Thailand’s PDPA Establishes Personal Data Compliance Framework for A2P Marketing SMS

Thailand’s Personal Data Protection Act (PDPA) entered into full force on 1 June 2022. Although the statute itself does not contain technical terms related to A2P SMS, it sets out basic data compliance rules for A2P marketing SMS under the section of “direct marketing”. The Act has extraterritorial jurisdiction. Any overseas enterprise sending marketing SMS to users located in Thailand must comply with PDPA provisions, regardless of whether the enterprise has a local legal entity in Thailand.

Four core articles directly govern SMS marketing activities. Article 24 stipulates that enterprises must have a lawful basis for processing personal data such as mobile phone numbers for marketing purposes. In practice, obtaining explicit consent from users is the safest compliance route. Article 19 sets strict criteria for valid consent: user authorisation must be voluntary, specific, clear and fully informed. Consent embedded as a default clause within service agreements or obtained via pre‑ticked checkboxes is deemed invalid and cannot serve as proof of user permission. Article 27 guarantees users the right to withdraw consent at any time, and the withdrawal process shall not be more cumbersome than the original subscription process. Article 30 grants users the right to object to direct marketing. Upon receiving opt‑out or marketing rejection requests, enterprises must immediately cease sending marketing SMS to the relevant number.

For A2P business implementation, enterprises need to fulfil five compliance obligations. First, obtain prior, explicit and informed consent from users before dispatching marketing SMS. Second, attach a clear and functional opt‑out mechanism on every marketing SMS, which can be implemented via links or other viable methods. Third, strictly segregate OTP verification messages, transactional alerts and promotional marketing SMS; marketing content shall not reuse Sender‑IDs reserved for transactional notifications. Fourth, retain all records such as user consents and opt‑out requests for the long term to prepare for regulatory audits. Fifth, cross‑border service providers must take the extraterritorial effect seriously and cannot evade PDPA liabilities merely by virtue of being an overseas entity.

It should be noted that functional notifications such as OTP codes and transaction reminders are not treated as direct marketing and are exempt from the consent rules for marketing SMS. Nevertheless, they still need to comply with the basic data security obligations under PDPA. From the perspective of user privacy, PDPA complements the telecom regulations issued by NBTC. Together they form a dual regulatory framework for Thailand’s A2P industry.