

To protect organizations from such threats, organizations should prepare and implement personal data protection measures in accordance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA). This includes key issues such as establishing appropriate security measures, preventing misuse of data, establishing systems to monitor the deletion or destruction of personal data, training and raising awareness among relevant personnel, and other duties to protect data and mitigate potential risks.
PDPA Thailand compiles 5 cases of personal data violations in Thailand in 2024 (for use as case studies)
1. Hackers announce the sale of nearly 20 million sets of data belonging to Thai people.
2. JIB admits to customer data leak, prosecutes former employees, and speeds up compensation for 4 victims.
3. PDPC urgently coordinates with the Election Commission to clarify the reason for the leak of 20,000 names of Senate candidates.
4. The hacker group has hacked Black Canyon’s data, amounting to more than 958GB, and has access to all servers.
5. Hackers claim to have stolen information of over 5 million Central The 1 Card members, announcing the release of 500,000 names.
1. Hackers announced the sale of nearly 20 million sets of Thai data in January 2024, including data from two government agencies: the Department of Older Persons Affairs and the Royal Thai Navy.
What happened?
On January 22, 2024, BBC Thai received confirmation from both the Department of Older Persons Affairs and the National Cyber Security Council that a personal data breach involving nearly 20 million personally identifiable information (PII) of Thais was leaked and posted for sale on illegal data trading platforms. This information included names, surnames, national ID card numbers, phone numbers, and more.
The leaked personal data is Personally Identifiable Information (PII), which includes:
- Basic personal data and order history from Chulalongkorn University Book Center
- Information claimed to be personal information of Navy personnel
- Personal information of online job seekers
Why did this happen?
These agencies have vulnerabilities in both public and private sector security systems, which have led to the leakage of citizens’ personal data. These include the use of unsecured channels to collect personal data, the lack of control over access rights to personal data, and even the violation of personal data without adequate security measures.
2. JIB acknowledges customer data leak, prosecutes former employees, and expedites compensation for four victims. The Personal Data Protection Committee (PDPA) issued an order stating administrative penalties under the PDPA, including fines of up to 7,000,000 baht.
What happened?
On March 28, 2024, a large number of customers’ personal data of a major private company in the country engaged in online shopping were leaked, resulting in damages through the improper use of personal data. The Personal Data Protection Committee (PDPC) investigated the breach and found that it contained actual purchase and personal data of the company’s customers, and that there were several deficiencies in compliance with the Personal Data Protection Act (PDPA).
Why did this happen?
A person claiming to be an employee of this company contacted the company, providing accurate personal information, and used deceptive tactics to deceive customers, resulting in damages. After the damage occurred, an investigation revealed that the company had not acted in accordance with the PDPA. The customer then filed a complaint with the Office of the Consumer Protection Board (OCSB), requesting the agency’s assistance in investigating the matter. The OCSB subsequently issued a fine totaling over 7 million baht.
Details of administrative penalties and fines
- In the case of not appointing a Data Protection Officer (DPO) – 1,000,000 baht
- In the event that there are no appropriate security measures – 3,000,000 baht
- Failure to report a personal data breach as required by law – 3,000,000 baht
What happened?
On June 11, 2024, the names and ID card numbers of over 20,000 people who passed the selection process for Senate members at the district level were revealed, which led to an online trend regarding the leakage of personal data.
Why did this happen?
This data leak was not caused by an external hack or cyberattack, but rather an internal system breach, possibly due to a vulnerability in the Election Commission’s data management or unauthorized access to candidate information. The leaked information may have included names, addresses, or other sensitive personal information of candidates. The Personal Data Protection Committee (PDPC) has coordinated with the Election Commission (EC) to investigate the incident and clarify the facts.
4. The Facebook page “Black Canyon” posted a warning to customers not to click on the link after Line was hacked. A group of hackers hacked Black Canyon’s data, amounting to more than 958GB, and were able to access all servers.
What happened?
On November 2, 2024, LINE Thailand reported that Black Canyon Coffee had been hacked. The “Black Canyon Coffee” account was accessed without permission, and false messages and links were being shared with followers. LINE investigated and monitored the situation and found that none of these incidents were caused by direct access to LINE’s servers. The “Black Canyon” Facebook page posted a warning to customers to strictly avoid clicking on links after LINE was hacked and sent inauthentic messages. They confirmed that all customer information is stored with the highest security measures. The information is general information, and no customer financial information is stored.
Why did this happen?
Black Canyon was hacked, exposing customers’ personal information. The hackers revealed that the company’s Line OA accounts, including financial information and internal data used in various operations, were leaked. The hackers threatened that if the company doesn’t contact them, they will release all the information they have obtained by November 5, 2024.
What happened?
On November 19, 2014, a hacker using the name 0mid16B announced that he had hacked personal information of The1 card members, Central’s member cards used to accumulate points when purchasing products. The hackers obtained information from over 5 million accounts, including first and last names, member numbers, ID card numbers, country, phone numbers, and email addresses. By testing the phone number input and displaying the response of the back-end server, it was found that there was a real response.
Why did this happen?
The hackers claim they contacted management but negotiations were unsuccessful, so they decided to sell The 1 cardmember data on the dark web. They posted a video showing how to verify sample data and some member information, stating that the Thai company doesn’t care about data protection, saying nothing will happen to them, there are no PDPA fines, no compensation for customers, and no responsibility. Initially, there is no evidence of a system hack or data leak, and the company has filed a report with the cyber police to prosecute the perpetrators.
summarize
Every organization has a crucial duty to protect personal data. Under the PDPA, we recognize that personal data is simply “borrowed” from the data subject. Therefore, the organization’s use of such data should be guided by appropriate security measures to prevent and minimize the risk of personal data breaches.
Compliance with the PDPA not only helps avoid legal risks and reputational damage, but also helps build trust among customers and service users in the security of personal data.
