PDPA for a small hotel or restaurant, in plain terms

Updated 2026-07-25

Thailand's Personal Data Protection Act, the PDPA, applies to businesses that collect people's personal information, and a hotel or restaurant does that every day: names, phone numbers, bookings, emails. It is not only for big companies. This is a plain-language overview to help you understand the shape of it and start a proper conversation with an adviser. It is not legal advice, and where your specific obligations are concerned, confirm them with a professional.

What the PDPA is trying to do

Stripped of the jargon, the law asks you to be honest and careful with the personal data of your guests: to tell them what you collect and why, to have a proper reason for collecting it, to keep it reasonably safe, and to let them ask what you hold or have it removed. Most of it is common decency written into law. Understanding that spirit gets you most of the way.

What counts as personal data

Personal data is anything that identifies a specific person: a name, a phone number, an email address, a booking tied to a guest, a passport or ID number, a photograph, even an IP address from your website. If you hold it and it points to an individual, the law treats it as personal data. A guest list, a reservation book and an enquiry inbox are all full of it.

The basics you are expected to have

At a practical level, for a small venue, the essentials usually come down to:

  • A privacy notice, telling guests plainly what data you collect, why, and what you do with it.
  • A lawful basis for collecting it, most often that you need it to provide the booking or service the guest asked for.
  • Reasonable security, so the data you hold is not carelessly exposed.
  • A way to respond if a guest asks what you hold, or asks you to correct or delete it.

Exactly how these apply to your business is something an adviser can confirm; the point here is to know they exist so nothing takes you by surprise.

Where your website fits in

If your site collects any personal data, an enquiry form, a booking, even analytics that track visitors, then it should carry a privacy notice explaining what it collects, and for non-essential cookies it should ask consent rather than assume it. We build these in as standard: a privacy page, a cookie consent banner that genuinely lets a visitor decline, and forms that only collect what they need. The mechanics we handle; the exact wording of your policy is worth confirming with your adviser, because it should describe your real practices.

A sensible place to start

You do not need to solve everything at once. Start by writing down what personal data you actually collect and where it lives, the booking system, the LINE chats, the guest book, the website. Once you can see it, a privacy notice and the basic safeguards follow naturally, and a professional can review the rest.

This is one of several trust and admin questions that come with running a venue and hiring help, alongside what changes on your paperwork when you buy from a foreign company. If you want a website built with privacy and consent handled properly from the start, tell us what you are working with.

Common questions

Does the PDPA apply to my small hotel or restaurant?

In general the PDPA applies to any business that collects personal data, regardless of size, and a venue collecting names, phone numbers, bookings and emails is doing exactly that. There is no small-business exemption from the basics. This guide is a plain overview, not legal advice; confirm your situation with a professional.

What counts as personal data?

Anything that identifies a person: a name, a phone number, an email, a booking tied to them, a photo, an IP address. If you hold it and it points to a specific guest, it is personal data and the law expects you to handle it with care.

What is the minimum I should have?

At a practical level: a privacy notice telling guests what you collect and why, a lawful reason for collecting it, reasonable security, and a way for a guest to ask what you hold or to have it deleted. A professional can confirm what your specific business needs.

Does my website need a privacy notice and cookie consent?

If it collects any personal data, an enquiry form, a booking, analytics, then yes, it should tell visitors what it collects and, for non-essential cookies, ask consent. We build these in as standard, but the wording of your policy is something to confirm with your adviser.

Tell us what you’re working with

Send us your current site, or the LINE page you’re using instead of one, and we’ll tell you honestly what we’d change and what it would cost. No charge for that, and no pitch if it isn’t worth doing.

Contact

Fastest reply, usually within the hour

Your cookie choices have been saved.