THIM logo
Thai Immigration Application
Privacy Notice
PRIVACY NOTICE

THAI IMMIGRATION APPLICATION (THIM)

This page presents the Privacy Notice for the Thai Immigration mobile application operated by the Immigration Bureau of Thailand.

Immigration Bureau emblem

PRIVACY NOTICE
THAI IMMIGRATION APPLICATION

WHEREAS, the Immigration Bureau of Thailand, Royal Thai Police (the “Bureau,” “we,” “us,” or “our”) operates the Thai Immigration mobile application (the “Application” or “THIM”);

WHEREAS, the Bureau is vested with authority under the Immigration Act B.E. 2522 (1979) and the Personal Data Protection Act B.E. 2562 (2019) (the “PDPA”) to collect, process, and maintain personal data for immigration control purposes;

NOW, THEREFORE, this Privacy Notice (the “Notice”) sets forth the terms governing the collection, use, processing, storage, disclosure, and protection of personal data obtained through the Application.

I. Definitions and Interpretation

1.1 Definitions.

For the purposes of this Notice, the following terms shall have the meanings set forth below:

  1. "Data Controller" means the Immigration Bureau of Thailand, Royal Thai Police;
  2. “Data Processor” means any person or entity appointed by the Data Controller to process personal data on its behalf, without authority to determine the purposes or means of processing;
  3. “Data Subject” means any natural person who is the subject of Personal Data;
  4. “Personal Data” means any information relating to an identified or identifiable natural person;
  5. “Processing” means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, or destruction;
  6. “Third Party” means any natural or legal person other than the Data Subject, the Data Controller, or persons authorized by the Data Controller to process Personal Data.

1.2 Statutory Authority.

This Notice is promulgated pursuant to:

  • the Immigration Act B.E. 2522 (1979), as amended;
  • the Personal Data Protection Act B.E. 2562 (2019)
  • the Computer Crime Act B.E. 2550 (2007); and
  • the Royal Decree on Personal Data Protection B.E. 2564 (2021)

II. Data Controller Information

2.1 Identity of the Data Controller.

  • Legal entity: Thai Immigration Bureau, Royal Thai Police.
  • Registered Address: Chalermprakiat Building, His Royal Highness Crown Prince Maha Vajiralongkorn 60th Birthday Anniversary, No. 904, Village No. 6, Ban Mai Subdistrict, Pak Kret District, Nonthaburi Province 11120, Kingdom of Thailand.
  • Contact: saraban_imm@police.go.th | Telephone: +66-2-141-9889.

2.2 Data Protection Officer.

  • Designated officer: Data Protection Officer, Immigration Bureau.
  • Contact: dpo.tdac@immigration.go.th.
  • Supervisory authority: Personal Data Protection Committee of Thailand.

III. Categories of Personal Data Collected

3.1 Personal Data.

The following categories of Personal Data are collected as mandatory requirements for immigration processing:

  1. Identification Data: legal first name, legal surname, passport number, nationality, gender, and date of birth;
  2. Contact Data: electronic mail address and mobile telephone number.

3.2 Location Data.

Location-related data, including real-time or periodic location information, may be collected through the Application or User device permissions where required for the provision of specific Services.

IV. Categories of Sensitive Data Collected

4.1 Sensitive Data.

The following categories of sensitive data are collected strictly where necessary and as legally permitted under the Personal Data Protection Act B.E. 2562 (2019):

  1. Biometric Data: facial biometric template derived from a liveness-detection photograph;
  2. Document Data: machine-readable zone data extracted from the passport by optical character recognition;
  3. Electronic Data: Near Field Communication (NFC) chip data embedded in the passport.

V. Rights in Personal Data

  1. 5.1 Right to Withdraw Consent. The right to withdraw consent to the collection, use, or disclosure of personal data at any time, without affecting the lawfulness of prior processing.
  2. 5.2 Right of Access. The right to access and obtain a copy of personal data held by the Bureau, and to request information on the source from which such data was obtained.
  3. 5.3 Right to Rectification. The right to request correction of inaccurate or incomplete personal data.
  4. 5.4 Right to Erasure. The right to request deletion or anonymization of personal data on specific legal grounds.
  5. 5.5 Right to Restrict Processing. The right to request suspension of personal data processing under certain conditions.
  6. 5.6 Right to Data Portability. The right to obtain personal data and transmit it to another data controller where technically feasible.
  7. 5.7 Right to Object. The right to object to the processing of personal data for certain purposes, such as direct marketing or processing based on legitimate interest.

VI. Collection, Use, and Disclosure of Personal Data Without Consent

6.1 Personal data may be collected, used, or disclosed without prior consent only where permitted by law, including:

  1. Research or archival purposes: for research, statistical, or archival purposes with appropriate safeguards;
  2. Vital interests: to protect the life, health, or safety of an individual in emergencies;
  3. Contractual necessity: as necessary for the performance of a contract or the fulfillment of pre-contractual requests;
  4. Public interest: to carry out duties in the public interest or under official authority;
  5. Legitimate interests: for legitimate interests, except where overridden by the fundamental rights of the data subject; and
  6. Legal obligations: to comply with applicable legal obligations.

VII. Collection, Use, and Disclosure of Sensitive Data

7.1 Sensitive data may be collected, used, or disclosed without prior consent only where legally permitted and strictly necessary, including:

  1. Vital protection: to prevent or mitigate danger to the life, body, or health of individuals unable to give consent;
  2. Lawful non-profit activities: for lawful activities by foundations, associations, or non-profit organizations relating to political, religious, philosophical, or trade-union purposes, limited to internal use with appropriate safeguards;
  3. Public data: where the data has been made public with the data subject's explicit consent;
  4. Legal claims: for the establishment, exercise, or defense of legal claims; and
  5. Statutory purposes: as required by law to achieve specific purposes, including:
    • preventive or occupational medicine, including health assessments, medical diagnosis, or social or medical service provision, particularly under confidentiality obligations;
    • public health, including protection from communicable diseases and regulation of drugs or medical devices, with appropriate confidentiality safeguards;
    • labor protection and social security, including healthcare, accident compensation, and other social welfare under applicable laws;
    • research or public interest, including scientific, historical, or statistical research, with safeguards aligned with the PDPA;
    • significant public interest, subject to protective measures for individual rights and freedoms.

VIII. Legal Basis for Processing

  1. 8.1 Primary Legal Basis. Processing of Personal Data is undertaken pursuant to Section 24(1) of the PDPA, namely the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.
  2. 8.2 Statutory Authority. Such processing is specifically authorized under:
    • the Immigration Act B.E. 2522 (1979), Sections 12, 34, and 35;
    • the Ministerial Regulation on Immigration Procedures; and
    • the Cabinet Resolution on Digital Government Transformation.
  3. 8.3 Legitimate Interests. Where applicable, processing may also be based on legitimate interests, including:
    • national security and border control;
    • prevention of immigration fraud; and
    • facilitation of lawful travel and commerce.

IX. Purposes of Processing

9.1 Primary Purposes.

Personal Data is processed for the following purposes:

  1. Identity Verification: authentication of the Data Subject's identity through biometric and documentary evidence;
  2. Immigration Control: facilitation of border control procedures and entry authorization;
  3. Security Screening: assessment of security risks and prevention of unlawful entry;
  4. Service Delivery: generation of digital credentials and provision of expedited immigration services;
  5. Record Keeping: maintenance of immigration records as required by law;
  6. Communication: delivery of service-related notifications and updates; and
  7. Location Verification: verification of the Data Subject's physical presence within the Kingdom of Thailand for the purpose of providing certain immigration or administrative Services.

9.2 Secondary Purposes.

Personal Data may also be processed for:

  • statistical analysis and policy development;
  • system security and fraud prevention; and
  • quality assurance and service improvement.

X. Disclosure and Sharing

10.1 Authorized Recipients.

Personal Data may be disclosed to:

  1. Government Agencies: Royal Thai Government agencies, including but not limited to the Tourist Police Bureau, the Ministry of Foreign Affairs, the Royal Thai Armed Forces, and the National Intelligence Agency;
  2. Immigration Officers: authorized immigration officers at ports of entry throughout the Kingdom of Thailand;
  3. Law Enforcement: Thai law enforcement agencies pursuant to lawful requests or court orders; and
  4. Service Providers: third-party processors operating under written data-processing agreements, including KYCNow Company Limited for biometric and document verification services.

10.2 International Transfers.

Personal Data may be transferred internationally where:

  • required by an international treaty or agreement;
  • necessary for diplomatic or consular purposes;
  • requested by foreign law enforcement through mutual legal assistance; or
  • authorized by the Data Subject's explicit consent.

10.3 Legal Safeguards.

All disclosures are governed by:

  • written data-sharing agreements;
  • adequate security measures;
  • purpose-limitation principles; and
  • data-minimization requirements.

XI. Data Security and Protection

Technical Safeguards. The following technical measures are implemented:

  • end-to-end encryption for data in transit; and
  • Advanced Encryption Standard (AES-256) for data at rest.

XII. Data Retention

  1. 12.1 Retention Period. Personal Data shall be retained for a period of three (3) years from the date of collection or the last processing activity, whichever is later.
  2. 12.2 Extended Retention. The retention period may be extended where:
    • required by ongoing legal proceedings;
    • necessary for national-security purposes;
    • mandated by court order or legal obligation; or
    • needed for legitimate government purposes.
  3. 12.3 Secure Disposal. Upon expiration of the retention period, Personal Data shall be anonymized beyond reasonable possibility of re-identification.

XIII. International Data Subjects

  1. 13.1 Jurisdictional Application. This Notice applies to the processing of Personal Data of Data Subjects regardless of nationality or location when using the Application.
  2. 13.2 Cross-Border Processing. International Data Subjects acknowledge that:
    • Thai law governs data processing activities;
    • data will be processed within Thailand for immigration purposes;
    • local privacy laws may provide additional protections; and
    • diplomatic recourse may be available through the respective embassies.

XIV. Automated Decision-Making

  1. 14.1 Automated Processing. The Application employs automated systems for:
    • identity verification through biometric matching;
    • document-authenticity assessment;
    • risk scoring for security purposes; and
    • QR code generation for service delivery.
  2. 14.2 Human Oversight. All automated decisions are subject to:
    • human review and intervention;
    • appeal processes through immigration officers;
    • manual-override procedures; and
    • regular algorithmic auditing.

XV. Policy Amendments

  1. 15.1 Amendment Authority. This Notice may be amended by the Immigration Bureau to reflect:
    • changes in applicable law or regulation;
    • updates to Application functionality;
    • enhanced security measures; and
    • international best practices.
  2. 15.2 Notice of Changes. Material amendments shall be communicated through:
    • an updated Notice posted in the Application;
    • email notification to registered Users;
    • publication on official government websites; and
    • in-application notifications upon next use.

XVI. Governing Law and Jurisdiction

  1. 16.1 Applicable Law. This Notice and all data-processing activities are governed by the laws of the Kingdom of Thailand.
  2. 16.2 Jurisdiction. Thai courts shall have exclusive jurisdiction over disputes arising from this Notice, subject to applicable diplomatic immunities.

IN WITNESS WHEREOF

This Privacy Notice has been duly adopted by the Thai Immigration Bureau.

THAI IMMIGRATION BUREAU
ROYAL THAI POLICE

Date: April 27, 2026