PDPA Checklist for Clinics in Thailand: 9 Obligations, 9 Documents

Your clinic collects patient health data, and health data is one of the most strictly protected categories of "sensitive data" under the law. Under Section 26 of the Personal Data Protection Act B.E. 2562 (2019) ("PDPA"), having patients simply tick a generic terms-and-conditions box on your website isn't enough.
Most clinic owners know they "have to do PDPA," but few know exactly what that means in practice — what to do, which documents to prepare, and in what order. This article summarizes the obligations that apply directly to clinics, based on the text of the Personal Data Protection Act B.E. 2562 (2019), and is not specific legal advice for your particular clinic.
By the end of this article, you'll have a checklist you can actually tick off, know exactly what document each item requires, and know which documents are already ready to sign. One private company was hit with an administrative fine of up to ฿7,000,000 (roughly US$195,000) over a lack of adequate security measures in 2024 (isranews.org; amarintv.com). This isn't a theoretical risk anymore.
Related reading: Digital Informed Consent for Aesthetic and Dental Clinics
TL;DR: Clinics must comply with PDPA because health data is sensitive data (Section 26) requiring explicit consent. The main things you need to do: (1) publish a Privacy Notice; (2) obtain written consent; (3) consider appointing a DPO if processing large volumes of health data is a core activity of your business — confirm your clinic's status with legal counsel; (4) sign a DPA with labs, accounting firms, or other external processors; (5) maintain a RoPA and minimum security measures. Failing to do so risks administrative fines — one private company was fined ฿7 million in 2024. This article is not legal advice — it's a starting point before consulting your own legal counsel.
Key Takeaways
- Patient health data = sensitive data under Section 26 of PDPA 2562, requiring explicit, written consent
- Most clinics fall into the category that should consider appointing a DPO under Section 41(3), but the law doesn't define an exact data-volume threshold, so confirm your status with legal counsel
- There are 9 minimum documents you need, from a Privacy Notice to a patient rights-request form
- PDPA 2562 (data protection) and ETA 2544 (electronic signature validity) are two separate laws — you need to comply with both, in parallel
- A private company has already been fined ฿7,000,000 in 2024, and total fines of roughly ฿21.5 million were issued in 2025, according to pdpathailand.com's tracking
- This article is not specific legal advice — it's a starting point before consulting your clinic's own legal counsel
Table of Contents
- Is Patient Data Sensitive Data?
- Does a Clinic Need a DPO?
- The Privacy Notice: The First Thing You Need
- Written Consent: Why Paper Isn't Enough
- DPA: Contracts With External Data Processors
- RoPA: Record of Processing Activities
- Minimum Security Measures and the 72-Hour Breach Notification
- PDPA Is Not ETA: Don't Confuse the Two Laws
- What's the Risk of Not Doing PDPA?
- The Full 9-Item Checklist, With Required Documents
- From Checklist to Ready-to-Sign Documents
- Frequently Asked Questions
Is Patient Data Sensitive Data?
Yes. Patient health data is classified as "Sensitive Personal Data" under Section 26 of PDPA 2562 — a category subject to stricter consent requirements than general personal data.
This category covers diagnostic history, treatment records, test results, and biometric data — such as fingerprints or facial recognition if your clinic uses either at reception.
In practice, this means a generic "accept terms" button isn't enough. Clinics need explicit, written consent for processing health data, except in a few legally exempted cases, such as emergency medical necessity.
Does a Clinic Need a DPO?
In most cases, a clinic falls into the category that should consider appointing a Data Protection Officer (DPO), because Section 41(3) of PDPA 2562 requires a DPO when an organization's core activity is processing sensitive data under Section 26 "on a large scale" — and health data is already at the core of a clinic's business.
The point worth flagging: the law doesn't set a clear data-volume threshold for small or solo-practitioner clinics. What counts as "large scale" depends on the actual patient volume your clinic handles.
A DPO's role is to provide internal advisory support, oversee data security, and act as the point of contact with Thailand's Personal Data Protection Committee (PDPC) and with patients exercising their rights.
The Privacy Notice: The First Thing You Need
Before collecting any patient data, a clinic must publish a Privacy Notice stating what data is collected, for what purpose, on what legal basis, for how long, and what rights the patient has.
This notice must be visible at the point data is actually collected — whether that's the reception desk, an online form, or the booking process.
One thing to watch for: a Privacy Notice (shown to patients) and an internal Privacy Policy (your clinic's internal governance policy) are two separate documents. A common mistake seen across many websites is using a generic notice copied from another business, without specifying the actual health data the clinic collects.
Written Consent: Why Paper Isn't Enough
Consent for health data must be explicit, specific, and provable. A paper form kept in a drawer can't prove an exact date, and there's no way to confirm the patient actually received the latest version of your Privacy Notice.
Valid PDPA consent must identify the data controller, state a clear purpose, include the right to withdraw consent, and record the time consent was given.
An electronic signature with an audit trail (timestamp and OTP) strengthens your ability to demonstrate compliance if audited — but it's a way to strengthen the evidentiary weight of the document, not an absolute legal guarantee.
DPA: Contracts With External Data Processors
A clinic that shares patient data with a third party — such as a lab, an accounting firm, or a cloud provider — needs a Data Processing Agreement (DPA) under Section 40 to bind that external processor to security and confidentiality measures equivalent to those of the data controller itself.
A real-world example: a toy business whose online booking system was hacked saw the business owner, as data controller, fined ฿500,000, while the system developer, as data processor, was fined a separate ฿3,000,000, in 2025, according to a PDPA consulting provider's tracking (not yet confirmed against an official PDPC announcement) from pdpathailand.com. This shows that external processors carry independent liability, not just the data controller alone.
RoPA: Record of Processing Activities
A Record of Processing Activities (RoPA) is an internal register logging the purpose, legal basis, data recipients, and retention period for each category of data your clinic processes, under Section 39. This document is often the first thing PDPC asks for during an audit.
For a clinic, RoPA should be broken into at least 4 categories: patient medical records, financial and receipt data, staff data, and marketing data such as newsletters or appointment reminders.
A common mistake is creating a RoPA once and never updating it, when it should be updated every time a new type of data processing is introduced, such as a new booking app or accounting system.
Minimum Security Measures and the 72-Hour Breach Notification
A clinic must have minimum security measures as defined by ministerial notification, and must notify PDPC of a data breach within 72 hours of becoming aware of it, if it poses a risk to patients' rights, under Section 37(4).
Basic measures should include access controls on medical records, secure backups, and a log of who accessed what data and when.
A real-world example: a government agency was fined ฿153,120 as data controller over a breach affecting around 200,000 people, while the related external service provider was separately fined the same amount as data processor, according to the same source, in 2025. This is further evidence that inadequate security measures create risk for both parties.
PDPA Is Not ETA: Don't Confuse the Two Laws
PDPA B.E. 2562 (2019) and ETA B.E. 2544 (2001) are two separate laws, serving two different functions, and must never be used interchangeably.
- PDPA B.E. 2562 (2019) (Personal Data Protection Act) protects personal data — covering consent, security, and data subject rights.
- ETA B.E. 2544 (2001) (Electronic Transactions Act) is a separate law that validates electronic signatures themselves — it has nothing to do with the nature of the data inside the signed document.
Documents related to PDPA, such as patient consent forms or DPA contracts, must be substantively compliant with PDPA (content, purpose, legal basis) and correctly signed under ETA, if you want a citable electronic record. The two laws complement each other — they never substitute for one another.
Read more about the legal basics of electronic signature validity under ETA 2544
What's the Risk of Not Doing PDPA?
PDPC has already issued real administrative fines ranging from ฿153,120 to ฿7,000,000, depending on severity and the volume of data involved. This isn't a theoretical threat.
The highest disclosed fine to date is ฿7,000,000, against an IT equipment retailer in 2024 (B.E. 2567), over a lack of adequate security measures that led to a data leak affecting more than 100,000 customers — the first administrative fine order issued under PDPA (isranews.org; amarintv.com).
The total of publicly disclosed fines since PDPA came into force stands at roughly ฿21.5 million across 6 disclosed cases in 2025, according to the same source (pdpathailand.com).
One thing to note: there's no data confirming that any disclosed fine specifically targeted a "small clinic." Real cases have involved businesses of various sizes, so you shouldn't assume a small clinic would be fined a similar amount.
The Full 9-Item Checklist, With Required Documents
Here are the 9 core obligations most clinics need to meet, with the related document for each. Three of the items in this table already have ready-to-use templates in the Jabmue clinic template gallery — the rest are internal documents you prepare yourself, which you can also send for signature through Jabmue's general document editor.
| # | Obligation | Related Document | Done ✅ |
|---|---|---|---|
| 1 | Publish a Privacy Notice visible to patients | Draft it and send it to patients via the Jabmue document editor | ☐ |
| 2 | Create an internal Privacy Policy | Prepare it as an internal document via the Jabmue document editor | ☐ |
| 3 | Obtain explicit, written PDPA consent before processing health data | Patient PDPA consent form (ready to use in the clinic gallery) | ☐ |
| 4 | Assess and consider appointing a DPO | DPO appointment letter, prepared yourself via the Jabmue document editor | ☐ |
| 5 | Sign a DPA with each external processor (lab, accountant, cloud provider) | Data Processing Agreement (ready to use in the clinic gallery) | ☐ |
| 6 | Have staff with access to medical records sign a confidentiality agreement | Staff confidentiality agreement (ready to use in the clinic gallery) | ☐ |
| 7 | Maintain a Record of Processing Activities (RoPA) | Internal register, not a signed document — prepare and update it yourself | ☐ |
| 8 | Put minimum security measures in place, with a 72-hour breach notification process | Internal security policy, prepared via the Jabmue document editor | ☐ |
| 9 | Set up a channel for patient rights requests (access, correction, deletion) | Rights request form, prepared via the Jabmue document editor | ☐ |
All 9 items are mandatory — none is "more important" than another. The order in this table reflects a suggested starting sequence based on risk, not a priority ranking.
From Checklist to Ready-to-Sign Documents
Three of the nine checklist items — the patient PDPA consent form, the DPA with external processors, and the staff confidentiality agreement — already have ready-to-use Thai-language templates in the Jabmue clinic gallery. Customize and send them for electronic signature right away.
The remaining documents in the table, such as the Privacy Notice or the rights-request form, don't yet have a ready-made template in the gallery, but you can draft them yourself and send them through Jabmue's general document editor, since the platform supports uploading your own documents and sending any type for signature.
A reminder: Jabmue provides document templates and an e-signature tool — it is not a legal advisor. Every document should be adapted to your clinic's specific situation and reviewed by legal counsel before actual use.
Beyond PDPA documents, the clinic gallery also includes other documents most clinics need, such as informed consent forms, before/after image release forms, treatment-plan payment schedules, and patient intake forms.
See all documents in the clinic gallery
Frequently Asked Questions
Does a clinic need a DPO?
In most cases, yes, you should consider appointing one, because health data sits at the core of a clinic's activity and is classified as sensitive data under Section 26. The law (Section 41(3)) requires a DPO when large-scale processing of sensitive data is a core activity — but since the exact volume threshold isn't defined for small clinics, confirm your status with legal counsel.
What are the fines for not complying with PDPA?
Real administrative fines issued so far range from ฿153,120 to ฿7,000,000, depending on severity and the volume of data involved. There's no fixed rate specifically published for clinics.
Is patient data sensitive data?
Yes. Health data — such as diagnostic results, treatment history, and medication history — is classified as "sensitive data" under Section 26 of PDPA, requiring a stricter level of consent than general personal data.
What's the difference between PDPA and ETA?
PDPA B.E. 2562 (2019) protects personal data, while ETA B.E. 2544 (2001) validates electronic signatures themselves. Documents that comply with PDPA also need to be signed correctly under ETA to create a citable electronic record. The two laws complement each other — they're not interchangeable.
What PDPA documents does a clinic need?
At minimum: a Privacy Notice, an internal Privacy Policy, a patient consent form, a DPA with each external processor, a staff confidentiality agreement, and a Record of Processing Activities (RoPA).
Conclusion
Patient health data is sensitive data requiring written consent. Most clinics need to consider appointing a DPO, need a DPA with external processors, and PDPC's administrative fines are already a reality — not a theoretical risk anymore.
Tick off your own checklist, then pull ready-to-customize, ready-to-sign PDPA documents from the Jabmue clinic gallery.
Start free and see all clinic documents Related reading: Digital Informed Consent for Aesthetic and Dental Clinics
This article is not specific legal advice for your clinic. It's a starting point before consulting your legal counsel to confirm accuracy and completeness for your clinic's actual situation.
Last updated: August 2026. This article is reviewed against new legal developments and fine orders at least once a year.
What Is Stamp Duty in Thailand? Which Contracts Need It, and What to Do When You Sign Online (2026)
What is stamp duty, which contracts in Thailand need it, and do contracts signed online through a system like Jabmue still owe stamp duty? Plus how to pay electronic stamp duty (e-Stamp) through the Thai Revenue Department.
Read article →Can You Sign Documents via LINE? A Straight Answer (2026)
Can you sign documents via LINE? Yes, but sending a photo of a signature in chat and signing through an OTP-verified link carry very different legal weight. Here's the comparison.
Read article →Is Daily Condo Rental (Airbnb-Style) Legal in Thailand? What to Know Before Signing a Short-Term Rental Contract
Renting out a condo by the day, Airbnb-style, sits in a genuine legal grey zone in Thailand. The Hotel Act B.E. 2547 (2004) and condominium juristic person rules can both apply. This article explains the risks honestly, plus the clauses a short-term rental contract should include.
Read article →Service Agreement in Thailand: Hire of Work vs Employment Contract, What Actually Changes
A Thai service agreement (hire of work) and an employment contract look similar, but the tax and legal consequences are very different. See the 6 clauses every B2B service agreement needs, plus the points Thai businesses miss most often.
Read article →Rental Security Deposit in Thailand: When It Must Be Returned, What Can Be Deducted, and the Refund Letter
When must a rental security deposit be returned in Thailand? What deductions are lawful, what tenants can do if it isn't returned, and the deposit refund letter every landlord should use — with a ready-made template.
Read article →Thai Receipt Template: How It Differs from e-Tax Invoice, and What Jabmue Can (and Can't) Do
An ordinary receipt and the Revenue Department's e-Tax Invoice are not the same document. This article explains the difference, and says it plainly: Jabmue can create and sign electronic receipts, but it is not an e-Tax Invoice system that files directly with the Revenue Department.
Read article →Quotation Template Thailand: What to Include, Is It Binding, and Can Clients Accept Online?
Quotation template for Thailand: the elements every quote needs, itemized pricing, 7% VAT, validity period, how a quote differs from a purchase order, and how to get clients to sign their acceptance online.
Read article →Property Purchase Agreement + Deposit in Thailand: What to Check Before You Sign
Thailand's agreement to purchase and sell explained: the deposit terms, the clauses it must contain, what happens on breach, and how it differs from the ownership transfer at the Land Department.
Read article →Loan Agreement in Thailand: Over ฿2,000 Needs Written Evidence, Interest Capped at 15%/Year
What must a Thai loan agreement include? Loans over ฿2,000 need signed written evidence (Section 653), interest is capped at 15% per year (Section 654), plus stamp duty and how to sign online.
Read article →Thailand's Draft ETA Amendment (2026): What Could Change
ETDA is seeking public comment on a draft ETA amendment. This is still a draft, not law in force yet: here's what it proposes and the latest status.
Read article →PDPA for Real Estate Agents: How to Collect Tenant and Buyer Data Legally
How real estate agents can collect tenant and buyer data in line with the PDPA — a practical checklist, plus what to watch out for when asking for ID card copies
Read article →Is a Pasted Signature Image in a PDF Valid? How It Differs from a Real E-Signature (2026)
Is a pasted signature image in a PDF valid? It works in practice, but it is not an electronic signature in the legal sense. Here's the difference, and the risks you should know before using one.
Read article →Is an MOU Legally Binding in Thailand? The Honest Answer Is "It Depends", and Here's How to Check
Many people assume an MOU is never legally binding. In some cases, though, a Thai court may read an MOU as an enforceable contract. Learn the 4 things that make an MOU binding by accident, and how to draft one that matches what you actually intend.
Read article →NDA in Thailand: Template, Key Clauses and E-Signing
A sample NDA for Thai businesses: essential clauses, fair duration, penalties courts won't reduce, and how it differs from PDPA. Ready-to-sign template.
Read article →Jabmue vs zDOX: 2026 Comparison (Generic Templates or Ready-to-Use Thai Legal Contracts)
Jabmue vs zDOX compared: per-user pricing, Thai legal contract templates, LINE bot, NDID, and PromptPay (prices verified Aug 2026)
Read article →Jabmue vs eSigns.cloud: 2026 Comparison (Tax-Audit Readiness or an All-in-One Contract Tool)
Jabmue vs eSigns.cloud compared: pricing, document editor, Thai legal templates, e-Tax XML, and PromptPay (prices verified Aug 2026).
Read article →Jabmue vs DocuSign (2026): Which E-Signature Tool Fits Your Thailand Operations?
Jabmue vs DocuSign compared for companies operating in Thailand: pricing, Thai-language support, PromptPay, LINE, and legal templates. Verified August 2026.
Read article →Best E-Signature Tools in Thailand (2026): Pricing, Features, and the Right Pick for Your Business
Compare Jabmue, eSigns.cloud, zDOX, Veracity, and 5 more: real pricing, Thai legal templates, PromptPay, and LINE support — pricing verified Aug 2026
Read article →Real Estate Broker Agreement in Thailand: Protect Your Commission
Real estate broker agreement Thailand sample with explanation: Thai law doesn't require it in writing, but in practice, without written proof, claiming your commission is extremely difficult. References Sections 845-846 of the Civil and Commercial Code, plus a ready-to-use exclusive listing agreement template.
Read article →Are Electronically Signed Documents Admissible in Thai Courts? FAQ (Updated 2026)
Are electronically signed documents admissible in Thai courts? The short answer is yes, with conditions, under the Electronic Transactions Act B.E. 2544 (2001) — with real Supreme Court decisions and ways to strengthen reliability using OTP and an audit trail.
Read article →Lease Termination Notice in Thailand: Templates and Legal Steps
What must a lease termination notice and overdue rent demand letter include? Read the steps under Sections 560/566 of the Civil and Commercial Code, with the correct structure and provable delivery methods (Updated 2026).
Read article →The HR Documents You'll Issue Most Often in Thailand: Warning Letters, Resignation Letters, Employment Certificates
Warning letters, resignation letters, and employment certificates are the 3 HR documents Thai SMEs issue most often, and getting them wrong creates real legal problems. Learn how long a warning letter stays valid, the real resignation notice rules, and what employers are legally required to issue.
Read article →How to Send a Document for Online Signature in 10 Minutes (With Real Screenshots)
Send a document for online signature in 10 minutes — no printing, no scanning, no account needed for the signer, with real screenshots of every step
Read article →Debt Acknowledgment in Thailand: What It Is, How It Differs From a Loan Agreement, and How the Limitation Period Resets
What is a debt acknowledgment letter in Thailand? How it differs from a loan agreement, how it interrupts and resets the limitation period, whether witnesses are required, what it must say, and how to sign it online.
Read article →Can AI Draft a Contract? What the Risks Are (A Straight Answer for 2026)
Can AI like ChatGPT or Gemini draft a contract? Yes, but there are risks you need to know: legal references that may be outdated, potentially unfair contract terms, and the fact that AI-written text is not a legally binding document.
Read article →Power of Attorney in Thailand: Which Form for Which Use?
Power of Attorney Thailand: which form for which use? This guide maps every POA type, Land Office to general business, and what is e-signable.
Read article →PDPA Consent Form Generator: Beyond the Cookie Banner
Most PDPA consent form generators only cover cookies. Build a printable, bilingual consent form for Thai clinics and SMEs, free templates included.
Read article →Notary Public in Thailand vs. E-Signature: What Foreigners Need
Thailand has no Western-style notary public, only Notarial Services Attorneys. Here's when you actually need one and when a legally valid e-signature is enough.
Read article →Is E-Signature Legal in Thailand? The Complete Guide to Thai Law (2026 Update)
Is an electronic signature legal in Thailand? Yes — under the Electronic Transactions Act B.E. 2544 (2001). Full guide: signature types, court evidence, exceptions, and the 2026 draft law.
Read article →Freelance Contract in Thailand: From LINE Chats to a Signed Agreement
Freelancers in Thailand have no labor-law protection. See the 8 clauses your contract needs, and how to turn LINE chats into a signed agreement.
Read article →Employment Contract in Thailand: Template and E-Signing Guide
A ready-to-use bilingual Thai-English employment contract template, with a legally compliant e-signing process via OTP and audit trail, plus a staff NDA.
Read article →Electronic Signature vs Digital Signature in Thailand (2026)
Electronic signature (Section 9) vs digital signature (Sections 26-28) under Thai law: which one your business actually needs, with a comparison table.
Read article →How Secure Are Electronic Signatures? An Honest Answer
How secure are electronic signatures? An honest look at what OTP and an audit trail protect, what they don't, and how to spot fake signing links.
Read article →Condo Lease Agreement in Thailand (Thai-English): Complete Guide
A ready-to-use Thai-English condo lease agreement you can fill in and sign online with OTP, valid under Thai law (Electronic Transactions Act B.E. 2544 (2001)). No printing or scanning required — plus a clear explanation of when leases over 3 years must be registered.
Read article →Digital Informed Consent for Aesthetic and Dental Clinics in Thailand
What must a valid informed consent form include? A guide for aesthetic and dental clinics in Thailand: legally required content, how to separate it from PDPA consent, and how to digitize it without legal risk.
Read article →Certified True Copies in Thailand: Can You Sign Them Online?
Can you sign a certified true copy online in Thailand? A straight answer on when e-signatures work, when you still need wet ink, and how to certify safely.
Read article →Documents for Accounting Firms: Tax Filing Power of Attorney, Engagement Letters, and the Paperwork That Comes Back Every Month
The tax filing power of attorney, engagement letter, and other documents Thai accounting firms handle every month — plus how to get clients to sign online without printing anything
Read article →Ready to stop chasing paper signatures?
Start your free 14-day trial — no credit card required.