Employers should treat employee data collection as a controlled processing activity, not a routine HR formality. They need explicit consent before or at the time of collection unless a clear statutory exemption applies, and they should limit collection to what is necessary for the stated purpose. Employers also need to tell employees why the data is being collected, how long it will be retained, and who may receive it.
When consent is required, and when an employer can rely on another lawful basis
Thailand’s PDPA treats employee data collection as a regulated processing activity, not a formality tucked into onboarding. In practice, the first question is whether the employer truly needs consent or whether another PDPA basis clearly applies under the facts. For routine HR handling, employers should avoid collecting first and justifying later, because that creates avoidable compliance and trust problems.
Consent also has to be meaningful in an employment setting. The power imbalance between employer and employee means a blanket or bundled consent request can be hard to defend if it is not specific, informed, and tied to a real purpose. Where a statutory exemption or another lawful basis applies, employers should document that basis instead of using consent as a default placeholder.
The Thailand PDPA official text is the right reference point when you need to map collection, notice, and lawful-basis decisions to the statute itself, especially where the employer is dealing with employee records that include sensitive information or special handling obligations: Thailand Personal Data Protection Commission.
What to collect, why to collect it, and how to frame the notice
Employers should collect only the employee data needed for the stated purpose, then describe that purpose in plain language. The practical test is whether each data field has a defensible link to payroll, benefits, access administration, legal compliance, safety, or another concrete business need. If a field is only helpful or convenient, it probably belongs in the “nice to have” bucket, not the collection form.
The notice should do more than announce that data is being gathered. It should tell employees what data is being collected, why it is needed, how long it will be retained, and who may receive it. That is especially important when data moves between HR, payroll, legal, security, or external processors, because employees need to understand the full processing chain rather than just the intake point.
Where collection is tied to access control, background checks, or system administration, employers should keep the collection scope aligned with the business function and not expand it into open-ended profiling. A useful control reference for that kind of structured collection and retention discipline is NIST SP 800-53 Rev 5 Security and Privacy Controls, which helps teams frame collection and retention as controlled processing rather than ad hoc data capture.
How employers should operationalise compliance across HR, legal, and payroll
PDPA compliance works best when employee data collection is treated as a governed workflow with clear ownership. HR may initiate collection, but legal, privacy, IT, and payroll often shape what is collected, where it is stored, and who can access it. That division matters because the biggest failures usually come from inconsistent forms, shadow spreadsheets, and uncontrolled reuse of employee records across departments.
Employers should also align collection with retention and recipient controls from the start. If a third party processes employee data, the employer should verify that the transfer purpose is documented, the processor relationship is understood, and the employee notice matches the real data flow. If access to the data is broader than the stated purpose, the collection practice is too loose even if the form itself looks compliant.
For organisations building a broader privacy and control programme around employee information, the NIST Privacy Framework is useful for structuring data governance, while NIST Cybersecurity Framework 2.0 helps connect collection practices to governance, protection, and recovery expectations. Where the employee data includes identifiers used for authentication or system access, NIST SP 800-63 Digital Identity Guidelines provides a relevant reference for identity proofing and authentication design.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while GDPR defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art.5 — Principles relating to processing of personal data | Employee data collection needs purpose limitation and minimisation. |
| Art.6 — Lawfulness of processing | The question turns on lawful basis and consent versus other bases. | |
| Art.13 — Information to be provided where personal data are collected from the data subject | Notice content mirrors the need to tell employees purpose, retention, and recipients. | |
| Recommendation — Map each field to a declared purpose and remove unnecessary collection. Document the lawful basis before collecting employee data. Provide a clear collection notice covering purpose, retention, and recipients. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Employee data often includes identity material that requires controlled handling. |
| AC-6 — Least Privilege | Employee records should be limited to the smallest set of authorised recipients. | |
| Recommendation — Treat identity-related data as controlled material with defined lifecycle handling. Restrict employee-data access to only the roles that need it. | ||
Practitioner Guidance
What to verify: Before collection goes live, verify that each field on the form maps to a specific purpose, a lawful basis, a retention period, and a defined recipient group. If any field cannot be justified that way, remove it or separate it into a different collection process.
Decision rule: If the employee data is needed for employment administration but not strictly necessary for the declared purpose, treat it as a scope reduction issue, not a paperwork issue. Narrow the collection first, then fix the notice and workflow around the reduced data set.
Common mistake: The most common failure is copying a generic consent clause into every HR form and assuming that satisfies PDPA. That approach usually obscures purpose limitation, retention discipline, and recipient transparency, which are the parts employees and regulators are most likely to scrutinise.
Practitioner takeaway: The safest PDPA posture is to make employee collection purpose-led, minimally scoped, and traceable from the form to the retention rule to the recipient list.
Related resources from NHI Mgmt Group
- How should employers decide what employee data they can process without consent under Singapore’s PDPA?
- How should employers handle employee and applicant data under the Australian Privacy Act when multiple laws apply?
- How should employers handle employee personal data under LGPD to stay compliant?
- How should employers handle employee data requests while staying compliant with privacy laws?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org