OOZOU
Get in Touch

PDPA Compliance

Practical PDPA compliance for Thailand: audits, consent flows, and privacy engineering from a founding partner of PDPA.org.

Get Started
consentPDPAAUDIT3/4 compliant

Thailand's PDPA applies to any organization handling the personal data of people in Thailand. Falling short means fines, criminal liability, and lost customer trust, and a privacy policy page alone does not fix that: compliance lives in how your products capture consent, where data is stored, and how fast you answer data subject requests. OOZOU is a founding partner of PDPA.org, the PDPA Alliance uniting legal, process, and technical specialists in one engagement. We handle the technical side: audits, consent and request workflows built into your products, and security controls that keep you compliant as you ship.

Founding partner of PDPA.org

PDPA.org is the PDPA Alliance: legal, process, and technology specialists who make organizations in Thailand PDPA compliant in a single engagement. OOZOU co-founded the alliance and leads its technical side, from audits to consent systems and secure data handling.

Visit PDPA.org
Capabilities

Key Capabilities

Concrete capabilities we bring to this engagement — not buzzwords.

PDPA Audit & Gap Analysis

We map how personal data enters, moves through, and leaves your systems, then rank the gaps between current practice and what the PDPA requires.

Consent & Cookie Management

Purpose-specific consent flows, cookie banners, and preference centers, with consent records you can actually produce when a regulator or customer asks.

Data Subject Request Workflows

Access, correction, deletion, and objection requests handled through workflows your team can run within statutory deadlines, not a scramble across databases.

Privacy & Security Engineering

Data minimization, encryption, access controls, retention rules, and audit logging built into your systems, so compliance is a property of the product.

Tech Stack

Technologies We Use

Proven tools and platforms we apply where they fit — chosen for the problem, not the trend cycle.

PDPA (Thailand)
GDPR
Consent Management
Cookie Compliance
Data Mapping
DSAR Workflows
Encryption
Access Control & IAM
Audit Logging
ISO 27001
How We Work

Our Approach

A clear path from problem to production — adjusted per service, never one-size-fits-all.

01

Audit

We inventory personal data across systems, vendors, and teams, and document how it is collected, used, shared, and retained.

02

Gap Analysis

We map findings against PDPA requirements and rank every gap by risk, so effort goes where the exposure is highest.

03

Roadmap

A prioritized remediation plan across legal, process, and technical work, with owners and timelines your team can commit to.

04

Implementation

We build the fixes: consent capture, data subject request handling, retention automation, and security controls inside your products.

05

Training

We train the people who touch personal data, from engineers to support staff, so good practice outlives the project.

06

Monitoring

Ongoing reviews, audit trails, and compliance checks that keep you covered as products, vendors, and regulation evolve.

Budget

Budgets of All Sizes

We work with budgets across the full range. The team adapts scope, size, and engagement model to what you can spend, without lowering the bar on how we build.

Enterprise

Full delivery teams for complex platforms, with the security, compliance, and process rigor large organizations expect.

Growing Teams

Flexible engagements that scale with you. Add capacity when you need it, scale back when you don't, without renegotiating from scratch.

Small Business & Startups

Lean, focused builds that get the essentials right. We help you trim scope, not quality, so a modest budget still ships a solid product.

Why Us

Why This Matters

Outcomes we aim for — measurable in product quality, speed, and business impact.

Lower Regulatory Risk

Documented compliance and evidence you can produce on demand reduce exposure to fines and keep due diligence from stalling deals.

Customer Trust

Visible care with personal data is a selling point for customers, and for enterprise partners who audit their vendors.

Privacy Built In

Compliance implemented inside the product rather than as paperwork on the side, so new features ship without reopening old risks.

Founding Partner of PDPA.org

Through PDPA.org we work alongside legal and process specialists, so one engagement can cover the law, the process, and the technology.

Have a project in mind?

We'd love to hear what you're building.

Start a Conversationhello@oozou.com
OOZOU Logo

Bangkok · Singapore · Hong Kong

X
Facebook
Instagram
LinkedIn

Services

  • Web Development
  • AI Agents & Generative AI
  • Mobile App Development
  • Data Analytics & Engineering
  • UI/UX & Product Design
  • Digital Transformation

Company

  • About Us
  • Careers
  • Blog
  • Case Studies
  • Today I Learned
  • Contact

More

  • Industries
  • Partner Network
© 2026 OOZOU. All rights reserved.
Privacy PolicyCode of ConductABAC Policy