every consent directly within the customer's profile, making compliance simple and auditable. If your website still uses a single consent checkbox, it's time to review your setup for PDPA compliance.

Audit Trails: Your Proof of Compliance

The PDPC Eagle Eye unit monitors the dark web for leaked data. If they find your customer data online before you've reported a breach, the investigation starts automatically, not after a complaint.

What Odoo Logs

Every user action. Every data change. Every export. Every login attempt. All timestamped. All user-attributed. Nothing can be deleted without admin-level access. Regulators can see exactly who accessed what personal data and precisely when. Odoo audit trail data compliance isn't an optional module; it runs automatically across every record in your system.

The 72-Hour Breach Notification

The 72-Hour Breach Notification PDPA requires breach reporting within 72 hours.

Odoo's audit logs give you everything needed to write that report immediately: what data was involved, who had access, and when the breach window opened. Elevanta pairs both during implementation.

Right to Be Forgotten: Data Deletion in Odoo

Under PDPA, any person can request that their personal data be deleted. Your business must respond and act. Ignoring the request = clear violation.

Practical Step-by-Step in Odoo

  1. Customer submits deletion request

  2. Search their contact record in Odoo

  3. Export their record as CSV, for your own compliance file

  4. Archive or delete the contact from Odoo

  5. Log the action with date and requester details in your compliance register

These requests in Odoo don't need a developer. The tools are already there. What most businesses are missing is the process for handling requests consistently.

PDPA for Employee Data: The Gap Most Businesses Miss

Every competitor's PDPA guide focuses on customer data. Almost none of them mention employee data. But PDPA covers it too. Salary records, attendance data, health information, personal contact details, and performance reviews are all personal data under the same law. Your HR system carries as much PDPA risk as your CRM.

How Odoo HR Protects It

Sensitive employee data is restricted to the HR group only. Contracts, payslips, and private records aren't visible to your sales or warehouse teams. Role-based access and full audit logs apply to the HR module identically to customer data.

PDPA employee data protection in Thailand is where most businesses are currently non-compliant without knowing it. Their customer data is locked down. Their HR data is visible to anyone with general system access. Odoo fixes this with proper group configuration, and it takes less than a day to set up correctly.

How Elevanta Sets Up Odoo for PDPA

PDPA compliance doesn't start with a software setting. It starts with a data audit.

Elevanta is an Official Odoo Ready Partner based in Thailand. Before touching any Odoo configuration, we map every personal data flow in your system where customer data enters, who touches it, how long it's stored, how deletion requests get processed, and which staff have access to what. Then we configure your PDPA settings in Odoo to match your actual data reality. Not a generic template. A setup built around how your business operates.

Conclusion

PDPA is here. Fines are real. 2,672 complaints and counting across the country. The right PDPA compliance in Thailand foundation starts with clean data flows, proper access controls, and a system that logs every action automatically. Odoo does all three when it's configured correctly.

Ready to make your Odoo system ready for PDPA compliance in Thailand? Elevanta audits your data flows and sets up access controls for businesses in Si Racha, Bangkok, and across the rest of Thailand. Book your free consultation today.

FAQs

Q1. How does Odoo help with PDPA compliance in Thailand?

Odoo provides role-based access control, consent management tools, full audit trails, data export for subject access requests, and data deletion for erasure requests, all built in. Paired with proper configuration, it covers the core technical requirements of PDPA compliance in Thailand businesses face.

Q2. How much is the PDPA fine in Thailand in 2026?

Up to THB 5,000,000 for administrative violations and up to THB 1,000,000 for criminal violations. Individuals who directed violations may also face imprisonment. THB 21.5 million in fines was issued in August 2025 alone.

Q3. Does Odoo store personal data securely for local businesses?

Yes. Odoo meets ISO 27001 and GDPR standards, and the exact framework of PDPA is modelled. Password hashing, OAuth 2.0 authentication, encrypted data storage, and role-based access are all standard in Odoo.

Q4. What should an Odoo PDPA compliance checklist for Thai businesses include?

 Enable role-based access per department, add purpose-specific consent checkboxes via Odoo Studio, verify audit logging is active, document your data deletion process, and restrict HR data to HR-group users only. Elevanta reviews all five in every PDPA setup.


Q5. Does PDPA apply to employee data in Thailand?

Yes, fully. Salary records, attendance, health data, and personal contact details are all personal data under PDPA. Most focus only on customer data and leave their HR system unprotected. Odoo HR's group-based access control addresses this directly.

How We Fixed 5 Failed Odoo Implementations in Thailand