AI Governance · PDPA

PDPA and Generative AI: Using Enterprise Data Responsibly

A practical framework for Thai organizations seeking value from generative AI while protecting privacy, security, and trust.

Published 20 September 2026 · 10 min read

Generative AI can accelerate document summaries, customer responses, knowledge retrieval, and drafting. It can also move sensitive information outside normal processes. The central question is not only which tool to use, but which data may enter it, under what conditions, and who is accountable.

PDPA belongs in use-case design, not at the finish line

When a use case involves personal data, define its purpose, test necessity, establish the appropriate lawful basis, and communicate transparently with data subjects. Data collected for one purpose is not automatically suitable for every new AI purpose.

Classify data before selecting controls

Use an actionable classification: public, internal, confidential business, and personal or sensitive data. Define what must never enter public tools, what can use only an approved environment, and when data must be minimized, pseudonymized, or de-identified.

Six questions before approving a use case

  • What business outcome is sought, and is there a less data-intensive alternative?
  • What data will be submitted, processed, retained, or transferred?
  • Is personal data truly necessary, or can lower-risk data be used?
  • Who owns the use case, the data, and the risk of the output?
  • Can the provider use data for training, and can retention be configured?
  • If an answer is wrong, leaked, or biased, how will it be detected, stopped, and reported?

Vendor due diligence must go beyond price terms

Before connecting data or scaling a tool, business, IT, security, legal, and privacy teams should jointly review provider roles, data-processing terms, cross-border transfers, encryption, access controls, logging, incident notification, and audit or exit rights.

Turn principles into daily behavior

A good policy tells people what they may do, must not do, and when to seek advice. Sustainable control also needs approved tools, configured access, role-based training, use-case screening, and a simple reporting path—not reliance on employee memory alone.

Start with a controllable path

Choose a pilot with clear value and lower risk, such as summarizing public documents or drafting internal content without personal data. Build evidence from real use, then expand toward more complex use cases.

Frequently asked questions

Can personal data be entered into generative AI?

Evaluate purpose, necessity, lawful basis, notice, and controls first. Where data can be minimized or de-identified, choose that path first.

Is an AI policy alone enough?

No. It must be supported by use-case screening, data approval, provider configuration, user training, and incident monitoring.

Talk to us about Data & AI Governance