Website Speed & Performance

Cloud Hosting and the PDPA: What 'Data Residency in Thailand' Actually Means

AWS and Google Cloud now have Thailand regions, but hosting data in-country isn't the same as full data sovereignty. What Thai ecommerce businesses actually need to know before choosing where their store lives.

BangkokSync5 min read

Hyperscale cloud providers now operate regions physically inside Thailand, which is genuinely useful — and also frequently misunderstood. "Our data is hosted in Thailand" has become a line businesses reach for when someone asks about PDPA compliance, as if the location of the server settles the question. It doesn't. It's one input into a larger answer.

Residency is not sovereignty

Thailand hosting supports data residency — meaning selected data is stored within Thailand's borders — but that is a narrower claim than full data sovereignty, which would mean Thai law has exclusive authority over that data regardless of who operates the infrastructure. A global cloud hosting provider with a Bangkok region still operates under its own corporate structure, and backups, redundancy copies, or support access can still touch systems outside Thailand depending on how the account is configured. Choosing the Thailand region is a meaningful step. It is not, by itself, a compliance certificate.

What the PDPA actually asks for

Thailand's Personal Data Protection Act governs how personal data is collected, secured, used, disclosed, and transferred — and it applies regardless of which cloud you're on. Since March 2024, cross-border transfer rules have specifically governed how Thai personal data can legally leave the country, which matters directly for any store using international payment gateways, marketing tools, or analytics platforms that process data overseas as a normal part of how they work.

None of this means avoiding global cloud providers. It means treating compliance as a configuration and process question, not a marketing checkbox:

  • Know what personal data you actually hold, and where each piece of it is processed — including by third-party tools plugged into your store.
  • Encrypt data in transit and at rest, and manage who has access to it, rather than relying on defaults.
  • Review cross-border transfers deliberately — payment gateways, email platforms, analytics — rather than accepting whatever a plugin does by default.
  • Put this in writing with your provider. Responsibility for securing content and access typically sits with you as the customer, not automatically with the cloud vendor, even when the servers are in-country.

A Data Processing Agreement is worth actually reading

Any vendor that processes personal data on your behalf — the hosting provider, but also the payment gateway, the email platform, the analytics tool — should be operating under a Data Processing Agreement that spells out what they do with the data, where it goes, and what happens if something goes wrong. In practice, many of these are accepted unread as part of a standard signup flow. Worth actually reading at least the sections covering sub-processors and data location for any vendor handling genuinely sensitive customer data, rather than treating the DPA as a formality.

Breach notification obligations don't wait for a convenient time

The PDPA requires notifying the regulator, and in some cases affected individuals, within a defined window after becoming aware of a data breach — which means a business needs to actually know when a breach has happened, not discover it weeks later during an unrelated audit. This is where monitoring that's genuinely watched, not just technically running, matters: a breach detected on day one and a breach detected on day forty are very different compliance situations, even if the underlying incident was identical.

Why the hosting decision still matters for Thai ecommerce

Location affects more than compliance optics. Serving Bangkok from Bangkok rather than Singapore or further away removes a real round trip from every request, which shows up directly in load times — and load time is not a cosmetic metric. Every additional second of delay measurably reduces conversion rate, and on the mobile connections most Thai shoppers actually use, that gap is more noticeable than it looks on an office fibre connection.

Baht billing and local tax invoices matter too, in a smaller but real way: foreign card statements in a different currency create reconciliation work for a finance team that a local billing relationship avoids entirely.

Backups that aren't tested aren't really backups

A backup schedule running successfully is not the same claim as a backup that can actually be restored — and the difference only becomes visible at the worst possible moment, during an actual incident, unless it's tested deliberately beforehand. A genuine disaster recovery process includes a periodic real restore test, not just confirmation that the backup job completed without an error, because a corrupted or incomplete backup can run "successfully" for months before anyone tries to use it.

Choosing between a hyperscaler and a Thai provider

There isn't a universally correct answer — it depends on what the business actually needs:

  • Hyperscale cloud (AWS, Google Cloud, Azure) suits stores that need auto-scaling for traffic spikes, a broad ecosystem of managed services, and global reach alongside a Thailand presence.
  • Thai-based hosting providers (like INET) suit businesses where local support relationships, straightforward baht billing, and dealing with a provider governed entirely under Thai jurisdiction outweigh the breadth of a hyperscaler's feature set.

What both options need regardless of the choice: managed patching, monitoring that actually gets watched, backups that are tested, and someone who can explain — specifically, not generically — how your setup satisfies PDPA obligations if you're ever asked.

A practical checklist before signing with a provider

  1. Confirm exactly which region and sub-processors will touch the data, not just the primary hosting location.
  2. Get the Data Processing Agreement and actually read the sub-processor and data-location sections.
  3. Ask how breach notification actually works — who gets alerted, how fast, and what the provider's own obligations are versus yours.
  4. Confirm backups are tested with real restores, not just scheduled and assumed to work.
  5. Map every third-party tool — payment gateway, analytics, email — that touches personal data and where each one processes it.

The practical takeaway

"We host in Thailand" is a reasonable starting sentence. It stops being a sufficient one the moment someone in your legal team, or a customer, or a regulator, asks the follow-up question: where exactly does the data go after that, and who can see it along the way. Managed hosting done properly has an answer ready for that question before it's asked, not after.

Not sure your hosting setup actually satisfies PDPA?

We'll review where your data actually goes — including through third-party tools — and give you a clear answer, not a marketing checkbox.