When does a contract in Thailand need a data processing agreement (DPA)?
Contents · 44 subsections
- Personal data in each type of contract
- AI Governance Assessment Agreement
- AI Implementation and Automation Agreement
- AI Model Development and Fine-Tuning Agreement
- AI Model Evaluation Services Agreement
- AI Use Addendum
- API Access and Licence Agreement
- Business Asset Purchase Agreement
- Backup and Disaster Recovery Services Agreement
- Bookkeeping and Accounting Services Agreement
- Cargo Survey Services Agreement
- Cold Chain Logistics Agreement
- Commercial Photography Agreement
- Construction Project Management Agreement
- Consulting Retainer Agreement
- Cross-Border Data Transfer Agreement
- Data Analytics Services Agreement
- Data Annotation Services Agreement
- Secure Data Destruction Agreement
- Data Migration Services Agreement
- Data Processing Agreement (DPA)
- Data Sharing Agreement
- Dataset Licence Agreement
- Product Demonstration Loan Agreement
- Digital Product Licence Agreement
- Digital Replica and Synthetic Voice Licence Agreement
- Distributorship Agreement
- Domestic Transportation Agreement
- Dropshipping Agreement
- Employment Agreement
- Equipment Hire Agreement
- EV Charger Installation Agreement
- Event Management Agreement
- Export Management Services Agreement
- Facilities Maintenance Agreement
- Franchise Agreement
- Ghostwriting Agreement
- Hotel Room Allotment Agreement
- Importer of Record Services Agreement
- Cyber Incident Response Retainer Agreement
- Independent Contractor Agreement
- Influencer Marketing Agreement
- Internship Agreement
- Last-Mile Delivery and COD Collection Agreement
- 53 more contracts with notes on this topic
- Read more on this subject
- Author and sources
Almost any contract in which the other party handles your customers' or employees' data raises a personal data issue. The deciding question is whether the other party uses the data on your instructions or for its own purposes, because Thai law gives those two roles different duties. Below is what the notes to each English contract say about this.
| Found in | 96 contracts |
|---|---|
| Last updated | 2026-09-30 |
Personal data in each type of contract
AI Governance Assessment Agreement
Thailand does not yet have an AI-specific law in force. The law that already applies to most AI use is the Personal Data Protection Act, together with consumer protection, advertising and sector rules. The frameworks you selected are reference criteria agreed in the contract (Clause 3.2).
ISO/IEC 42001 is a management system standard. Only a certification body accredited for it can certify your organisation. This Assessment helps you prepare, but it is not certification (Clause 8.2).
The NIST AI Risk Management Framework is a voluntary framework. It is useful for structuring risk management, especially when customers in the United States ask about it.
The EU AI Act applies to AI systems placed on the market or used in the European Union, including by companies outside the EU. The Assessor gives an indicative risk classification only (Clause 6.3). If a system may be high-risk, take specialist EU legal advice before selling or using it there.
If a Thai AI law or binding guideline comes into force during the fieldwork, agree in writing whether to add it to the criteria (Clause 3.3).
Approve the Assessment Plan within 5 Business Days (Clause 4.1) and appoint a coordinator who can collect documents quickly (Clause 5.1).
Make an honest list of the AI tools your staff actually use, including free generative AI tools and AI features inside vendor software. Hidden use is one of the most common gaps.
Send only the evidence that is needed, and mask personal data that is not needed (Clause 5.2). The Assessor handles the rest as your data processor (Clause 14.2).
The Assessment does not include technical testing of AI systems. If you want systems tested, sign a separate agreement with written authorisation for each system (Clause 4.4).
Open this form — 790 THB
AI Implementation and Automation Agreement
- The Client is the data controller and the Implementer is its processor (Clause 16.2). Update your privacy notice to explain that customers may talk with an AI system and how their messages are used.
- If data is processed outside Thailand (…), check before Go-Live that the transfer meets the Personal Data Protection Act rules on cross-border transfers (Clause 16.3). The controller must notify the Personal Data Protection Committee of most breaches within 72 hours, which is why the Implementer must report to the Client within 48 hours.
- Do not let the AI collect health, biometric or other sensitive data unless you have explicit consent or another lawful basis (Clause 16.4).
Open this form — 990 THB
AI Model Development and Fine-Tuning Agreement
- Decide which data the model really needs. Remove or mask names, ID numbers and other personal data that the purpose does not need (Clause 4.5).
- Check your lawful basis for using the personal data to train a model. Data collected to serve customers is not automatically usable for training; you may need consent or a documented legitimate-interest assessment, and your privacy notice should mention it. A model may memorise personal data, and removing it later may require retraining (Clause 5.3).
- Sensitive personal data needs explicit consent or another basis that the Personal Data Protection Act allows for that category. Give the Developer the written confirmation required by Clause 5.4 only when you have it.
- Ask for the Base Model licence summary (Clause 3.1) and read the restrictions on commercial use, number of users and redistribution before training starts.
Open this form — 990 THB
AI Model Evaluation Services Agreement
- A Critical Finding is reported within … hours (Clause 6.2). Decide quickly whether to contain it, for example by switching off a tool or tightening access, and ask for the free re-test while the Testing Period is still running (Clause 6.3).
- Red-teaming produces harmful test content by design. It is kept by the Evaluator under strict access rules and deleted at the end (Clause 5.2). Do not circulate examples from the Report more widely than needed.
- Keep real personal data out of the test environment. If a test genuinely needs real data, sign a separate data processing agreement first (Clause 12.2).
Open this form — 790 THB
AI Use Addendum
- No personal data may go into AI tools, because AI tools may not be used for the work (Clause 4.2).- When personal data is put into an AI tool, the tool provider becomes a sub-processor. Ask the Supplier which providers are used and where they process data (Clause 4.2), and check that your privacy notice covers it.- The Supplier must remove names and other identifying details before using AI with your data (Clause 4.2). If a task genuinely needs personal data, agree it in writing first.
- If the Supplier reports an AI-related incident, decide quickly whether you must notify the Personal Data Protection Committee, which in most cases must be done within 72 hours after you become aware of the breach (Clause 10).
Open this form — 590 THB
API Access and Licence Agreement
- When you send personal data to the API, the Provider is your data processor (Clause 11.2). The Personal Data Protection Act requires a processor to act only on your instructions, keep the data secure and report breaches (section 40), and you must usually notify the Personal Data Protection Committee within 72 hours after becoming aware of a breach (section 37).Personal data you receive through the API becomes your responsibility as a separate data controller (Clause 11.2). You need your own lawful basis and must tell the individuals how you use their data.The Parties agreed that no personal data will pass through the API (Clause 11.2). If that changes, agree data protection terms before sending any. Transfers of personal data outside Thailand must meet the conditions in sections 28 and 29 of the Act.
- Do not keep API Data longer than … hours unless the Documentation allows it, and do not use it to train AI models outside the Licensee Application (Clause 3.2 and Clause 12).
Open this form — 790 THB
Business Asset Purchase Agreement
- Customer lists and databases are personal data. The Seller must confirm the basis on which the data was collected, and the Parties must inform customers of the transfer within 30 days after Completion unless the law does not require it (Clause 10.2). Do not use the data for new purposes without a lawful basis.
Open this form — 990 THB
Backup and Disaster Recovery Services Agreement
A backup that has never been restored is a hope, not a control. Restore Tests are due every … months, and a full exercise once a year (Clause 9). Take part, check that the restored systems really work, and keep the reports.
The Personal Data Protection Committee's minimum security measures expect a controller's measures to cover recovering from incidents and to keep personal data available, not only confidential. Test reports are good evidence that you have done so.
An Immutable Copy is required (Clause 4.2). Ransomware groups routinely delete backups before encrypting systems, and this copy is what survives.- You chose not to require an Immutable Copy (Clause 4.2). If an attacker takes over the backup system, the backups may be lost together with your production systems. Reconsider this before signing.
You hold the encryption keys (Clause 4.1). If they are lost, the Backup Data cannot be read by anyone. Keep a protected copy of the keys outside the systems being backed up.- The Provider holds the keys but must give you an escrow copy after the Start Date and after every key change (Clause 4.1). Store it safely, separate from your servers, and check that you actually received it.
Only the persons named in Schedule 1 can declare a Disaster (Clause 8.1). Keep the list current and make sure the Provider's emergency number is in their phones.
After ransomware, the Provider will first agree with you a clean point in time to restore to (Clause 8.3). Recovery may be slower than the RTO while that point is found; this is to avoid restoring the attacker's tools with the data.
If personal data was encrypted, deleted or copied, that is a personal data breach. As data controller you must notify the Office of the Personal Data Protection Committee without delay and within 72 hours after becoming aware of it, unless the breach poses no risk to individuals' rights and freedoms (Personal Data Protection Act section 37(4)). The Provider must tell you of any breach of the Backup Data within … hours (Clause 12.2(f)).
If your business is critical information infrastructure under Thai cybersecurity law, check whether a serious outage must also be reported to your regulator, and put that contact in your incident plan.
The Provider stores personal data for you as your data processor (Clause 12). The Personal Data Protection Act requires a written arrangement that controls the processor (section 40), and Clause 12 is designed to meet it. If your organisation uses its own standard form, you may sign a separate Data Processing Agreement instead and state that it prevails.
Backups are allowed in …. Storing personal data abroad is a transfer that is lawful only if the destination has adequate protection or another condition in sections 28 and 29 of the Act is met, such as appropriate safeguards in a written agreement with the storage provider. Check this before the first backup runs.- Backups must stay in Thailand (Clause 5). Check the data centres named in Schedule 1, including where any cloud provider's region actually is.
A request by an individual to erase their data cannot always be carried out inside old backups. Clause 12.3 ensures such data is not restored into live use and expires with the backup. Explain this in your privacy notice.
Some laws require data to be kept for a minimum time, for example accounting records or computer traffic data for service providers. Set the retention periods in Clause 3.2 so that they meet those rules and are not longer than needed.
Open this form — 790 THB
Bookkeeping and Accounting Services Agreement
- Payroll files contain employees' personal data, including sensitive items such as health or union deductions. The Firm is the Client's data processor (Clause 10.2), and the Personal Data Protection Act requires those processor terms (section 40).
Open this form — 790 THB
Cargo Survey Services Agreement
- Photographs may show people, identity cards or vehicle plates. You are the data controller and the Surveyor is your data processor for that data (Clause 13.2). Ask for obscured copies before sharing Evidence widely.
Open this form — 790 THB
Cold Chain Logistics Agreement
- The Provider handles your consignees' names, addresses and signatures as your data processor (Clause 16.2). The Personal Data Protection Act requires a processing agreement of this kind (section 40).
- GPS data about the Provider's drivers belongs to the Provider as their employer. You receive only the location of your Goods in transit (Clause 16.3).
Open this form — 990 THB
Commercial Photography Agreement
- Recognisable faces are personal data. The Client decides how the images of people are used; the Photographer stores and edits them for the Client, reports any loss within 48 hours and deletes unused images of people within 12 months (Clause 9.4). If a person asks to be removed from future use, the Client should stop new uses where the law requires it.
Open this form — 790 THB
Construction Project Management Agreement
- Read the monthly report (Clause 7.1) and answer the decisions it lists by the dates stated. Late decisions by the Owner are a common reason why contractors are entitled to more time and money.
- Only the Owner pays contractors (Clause 8.2). Pay against the Project Manager's written recommendation and keep it with the payment records.
- Never let anyone accept the works or waive delay damages on your behalf (Clause 4.2). When accepting late works from a contractor, reserve the right to delay damages in writing on the day of acceptance.
- The Project Manager processes worker and CCTV data for you as a data processor (Clause 14.2). As the data controller, you must have a privacy notice for workers and visitors at the site entrance, and you must notify the Personal Data Protection Committee within 72 hours after learning of a breach that risks people's rights.
Open this form — 790 THB
Consulting Retainer Agreement
- If the Consultant analyses the Client's employee or customer data, it is the Client's data processor (Clause 14.2), and the Personal Data Protection Act requires the terms in that Clause (section 40). The Client must usually notify the regulator of a breach within 72 hours (section 37).
Open this form — 790 THB
Cross-Border Data Transfer Agreement
Sign this Agreement before any personal data is sent or made accessible abroad. Remote access from another country, for example by an overseas support team, is a transfer too (Clause 1.1, definition of Transferred Data).
Check that your privacy notice tells data subjects that their data may be disclosed to recipients outside Thailand and for what purposes (Clause 4.1(b), PDPA section 23). If it does not, update the notice first.
Record the transfer in your record of processing activities (PDPA section 39), including the destination countries and the basis chosen in Clause 2.2.
You chose appropriate safeguards (section 29, paragraph three). The Personal Data Protection Committee has issued rules on what such safeguards must contain. Compare the current rules with this Agreement before signing; Clause 2.2 treats any missing mandatory terms as included, but you should still sign a written amendment recording them.
You chose adequacy of the destination country (section 28). Keep a written record of why the destination meets the Committee's criteria (Clause 2.2). If that assessment is later questioned, this Agreement still gives contractual protection, but consider switching to the safeguards basis.
You rely on the exception in …. Exceptions are narrow. Keep evidence for each transfer (Clause 2.2), for example the signed consent form that told the data subject the destination's protection may be inadequate, or the contract with the data subject that requires the transfer.
The Importer is a separate controller and may use the data only for the agreed purposes in Annex 1 (Clause 5.1). A recipient of disclosed personal data may not use it for any purpose other than the one notified to the disclosing controller (PDPA section 27, paragraph two). If the Importer only processes data on your instructions, change the role to controller to processor.
The Importer is your processor. Clause 3.1 makes this Agreement the controller–processor agreement that section 40 requires. If you already have a data processing agreement with the Importer, keep it; this Agreement prevails on the protection of the data (Clause 19.2).
You are a processor for …. Before signing, obtain that controller's written authorisation to use the Importer and to send the data to the countries in Annex 1 (Clause 3.1). Without it, the transfer is a breach of your own processing agreement and of the PDPA.
The Importer must report a personal data breach within … hours (Clause 7.1). The controller must notify the Office of the Personal Data Protection Committee within 72 hours after becoming aware of a breach, unless it poses no risk to individuals' rights and freedoms, and must also notify affected data subjects without delay if the risk is high (PDPA section 37(4)).
Put the Importer's contact point and your own urgent contact in Annex 1, and test the channel once a year.
If the Importer notifies you of a foreign authority's request for the data or of a change in its local law (Clause 10), decide promptly whether to suspend transfers under Clause 15.1.
A controller that transfers personal data abroad without meeting section 28 or 29 faces an administrative fine of up to THB 3 million, or THB 5 million for sensitive data (sections 83 and 84). A processor faces up to THB 3 million, or THB 5 million for sensitive data (sections 86 and 87). Civil compensation to data subjects, with punitive compensation of up to twice the actual damage, is separate (sections 77 and 78).
If a group of companies wants a single internal policy for transfers between group members, that policy must first be examined and certified by the Office (section 29, paragraph one). This Agreement does not replace that certification (Clause 2.3).
Open this form — 990 THB
Data Analytics Services Agreement
- The Client is the data controller and the Analyst its processor (Clause 13.2). Send only the fields the questions need. Replace names, ID numbers and contact details with codes before sending, and keep the key yourself.
- The data will be held in the Analyst's environment in …. If that is outside Thailand, check the Personal Data Protection Act rules on cross-border transfers first.
Open this form — 790 THB
Data Annotation Services Agreement
- The Annotators are the Vendor's staff. Give instructions about the work through the Vendor's project lead, not directly to individual Annotators about their hours or conditions, so that you do not become their employer under Thai labour law (Clause 4.1).
- Images of faces, voice recordings and messages are personal data. Check that you have a lawful basis for using them to build AI, and do not allow access from outside Thailand unless you have approved it and the transfer meets the Personal Data Protection Act (Clause 10.2).
- At the end of the project, collect the final export and the Vendor's written confirmation that all copies have been deleted (Clause 11.2).
Open this form — 790 THB
Secure Data Destruction Agreement
Decide what may be destroyed. Thai accounting, tax, labour and sector rules require many records to be kept for fixed periods, and records relevant to a dispute or investigation must not be destroyed. The Provider does not check the content (Clause 3.2), so the decision and the risk are yours. Keep a signed internal approval listing what each batch contains.
As data controller you must have a system to delete or destroy personal data once it is no longer needed or the retention period ends (Personal Data Protection Act section 37(3)). This Agreement and its certificates are part of the evidence that the system works.
Prepare a list of storage devices with serial numbers before collection (Clause 3.1). The Certificate of Destruction can only be as precise as the list that goes in.
Media leaves your premises, so the chain of custody matters most. Check on the first collection that the containers are sealed, the seal numbers are written down and the vehicle is locked (Clause 4). The Provider must destroy each batch within … days.- Media is destroyed at your premises (Clause 2.2). Arrange a safe place for the mobile unit and a staff member to watch the process.
Loss of Media containing personal data is a personal data breach. The Provider must tell you within … hours (Clause 11.3). You, as controller, must notify the Office of the Personal Data Protection Committee without delay and within 72 hours after becoming aware of it, unless the breach poses no risk to individuals' rights and freedoms, and must tell affected individuals if the risk to them is high (section 37(4)). Unlawful destruction of data you still needed is also a breach.
The Provider bears the risk from the moment its staff sign for the Media (Clause 9.2). Its liability for lost Media is capped at the amount in Clause 17.2, but not for fraud, a false certificate, or data its staff kept or sold (Clause 17.3).
Ask for the insurance certificate before the first collection and check that it covers loss of client data, not only damage to property (Clause 15).
The Provider handles the Media as your data processor. The Personal Data Protection Act requires a written arrangement that controls a processor (section 40), and Clause 11 is designed to meet it for destruction work. If your organisation uses its own standard form, you may sign a separate Data Processing Agreement instead and state that it prevails.
Clause 11.2(e) keeps the Media in Thailand. Sending it abroad for destruction would be a transfer of personal data abroad and would need a lawful basis under sections 28 and 29 of the Act.
Open this form — 790 THB
Data Migration Services Agreement
- The Client is the data controller and the Provider its processor (Clause 13.2). If the Staging Environment in … is outside Thailand, check that the transfer meets the Personal Data Protection Act rules on cross-border transfers before the first Mock Migration.
- Use the migration to delete personal data that you no longer need. Data you keep must still have a lawful basis.
Open this form — 790 THB
Data Processing Agreement (DPA)
Under section 40 of the Personal Data Protection Act (PDPA), a data controller that lets a service provider process personal data on its behalf must put in place an agreement that controls how the processor performs its duties. Without it, the controller cannot show that it has taken steps to prevent the processor from using or disclosing the data without authority (section 37(2)), and a controller that fails its duties under section 37 may face an administrative fine of up to 3 million THB (section 83). A processor that fails its own duties under section 40 may face the same maximum (section 86).
This DPA is written to attach to any main agreement: a service contract, an accepted quotation or a provider's online terms. Keep a copy of the Principal Agreement named in Annex 1 with this DPA, because the two documents are read together (Clause 2.2).
If the service provider also uses the data for its own purposes, it is not a processor but a second controller. Use a data sharing agreement instead, and check that you have a lawful basis to disclose the data to it.
Sign this DPA before any personal data is sent. Clause 2.2 also covers processing that already happened under the Principal Agreement, but it does not cure a period without any agreement.
Check that your privacy notice tells data subjects that their data may be disclosed to service providers (PDPA section 23) and that you have a lawful basis for the processing (sections 24 and 26). These are the Controller's promises in Clause 3.1.
You ticked sensitive personal data. You must have the data subjects' explicit consent or a specific exception under section 26 of the PDPA, and the Processor must apply the extra safeguards in Clause 5.4 from the first day.
Update your record of processing activities (section 39) to show this Processor, the data it receives and the countries in Annex 1.
The Controller must notify the Office of the Personal Data Protection Committee within 72 hours after becoming aware of a breach, unless the breach poses no risk to individuals, and must also notify affected individuals without delay if the risk is high (PDPA section 37(4)). The Committee's notification on breach reporting (2022) requires the Processor to tell the Controller within 72 hours as well; this DPA sets … hours (Clause 6.1) so that you have time to assess the breach.
Put both breach contacts in Clause 15.2 on a list that your team can reach outside office hours. Weekends and holidays count towards the 72 hours.
The Processor may not notify the regulator or the public on your behalf without your approval (Clause 6.4). The decision to notify, and the notification itself, remain yours.
The Processor may add sub-processors after giving … days' notice. Read each notice: if you do not object in time, the new sub-processor is treated as approved (Clause 7.1).- The Processor needs your written consent for each new sub-processor (Clause 7.1). Reply to each request within 15 days.
Whatever AI option you chose, the Processor may never use your personal data to train AI models used by others, and automated decisions with significant effects on individuals need human review (Clause 8).
A server abroad, a backup abroad, or a support team that logs in from abroad is a transfer of personal data outside Thailand. It is lawful only if the destination has adequate protection under the Committee's criteria (section 28), one of the exceptions in section 28 applies, or appropriate safeguards are in place under section 29, usually a written agreement with the recipient in the form the Committee requires (Clause 9.2). Ask the Processor for a copy of its safeguards.
Because the GDPR may also apply, check whether the data comes from the European Economic Area. Transfers out of the EEA need the European Commission's standard contractual clauses or another GDPR transfer tool, signed separately (Clause 9.5).
A controller established outside Thailand that offers goods or services to people in Thailand, or monitors their behaviour, falls under the PDPA (section 5) and may need to appoint a representative in Thailand (section 37(5)).
Open this form — 990 THB
Data Sharing Agreement
In this Agreement each Party uses the shared personal data for its own business, and the Parties decide the purposes and means of the processing together. If one Party only processes data on the other's instructions, for example as a cloud, payroll or mailing service, it is a data processor, and you need a data processing agreement under section 40 of the Personal Data Protection Act (PDPA) instead (Clause 2.2).
The PDPA does not have a separate chapter on joint controllers. The allocation in the clause headed "Allocation of Joint Controller Responsibilities" binds the Parties to each other, but a data subject may still exercise rights and claim compensation against either Party.
No money is paid for the Shared Data (Clause 2.3). If one Party pays for access to a customer database, treat it as a sale of personal data, which needs specific consent and carries high legal and reputational risk.
Discloser: check that your privacy notice names this kind of recipient and purpose (PDPA section 23) and that you have a lawful basis or consent to disclose (sections 24, 26 and 27). If you have not told customers, update the notice or obtain consent before sharing. The Discloser gives these promises in Clause 4.1.
Recipient: personal data received from another organisation is collected from a source other than the data subjects. Under section 25 the Recipient must either notify the data subjects of that collection without delay and within 30 days and obtain their consent, or rely on an exemption from consent under section 24 or 26 and still give them the section 23 information, unless they already know it (Clause 5.2). Plan who sends that notice and how.
The Shared Data includes sensitive personal data. Explicit consent or a specific exception under section 26 of the PDPA is required for both the disclosure and the Recipient's use.
Both Parties should record the sharing in their records of processing activities (section 39) and keep the disclosure log required by Clause 10.1.
Each Party must notify the Office of the Personal Data Protection Committee of a breach within 72 hours after becoming aware of it, unless the breach poses no risk to individuals (PDPA section 37(4)). This Agreement does not shift that duty; it only requires each Party to warn the other within … hours (Clause 8.2).
A data subject may ask either Party for access, correction or deletion. Answer requests about the data you hold within the legal time limit (30 days for access requests under section 30) and forward the rest within … Business Days (Clause 7.2).
The Recipient may not send the Shared Data abroad or let anyone access it from abroad without the Discloser's written consent (Clause 9.1). Cloud storage abroad counts as a transfer.- Transfers to … are allowed only if the destination has adequate protection under the Personal Data Protection Committee's criteria, an exception in section 28 applies, or appropriate safeguards are in place under section 29, usually a written agreement with the recipient (Clause 9.2). Keep evidence of the mechanism used.
Open this form — 790 THB
Dataset Licence Agreement
- Read Schedule 1 Part B carefully. Ask how the data was collected, whether any of it was taken from websites or apps, and whether the Licensor had permission to license it for your purpose (Clause 6.1).
- The Dataset contains personal data. As Licensee you become a data controller with your own duties under the Personal Data Protection Act: record your processing, protect the data, answer requests from data subjects and inform them as the Act requires. Ask the Licensor to confirm in writing the lawful basis on which it discloses the data to you (Clause 7.2).- The data is described as de-identified. Keep it separate from customer lists and other data that could re-identify people, and never try to re-identify anyone (Clause 3.1 and Clause 7.2).- The Licensor has confirmed that there is no personal data in the Dataset. If you find any, tell the Licensor within 5 Business Days (Clause 7.2).
Open this form — 790 THB
Product Demonstration Loan Agreement
- Demonstrating a product to customers can count as offering it for sale under the Unsafe Products Liability Act B.E. 2551 (2008), so the Lender and a dealer who demonstrates it may be responsible to a person injured by an unsafe product. Train the staff who operate the Equipment (Clause 6.1) and keep a record of the training.
- Some products need an approval before they may be imported, advertised or demonstrated in Thailand, for example medical devices and radio equipment. Equipment brought in temporarily for a trade fair or demonstration may qualify for temporary admission without duty if it is re-exported; ask your customs broker before shipping.
- Delete personal data before return, and the Lender must erase anything left without looking at it (Clause 6.3). This matters for computers, medical devices, cameras and anything with a memory.
Open this form — 590 THB
Digital Product Licence Agreement
- The Parties exchange only contact details of their representatives. If the files include photographs of people, those images are personal data of the people shown, and the release should cover their use in the way this licence allows.
Open this form — 790 THB
Digital Replica and Synthetic Voice Licence Agreement
The Talent's face and voice used to build a model that imitates or identifies the Talent are biometric data under the Personal Data Protection Act. The Act requires explicit consent, given separately from the other terms. That is why the Talent signs Schedule 3 separately. Keep the signed Schedule 3 with the Agreement; without it the Licensee has no lawful basis to build or use the Replica Model.
Explain Schedule 3 to the Talent before signing, and give a translation if asked (Clause 18.9).
The Talent can withdraw consent at any time (Clause 9.3). If that happens, stop generating content at once, take down Outputs within … days and delete the model within … days (Clause 14.1). The Talent refunds only the Licence Fee for the unused part of the term (Clause 14.4).
The model and recordings may be kept in …. If that includes a country outside Thailand, check that the transfer meets the Act's rules on transfers abroad, and sign a data processing agreement with the Technology Provider (Clause 8.2 and Clause 8.4).
Store the Replica Model encrypted, limit access to named staff and use multi-factor authentication (Clause 7.1). A leaked voice or face model can be used by criminals for scams.
If the model or the recordings are lost or misused, notify the Talent within 48 hours (Clause 7.3). As data controller, the Licensee may also have to notify the Personal Data Protection Committee within 72 hours.
Open this form — 990 THB
Distributorship Agreement
- Thailand's Unsafe Products Liability Act B.E. 2551 (2008) makes everyone in the chain, including the importer and the seller, jointly liable to an injured consumer, without proof of fault (sections 4 and 5). A term that excludes this liability towards consumers is void (section 9). The Parties can only agree between themselves who finally pays — that is Clause 15.
- An indemnity is only as good as the Supplier's ability to pay. Ask the Supplier for its product liability certificate each year (Clause 17.3) and check that it covers sales in the Territory.You chose no insurance clause. Consider asking the Supplier for a product liability certificate anyway.
- Keep the customer and batch records required by Clause 11.2. Without them a recall costs far more, and customer data must be kept under the Personal Data Protection Act.
Open this form — 990 THB
Domestic Transportation Agreement
- Consignee names, addresses, telephone numbers, signatures and delivery photographs are personal data. The Customer is the data controller and the Carrier is its data processor (Clause 15.2), which the Personal Data Protection Act requires to act only on the controller's instructions and keep the data secure (section 40). The Customer must report a serious breach to the regulator within 72 hours in most cases (section 37), so the Carrier must report to the Customer within 48 hours.
Open this form — 590 THB
Dropshipping Agreement
- The Retailer is the data controller of Customer data and the Supplier is its data processor (Clause 12). The Personal Data Protection Act requires a written agreement between them (section 40), which Clause 12.2 provides.
- Tell Customers in the Store's privacy notice that their delivery details go to the Supplier and its carriers, and name the countries if the Supplier is abroad (sections 28 and 29).
- The controller must generally notify the Personal Data Protection Committee of a data breach within 72 hours after becoming aware of it (section 37(4)), which is why the Supplier must report to the Retailer within 48 hours.
Open this form — 790 THB
Employment Agreement
- Give the Employee a privacy notice explaining what personal data you collect and why. Health data, criminal records and biometric data (such as fingerprints for time clocks) are sensitive data and need explicit consent or another legal basis (Personal Data Protection Act, sections 24 and 26).
Open this form — 790 THB
Equipment Hire Agreement
- The Hirer is responsible for safety at the Site (Clause 5.3). Some machines, such as cranes and forklifts, may only be operated by trained or certified operators under Thai occupational safety rules. If you also need an operator from the Owner, use a service contract with an operator instead.- Flying a drone in Thailand requires registration and permission from the aviation and telecommunications authorities, and flying is restricted near airports, government buildings and crowds. Check before the shoot (Clause 5.3).- Delete your data before returning computers, phones or storage devices, and ask the Owner for written confirmation that the storage has been wiped (Clauses 5.3 and 9.2). Personal data left on a returned device can be a data breach under the Personal Data Protection Act.- Follow the manufacturer's instructions and any special instructions in Schedule 1 (Clause 5.3).
Open this form — 790 THB
EV Charger Installation Agreement
- You are the data controller of EV Users' personal data, and the Provider is your processor (Clause 9.1). Publish a privacy notice for EV Users in the app and at the Charging Bays, and check each monthly statement of collected payments against the platform reports (Clause 8.1).- The Provider is the data controller of EV Users' data and will give you only aggregated reports (Clause 9.1). Check each monthly statement of charging revenue, and use your right to audit if the figures look wrong (Clause 12.3).
- If personal data is stored on cloud servers outside Thailand, ask which countries and what safeguards apply (Clause 9.2).
Open this form — 990 THB
Event Management Agreement
- Tell attendees, in the registration form and at the entrance, that the Event may be photographed or filmed and how the images will be used (Clause 12.2).
- The Event Manager is your data processor (Clause 12.3). Approve the registration platform in writing, and confirm deletion of the Attendee Data 30 days after the Event.
- Dietary needs linked to health or religion, and disability information, are sensitive personal data. Collect them only with each attendee's explicit consent and only as far as needed.
Open this form — 990 THB
Export Management Services Agreement
- The Export Manager handles your Buyers' contact details on your behalf, so it acts as your data processor and Clause 10.1 contains the written terms that the Personal Data Protection Act requires of a processor (section 40). A controller must usually notify the regulator of a breach within 72 hours (section 37), which is why the Export Manager must tell you within 48 hours.
- AI tools may be used for translations and drafts, but not with your confidential data in tools that train on it, and a competent person must check every document before it is issued (Clause 10.2).
Open this form — 790 THB
Facilities Maintenance Agreement
- Give the Provider the drawings, manuals, warranties and maintenance history within 10 Business Days (Clause 3.3), and read the condition report carefully when it arrives (Clause 3.1). Decide in writing on the repairs it recommends — a Fault caused by a reported defect that you chose not to repair is not the Provider's responsibility.
- Check the annual PPM plan against the manufacturers' requirements, especially for equipment still under warranty (Clause 4.3).
- Ask for the list of technicians who will attend, with their licences and certificates for electrical, refrigerant, fire system and lift work (Clause 8.1).
- The owner of the Building remains legally responsible for the annual building inspection and report to the local authority (Clause 4.6). Diarise the submission date.
- Create named accounts for the Provider's engineers on the building management system, turn on multi-factor authentication, and remove any default password (Clause 7.3).
- The Provider processes CCTV and access-control data for you as a data processor (Clause 13.2). As the data controller, keep your privacy notice for occupants and visitors up to date, and notify the Personal Data Protection Committee within 72 hours after learning of a breach that risks people's rights.
Open this form — 790 THB
Franchise Agreement
- The Franchisee needs its own permits to run the Outlet, for example a food shop licence from the local authority, and is the employer of the staff (Clause 9.5). The Franchisor should give standards and training, not instructions to individual staff, so that it is not treated as their employer.
- The Franchisor is the data controller of customer data collected through its point-of-sale, loyalty or ordering system, and the Franchisee is the data controller of data that the Outlet collects for its own purposes (Clause 12.1). Each Party must protect it under the Personal Data Protection Act B.E. 2562 (2019) and report a breach to the other within 48 hours. CCTV at the Outlet also needs a privacy notice.
- If an ingredient or product causes injury, Thai product liability law may make everyone in the chain liable to the consumer. Clause 16 decides who finally pays between the Parties, and the insurance under Clause 9.6 is the Franchisee's first line of protection.
Open this form — 990 THB
Ghostwriting Agreement
- Interview recordings and transcripts contain personal data and may contain health or family information. The Writer keeps them secure and deletes them within 90 days after delivering the Manuscript unless the Client asks for them to be kept (Clause 12.4). If you want the recordings, ask before that date.
- The Writer has agreed not to use generative AI to write the text (Clause 11.1).- The Writer may use AI tools for research and transcription and must disclose them on delivery (Clause 11.1). Text created mainly by an AI tool may not be protected by copyright. Neither Party may upload the recordings to an AI tool that uses them for training (Clause 11.2).
Open this form — 790 THB
Hotel Room Allotment Agreement
- The Hotel and the Agency are separate data controllers (Clause 9.3). The Hotel may use rooming-list data for registration and the stay, but not to market to the Guests without their consent.
Open this form — 790 THB
Importer of Record Services Agreement
- The IOR receives consumers' names, addresses and telephone numbers to clear and deliver Shipments. Under the Personal Data Protection Act B.E. 2562 (2019), the Client is the controller and the IOR its processor, which requires the written processing terms in Clause 11.2 (section 40).
- Transfers of that data between Thailand and the Client's country must meet the rules on cross-border transfers (sections 28 and 29). The Client, as controller, must notify the regulator of a breach within 72 hours where required, which is why the IOR must report to the Client within 48 hours.
Open this form — 990 THB
Cyber Incident Response Retainer Agreement
- Call the hotline and send the email (Clause 5.1). Do not wipe or rebuild affected machines before the Responder advises, because that destroys Evidence.
- Personal data breach: as data controller you must notify the Personal Data Protection Committee Office without delay and, where feasible, within 72 hours after becoming aware of a breach, unless the breach poses no risk to individuals' rights and freedoms, and must also tell affected individuals where the risk is high (Personal Data Protection Act section 37(4)). The PDPC's notification rules list what the notice must contain; the Responder is obliged to give you those facts in time (Clause 9.2). If you cannot notify within 72 hours for a necessary reason, the rules allow you to explain the delay to the Office, but no later than 15 days after becoming aware.
- If you are, or serve, a critical information infrastructure organisation under Thailand's cybersecurity law, or you are regulated by a sector regulator, you may have a separate duty to report cyber threats to that regulator and the national cybersecurity authority. Record those duties in onboarding (Clause 9.3).
- Notify your cyber insurer within the time in your policy, and check whether the insurer must approve the Responder before costs are incurred (Clause 11.1).
- Consider reporting to the police. A police report is often needed for insurance and for pursuing the attacker.
- Do not pay a ransom without legal advice. A payment may breach anti-money laundering or sanctions laws and does not guarantee recovery; the Responder will not negotiate or pay without your written instruction (Clause 10).
- Beware of fake payment instructions during an incident. Confirm any change of bank account by telephone (Clause 14.5).
Open this form — 990 THB
Independent Contractor Agreement
The Client owns the Deliverables once it has paid for them in full (Clause 9.2). A transfer of copyright must be in writing and signed by both Parties, so both Parties must sign this Agreement. If an assistant creates part of a Deliverable, the Contractor must first obtain the assistant's written assignment (Clause 3.7).- The Contractor keeps ownership and the Client receives a permanent licence once paid (Clause 9.2). The Client may not resell the Deliverables as a product.
Thai copyright protects works created by human beings. Output generated by an AI Tool with little human input may have no copyright owner at all, so neither Party can stop others from copying it. Clause 10 requires human review and disclosure on request.
Never paste the Client's confidential material or personal data into a free AI tool that trains on user input (Clause 10.2). Check the tool's data settings or business terms first.
A synthetic voice or likeness of a real person needs that person's separate written consent (Clause 10.5).
For the personal data handled in the Services, the Client is the data controller and the Contractor its data processor (Clause 12.2). The Personal Data Protection Act requires a processor to act only on instructions, keep the data secure and report breaches (section 40). The controller must usually notify the regulator of a breach within 72 hours (section 37), which is why the Contractor must report within 48 hours.
If the Contractor works from outside Thailand, the data is being transferred abroad. The Client must make sure the transfer meets the Act's conditions (sections 28 and 29).
Open this form — 790 THB
Influencer Marketing Agreement
- The Brand may repost the Deliverables on its own channels for … months after each post, in … (Clause 8.2). It may also run paid ads with them for the first … months, and must stop those ads within 5 Business Days after that period ends (Clauses 8.3 and 8.6). Paid advertising with the Content, including boosting reposts or creator-handle ads, needs a separate written agreement and fee (Clause 8.3).
- Using the Creator's face or voice to train AI, or creating a digital replica or synthetic voice, is prohibited without a separate agreement signed by the Talent (Clause 8.5). This protects the Talent's personal data and reputation as well as the Brand's legal position.
Open this form — 990 THB
Internship Agreement
- Give the Intern a privacy notice. Health data needs explicit consent (Personal Data Protection Act section 26).
- Photos or videos of the Intern in social media posts or recruitment material need a separate written consent (Clause 9.3), signed by the Guardian as well.
Open this form — 790 THB
Last-Mile Delivery and COD Collection Agreement
- You are the data controller of your customers' data, and the Courier is your data processor (Clause 13). The Personal Data Protection Act requires a processing agreement of this kind (section 40). If a breach occurs, you may have to notify the Personal Data Protection Committee within 72 hours (section 37), which is why the Courier must tell you within 48 hours.
- Tell your customers in your privacy notice that their name, address, telephone number and delivery photographs are shared with your delivery partner.
Open this form — 790 THB
53 more contracts with notes on this topic
- Lead Generation Services Agreement
- Managed Cloud Services Agreement
- Managed IT Services Agreement
- Managed Security Services Agreement
- Market Research Services Agreement
- Marketplace Seller Agreement
- Master Services Agreement
- Model Release and Image Licence Agreement
- Mutual Termination Agreement
- Non-Disclosure Agreement
- Novation Agreement
- Consent to Use Premises as Company Office
- Online Store Terms of Sale
- Outsourced Data Protection Officer Agreement
- Parking Space Rental Agreement
- Penetration Testing Agreement
- Product Pre-Order Agreement
- Pre-Shipment Inspection Agreement
- Product Certification Services Agreement
- Product Development and Prototyping Agreement
- Product Recall Services Agreement
- Property Management Agreement
- Assignment of Receivables Agreement
- Recruitment Services Agreement
- Repair and Refurbishment Services Agreement
- Remote and Hybrid Working Agreement
- Authorised Repair Centre Agreement
- Returns Management Services Agreement
- SaaS Subscription Agreement
- Sales Commission Agreement
- Secondment Agreement
- Information Security Assessment Agreement
- Self-Storage Agreement
- Service Agreement
- Website and Software Development Agreement
- Software Licence Agreement
- Software Pilot Agreement
- Software Reseller Agreement
- Software Maintenance and Support Agreement
- E-Commerce Store Management Agreement
- Subscription Box Agreement
- Customer Support Outsourcing Agreement
- Systems Integration and Implementation Agreement
- Trade-In and Buyback Agreement
- Transition Services Agreement
- Translation and Localisation Agreement
- Travel Agency Supplier Agreement
- Video Production Agreement
- Virtual Assistant Services Agreement
- Virtual Office Services Agreement
- Warehousing and Fulfilment Agreement
- Waste Collection and Recycling Agreement
- White-Label Services Agreement
Read more on this subject
This page only answers how this subject appears in contracts. For the Personal Data Protection Act, the Committee's notifications and tools for ROPA and DPIA (in Thai), see https://aipdpa.com.
Author and sources
Compiled from the notes that accompany the English contract templates on this site, published by Phuwara Krobtaku (ภูวรา ครอบตะคุ), Thai attorney-at-law, licence no. 477/2558. The short answer and summary at the top of this page are put together by the site from the template's clause headings and notes. Statutes are quoted only in the official Thai text: Thai is the only official language of Thai legislation, and an unofficial translation can mislead. Article registry OKC-5DB933. If you reuse this content, please credit the author and link to the original.
Frequently asked questions
How does the AI Implementation and Automation Agreement deal with personal data?
The Client is the data controller and the Implementer is its processor (Clause 16.2). Update your privacy notice to explain that customers may talk with an AI system and how their messages are used. If data is processed outside Thailand (…), check before Go-Live that the transfer meets the Personal Data Protection Act rules on cross-border transfers (Clause 16.3). The controller must notify the Personal Data Protection Committee of most breaches within 72 hours, which is why the Implementer must report to the Client within 48 hours. Do not let the AI collect health, biometric or other sensitive data unless you have explicit consent or another lawful basis (Clause 16.4).
How does the AI Model Development and Fine-Tuning Agreement deal with personal data?
Decide which data the model really needs. Remove or mask names, ID numbers and other personal data that the purpose does not need (Clause 4.5). Check your lawful basis for using the personal data to train a model. Data collected to serve customers is not automatically usable for training; you may need consent or a documented legitimate-interest assessment, and your privacy notice should mention it. A model may memorise personal data, and removing it later may require retraining (Clause 5.3). Sensitive personal data needs explicit consent or another basis that the Personal Data Protection Act allows for that category. Give the Developer the written confirmation required by Clause 5.4 only when you have it. Ask for the Base Model licence summary (Clause 3.1) and read the restrictions on commercial use, number of users and redistribution before training starts.
How does the AI Model Evaluation Services Agreement deal with personal data?
A Critical Finding is reported within … hours (Clause 6.2). Decide quickly whether to contain it, for example by switching off a tool or tightening access, and ask for the free re-test while the Testing Period is still running (Clause 6.3). Red-teaming produces harmful test content by design. It is kept by the Evaluator under strict access rules and deleted at the end (Clause 5.2). Do not circulate examples from the Report more widely than needed. Keep real personal data out of the test environment. If a test genuinely needs real data, sign a separate data processing agreement first (Clause 12.2).
How does the AI Use Addendum deal with personal data?
No personal data may go into AI tools, because AI tools may not be used for the work (Clause 4.2).- When personal data is put into an AI tool, the tool provider becomes a sub-processor. Ask the Supplier which providers are used and where they process data (Clause 4.2), and check that your privacy notice covers it.- The Supplier must remove names and other identifying details before using AI with your data (Clause 4.2). If a task genuinely needs personal data, agree it in writing first. If the Supplier reports an AI-related incident, decide quickly whether you must notify the Personal Data Protection Committee, which in most cases must be done within 72 hours after you become aware of the breach (Clause 10).
How does the Business Asset Purchase Agreement deal with personal data?
Customer lists and databases are personal data. The Seller must confirm the basis on which the data was collected, and the Parties must inform customers of the transfer within 30 days after Completion unless the law does not require it (Clause 10.2). Do not use the data for new purposes without a lawful basis.
How does the Bookkeeping and Accounting Services Agreement deal with personal data?
Payroll files contain employees' personal data, including sensitive items such as health or union deductions. The Firm is the Client's data processor (Clause 10.2), and the Personal Data Protection Act requires those processor terms (section 40).
How does the Cargo Survey Services Agreement deal with personal data?
Photographs may show people, identity cards or vehicle plates. You are the data controller and the Surveyor is your data processor for that data (Clause 13.2). Ask for obscured copies before sharing Evidence widely.
How does the Cold Chain Logistics Agreement deal with personal data?
The Provider handles your consignees' names, addresses and signatures as your data processor (Clause 16.2). The Personal Data Protection Act requires a processing agreement of this kind (section 40). GPS data about the Provider's drivers belongs to the Provider as their employer. You receive only the location of your Goods in transit (Clause 16.3).
How does the Commercial Photography Agreement deal with personal data?
Recognisable faces are personal data. The Client decides how the images of people are used; the Photographer stores and edits them for the Client, reports any loss within 48 hours and deletes unused images of people within 12 months (Clause 9.4). If a person asks to be removed from future use, the Client should stop new uses where the law requires it.
How does the Construction Project Management Agreement deal with personal data?
Read the monthly report (Clause 7.1) and answer the decisions it lists by the dates stated. Late decisions by the Owner are a common reason why contractors are entitled to more time and money. Only the Owner pays contractors (Clause 8.2). Pay against the Project Manager's written recommendation and keep it with the payment records. Never let anyone accept the works or waive delay damages on your behalf (Clause 4.2). When accepting late works from a contractor, reserve the right to delay damages in writing on the day of acceptance. The Project Manager processes worker and CCTV data for you as a data processor (Clause 14.2). As the data controller, you must have a privacy notice for workers and visitors at the site entrance, and you must notify the Personal Data Protection Committee within 72 hours after learning of a breach that risks people's rights.