02-347-7730  |  Saeree ERP - Comprehensive ERP System for Thai Businesses Contact Us

PDPA and Accounting

PDPA and Accounting — The Data Your Accounting Department Holds Is More Dangerous Than You Think
  • 25
  • February

If you ask which department in an organization holds the most personal data, many people would think of IT or HR. But the correct answer is "the Accounting Department."

National ID numbers, bank account numbers, employee salaries, vendor data, customer data, tax identification numbers, photocopies of directors' ID cards — all of this is in the hands of the accounting department.

Yet many organizations still do not realize that PDPA (the Personal Data Protection Act) directly impacts accounting operations — and failure to comply can result in both imprisonment and fines.

Updated 3 September 2026 — three things that have changed since this article first went live

  • On 14 September 2026, the PDPC notification on access to and copies of personal data (B.E. 2569) takes effect — organisations must complete each request within 30 days, and most of that work lands on accounting and HR (see PDPA Data Subject Access Requests 2026)
  • PDPA is no longer an unenforced law — on 26 June 2026 the PDPC reported that it had reviewed more than 590,000 public and private organisations and issued administrative fines totalling over 21.5 million baht (see the actual cases in Thailand PDPA Crackdown 2026)
  • There is a new variable called AI — an Excel file your accounting team exports today may well be fed into an AI tool downstream, which is a data transfer that has to be assessed under PDPA (read on: Auditors Feeding Your Excel Data to AI)

What Is PDPA? — A Brief Summary for Accounting Professionals

PDPA stands for Personal Data Protection Act — Thailand's data protection law enacted in 2019, fully enforced since June 1, 2022. This law protects "personal data" — any information that can identify an individual, whether directly or indirectly.

What many people do not realize is that PDPA carries severe penalties:

  • Civil penalties — Compensation for actual damages, and the court may order punitive damages up to double the amount
  • Criminal penalties — Imprisonment of up to 1 year and/or fines of up to 1 million baht
  • Administrative penalties — Fines of up to 5 million baht

This means that if an organization mishandles personal data — whether intentionally or negligently — both the organization and the responsible individuals may face legal prosecution.

And those figures are no longer just ceilings written into the statute. Marking its fourth anniversary on 26 June 2026, the Personal Data Protection Committee office (PDPC) reported that it had reviewed the readiness of more than 590,000 public and private organisations and issued administrative fine orders totalling over 21.5 million baht, with the largest single case at 7 million baht for three combined violations.

Personal Data Held by the Accounting Department — More Sensitive Than You Think

Let us examine what data the accounting department holds and the sensitivity level of each type:

Data Type Examples Sensitivity Level
Employee Data National ID number, salary, bank account, social security Very High
Vendor/Supplier Data Tax ID number, full name, address, bank account High
Customer Data Full name, address, tax number, purchase history, payment information High
Director/Authorized Signatory Data ID card copies, signatures, personal addresses Very High

As you can see, this data is far from ordinary information — if leaked, it can cause severe damage ranging from document forgery and identity theft to legal lawsuits.

5 PDPA Risks That Accounting Departments Often Overlook

From our experience working with numerous organizations — both government agencies and private companies — these risks appear repeatedly:

1. Sending Payslips via LINE/Email Without Encryption

Many organizations still send payslips through LINE chat or email without password protection. Payslips contain national ID numbers, bank account numbers, and salary amounts — even a single leak constitutes a PDPA violation. This is directly related to data security in ERP systems

2. Storing ID Card Copies in Paper Files — Without Access Management

ID card copies of vendors, employees, and directors are stored in filing cabinets accessible to anyone. There are no records of who accessed them or when, no locking system, and no redaction of sensitive details — this is the most dangerous PDPA vulnerability.

3. Sharing Employee Data Excel Files Back and Forth

Shared Excel files passed between departments often contain salary data, national ID numbers, and bank account numbers — without encryption, without password protection, and without records of who viewed, copied, or forwarded them. If a file leaks, there is no way to trace where it originated from.

4. No Policy for Deleting Data When No Longer Needed (Data Retention Policy)

PDPA stipulates that when data is no longer needed, it must be deleted or destroyed. In practice, however, most accounting departments retain documents indefinitely — ID card copies of vendors who have not done business with the company for 5 years still sit in filing cabinets. This is an unnecessary risk.

5. Allowing All Accounting Staff to Access Salary Data at Every Level — No Access Control

In many organizations, every accounting employee can view the salary of every person in the company — from daily workers to senior executives. Unnecessary data access (Excessive Access) is also considered a risk under PDPA. This can be prevented with two-factor authentication (2FA) and proper access permission settings.

What Does PDPA Require That Affects the Accounting Department?

PDPA does not specifically mention accounting departments, but every principle in the law directly impacts accounting operations:

  • Consent is required — Before collecting personal data from employees, vendors, or customers, explicit consent must be obtained — except when the law mandates data retention (e.g., the Revenue Department requires retention of tax documents).
  • Purpose must be disclosed (Privacy Notice) — Data subjects must be informed about what their data is used for, how long it will be retained, and who can access it.
  • Access must be restricted (Access Control) — Not everyone in accounting needs to see everything. Access must be limited based on job duties and necessity.
  • Retention periods must be defined (Data Retention) — A clear data retention period must be established, and data must be deleted when that period expires.
  • Security measures must be in place — Appropriate security measures must be implemented, both physical (locked cabinets) and technical (encryption, security systems)
  • Data subjects have the right to view, correct, and delete (Data Subject Rights) — Employees, vendors, and customers have the right to access their own data, request corrections, or request deletion. The accounting department must be able to respond to these requests — and from 14 September 2026 that right comes with a hard deadline (see the next section).

The accounting department is the true Data Controller of an organization — holding the most sensitive data, yet often being the last department to receive PDPA training.

14 September 2026: When a Former Employee Asks for a Copy of Their Own Data

The PDPC notification on the criteria for accessing and obtaining copies of personal data (B.E. 2569) was published in the Royal Gazette on 16 July 2026 and takes effect 60 days later — that is, 14 September 2026. It converts a right that the parent act described loosely as "without delay" into a deadline you can actually measure against.

The parts that hit accounting hardest:

  • The request must be completed within 30 days of receipt, extendable by no more than a further 30 days where genuinely necessary, and the requester must be told.
  • Data must be gathered from every system the organisation is responsible for, not just one — if payroll data is scattered across several files on several machines, this is the point where you miss the deadline.
  • Third-party data must be redacted before handover — a payroll file with every employee on one sheet cannot be handed over as is; the individual's rows have to be extracted.
  • No fee may be charged for delivery by ordinary electronic means. Charges are limited to real and reasonable costs — for example, no more than 1 baht per A4 page for paper copies.
  • Records of each request must be kept for at least two years, including the reasoning where a request is refused.

The scenario that fits accounting most closely: a former employee asks for their salary history, payslips, and withholding-tax certificates going back several years. If that lives in one system and can be pulled by employee code, the job takes minutes. If it lives in paper files mixed with spreadsheets named by whoever created them, 30 days may not be enough. The full breakdown, including when a request can legitimately be refused, is in PDPA Data Subject Access Requests 2026.

Two Duties Accounting Departments Often Do Not Know They Have

The five risks listed earlier are about doing something wrong. PDPA also imposes two active duties where organisations get fined for not doing anything at all — and in the 7-million-baht case, both appeared among the violations.

1. Report a Data Breach Within 72 Hours

Where there are reasonable grounds to believe personal data has actually been breached and the breach risks the rights and freedoms of data subjects, the data controller must notify the PDPC without delay and within 72 hours of becoming aware. Where the risk is high, data subjects must also be notified, together with remedial guidance.

The trap is that the 72 hours run from "becoming aware," not from the day the investigation wraps up. If an accounting clerk emails a file to the wrong person late on a Friday and it only reaches management on Monday morning, most of the window is already gone. Organisations therefore need an internal reporting channel that accounting can use immediately, without working up the chain of command.

2. Appoint a Data Protection Officer (DPO)

Organisations that collect or use personal data at scale must appoint a DPO and publish contact details so data subjects can reach them. In the 7-million-baht case, one of the three violations was having no DPO despite large-scale data collection. The PDPC also announced in mid-2026 that it intends to extend DPO requirements to more organisations during the second half of the year.

For a mid-sized organisation, the DPO is rarely a brand-new headcount — it is an assignment to someone already on staff. And one person who always belongs in that circle is the head of accounting, because they are the person who knows which file, which cabinet, and which system the organisation's sensitive data actually sits in.

Outsourced Bookkeeping or Payroll — Who Is Liable If Data Leaks?

The answer most organisations do not want is both parties can be. PDPA separates the roles: the data controller is the organisation that decides what the data is collected for, and the data processor is the contractor acting on instructions — an accounting firm, a payroll bureau, a document-destruction vendor, or a system administrator.

In one PDPC case against a public-sector body, roughly 200,000 records leaked and were sold on the dark web, traced to inadequate security measures, weak passwords, no risk assessment, and no data processing agreement (DPA) in place. Both sides were fined — 153,120 baht for the data controller and the same amount again for the data processor.

Three things accounting can act on immediately:

  • Put a DPA in place with every contractor — defining the scope of data shared, the purpose, the retention period, and a duty to report breaches back to you fast enough to meet the 72-hour clock.
  • Send only what is needed — a bookkeeping contractor does not need the full company payroll file complete with every national ID number if the actual job only requires posting totals.
  • Close access when the work ends — contract completion should trigger return or destruction of the data and deactivation of any accounts granted, rather than leaving them open "in case we need them again."

PDPA Says Delete, Accounting Law Says Keep — Which Wins?

This is the question accounting teams ask most often, and it is where many organisations pick the easiest option — "keep everything, just in case" — which turns out to be the riskiest one.

The way through is not to choose between the two laws but to sort documents into layers: which items are legally required to be kept, and which are kept only out of habit.

Document / Data Law Requiring Retention Period When the Period Ends
Accounts and supporting accounting documents Accounting Act B.E. 2543, section 14 Not less than 5 years from the closing date (the DBD Director-General may extend, but not beyond 7 years) Destroy with an evidence trail, not left in a pile
ID card copies of vendors you no longer trade with None Only as long as the original stated purpose lasts; purpose ends, grounds to keep end Delete or destroy
Excel files exported for temporary use None Should never have been lying around in the first place Delete as soon as the task is done
Director ID copies used for a one-off filing Depends on the filing Only while that matter remains open Delete, and stop keeping duplicate copies

Notice that only one row is genuinely mandated. The rest is material nobody dares delete. A system that can assign an expiry to data therefore turns "delete when the period ends" from something that depends on human memory into something the system does — and shrinks the pile of Excel files floating around outside the system at the same time.

How ERP Helps Manage PDPA Compliance

Many of the problems above are not caused by "people" but by "systems" that do not support compliance. If you still rely on Excel, paper files, and LINE chat as your primary tools — PDPA compliance will be extremely difficult.

A well-designed ERP system directly addresses these problems:

ERP Feature How It Helps with PDPA
Access Control / Role-Based Permission Restricts data access based on role and responsibilities — accounts payable staff see only vendor data, not employee salaries.
Audit Trail Records who accessed what data, when, and what was modified — enabling traceback investigation if a data breach occurs.
Data Encryption Encrypts sensitive data such as national ID numbers and bank account numbers — even if the database is breached, the data remains unreadable.
Data Retention Management Automatically deletes data when retention periods expire — no need to remember, no risk of forgetting.
Centralized Data Data is stored in a single centralized database rather than scattered across multiple Excel files — it can be controlled, audited, and deleted immediately.

A solid accounting system must support PDPA compliance from day one — it is not just about recording numbers, but also about protecting the personal data within the system.

PDPA is not solely the IT department's responsibility — the accounting department, which holds the most personal data, must understand and comply as well. A quality ERP system makes PDPA compliance easier without adding extra burden to the accounting team.

Checklist: Is Your Accounting Department Ready for PDPA?

Check how many of these your organization can pass:

  • Do you have a Privacy Notice for employees, vendors, and customers?
  • Are payslips sent encrypted, or are they still shared via LINE without a password?
  • How are ID card copies stored? Is there a locking system and an access log?
  • Are Excel files containing personal data password-protected?
  • Is there a Data Retention Policy defining data retention periods?
  • Can every accounting employee really access everyone's salary data? (It should be restricted by role.)
  • If a former employee requests data deletion, how many days does it take to fulfill?
  • Is there an Audit Trail recording who accessed what data and when?
  • If data leaked late on a Friday, is there a channel that would let you notify the PDPC inside 72 hours?
  • Has a DPO been appointed and their contact details published?
  • Is there a DPA with every accounting firm, payroll bureau, and document-destruction contractor?
  • If a former employee requested a copy of their own data today, could you gather it from every system within 30 days?

If you answered "No" to more than 3 items — your organization faces high PDPA risk and should consider upgrading your systems promptly.

A Real Case: Data Leaking Out of Paperwork, Not Out of a Hack

Among the cases the PDPC has fined, one deserves accounting's attention above the rest. A private hospital was fined 1,210,000 baht after roughly 1,000 patient medical records were exposed. The cause was not a system breach — it was inadequate oversight of the contractor hired to destroy the documents. That contractor was fined a further 16,940 baht.

Swap "medical records" for "payment voucher files with vendor ID card copies attached" and this becomes the exposure carried by every accounting department that sends old paperwork out for destruction with no certificate of destruction, nobody from the organisation present, and no DPA.

Another scenario needs no contractor at all. An accounting employee sends an Excel file containing the entire company's salary summary to a department manager via email — and mistypes the address by a single character. The file reaches someone outside the organization.

The consequences:

  • Every employee's salary data is exposed.
  • National ID numbers and bank account numbers are disclosed.
  • Affected employees can sue both the company and the responsible individual.
  • Penalty: Fines up to 5 million baht plus civil damages.

And the moment you realise it went to the wrong address, the 72-hour clock starts running — not when the investigation finishes.

Both cases share one feature: the damage occurred inside ordinary working procedure, not in an external attack. With an ERP system that has Access Control, accounting staff would only access necessary data and would be unable to export the entire company's salary data into a single file in the first place — and a file that does not exist cannot be emailed to the wrong person.

Conclusion

The accounting department holds the most personal data in any organization — yet it is often the department that receives the least attention regarding PDPA compliance. The risk does not lie in intentional human error but in "systems" that do not support compliance — transmitting data through insecure channels, storing documents without a management system, and lacking Access Control.

A well-designed ERP system helps the accounting department achieve PDPA compliance automatically — without adding workload, without needing to remember, as the system handles it all.

If your organization is concerned about PDPA compliance or needs a secure accounting system, you can schedule a Demo of Saeree ERP or consult with our expert team from Grand Linux Solution.

References

  1. Royal Gazette. "Personal Data Protection Act B.E. 2562 (2019)." https://www.ratchakitcha.soc.go.th
  2. Ministry of Digital Economy and Society. "PDPA." https://www.mdes.go.th
  3. Personal Data Protection Committee (PDPC). "PDPC Notifications." https://www.pdpc.or.th
  4. Telecom Lover. "PDPC Fourth Anniversary — PDPA Enforcement Update (26 June 2026)." telecomlover.com
  5. PDPA Thailand. "PDPA Fines in Practice — Public and Private Sector Cases." pdpathailand.com
  6. PDPA Thailand. "Personal Data Breach Notification — the 72-Hour Window." pdpathailand.com
  7. Department of Business Development. "Accounting Act B.E. 2543 (section 14, retention of accounts and supporting documents)." dip.go.th

Interested in an ERP System for Your Organization?

Consult with our expert team at Grand Linux Solution

Request More Information

Call 02-347-7730 | sale@grandlinux.com

Saeree ERP Team

About the Author

Expert ERP team from Grand Linux Solution Co., Ltd. Ready to provide comprehensive ERP consulting and services.