Model Regulations on The Providing of Personal Data Protection Officers
Keywords:
Standard Rules, Protection officer, Personal DataAbstract
This purposes of the research were 1) to examine the concepts, theories, and principles concerning the appointment of Data Protection Officers, 2) to study legal measures relating to the appointment of Data Protection Officers in both international contexts and Thailand, 3) to analyze legal issues concerning the appointment of Data Protection Officers, and 4) to study the development of model regulations on the appointment of Data Protection Officers. This qualitative research employed documentary research, in-depth interviews, and focus group discussions. The findings reveal the following issues; 1) Thai law lacks a clear definition of a "Data Protection Officer (DPO)," resulting in difficulties in interpreting the scope of DPO’s roles and responsibilities. Although many international laws also do not provide a precise definition, India specifically addresses this issue. Therefore, Thai law should be amended to include a clear definition in order to enhance legal clarity and enforcement effectiveness, 2) Thai law limits the role of DPOs to advisory functions without granting compulsory or supervisory powers, resulting in ineffective data protection enforcement and potential organizational negligence. Furthermore, DPOs lack the authority to conduct in-depth investigations or directly report violations to regulatory authorities, 3) Thai law does not sufficiently recognize the independence of DPOs, making them vulnerable to organizational pressure and the concealment of data violations. This lack of independence undermines transparency in auditing and reporting processes and may adversely affect the rights of data subjects, 4) Thai law does not clearly prescribe the qualifications of a DPO, providing only broad criteria that primarily to public sector. Consequently, there is insufficient comprehensive coverage across various business sections and a lack of clearly identified professional competencies and essential skills, and 5) Thai law does not clearly specify which types of organizations are required to appoint DPOs, This ambiguity enables some organizations to avoid compliance, resulting in ineffective and inconsistent enforcement. Therefore, clear criteria should be establised to ensure comprehensive compliance and effective enforcement of data protection laws.
References
ฉัตรฑริกา นภาธนาพงศ์ และอัชราภรณ์ อริยสุนทร. (2566). ปัญหาการบังคับใช้ตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 : ศึกษากรณีการคุ้มครองข้อมูลส่วนบุคคลของเด็ก. วารสารนิติศาสตร์ มหาวิทยาลัยธรรมศาสตร์, 52(3), 640-670. https://so05.tci-thaijo.org/index.php/tulawjournal/article/view/264929
วันพิชิต ชินตระกูลชัย. (2564). DPO (Data Protection Officer) มีหน้าที่อะไร และต้องรู้อะไรบ้าง. https://openpdpa.org/dpoduty/.
ศิริกร สีสดดี. (2568). ปัญหาการบังคับใช้กฎหมายคุ้มครองข้อมูลส่วนบุคคลในโรงพยาบาลของรัฐ. วารสารกฎหมายและสังคมรังสิต, 7(1), 16-34. https://so07.tci-thaijo.org/index.php/RJL/article/download/6256/4667
ศิริญญา ดุสิตนานนท์. (2565). ปัญหาและข้อเสนอแนะในการบังคับใช้พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562. วารสารสังคมศาสตร์ มหาวิทยาลัยศรีนครินทรวิโรฒ, 25(2), 154-174.
https://ejournals.swu.ac.th/index.php/JOS/article/download/14420/12256/50825
ปิติ เอี่ยมจำรูญลาภ. (2566). แนวทางการเปิดเผยข้อมูลข่าวสารของราชการตามพระราชบัญญัติข้อมูลข่าวสารราชการ พ.ศ. 2540 ที่มีข้อมูลส่วนบุคคลรวมอยู่ด้วย. วารสารกฎหมายนิติพัฒน์ นิด้า, 12(1), 66–83. https://so04.tci-thaijo.org/index.php/nitipat/article/view/263675
ณฐพร วิริยะลัพภะ และธเนศ สุจารีกุล. (2563). ปัญหาทางกฎหมายเกี่ยวกับพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ.2562 :ศึกษากรณีหน้าที่ของผู้ควบคุมข้อมูลส่วนบุคคลตามมาตรา 39. การประชุมนำเสนอผลงานวิจัยระดับบัณฑิตศึกษาครั้งที่ ๑๕. จัดโดย บัณฑิตวิทยาลัย มหาวิทยาลัยรังสิต. 2195-2204.
https://rsujournals.rsu.ac.th/index.php/rgrc/article/download/1875/1462
Donnelly, J. (2013). Universal human rights in theory and practice (3rd ed.). Cornell University Press.
European Union. (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). Official Journal of the European Union, L119, 1–88. https://eur-lex.europa.eu/eli/reg/2016/679/oj
Greenleaf, G. (2018). Global data privacy laws 2017: 120 national data privacy laws, including Indonesia and Turkey. Privacy Laws & Business International Report, 145, 10–13.
Office of the National Human Rights Commission of Thailand. (1999). National Human Rights Commission Act B.E. 2542 (1999). Bangkok, Thailand.
Office of the Personal Data Protection Committee. (2019). Personal Data Protection Act B.E. 2562 (2019). Bangkok, Thailand.
Solove, D. J. (2006). A taxonomy of privacy. University of Pennsylvania Law Review, 154(3), 477–564. https://zoo.cs.yale.edu/classes/cs457/fall13/SoloveTaxonomy.pdf?utm
United Nations. (1948). Universal Declaration of Human Rights. https://www.un.org/en/about-us/universal-declaration-of-human-rights
United Nations. (1966). International Covenant on Civil and Political Rights.
United Nations. (1948). Universal declaration of human rights. https://www.un.org/en/about-us/universal-declaration-of-human-rights
Warren, S. D. and Brandeis, L. D. (1890). The right to privacy. Harvard Law Review, 4(5), 193–220. https://www.gutenberg.org/files/37368/37368-h/37368-h.htm
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 NEU ACADEMIC AND RESEARCH JOURNAL

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.