Callstrike
Compliance

Voice phishing simulations in Thailand

Phone numbers in ThailandProvisioned by Callstrike after approval

Thailand reads differently from its neighbours in both directions, and a voice phishing simulation here is gated by a document rather than by a regulator. The privacy statute is a prohibition with exceptions rather than a menu of grounds, the criminal code contains no eavesdropping offence at all, and any disciplinary consequence the programme can lead to has to already exist in your posted work rules before the first call rather than be constructed after the first result.

Phone numbers

Supplied by Callstrike

Local numbers in Thailand, after a one-time approval.

Running a simulation

Permitted, and the work rules gate it

Discipline has to be in the posted rules before the campaign, not written afterwards.

Consent

Strained by the statute itself

The freely-given test is what pushes an employer to the balancing exception instead.

Getting a phone number in Thailand

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

The Thai table below has one line that catches companies out and it is not the address. Both the name and the identity number of your legal representative have to be evidenced by a Thai government-issued identity card, so a company whose authorised signatory is not Thai has a problem to solve before the filing rather than during it. Alongside that, the business name and the business registration number come from an excerpt of the commercial register, and the console form asks you to type your business type.

The address line is the ordinary regional one: it has to fall inside the locality covered by the number's own prefix, evidenced by a register excerpt, a utility bill, a tax notice, a rent receipt or a title deed, and a post office box is not accepted where a local address is required. Plan the number's area code and the address you can evidence together rather than in sequence.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Thailand is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Business addressMust be within locality or region covered by the phone number’s prefix; a PO Box is not acceptable where a local address is required.Excerpt from the commercial register, Utility bill, Tax notice, Rent receipt, Title deed
ID number of the legal representativeThai government issued ID card
Business registration numberExcerpt from commercial register
Business nameExcerpt from commercial register
Name of legal representativeThai government issued ID card

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Thailand?

The position in short, before your counsel reads the detail below.

Yes, and the first thing to get right is structural, because getting it wrong changes every sentence after it. The Personal Data Protection Act does not set out co-equal grounds. It opens by providing that the controller shall not collect personal data without the agreement of the data subject unless one of six situations applies, so Thailand is agreement-default with carve-outs and anyone describing it from the European regulation will describe it incorrectly. The situation an employer works from is the fifth: necessity for the legitimate interests of the controller or another person, except where those interests are overridden by the fundamental rights of the data subject. Read that clause carefully, because the words for freedoms do not appear in it and a Thai assessment should quote the Thai wording rather than the European formula it resembles.

A second structural point follows from the same drafting and changes how the assessment is written. That provision governs collection, and the Act treats use and disclosure separately, so the Thai analysis is not the single one-shot selection the European model encourages. Work through collection, use and disclosure as three questions and record three answers.

On agreement, Thailand belongs with Czechia and Israel in this portal, and the reason is in the statute rather than in a regulator's opinion. A request has to be made explicitly in writing or by electronic means, presented in a manner clearly distinguishable from other matters, in an easily accessible and intelligible form, in clear and plain language, and not deceptive or misleading as to the purpose. The controller then has to take utmost account of whether the agreement is freely given, and the data subject may withdraw it at any time. An employment relationship strains every one of those, which is why the balancing carve-out rather than agreement is the realistic route, and it is also why what your staff were told still has to be evidenced even though it is not what the processing rests on.

Recording is the one thing this page cannot resolve, and the reason is unusual enough to be useful. There is no Thai eavesdropping offence: the words for eavesdropping, intercepting, listening in, conversation and recording device return zero across all three hundred and ninety-eight sections of the penal code, and the provisions that do exist cover sealed physical correspondence, a closed list of professions that excludes an employer and a testing vendor, industrial secrets, and state telecoms officials. The one remaining candidate is a computer crime provision with five cumulative elements that on its face does not catch a party to the call, but whether a telephone call is computer data within a computer system for its purposes is unresolved on every source reachable under this portal's standard. Thailand is neither the all-party model of the Philippines nor the participant-permitted default of Europe, and we are not going to borrow either.

What your company needs to do

8 items, in the order you will need them.

  • Decide whether failing can carry a consequence, before you buyThailand-specificDiscipline and disciplinary penalties are one of the eight matters the work rules must contain, and the basis for any consequence has to exist in the posted rules before the campaign runs. Constructing it afterwards is the failure mode, and it is the one Thai decision that has to be made before a purchase rather than during a rollout.
  • Post the work rules in Thai where staff can read them convenientlyThailand-specificAt ten employees in total the rules have to be announced within fifteen days, a copy kept at the establishment at all times, and the rules publicised and posted openly at the workplace so employees may know and read them. Where they are amended, the amended rules have to be announced within seven days of being brought into use.
  • Do not file the work rules with the labour departmentThailand-specificThe duty was removed and the provision says so in terms: there is no need to send a copy to the Director-General or a delegate. Several Thai government pages state the removal expressly, which suggests the stale belief is common enough to be worth correcting on a checklist someone else wrote.
  • Make sure the grievance route is in the same documentThailand-specificGrievances are a separate one of the eight required matters, and it is where an employee who objects to having been tested will go. Knowing that in advance is the difference between a complaint that has a route and one that arrives somewhere nobody expected it.
  • Record the balancing exception three times overThailand-specificOnce for collection, once for use and once for disclosure, because the Act treats them separately. Quote the Thai override wording rather than the European one: the clause reads overridden by the fundamental rights of the data subject, with no freedoms limb, and whether that narrows the override in practice is untested.
  • Write the security measures down and review them when the technology changesThe statute imposes a standing duty to provide appropriate measures preventing unauthorised or unlawful loss of, access to, use, alteration, correction or disclosure of personal data, reviewed when necessary or when the technology changes, and in accordance with the minimum standard the committee announces.
  • Present a Thai number exactly as it was allocatedThailand-specificThe rule is not in the anti-scam emergency decree everyone reaches for, which carries no caller identity provision at all. It is a clause in the numbering notification requiring a number to be used exactly as allocated without any modification whatsoever, naming the display of the originating number as a case it covers. It admits no modification, so this is not a question of whether the number you present is misleading.
  • Take an employee committee to Thai counsel if you have oneThailand-specificThe work rules provisions contain no consultation, agreement or negotiation step at all, and the verbs are to provide and to announce. What this page has not covered is the labour relations statute's employee committee, which is a separate institution with its own threshold and its own duties, so a work-rules provision that contains no consultation step is not Thailand having no consultation duty anywhere.

The controls that do the work

How Callstrike is configured, and which provision in Thailand each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Thailand has no acquisition-by-deception offence for this to dispose of, so what it answers here is the shape of the assessment rather than a criminal provision. The override clause is bare, reading overridden by the fundamental rights of the data subject with no freedoms limb and no case law on it, and the Act makes you justify collection, use and disclosure separately. A credential that is never spoken into the system is not three questions you have to answer, it is none, and the smaller the exercise's actual collection the less weight that untested override is ever asked to carry. It also keeps the security duty proportionate to something you are still holding a year later.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

Two of the eight matters your work rules have to contain are discipline and grievances, and both of them are about what happens to a person after they fail. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, keeps the exercise out of the disciplinary limb entirely, which is the cleanest way to answer the decision this page opens with, and it is also the reason most people never reach for the grievance route in the first place.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Agreement is not what the programme rests on, because the statute's freely-given test is one an employment relationship strains, and the balancing carve-out is the realistic route instead. What is distinctly Thai is that the work rules mechanism is unilateral promulgation plus publication, with nothing filed anywhere: you announce, you keep a copy at the establishment and you post them openly. Nobody can later prove from a notice board that the rules reached a particular person, and a dated per-employee record that they did is exactly the evidence that publication duty cannot leave behind on its own.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

The Thai numbering clause is the friction worth designing around, because it admits no modification whatsoever and it binds the allocatee, which means it reaches you through whichever Thai party holds your numbering. A learner-initiated session presents no number for that clause to be about: Callstrike's vishing simulator carries the same deepfake voice into a web call the learner opens after working through the module. State the limit honestly, though. There is no Thai synthetic-voice disclosure duty for the module to satisfy, and the computer crime provision on manipulated content says image throughout with no voice limb, so this route answers delivery rather than an obligation that does not exist.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

A prohibition with exceptions, not a menu of grounds

The first thing to get right about Thailand is structural, and getting it wrong changes every sentence after it. The Personal Data Protection Act does not set out co-equal lawful bases. It opens by providing that the data controller shall not collect personal data without the consent of the data subject, unless one of six situations applies. Thailand is consent-default with carve-outs, and anyone who learned this shape from the European regulation, or even from the Philippine statute, will describe it incorrectly.

The carve-out an employer works from is the fifth: where it is necessary for the legitimate interests of the controller or of any other person, except where such interests are overridden by the fundamental rights of the data subject. Read that last clause carefully, because it is not the formula it resembles. The words for freedoms do not appear. Whether that narrows the override in practice is untested and we make no claim about it, but a Thai assessment should quote the Thai wording rather than the European one it will be tempting to paste in.

A second structural point follows from the same drafting. That provision governs collection, and the Act treats use and disclosure separately, so a Thai analysis is not the single one-shot basis selection that the European model encourages. Work through collection, use and disclosure as three questions.

Agreement is a poor foundation here for the reason it is a poor foundation everywhere, and the statute makes the point twice over. A request for agreement must be explicitly made in writing or by electronic means, presented in a manner clearly distinguishable from other matters, in an easily accessible and intelligible form, in clear and plain language, and not deceptive or misleading as to the purpose. The controller must take utmost account of whether the agreement is freely given, entering into a contract or providing a service must not be made a condition of agreeing to processing unrelated to it, and the data subject may withdraw. An employment relationship strains every one of those, which is why the balancing carve-out rather than agreement is the realistic route.

Alongside that sits a standing security duty: the controller must provide appropriate security measures preventing unauthorised or unlawful loss of, access to, use, alteration, correction or disclosure of personal data, reviewed when necessary or when the technology changes, and in accordance with the minimum standard the committee announces.

Two honest notes about currency, because both are commonly stated with more confidence than we can support. The Act's own commencement clause brought several chapters into force a year after publication, and the royal decrees that later postponed them are documents we could not source. So we are not going to print the familiar sentence that the Act has been in force in full since 1 June 2022. What we can say is that the regulator continues to publish this Act as the operative law. And separately, a Thai emergency decree on technological crime expressly disapplies the data protection law for data handled under it, which is unusual enough to be worth knowing before reasoning from the premise that the Act always applies.

No eavesdropping offence at all, and a question the text leaves open

Thailand is the country in this portal where we can tell you least about recording, and the reason is interesting rather than a failure of research. There is no wiretapping statute to point at.

We searched the full consolidated penal code, all three hundred and ninety-eight sections across a hundred and nineteen pages, for the Thai words for eavesdropping, intercepting, listening in, conversation and recording device. Every one of them returns zero. Thailand has no general eavesdropping offence, which is unlike almost every other jurisdiction covered here.

What the code does have does not reach a simulated call. One provision covers opening or taking a sealed letter, telegram or document, and a telegram is a physical sealed message rather than telephony. Another covers disclosure of a secret learned through a closed list of occupations, running from physician and pharmacist to advocate and auditor, on which an employer, an internal security team and a testing vendor do not appear. A third covers industrial and scientific secrets learned through a position of trust, which a simulation call's contents will not be. The only telephone confidentiality offence in the code binds officials with duties in the postal, telegraph or telephone service, so it reaches a state telecoms official and not you. That whole chapter is compoundable, meaning prosecutable only on the victim's complaint and capable of settlement.

That leaves one candidate, in the computer crime statute, and the first thing to say is that it is narrower than it is usually reported. It has five cumulative elements, not three: the act must be unlawful, done by electronic means, aimed at intercepting computer data of another person, that data must be in the course of transmission within a computer system, and the data must not be held for public benefit or general public use. The penalty is up to three years, a fine of up to sixty thousand baht, or both.

On its face that provision does not catch a party to the call, for three separate textual reasons. The data must be another person's, and a participant's own call leg is at minimum arguably also theirs. The interception must occur while the data is in transmission within a computer system, and recording the audio at your own endpoint after delivery is not capture in transit. And the verb means to lie in wait and receive, which is not what the intended recipient does.

Here is the part we will not paper over, and it is the most consequential gap in our Thai research. Whether a telephone call is computer data within a computer system for that provision's purposes is the hinge of the whole question, and we could find no Thai statutory text and no Supreme Court judgment resolving it that is reachable under this portal's source standard. So the honest answer is that the texts do not settle the participant question, and Thailand is neither the all-party model of the Philippines nor the participant-permitted default of Europe. We are not going to borrow either.

What that means in practice is more workable than it sounds. The criminal exposure from recording your own simulated call to your own staff is weak to nil on the text as it stands. The real Thai duty on the recording is the data protection one described above, and the work rules described further down. Design to those, take the characterisation question to Thai counsel if the programme is large, and do not let anyone tell you the Philippine answer applies here.

The rule binds operators selling things, and says nothing about machines

Thailand's unsolicited-call rule is a regulator notification on conduct that takes unfair advantage of consumers in the telecommunications business, and it is scoped twice in ways that both put an internal exercise outside it.

The first scoping is by addressee. The duties run to licensed telecommunications operators, not to ordinary employers, and the notification's own annex names its target as telemarketing by telecom operators. An employer testing its own staff is not a licensee acting as one.

The second is by purpose, and it is defined rather than left to interpretation. The prohibited act is telephoning or sending an advertising message to a consumer's terminal so as to cause annoyance, or without the consumer's permission. Advertising is then defined in the notification itself as an act, by whatever method, causing the public to see, hear or know a message for commercial benefit, in a manner persuading consumers to perceive the quality of a service, for the purpose of seeking profit in the telecommunications business. An internal security exercise persuades nobody of anything and seeks no profit. The enforcement behind it is real, running to an order to stop and an administrative fine of up to five million baht plus up to a hundred thousand a day for continued non-compliance, but it does not reach this activity.

Now the finding that decides voice mode, and it is an absence. We could locate no Thai instrument regulating automated diallers, interactive voice outdial or pre-recorded voice at all. We searched the gazette title index for the consumer-exploitation notification, which returns exactly one document with no automation limb, and for telecommunications numbering, reviewing forty titles, and found nothing on automated calling. The honest statement is that Thailand regulates the commercial purpose of a call rather than the technology placing it. Nothing in the rules turns on whether a person or a machine is speaking.

On synthetic voice the answer is a clean negative, and we established it rather than assuming it. Thailand has no artificial intelligence statute, no deepfake statute and no synthetic-voice disclosure duty. The gazette returns two hundred and seventy-three documents for the Thai term for artificial intelligence, and of the hundred most recent we reviewed, every substantive one is the industry ministry adopting an international standard as a voluntary Thai industrial standard, or an association registration, or a national plan, or parliamentary minutes. No act, emergency decree or royal decree on artificial intelligence appears. Thailand's activity here is standards activity, not legislation, and the volume of gazette traffic makes that easy to mistake.

The nearest in-force provision is a computer crime offence about manipulated content, and reading it closes the question rather than opening it. It covers entering into a computer system accessible to the general public data appearing as an image of another person, created or altered by electronic or other means, in a manner likely to damage their reputation or expose them to contempt or humiliation. The operative word is image throughout. There is no voice limb, and a private call is not accessible to the general public. A cloned voice on a consented internal exercise is outside it on the text.

Not the anti-scam decree, and the real rule admits no modification at all

Everyone looking for Thailand's anti-spoofing rule reaches for the emergency decree on technological crime, and it is the wrong instrument. We read it, and its 2025 amendment, in full. Neither carries any caller identity or anti-spoofing provision. Its number-related offences are about permitting another person to use or borrow your mobile number where you know or ought to know it will be used for crime, about trafficking in registered numbers whose actual user cannot be identified, and about registration failures. None of them is about what number a caller presents. This is exactly the kind of rule that a search for the word spoofing does not find.

The rule that does govern it is a clause in the numbering administration notification, and it is absolute in its terms. An allocatee of numbers must use a number allocated by the regulator only within the purpose and scope permitted; and when a number is used for any purpose whatsoever, the notification giving sending to another network and displaying the originating number as its own examples, the number shall be used exactly as allocated, without making any modification whatsoever. The same duty is restated in the same words for short codes.

Two things about that are worth drawing out. It admits no modification at all, so this is not a rule about whether the number you present is misleading; presenting anything other than the number as allocated is the breach. And it binds the allocatee, meaning the licensee or entity the regulator allocated the number to, rather than every end user, so in practice it reaches you through the Thai party that holds your numbering. We checked that the clause survives: the notification was amended once, and we read the amendment's repealing clauses through, which replace a list of other clauses and an annex form and leave this one untouched.

Separately, telephone licensees must provide a calling-number display service, a facility to prevent display of the outgoing number, and a facility to reject unwanted numbers. We did not check that notification for later amendments, so treat its currency as unestablished.

On inbound international traffic the answer is more specific than the shorthand suggests, and the shorthand is backwards. Thailand does not blanket-block foreign calls presenting Thai numbers. It blocks a named list: inbound international calls presenting a Thai fixed-line number, a Thai three-digit short code or a Thai four-digit short code, and calls presenting a country code the international body has not allocated to anyone. Thai mobile numbers presented from abroad are not on that list. Calls arriving with no calling number at all have a plus sixty-six marker prepended, precisely so a recipient can see the call came from outside, which is the opposite of what blocking on that prefix sounds like. A separate marker is prepended to calls from Thai numbers roaming abroad, and inbound traffic is tested continuously for number modification.

We would rather be precise about what those measures are than let them read as more solid than they are. They are administrative measures the regulator's office directed at the six international gateway licensees and announced on its website, not gazetted notifications with commencement clauses, and we found nothing superseding them. So the gazetted rule to design against is the numbering clause, and the practical answer that follows from it needs no argument: originate on Thai numbering allocated to your own organisation and present it exactly as allocated.

What the country matrix holds for Thailand

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Work rules posted where staff can read them, and nothing to file

The Thai employment deliverable is a single document, and two things commonly said about it are out of date.

An employer with ten or more employees in total must provide work rules in the Thai language, containing at minimum eight enumerated matters: working days, normal hours and rest periods; holidays and the rules for taking them; overtime and holiday work; the date and place of payment of wages, overtime, holiday pay and holiday overtime; leave days and leave rules; discipline and disciplinary penalties; grievances; and termination, severance pay and special severance pay.

Two of those are the hooks for a simulation programme and they are the sixth and the seventh. If the programme can lead to any disciplinary consequence at all, the disciplinary basis has to already exist in the posted rules before the campaign runs, not be constructed afterwards. And the grievance route is where an employee who objects to having been tested will go, so it is worth knowing it is a required part of the same document.

The mechanism is unilateral promulgation plus publication, and the deadlines are short. The employer must announce the rules within fifteen days of reaching ten employees, keep a copy at the establishment at all times, and publicise and post them openly at the workplace so employees may know them and read them conveniently. Where the rules are amended, the amended rules must be announced within seven days of being brought into use.

Now the correction. The employer need not send a copy of the work rules to the Director-General of the labour protection and welfare department or a delegate. That wording is in the provision itself. Any guidance telling a Thai employer to file its work rules with the labour department is describing a duty that has been removed, and several Thai government pages state the removal expressly, which suggests it is a common enough belief to be worth correcting.

On consultation we are going to be careful about the scope of what we checked, because the tempting sentence is broader than the evidence. There is no consultation, agreement or negotiation step in the two work rules provisions: the verbs are to provide and to announce and bring into use, and no body appears in that mechanism at all. What we have not done is read the labour relations statute's provisions on the employee committee, which is a separate institution with its own threshold and its own duties, and that is not established either way in this research. So the accurate statement is that the work rules duty contains no consultation step, and not that Thailand has none anywhere in labour law. If your Thai workplace has an employee committee, take the question to Thai counsel rather than reading this page as an answer.

So the Thai file is: the work rules, in Thai, carrying a disciplinary basis that covers the programme and a grievance route, announced and posted where staff can read them; the record of the balancing carve-out worked through separately for collection, use and disclosure; the security measures the data protection statute requires; and a note of the recording characterisation question left open above, so that whoever revisits it knows it was considered rather than missed.

A state-run readiness test, and one example in a guideline

Thailand has two sector regimes worth checking and neither requires this activity. We counted the terms across every instrument rather than relying on impressions, and the word for this attack returns zero everywhere.

The cybersecurity statute puts real duties on organisations running critical information infrastructure. They must arrange a cyber risk assessment by an assessor and an information security audit by an internal or independent external auditor, at least once a year, and must send a summary report of what was done to the national agency's office within thirty days of completing it. Alongside those sits a monitoring mechanism and one further duty that reads like a testing obligation and is not the one a vendor would hope: the organisation must take part in the readiness test for responding to cyber threats that the agency's office organises. That is participation in a state-run exercise, not an obligation to run your own social engineering against your staff. The statute's only other drill reference is a function of the agency itself, which runs training and drills for the bodies it oversees.

In banking the position is finer and worth quoting precisely, because it is the one place in Thai regulation where these words appear at all. The central bank's binding information technology risk notification carries an annexed implementation guideline, and one clause of that guideline asks institutions to establish an awareness programme on information security, information technology risk and safe system use, giving as examples testing on social engineering and phishing, and rehearsing the plan for responding to a cyber attack, and so on, covering board level through every level of personnel and relevant external persons.

Read the framing rather than the keywords. The clause is an illustrative list inside a guideline, introduced and closed by the Thai words for for example and and so on. It recommends an awareness programme and offers social engineering testing as one way to build one. It does not mandate the testing, and there is no voice limb in it. A separate central bank supervisory manual requires annual application penetration testing by an external expert and staff awareness, with no mention of phishing, voice phishing or social engineering at all. A third central bank document uses the term social engineering once, and only to describe the fraud a bank must protect its customers against.

The counts make the position unarguable. Across the cybersecurity statute, the central bank's notification package, its fraud policy, its examination guideline and the emergency decree, the Thai and English terms for voice phishing return zero in every document. Phishing and social engineering each appear exactly once in the whole set, and both occurrences are that one guideline sentence and the fraud description. No Thai regime examined mandates a vishing simulation, and a Thai buyer should be told that plainly rather than sold an obligation that does not exist.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in THAILAND. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. Work rules are posted at the workplace.

Verify or correct each proposition below against primary Thai sources, and tell me what our work rules must already say:

1. ⚠ PDPA s 24 is a PROHIBITION with six exceptions, not a menu of co-equal bases, and s 24(5) reads 「overridden by the fundamental rights of the data subject」, and the words «and freedoms» DO NOT appear. Confirm both.
2. The Act treats collection, use and disclosure separately. Confirm we owe three assessments rather than one.
3. PDPA s 19's freely-given, distinguishable and non-deceptive requirements make employment-context agreement a poor foundation. Confirm this, and confirm that transparency evidence is still owed under the balancing route.
4. ⚠⚠ The Penal Code has NO eavesdropping offence (ดักฟัง, ดักรับ, แอบฟัง, สนทนา, เครื่องบันทึก all return zero across all 398 sections); s 322 is sealed PHYSICAL correspondence, s 323 a closed professional list, s 163 binds เจ้าพนักงาน only.
5. ⚠ CCA s 8 has FIVE cumulative elements including 「ด้วยวิธีการทางอิเล็กทรอนิกส์」 and the negative element about data not held for public benefit. Is a voice call 「ข้อมูลคอมพิวเตอร์ ... ในระบบคอมพิวเตอร์」 at all? This is our single most consequential open question: is there ANY Supreme Court judgment on it?
6. ⚠ The caller-ID rule is ข้อ ๑๙(๒) of the 2563 NBTC NUMBERING notification (use the number 「โดยไม่ทำการแก้ไขเปลี่ยนแปลงใด ๆ」, expressly including 「เพื่อแสดงเลขหมายต้นทาง」), NOT the Emergency Decree on Technological Crimes, which carries no caller-ID provision at all.
7. LPA s 110 expressly removes the duty to send work rules to the Director-General. Confirm, and confirm ss 108/110 contain no consultation step.
8. ⚠ NOT COVERED HERE: the Labour Relations Act B.E. 2518 คณะกรรมการลูกจ้าง duties. If our workplace has an employee committee, what does it change?

⚠ We could NOT source the royal decrees postponing PDPA Chapters II/III/V/VI/VII, so do not assume «in force in full since 1 June 2022». Flag anything that has changed since September 2026.

Common questions

Can we record a simulated call in Thailand?
The texts do not settle it, and we will not borrow a neighbour's answer. There is no Thai eavesdropping offence at all, and the computer crime provision does not catch a participant on its face, but whether a voice call is computer data for that provision is unresolved on reachable sources.
Which number can a Thai campaign display?
One allocated to you, presented exactly as allocated. The numbering notification requires an allocatee to use a number without making any modification whatsoever, and names displaying the originating number as a case it covers. The anti-scam emergency decree, despite its reputation, carries no caller identity rule.
Does Thailand require us to say the voice is AI generated?
No. There is no Thai artificial intelligence statute, no deepfake statute and no synthetic-voice disclosure duty in force. The nearest computer crime provision is confined to images of a person entered into a publicly accessible system, so it has no voice limb and does not reach a private call.
Do we file our work rules with the labour department?
No, and that is the most common stale belief about Thailand. The provision says expressly that the employer need not send a copy to the Director-General. What you must do is announce the rules, keep a copy at the establishment, and post them openly where employees can read them conveniently.

Elsewhere in Asia Pacific

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.