The Right to Privacy in Thailand: Privacy International Submission to Human Rights Committee
1. Introduction
Privacy International notes the written replies by the government of Thailand to
the Committee’s list of issues.1
The organisation remains concerned over the practices of surveillance by Thai
authorities. National legislation governing surveillance is inadequate, unclear
as to the powers, scope and capacity of state surveillance activities and thus it
falls short of the required human rights standards to safeguard individuals from
unlawful interference to the right to privacy.
In this submission, Privacy International provides the Committee with additional,
up to date information to that contained in the briefing submitted to the
Committee in advance of the adoption of the list of issues in 2016.2 Unless
otherwise stated, the concerns expressed in the 2016 submission are on going
and if they are not repeated here it is solely for brevity sake.
2. Concerns about the Computer Crimes Act - Lack of safeguards related
to retention and access of traffic data
As noted in the 2016 submission, Thailand does not have a comprehensive law
to cover communications surveillance. Instead a range of laws apply, including
most notably the Computer Crimes Act.3 Section 26 of
the Computer Crimes
Act requires that traffic data be retained by service providers, for a period not
exceeding 90 days.4 This period can be extended for up to a year if requested
by a competent official. Failure on the providers to retain the traffic data will
result in a fine.5
Access to such traffic data does not require any judicial authorization. In
fact, while officials must apply for court authorization to conduct certain
types of communications surveillance, this is not the case for traffic data (see
Section
18.)
In its replies to the list of issues, the government of Thailand noted that the
Computer Crimes Act is currently being amended. We understand that the
amendments to the Act were adopted in December 2016 despite significant
opposition by civil society organisations, including Thai Netizen Network. The
amendments fail to address concerns about protection of privacy and freedom
of expression, instead they expand on the unchecked powers of surveillance,
including notably allowing almost unfettered access to metadata for the
investigation of any crime.6
On the issue of differentiation in safeguards and procedural rules between the
1
2
3
4
5
6
Replies of Thailand to the list of issues, UN doc. CCPR/C/THA/Q/2/Add.1.
Available at: http://tbinternet.ohchr.org/Treaties/CCPR/Shared%20Documents/THA/INT_CCPR_ICO_THA_23558_E.pdf
The Computer Crimes Act deals with offences committed against computer systems or computer data and offences
which are already crimes under the Thailand Penal Code and are committed via a computer.
Traffic data is defined to include data showing sources of origin, starting points, destinations, routes,
time, dates, volumes, time periods, types of services or others related to that computer system’s
communications.
Section 26 of the Computer Crimes Act B.E. 2550 (2007).
An online petition by Thai Netizen Network to oppose the amendments attracted more than 370,000 signatures
(link to the petition and other relevant information: https://www.eff.org/deeplinks/2016/12/amendedcomputer-crime-act-and-state-internet-freedoms-thailand)
2