Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should employers handle employee data collection under…
Governance, Ownership & Risk

How should employers handle employee data collection under Thailand’s PDPA?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Employers should treat employee data collection as a controlled processing activity, not a routine HR formality. They need explicit consent before or at the time of collection unless a clear statutory exemption applies, and they should limit collection to what is necessary for the stated purpose. Employers also need to tell employees why the data is being collected, how long it will be retained, and who may receive it.

Thailand’s PDPA treats employee data collection as a regulated processing activity, not a formality tucked into onboarding. In practice, the first question is whether the employer truly needs consent or whether another PDPA basis clearly applies under the facts. For routine HR handling, employers should avoid collecting first and justifying later, because that creates avoidable compliance and trust problems.

Consent also has to be meaningful in an employment setting. The power imbalance between employer and employee means a blanket or bundled consent request can be hard to defend if it is not specific, informed, and tied to a real purpose. Where a statutory exemption or another lawful basis applies, employers should document that basis instead of using consent as a default placeholder.

The Thailand PDPA official text is the right reference point when you need to map collection, notice, and lawful-basis decisions to the statute itself, especially where the employer is dealing with employee records that include sensitive information or special handling obligations: Thailand Personal Data Protection Commission.

What to collect, why to collect it, and how to frame the notice

Employers should collect only the employee data needed for the stated purpose, then describe that purpose in plain language. The practical test is whether each data field has a defensible link to payroll, benefits, access administration, legal compliance, safety, or another concrete business need. If a field is only helpful or convenient, it probably belongs in the “nice to have” bucket, not the collection form.

The notice should do more than announce that data is being gathered. It should tell employees what data is being collected, why it is needed, how long it will be retained, and who may receive it. That is especially important when data moves between HR, payroll, legal, security, or external processors, because employees need to understand the full processing chain rather than just the intake point.

Where collection is tied to access control, background checks, or system administration, employers should keep the collection scope aligned with the business function and not expand it into open-ended profiling. A useful control reference for that kind of structured collection and retention discipline is NIST SP 800-53 Rev 5 Security and Privacy Controls, which helps teams frame collection and retention as controlled processing rather than ad hoc data capture.

PDPA compliance works best when employee data collection is treated as a governed workflow with clear ownership. HR may initiate collection, but legal, privacy, IT, and payroll often shape what is collected, where it is stored, and who can access it. That division matters because the biggest failures usually come from inconsistent forms, shadow spreadsheets, and uncontrolled reuse of employee records across departments.

Employers should also align collection with retention and recipient controls from the start. If a third party processes employee data, the employer should verify that the transfer purpose is documented, the processor relationship is understood, and the employee notice matches the real data flow. If access to the data is broader than the stated purpose, the collection practice is too loose even if the form itself looks compliant.

For organisations building a broader privacy and control programme around employee information, the NIST Privacy Framework is useful for structuring data governance, while NIST Cybersecurity Framework 2.0 helps connect collection practices to governance, protection, and recovery expectations. Where the employee data includes identifiers used for authentication or system access, NIST SP 800-63 Digital Identity Guidelines provides a relevant reference for identity proofing and authentication design.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt.5 — Principles relating to processing of personal dataEmployee data collection needs purpose limitation and minimisation.
Art.6 — Lawfulness of processingThe question turns on lawful basis and consent versus other bases.
Art.13 — Information to be provided where personal data are collected from the data subjectNotice content mirrors the need to tell employees purpose, retention, and recipients.
Recommendation — Map each field to a declared purpose and remove unnecessary collection. Document the lawful basis before collecting employee data. Provide a clear collection notice covering purpose, retention, and recipients.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementEmployee data often includes identity material that requires controlled handling.
AC-6 — Least PrivilegeEmployee records should be limited to the smallest set of authorised recipients.
Recommendation — Treat identity-related data as controlled material with defined lifecycle handling. Restrict employee-data access to only the roles that need it.

Practitioner Guidance

What to verify: Before collection goes live, verify that each field on the form maps to a specific purpose, a lawful basis, a retention period, and a defined recipient group. If any field cannot be justified that way, remove it or separate it into a different collection process.

Decision rule: If the employee data is needed for employment administration but not strictly necessary for the declared purpose, treat it as a scope reduction issue, not a paperwork issue. Narrow the collection first, then fix the notice and workflow around the reduced data set.

Common mistake: The most common failure is copying a generic consent clause into every HR form and assuming that satisfies PDPA. That approach usually obscures purpose limitation, retention discipline, and recipient transparency, which are the parts employees and regulators are most likely to scrutinise.

Practitioner takeaway: The safest PDPA posture is to make employee collection purpose-led, minimally scoped, and traceable from the form to the retention rule to the recipient list.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org