Nursing homes sit on some of the most sensitive data there is: the health, bodies and daily lives of vulnerable people. Thailand's Personal Data Protection Act (PDPA) isn't optional paperwork — it's the framework for handling that responsibility. Here's a practical, plain-language overview. (This is general guidance, not legal advice — confirm specifics with a qualified professional.)
01 What PDPA is, briefly
The Personal Data Protection Act B.E. 2562 (2019) is Thailand's main data-privacy law, fully in force since June 2022. It governs how organizations collect, use, store and share personal data, and gives individuals rights over their own information. It applies to care homes just as it applies to any business handling personal data.
02 Health data is “sensitive personal data”
PDPA treats health information as a special, higher-protection category of “sensitive personal data,” alongside things like disability and biometric data. That means nearly everything a care home records about a resident needs stronger justification and stronger safeguards than ordinary contact details. Treat every assessment and note accordingly.
03 Lawful basis and consent
You need a lawful basis to process personal data. For sensitive health data, explicit consent is the most common route, but there are others (such as protecting someone's vital interests in an emergency). The practical takeaway: know why you hold each piece of data, collect only what you need, and don't quietly repurpose it for something the resident never agreed to.
04 The rights residents and families have
Data subjects can ask what you hold about them, request corrections, and in many cases withdraw consent or ask for deletion. A care home should have a simple way to handle these requests rather than scrambling each time. Building those rights into your process is far easier than retrofitting them later.
05 Practical steps for a care home
Map what data you collect and where it lives. Restrict access so staff see only what their role needs. Keep records of consent. Have a breach-response plan. And choose software that is built with PDPA in mind — encrypted, access-controlled, hosted responsibly, with clear data ownership. Good tooling does much of this for you.
06 Sharing with families the right way
Families want updates — but not every relative is entitled to every detail, and the resident's wishes come first. Make consent for family communication explicit and configurable: who is on the list, what they can see, how they opt out. This is exactly how we designed CareConnect, because under PDPA — and for trust — it's the only responsible way to do it.