AI Regulation Tracker / Data protection
Thailand's PDPC Draft Guidelines Map PDPA Controller and Processor Duties Onto AI
A draft for consultation, not a binding rule. On February 17, 2026, Thailand's Personal Data Protection Committee released draft guidelines that apply the country's PDPA to how personal data is used across the AI lifecycle, including who is a controller, who is a processor, when a DPIA is needed, and what training on personal data requires.
Thailand is doing something a growing number of data regulators are doing. Rather than wait for a comprehensive AI statute, the Personal Data Protection Committee has taken the privacy law already on the books and spelled out how it applies to artificial intelligence. The draft Guidelines on Personal Data Protection in the Development and Use of Artificial Intelligence came out on February 17, 2026, and the comment window ran a short course to February 25, 2026. The document is a draft and it is advisory, but it is the clearest statement yet of how the PDPC intends to police AI that touches personal data.
Who is the controller and who is the processor in an AI system?
This is the question the draft answers most usefully, because it decides where the duties land. The PDPC's line is that the party deciding what the AI is for and what data feeds it carries the controller's obligations. In the draft's framing, "users of AI who determine the purpose of use and designate the input data are considered data controllers." The model provider or system integrator that handles personal data on the controller's instructions sits in the processor role. That distinction is not academic. Under a PDPA-style regime, the controller owns the heavy duties, lawful basis, transparency, honoring data-subject rights, and it is the controller a regulator comes to first. If you are deploying a third-party model on your own data for your own purposes, this draft is telling you that you are probably the controller, not a bystander.
When does high-risk AI trigger a DPIA?
The draft leans on the data protection impact assessment as the main control for higher-risk uses. It treats a DPIA as necessary where AI is used for automated decision-making that has legal or similarly significant effects on people, and where there is large-scale processing of sensitive data to train a model. As the PDPC puts it, "DPIAs for high-risk AI applications are necessary to identify, manage, and mitigate AI-specific risks." The practical read is straightforward. If your system makes or heavily influences decisions about people, or if you are training on sensitive personal data at scale, the regulator expects a documented assessment before you proceed, not an explanation after something goes wrong.
What does the draft say about training AI on personal data?
This is the part that will matter most to anyone building or fine-tuning models. The draft pushes the control down into contracts. It expects data processing agreements to prohibit using personal data to train AI models without authorization, and it goes further than most, contemplating remedies such as deleting model weights and vector databases where data was used without a proper basis. That is a strong signal. It means a vendor cannot quietly recycle a customer's personal data into its own model, and it means the paperwork between parties has to say so explicitly. For companies that both consume and provide AI services, the message is to get the training-data permissions and prohibitions written down clearly, on both sides of every deal.
How binding is this draft?
Be precise here. The guidelines are non-binding. They are draft guidance issued for consultation, and they interpret the PDPA rather than replace or extend it. What they carry is the regulator's expectations and, as one summary put it, the likely direction of interpretation and enforcement. That is worth taking seriously even though it is not law, because when the PDPC eventually enforces the PDPA against an AI use, this is the reasoning it will apply. But nobody should tell you Thailand has passed binding AI data rules. The binding duties live in the PDPA. The draft tells you how the regulator will read them.
What should US companies with Thai exposure do now?
If you process the personal data of people in Thailand, whether through Thai customers, users, or local operations, treat this draft as your working guide to PDPA-for-AI. Map your systems against the controller and processor definitions so you know which duties are yours. Stand up DPIAs for any AI that makes significant decisions about people or trains on sensitive data at scale, and keep them current. Then go through your vendor and customer contracts and make the training-data position explicit, both the authorizations you rely on and the prohibitions you impose. None of this is compelled by the draft itself, but all of it is what the PDPA already expects and what the regulator has now told you it will look for. Doing it now is cheaper than doing it under an enforcement notice later.
Questions professionals are asking
Are Thailand's PDPC AI guidelines binding?
No. The draft Guidelines on Personal Data Protection in the Development and Use of AI, released February 17, 2026, are non-binding guidance issued for consultation. They interpret Thailand's existing PDPA as applied to AI. The enforceable duties come from the PDPA itself, not from the guidelines.
Who counts as a controller when using an AI vendor?
The party that determines the purpose of the AI and designates the input data is the data controller under the draft. A model provider or system integrator handling personal data on the controller's instructions is the processor. If you deploy a third-party model on your own data for your own purposes, you are likely the controller.
When is a DPIA required for AI under the draft?
The draft calls for a DPIA where AI performs automated decision-making with legal or similarly significant effects on individuals, and where there is large-scale processing of sensitive data for model training. The DPIA is meant to identify, manage, and mitigate AI-specific risks before deployment.
Can a vendor use our data to train its AI models?
Not without authorization, under the draft. It expects data processing agreements to prohibit using personal data to train AI models without permission, and even contemplates deleting model weights and vector databases where data was used improperly. Get the training-data permissions and prohibitions written into every contract.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any guideline or statute applies to your situation with qualified counsel in the relevant jurisdiction.