
The Personal Data Protection Committee (PDPC) states that the issue of government data spreading online is not a "common data leak." They are expediting comprehensive protection measures covering "source–intermediary–endpoint" stages and uniting efforts to close illegal data trading channels.
The Personal Data Protection Committee (PDPC) is urgently investigating the case where personal data and ID photos of citizens, including the Prime Minister, ministers, and senior executives, have been shared online. They are coordinating with relevant agencies to take action against those publishing the data, the agencies managing the databases, and criminal networks illegally buying or accessing the information. They emphasize that citizens harmed can file complaints with the PDPC to pursue legal proceedings.
Pol. Col. Surapong Plengkam, Secretary-General of the Personal Data Protection Committee, revealed that IT experts reported personal data and ID photos from government databases have been leaked online, affecting various groups including the general public, the Prime Minister, ministers, and senior officials. The PDPC has promptly coordinated with relevant agencies to verify the facts.
“Preliminary investigations found this case involves illegal use of data or program access links created unlawfully by criminal networks, constituting unauthorized access to computer data protected by specific security measures. This violates Section 7 of the Computer Crime Act and is not a routine data leak. We have therefore mandated measures to protect citizens' data comprehensively,” said the PDPC Secretary-General.
The measures are divided into three parts, covering the entire chain—from the data source, the networks buying or selling data or access channels, to those publishing the data:
First, action against those who post or publish the data, considered the “endpoint.” If these individuals lack authorization, their actions constitute unauthorized access and may violate Section 7 of the Computer Crime Act. The PDPC has coordinated with the Ministry of Digital Economy and Society and related agencies to consider legal prosecution.
They also warn the public, social media users, and online page or channel administrators not to open, forward, or redistribute personal data, links, or database access channels involved, as this could increase harm to data owners and expose perpetrators to legal liability.
Second, action with the agencies managing the data or the “source,” including the Department of Land Transport and Department of Provincial Administration. The PDPC is coordinating with these agencies to promptly investigate and rectify issues, suspend or stop incidents, and report personal data breaches to the PDPC immediately. They must also enhance system and data security measures.
At the same time, coordination with the National Cybersecurity Committee (NCSC) is underway to establish measures to close vulnerabilities and implement basic security protocols for involved operational units to prevent recurrence of similar incidents.
Third, action against criminal groups buying and selling personal data or trading unauthorized access channels, considered the “intermediary.” The Ministry of Digital Economy and Society and the Central Investigation Bureau (CIB) are integrated to investigate, suppress, and arrest offenders for legal action while swiftly blocking illegal data trading and exchange channels.
The PDPC Secretary-General emphasized that the response must cover all dimensions—from the origin of data, methods of system access, networks selling access channels, to those posting or publishing the data. All agencies must act quickly to halt damage, preserve digital evidence, identify vulnerabilities, and upgrade security measures appropriate to the data risk level under their care.
“If any citizen whose personal data has been harmed believes they have suffered damage, they can file a complaint with the PDPC for investigation and legal action,” Pol. Col. Surapong Plengkam concluded.
Read the news " Government Policy " for more information.