Hotels Cafés & bars How it works Features Integrations Pricing Guides Support
Data protection · Thailand

Guest Wi-Fi in Thailand: ninety days of logs, with the right time on them.

A hotel in Phuket, a villa on Koh Samui or a beach bar in Krabi that offers internet access is a venue the Computer Crime Act has an opinion about. The duty is short to state and easy to get wrong, and Thailand’s PDPA adds the consent rules on top. Set the property to Thailand during setup and the platform follows both.

What the law expects

One act about logs, one act about people

Retention

Ninety days under the Computer Crime Act

Any venue offering internet access keeps traffic records for at least ninety days, and an official can order a longer period. The record has to say who was connected and when. A log with the wrong time on it is not a log, which is why the platform and the equipment keep their clocks in step.

Personal data

The PDPA, for the list

Thailand’s Personal Data Protection Act treats a guest’s name, email and device record as personal data. Marketing needs its own consent, given separately from getting online, and a guest can ask what is held and ask for it to go.

Consent

Never a condition of getting online

The marketing box is separate, un-ticked and per channel. A guest who says no is online at the same speed. Every yes is kept with the wording the guest saw, the page it was on, and when.

This page describes how the product behaves. It is not legal advice, and your own counsel decides what your property must do.

What the platform does

Pick Thailand at setup. The rest follows.

Identifiable session logs kept for ninety days by default, with a longer period available for a property that has been ordered to keep one. Synchronised clocks, so every record carries the right time. Marketing consent as its own tick, recorded with the exact wording. Erasure that deletes the personal data and keeps the logs the Act requires without the identifying details.

The data is held in a single hosting region serving every country today, with the cross-border safeguards in the processing agreement. If the data has to sit in Thailand, say so before signing up. Where the data is →

Set to Thailand

Retention · ninety days, extendable

Clocks · synchronised, so the time on a record is right

Consent · separate, un-ticked, per channel, recorded

Erasure · personal data deleted, required logs kept without identifying details

Export · a guest’s whole record, free on every plan

Who this is for

The island properties, mostly

Phuket, Koh Samui, Koh Phangan and Krabi are where the guest Wi-Fi gets used hardest and where the internet line is most often shared or metered, so the same setup that keeps the logs also sets the per-guest limits that keep the line usable. Thailand is one of the two markets where most of our installations are, and the ninety-day pack exists because the first properties needed it. Guest Wi-Fi for hotels and resorts → · How much Wi-Fi a resort needs →

Before you ask us

What Thai properties ask

How long must a hotel in Thailand keep guest Wi-Fi logs?

At least ninety days of traffic records, under the Computer Crime Act, and longer if an official orders it. The records have to carry the right time, so the clocks on the equipment and the platform are kept in step. Set the property to Thailand and ninety days becomes the default, with a longer period available.

Does Thailand’s PDPA apply to guest Wi-Fi?

Yes. A name, an email address and a device record are personal data, and marketing needs its own consent, separate from network access. The platform keeps the two apart and records every consent with the wording the guest saw.

What happens if a guest asks for their data to be deleted?

Their access is cancelled, their personal data deleted, and identifying details stripped from the records the Computer Crime Act requires the property to keep. Every connected system is told to do the same. A guest can also be given a copy of their whole record, free on every plan.

Where is the data held?

In a single hosting region serving every country today, with the cross-border safeguards described in the processing agreement. Every property’s data is encrypted with its own key. If data residency in Thailand is a hard requirement, say so before signing up.

Is this legal advice?

No. It describes how the product behaves once a property is set to Thailand. Your own counsel decides what your property must do.

Send us the questions your lawyer sent you

We would rather answer them now than discover the gap after the property has gone live. Indonesia has its own page, and every other country is in the table.