In brief
On 16 July 2026, the PDPC issued the Access Request Notification, setting out procedures for handling data subject requests to access or obtain copies of personal data and information on the sources of data obtained without consent. The notification introduces requirements relating to request submission, identity verification, extensions of response timelines, access methods, fees, and record retention.
Data controllers should review and update their request handling procedures to ensure compliance.
In more detail
The Personal Data Protection Committee (PDPC) Notification Re: Rules on Requests for Access to and Obtaining Copies of Personal Data Related to Data Subjects under the Responsibility of Data Controllers, or for Disclosure of the Source of Personal Data Obtained Without the Consent of the Data Subject B.E. 2569 (2026) ("Access Request Notification") was published in the Government Gazette on 16 July 2026 and will take effect on 14 September 2026 (60 days after the publication date).
- Scope
Who can submit a request?
Access requests may be submitted by the data subject, the person with parental powers for minors, a custodian, a curator, or an authorized representative (each a "Requester").
Requestable data
- Personal data directly collected from the Requester and personal data collected from other sources
- Sources of personal data obtained without the Requester’s consent
- Information as prescribed under the privacy notice and the Record of Processing Activities (ROPA)
- Request handling process
Step 1 – Request submission: Data controllers must provide at least physical and postal channels for submitting requests. Electronic channels are welcome. The request must meet the minimum required details and formality and include identification documents.
Step 2 – Identity and request verification: Data controllers must verify the details of the request and the identity of the Requester within a prescribed timeline after receiving the request. If the request is incomplete, the data controller must notify the Requester and allow a specified period for rectification.
Step 3 – Comply with the request: Data controllers must comply with the request within 30 days of receiving the complete and valid request. The data controller may extend the response period by up to an additional 30 days by notifying the Requester, for example, where the request involves a large volume of information.
- Grounds for refusal
The data controller may refuse a request on certain grounds, including where disclosure is prohibited by law or court order, where it may affect the rights (including IP rights) of others, where the request is unfounded, or for other prescribed reasons.
- Fees
Access requests shall generally be free of charge. Fees may only be charged in certain circumstances, such as where special formats, delivery costs, or repetitive and excessive requests create an additional burden.
- Recordkeeping
Data controllers must maintain records of access requests and other required details for at least two years.
Next steps
Businesses should update their data subject access request procedures, implement a contact channel, update their appropriate verification processes, update the fee policies, set up record retention measures, and train relevant teams on the new requirements before the Access Request Notification takes effect.
* * * * *
Chanaporn Anurukwongkul, Phocharaphol Yingamphol, and Pirun Suttiprapha, Associates, have contributed to this legal update.