Legal & Compliance

PDPA for Aesthetic Clinics: How to Collect Patient Data Legally

person By Inspire Eternity Team
calendar_today July 7, 2026
schedule Approx. 6 min read
PDPA for Aesthetic Clinics: How to Collect Patient Data Legally

Introduction

Regulatory authorities in Thailand, specifically the Personal Data Protection Committee (PDPC), have imposed administrative fines exceeding 1.2 million THB on private healthcare facilities for patient data breaches, with aggregate penalties reaching 21.5 million THB in related enforcement actions.*

This underscores that regulatory scrutiny of healthcare data privacy is expanding rapidly. Aesthetic clinics carry significant compliance responsibilities because they routinely collect, store, and process highly sensitive personal data—including diagnostic clinical records, pharmaceutical allergy histories, and identifiable biometric photographs.

This article outlines essential PDPA compliance guidelines for aesthetic clinic operators, covering data classification, penalty frameworks, marketing photo rules, and practical implementation checklists.

  • * Reference: Entech Review report on PDPC regulatory enforcement actions.

⚠️ Disclaimer: This article provides general educational information and should not be construed as formal legal counsel. PDPA regulations evolve through sub-regulations and committee interpretations. Always consult certified data privacy attorneys for clinic-specific compliance implementations.

What is the PDPA and How Does It Apply to Aesthetic Clinics?

The Personal Data Protection Act B.E. 2562 (2019) governs the collection, processing, usage, and disclosure of personal data, requiring verified consent from data subjects unless specific statutory exemptions apply.

Under the PDPA, an aesthetic clinic acts as a Data Controller, bearing legal accountability for determining the purposes, legal bases, retention periods, and security measures applied to patient records.*

  • * Reference: PDPAThailand healthcare data protection guidelines.

General PII vs. Sensitive Health Data

Data Category Clinic Examples Statutory Consent Requirement
General Personal Data (PII) Full name, phone number, email address, billing information Standard informed consent upon intake
Sensitive Personal Data (Sensitive PII) Medical history, drug allergies, diagnostic clinical records, facial/body photographs Explicit Consent (opt-in) with heightened security standards

Elevated Risk Profile: Aesthetic clinics routinely collect Sensitive PII (treatment histories, adverse reactions, and facial imagery), which requires explicit, unambiguous consent prior to processing.*

  • * Reference: PDPAThailand.

Statutory Penalties Under the PDPA

Penalty Type Statutory Sanctions
Civil Liability Actual damages awarded without statutory caps; courts may award punitive damages up to 2x actual damages.*
Criminal Penalties Imprisonment up to 6 months to 1 year, and/or criminal fines up to 500,000 to 1,000,000 THB for intentional unlawful disclosure.*
Administrative Fines Fines ranging from 500,000 THB up to 5,000,000 THB per violation, particularly when involving sensitive health data.*
  • * References: T-Reg Data Compliance and Ministry of Justice legal guidelines.

Essential PDPA Compliance Checklist for Clinics

1. Distinct Privacy Policies & Consent Forms

Clearly communicate processing purposes prior to collecting patient information. Crucially, the clinical medical history consent must be strictly segregated from promotional marketing or advertising consents.

2. Designated Data Protection Officer (DPO) / Lead

Clinics processing sensitive medical records on a continuous basis should designate an internal officer responsible for data governance and privacy audit oversight.

3. Data Retention and Secure Disposal Schedules

Establish clear retention schedules for electronic medical records (EMR) in alignment with the Sanatorium Act, accompanied by certified cryptographic or physical destruction protocols when retention terms expire.

4. CCTV Signage and Video Privacy Notices

Display conspicuous CCTV warning signage at all clinic entrances and public waiting lounges, supported by an explicit CCTV Privacy Notice.

5. Data Processing Agreements (DPA) with Cloud Vendors

When utilizing third-party Clinic Management Software (CMS) or cloud hosting providers, execute formal DPAs guaranteeing encryption and confidentiality standards.

6. Internal Staff Data Privacy Training

Train nurses, receptionists, and coordinators on data privacy hygiene—such as locking computer terminals and prohibiting unauthorized sharing of patient photos via personal chat apps.

The Two-Tier Rule for Before-and-After Photos

Patient before-and-after photographs represent the highest compliance risk area for clinics. Publishing them requires navigating two distinct legal authorizations:

Tier Regulatory Authority / Law Mandatory Action
Tier 1: Healthcare Advertising Department of Health Service Support (HSS) Submit advertising material for formal pre-publication approval.
Tier 2: Data Privacy Personal Data Protection Act (PDPA) Obtain explicit, documented individual written consent from the patient specifically for promotional use.

⚠️ Critical Reminder: Receiving marketing approval from the HSS does NOT waive PDPA consent requirements. Both steps are mandatory before publishing patient imagery.

Data Subject Rights That Clinics Must Support

  • Right to Access: Patients may request copies of their stored personal and medical files.
  • Right to Rectification: Patients may request corrections of outdated or inaccurate information.
  • Right to Erasure: Patients may request deletion of records where statutory retention obligations do not supersede.
  • Right to Object: Patients may object to data processing for direct marketing purposes at any time.
  • Right to Withdraw Consent: Patients may withdraw consent previously granted, without retroactive invalidation.

Frequently Asked Questions (FAQ)

Q: Does a small boutique clinic have to comply with the PDPA?

Yes. The PDPA applies to all entities processing sensitive health data regardless of clinic headcount or revenue volume.

Q: What should a clinic do if a patient withdraws consent for their promotional photo?

The clinic must promptly remove the photograph from all digital channels, social media feeds, and promotional collateral upon receiving the withdrawal notice.

Conclusion

PDPA compliance is an indispensable pillar of ethical healthcare administration. Establishing rigorous data governance protocols protects your clinic against substantial legal liability while strengthening patient confidence in your medical brand.

Operating a compliant medical clinic requires adherence across clinical safety, healthcare advertising codes, and data protection mandates. If you require further insights on medical device compliance, the Inspire Eternity team is here to assist.

References

  • * Entech Review. PDPC fines private healthcare facilities following patient data breaches. entechreview.com
  • * PDPAThailand. How medical clinics should handle patient personal data under PDPA. pdpathailand.com
  • * T-Reg. Summary of PDPA penalties and compliance frameworks. t-reg.co
  • * Ministry of Justice. Personal data protection statutory prescription periods. justicechannel.org

Planning to Open an Aesthetic Clinic or Seeking Equipment Feasibility Consultation?

The Inspire Eternity specialist team is ready to guide your clinic setup and equipment selection.

Contact Us Today