Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) has changed the risk landscape for organizations that collect, process, or store personal data. With enforcement activity increasing, the consequences of mishandling data are becoming harder to ignore — from regulatory investigations and mandated remediation to multimillion-baht penalties and reputational damage.
At the same time, cyber threats across Thailand continue to intensify. For businesses, that creates a dual challenge: managing the operational impact of a cyber event while also preparing for the regulatory consequences that may follow if personal data is exposed.
For many organizations, the question is no longer whether PDPA creates risk. It is whether they are prepared to manage it with confidence.
Many businesses understand PDPA at a high level. Fewer have a clear view of the financial and operational impact a privacy-related incident can trigger.
A single cyber event involving personal data can trigger multiple cost drivers simultaneously including:
Privacy risk does not sit apart from cyber risk. A ransomware attack, phishing incident, or unintentional system failure may not only disrupt operations — it may also compromise personal data and trigger regulatory scrutiny.
This is especially relevant in Thailand, where cyber incidents continue to rise and organizations are facing increased pressure to demonstrate stronger security and governance whilst having clearer accountability and faster incident response.
Three risk areas businesses should prioritize
1. Regulatory exposure under PDPA
PDPA enforcement can move quickly and create complex demands. Investigations, penalties, and required actions may call for immediate legal, compliance, cyber security and communications support. Without the right preparation, costs can escalate fast.
2. Business interruption following a cyber event
Both malicious and non-malicious cyber events can halt operations, disrupt revenue, and generate significant recovery costs. When personal data is involved, the impact often extends beyond operational loss to include regulatory and reputational consequences and sometimes civil liability.
3. People-related risk and data mishandling
Human error remains one of the most common starting points for privacy incidents. Even when security tools are in place, poor cyber security awareness, inconsistent data handling, or unclear ownership can increase the likelihood of an incident and undermine compliance efforts.
Managing your PDPA obligations alongside cyber risk takes more than a single solution. It requires a clearer understanding of your exposure, better insight into potential impact, and practical ways to strengthen resilience.
Marsh helps organizations take action across the full risk lifecycle:
Understand your exposure
Marsh Cyber Self-Assessment helps organizations evaluate cyber risk exposure, cyber maturity, and insurability. It can help you identify control gaps, benchmark against peers, and better understand the areas that may affect resilience and insurance readiness.
Measure the potential impact
Cyber Risk Quantification helps translate cyber and privacy risk into financial terms, supporting more informed business decisions. Marsh’s OT/IT Health Check can provide deeper visibility into technology environments and control effectiveness.
Manage financial risk
Insurance can play an important role in a broader PDPA and cyber risk management strategy. Cyber insurance and commercial crime insurance may help organizations manage the financial impact of data breaches, ransomware, business interruption, fraud, and related response costs.
Take a more confident approach to PDPA
As PDPA enforcement increases and cyber threats evolve, organizations that act now will be better positioned to reduce harm, protect trust, and respond with greater confidence. Marsh can help your organization understand, measure, manage, and respond to PDPA- and cyber-related risks — before an incident becomes a crisis.