Join our Newsletter — 33% off our NHI Course

What are the signs that an employer is misapplying Thailand’s PDPA data retention rules?

Common warning signs include retaining employee records without a stated retention period, keeping unnecessary applicant or employee data beyond its purpose, and lacking a documented destruction process when data is no longer needed. A weaker signal is failing to tell employees how long their information will be kept. Those gaps usually indicate retention is being managed informally rather than as a compliance control.

What misapplied retention looks like in practice

Thailand’s PDPA does not treat retention as an informal housekeeping task. When an employer is applying the rules properly, it can explain why each category of employee data is kept, for how long, and what happens when that period ends. Warning signs usually show up when those answers are missing, inconsistent, or handled case by case instead of through a defined retention schedule.

One common pattern is over-collection by default, then indefinite storage. That often appears in HR files, recruitment records, payroll attachments, CCTV extracts, access logs, or email archives that remain available long after the original purpose has passed. Another signal is when retention exists only in practice, not in policy, so staff cannot point to a documented standard for keeping or deleting records.

Which gaps are the strongest indicators of non-compliance?

The clearest indicator is the absence of a documented retention period tied to a purpose. If the employer cannot show how long applicant data, employee records, disciplinary files, or benefit records are retained, the retention rule is probably being driven by convenience rather than necessity. A second strong indicator is retaining more data than the purpose requires, especially when old records are kept “just in case” without a business or legal basis.

Another useful signal is weak disposal control. If there is no documented destruction process, no approval trail for deletion, or no evidence that records are actually removed when the retention period ends, the organisation may have a policy on paper but not in operation. That is exactly the kind of control gap that NIST SP 800-88 Media Sanitization helps practitioners think through, even though the legal test here is PDPA compliance rather than media handling alone.

What tells you the employer is managing retention informally?

Informal retention management usually shows up as inconsistency. One department deletes records quickly while another keeps the same type of record for years. Managers may approve ad hoc exceptions without written criteria, or HR may rely on individual judgement rather than a standard lifecycle. Employees may also be told that their data is retained, but not how long or under what rule, which weakens accountability even when the rest of the process appears orderly.

For a deeper privacy-control lens, it helps to review whether retention is linked to data minimisation, notice, and deletion discipline. NHIMG’s Identity Data Privacy and Consent Guide is useful here because it connects lawful handling with minimisation and retention discipline, which is the practical backbone of a defensible employee-data lifecycle.

Risk and Threat Considerations

Misapplied retention rules increase exposure because old employee data becomes available long after the original need has ended. That raises the chance of unnecessary privacy impact, disclosure during a breach, and internal misuse of records that should already have been deleted or anonymised. In an employment context, the risk is often cumulative: the longer the organisation keeps data, the larger the population exposed when a control fails.

Failure mechanism: retention is treated as an administrative habit instead of a governed lifecycle control, so records accumulate without a valid purpose, disposal trigger, or auditable deletion step.

Impact: the employer increases its compliance exposure, enlarges the blast radius of any incident, and makes it harder to prove that employee data is being handled proportionately.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 DM — Media Sanitization Retention errors often end in delayed or missing disposal of records and media.
Recommendation — Define disposal triggers and verify records are destroyed when retention ends.
ISO/IEC 27001:2022 A.5.33 — Protection of records Employee records need retention and disposal controls that preserve integrity and availability.
Recommendation — Set record retention and destruction rules for HR data.
GDPR Art. 5(1)(e) — Storage limitation The same retention discipline is central to a PDPA-style retention test.
Art. 25 — Data protection by design and by default Retention should be built into the lifecycle, not handled ad hoc.
Recommendation — Limit retention to the period needed for the stated purpose. Build default deletion and minimisation into HR data processes.

Practitioner Guidance

What to verify: check whether each employee-data category has a stated retention period, a defined purpose, and a documented deletion or destruction method. If those three elements are not linked, the control is not reliable enough to defend.

Common mistake: treating a privacy notice as if it replaces an operational retention schedule. Notice tells people what may happen; it does not prove the organisation can actually delete data on time.

Practitioner takeaway: The best test is not whether the employer has a retention policy, but whether it can consistently show purpose, duration, and disposal evidence for the data it holds.