2026.10.01

A PDPA Fine Every Business Should Study: When the Destruction Vendor Leaks, Both Pay

Thailand's PDPC fined a private hospital ฿1.21 million after a hired destruction contractor leaked over 1,000 medical records. What the case means for how you dispose of devices and data.

อ่านภาษาไทย

The Case: Medical Records Turned into Snack Bags

On 1 August 2025, Thailand's Office of the Personal Data Protection Committee (PDPC) announced administrative fines in five PDPA cases. One of them matters to every organisation that throws away data.

A large private hospital hired a small, family-run business to destroy patient medical records. The contractor did not follow the agreed process. Instead, it took the records back to a private home. More than 1,000 medical records leaked, and some were reused as paper bags for kanom Tokyo, a Thai street snack. Photos of the bags spread on social media.

Who Was Fined, and Why

  • The hospital: ฿1,210,000. The PDPC found it did not monitor, control or check the destruction process, and did not properly destroy the data within the required period. Health records are sensitive personal data under Section 26 of the PDPA.
  • The contractor: ฿16,940. It did not follow the agreed procedure and did not tell the hospital about the leak, which breached its duties as a data processor.

In total, the case cost ฿1,226,940 in fines, before counting the damage to the hospital's reputation.

The Lesson: You Cannot Outsource Liability

Hiring someone to destroy your data does not move the responsibility to them. The hospital paid by far the larger fine because it did not supervise its vendor. The PDPC is also willing to fine processors directly. In another case announced the same day, a collectible toy retailer was fined ฿500,000 while its data processor was fined ฿3 million.

The PDPC said at the time that total administrative fines since PDPA enforcement began had passed ฿21.5 million, and that many more cases were under review.

The Same Risk Applies to Devices

This case involved paper, but the pattern is identical for laptops, phones, hard drives and servers. A device handed to an informal recycler or a "we buy old computers" shop can leave your office with every file still recoverable. If something leaks later, you will have no record of what happened to it. That is why IT asset disposal needs the same paper trail as any other compliance process.

Checklist: Choosing a Disposal Vendor

  1. Put the job in a written agreement that defines the destruction method, timeline and duty to report incidents.
  2. Keep a serial-number inventory of every device or box of records you hand over.
  3. Know who collects the items, where they go and when they are destroyed.
  4. Require a certificate of destruction for each device, showing serial number, method and date.
  5. Make sure the vendor must tell you immediately if anything goes wrong. Under the PDPA, you as the data controller generally have 72 hours to notify the PDPC of a breach.
  6. Keep the certificates with your compliance records.

How We Work

We handle laptop data destruction, hard drive and SSD destruction and server data destruction, as well as desktops and phones, and issue a Certificate of Data Destruction for every device with its serial number, method and date. We do not handle paper documents. If you use a shredding company for paper, hold them to the same checklist above.

Get an instant quote or call 082-797-3702.

Sources: PDPC announcement of 1 August 2025, as reported by Thai Post and summarised by Rajah & Tann Thailand. The hospital and contractor were not named.

Related Articles

IT Asset Disposal Bangkok

Certified, PDPA-compliant destruction in Bangkok.

Learn More