PDPA and Logs — How to Collect Traffic Data Without Violating Thailand's Data Protection Law
How Thailand's Computer Crime Act and PDPA both apply to your logs: what counts as personal data, which legal basis to use, and 6 practices for both laws.
PDPA and Logs — How to Collect Traffic Data Without Violating Thailand's Data Protection Law
Thai organizations must retain logs under the Computer Crime Act 2017 (พ.ร.บ. คอมพิวเตอร์ 2560), but at the same time must comply with PDPA (Personal Data Protection Act, พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล 2562) — do the two laws conflict? How do you keep logs that satisfy both?
What Is PDPA?
PDPA (Personal Data Protection Act), Thailand's Personal Data Protection Act B.E. 2562 (2019), protects personal data belonging to individuals — including names, email addresses, IP addresses, and usernames that appear in logs.
What Personal Data Shows Up in Logs?
| Data in the Log | Personal Data Under PDPA? | Example |
|---|
| IP Address | ✅ Yes | 192.168.1.100, 203.0.113.50 |
| Username | ✅ Yes | somchai@company.co.th |
| Email | ✅ Yes | user@domain.com |
| MAC Address | ✅ Yes | 00:1A:2B:3C:4D:5E |
| URLs Visited | ✅ Possibly | health-related URLs |
| Device Name | ⚠️ Depends | SOMCHAI-LAPTOP |
| Timestamp | ❌ No | 2026-03-13T07:00:00Z |
| Port Number | ❌ No | 443, 8080 |
Computer Crime Act vs. PDPA — Do They Conflict?
No. But you need to satisfy both:
| Issue | Computer Crime Act 2017 | PDPA 2019 |
|---|
| Log retention | ✅ Required (Section 26) | ✅ Permitted (with legal basis) |
| Retention period | 90 days – 2 years | Only as long as necessary |
| Purpose | Security | Purpose must be specified |
| Access | Authorities can request it | Data subjects can request access |
Legal basis for retaining logs under PDPA:
- ✅ Section 24(6) — compliance with a legal obligation (the Computer Crime Act)
- ✅ Section 24(5) — legitimate interest
6 Practices for PDPA-Compliant Log Management
1. State the purpose clearly
- Document in your Privacy Policy that logs are collected for:
- Security
- Legal obligation (compliance with the Computer Crime Act)
- Audit / usage monitoring
2. Collect only what's necessary (Data Minimization)
- Keep only logs tied to a clear purpose
- Don't store the content of emails or chat messages (metadata only)
3. Limit the retention period
- Keep logs for 90 days as required by law → delete or anonymize after that
- Retaining logs beyond 90 days requires a clear justification
4. Encrypt and control access
- ✅ Encrypt logs (AES-128 or stronger)
- ✅ Use RBAC to restrict who can view logs
- ✅ Keep an audit log of who viewed whose logs
5. Anonymize where possible
- Convert IP addresses to ranges (192.168.1.x)
- Hash usernames in logs that don't need to be searchable
6. Support data subject rights
- ✅ Right of access — data subjects can request to view their data
- ✅ Right to erasure — can be refused while the log falls within the mandatory 90-day retention period (legal basis)
⭐ zcrLog Helps You Stay PDPA-Compliant
zcrLog includes features built for PDPA compliance:
- ✅ AES-128 encryption for data at rest
- ✅ 4-level RBAC to restrict log access
- ✅ Audit log recording every access event
- ✅ Retention policy with automatic log deletion
- ✅ Hash integrity to detect unauthorized log changes
📖 Read more: How to Retain Logs Under Thailand's Computer Crime Act 2017
🎯 See zcrLog →
📞 Free Consultation
Related articles
Continue with these related guides for the comparison and operating detail:
Related product
See zcrLog for the product scope, the pricing page for published prices, and the inputs to confirm with your delivery partner
Sources