Process
Villa rental guest data and Thailand's PDPA: what a Koh Phangan owner must do beyond TM30
Filing a TM30 for a guest covers only the immigration report itself — collecting passport copies, ID scans, payment details or CCTV footage from paying guests makes you a data controller under Thailand's Personal Data Protection Act, with its own consent, notice and breach-reporting duties. Enforcement has moved from theory to real fines since 2024.
Right Way Phangan · Editorial
Updated 16 September 2026
Does filing a TM30 for a guest cover your data-protection obligations as a villa owner? No — TM30 is a separate immigration duty. The moment you're collecting passport copies, ID scans, payment details or CCTV footage from paying guests, you're a data controller under Thailand's Personal Data Protection Act (PDPA) B.E. 2562 (2019), which has been fully in force since June 2022 — and the Personal Data Protection Committee (PDPC) has been issuing real administrative fines since 2024, not just guidance.
Why the household exemption doesn't save you
Section 4 of the PDPA exempts data processing carried out purely "for personal benefit or household activity," with no commercial connection. That exemption is narrowly construed and falls away the moment guest data is collected in the course of a paid rental — a villa, room or condo let via Airbnb, a booking platform or a direct reservation. An owner renting to paying guests is a data controller like any other business, regardless of how small the operation is.
What actually needs to happen
- Have a lawful basis for every use of guest data. TM30 reporting to Immigration is covered by the 'legal obligation' basis and needs no separate consent for that specific report. Using the same passport copy for anything else — a marketing list, sharing with a booking platform beyond what the booking itself requires, indefinite CCTV retention — needs its own basis, usually consent or the 'necessary to perform a contract' basis that covers ordinary booking administration.
- Tell guests what you're doing with their data. A short privacy notice — purpose, retention period, who it's shared with — covers most of the PDPA's core transparency requirement. It doesn't need to be a legal document, just clear, and given before or at the point of data collection.
- A passport copy or ID scan is ordinary personal data, not automatically 'sensitive.' Sensitive data under Section 26 is a specific list — health, biometric data, criminal record, religion, ethnicity and similar categories, each needing separate explicit consent. An ordinary passport photo page doesn't qualify on its own. It crosses into the sensitive-data tier only if you're extracting a biometric identifier from it — a facial-recognition check-in kiosk or a fingerprint-linked door lock, for example.
- CCTV needs its own notice and a narrower footprint. Cameras covering common areas and entrances are standard practice with a visible sign; cameras inside bedrooms or bathrooms are not defensible under any lawful basis.
- A Data Protection Officer is very unlikely to be required for a single villa or small rental operation. The DPO trigger needs large-scale processing — the PDPC's own guidance points to roughly 100,000+ data subjects — or regular, systematic monitoring as a core business activity, both well beyond a handful of bookings a month.
- Report a real breach within 72 hours. If guest data is exposed — a hacked booking system, a lost laptop with passport scans on it — the notification clock to the PDPC runs from when you become aware of the breach, not from when it happened.
The fine exposure is real, not theoretical
The PDPC's administrative fines run in three broad tiers depending on the violation: roughly up to ฿1 million for failures like not appointing a required DPO or not informing data subjects of processing purposes; up to ฿3 million for using data outside its stated purpose or processing without a valid lawful basis; and up to ฿5 million for mishandling sensitive data or an unsafe cross-border transfer. This isn't hypothetical — in November 2024 the PDPC issued its first major administrative fine, ฿7 million against a company that had failed to appoint a DPO, lacked adequate security around a data breach linked to a call-centre scam, and missed the breach-notification deadline. Criminal penalties exist on top of this — up to a year's imprisonment or a ฿1 million fine (or both) for unlawfully disclosing sensitive data for unlawful gain.
Where this fits alongside your other rental duties
This is a distinct compliance layer from the immigration reporting duty itself, covered in TM30 foreign guest notification, from the licensing question covered in Airbnb and short-term rentals in Thailand's 2026 crackdown, and from Renting out your villa: rules and taxes. If you use a property management company to handle bookings and guest onboarding, get written clarity on who is the data controller for guest data — you, the manager, or both jointly — since PDPA liability follows the controller relationship, not simply who physically holds the passport copies.
The bar for a small operation isn't complicated: a short privacy notice, a lawful basis for anything beyond the strict TM30 report, sensible CCTV placement, and secure, time-limited storage of passport copies covers most of the practical risk — but treat it as a real compliance duty, not paperwork theatre, given how active PDPC enforcement has become since 2024.
Key points
- Thailand's PDPA applies to any villa or room rental collecting guest data for payment — the Section 4 household exemption doesn't cover a commercial rental, however small.
- TM30 reporting to Immigration is covered by its own 'legal obligation' lawful basis; it does not cover other uses of the same guest data (CCTV, marketing, platform sharing), which need their own basis.
- An ordinary passport copy is not 'sensitive personal data' under the PDPA — biometric identifiers (facial recognition, fingerprint) are, and need separate explicit consent.
- Administrative fines run up to roughly ฿1m/฿3m/฿5m depending on violation type; the PDPC's first landmark case levied ฿7 million in November 2024 for a combination of failures.
- A Data Protection Officer is very unlikely to be required for a single villa or small rental operation — the threshold is large-scale processing (roughly 100,000+ subjects) or systematic core-activity monitoring.
Sources
- Tilleke & Gibbins — Landmark Fine Imposed under Thailand's Personal Data Protection Act
- Tilleke & Gibbins — Thailand: Operationalising PDPA (Lawful Basis, Sensitive Personal Data, Data Processing Safeguards)
- CMS Law — Thailand Provides Clarity on When a DPO Must Be Appointed
- Securiti — Thailand Personal Data Protection Act (PDPA): Ultimate Guide
- belaws — What Are the Penalties for Breaching the PDPA?
General information, not legal advice. Thai property law is fact-specific — verify any structure with a licensed Thai lawyer before you commit. Independent legal due diligence is part of every transaction we handle.
From reading to doing.
Every property we list passes checks like these — title, zoning, access and the real numbers — before it goes live. Browse what’s available, or find out what your own land or villa is worth.