The Right Not to Be Subject to Automated Decision-Making in the Age of Artificial Intelligence: A Comparative Legal Analysis of Thailand's Personal Data Protection Act and the EU GDPR and AI Act Frameworks
Main Article Content
Abstract
Background and Objectives: The rapid development of artificial intelligence (AI) technology has significantly transformed personal data processing, particularly through AI-driven Automated Decision-Making (ADM) in credit assessment, personnel screening, and insurance risk evaluation, while Thailand's Personal Data Protection Act B.E. 2562 (PDPA) still lacks protective provisions equivalent to the European Union framework. This research article aims to 1) analyse the principles and protection mechanisms of the right not to be subject to automated decision-making under GDPR Article 22, EU AI Act Article 86, and CJEU jurisprudence; 2) analyse and classify the legal gaps of the PDPA B.E. 2562 concerning the protection of data subjects from automated decision-making; 3) comparatively analyse the legal mechanisms of both systems using the Functional Equivalence Method; and 4) propose recommendations for improving Thai law to enhance the protection of data subjects in the context of artificial intelligence.
Research Methodology: This study is qualitative research conducted through documentary research, using Doctrinal Legal Research combined with Functional Equivalence comparative analysis following Zweigert and Kötz. The scope of primary sources covers GDPR Articles 4, 13–15, 22 and 35 together with Recitals 71–73; EU AI Act Articles 3, 5, 6, 9, 14, 59 and 86; CJEU case law in SCHUFA Holding (C-634/21) and Dun & Bradstreet Austria (C-203/22); EDPB guidelines (WP251 rev.01 and Opinion 28/2024); and the PDPA B.E. 2562 with its secondary legislation. Data were analysed through three mechanisms: doctrinal analysis, functional equivalence comparative analysis, and gap analysis.
Results: The research found that 1) the EU framework employs a Four-Tiered Protection System: (1) GDPR Article 22 establishing a prohibition with three exceptions and mandatory safeguards, including human intervention, the right to contest, and algorithmic explanation; (2) EU AI Act Articles 14 and 86 requiring Human Oversight-by-Design; (3) CJEU case law establishing the Determining Role Test and the standard of procedures and principles actually applied; and (4) EDPB Soft Law measures; and 2) the PDPA contains five legal gaps, namely the absence of a right to refuse ADM, the lack of profiling oversight, insufficient algorithmic transparency, the absence of DPIA provisions, and weak enforcement mechanisms, resulting in a Multidimensional Structural Divergence between the two legal systems.
Conclusion: The researcher proposes, as the researcher's own recommendation, amending the PDPA by enacting Section 32/1 to recognise the right not to be subject to automated decision-making, imposing duties of meaningful human intervention, algorithmic transparency, and mandatory DPIA for high-risk ADM, together with urgent interim measures through PDPC guidelines.
Article Details
References
ธนาคารแห่งประเทศไทย. (2566). แนวนโยบายการให้สินเชื่ออย่างรับผิดชอบ (Responsible Lending). ธนาคารแห่งประเทศไทย.
พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 [Personal Data Protection Act B.E. 2562]. (2562, 27 พฤษภาคม). ราชกิจจานุเบกษา, 136(69 ก).
รัฐธรรมนูญแห่งราชอาณาจักรไทย พ.ศ. 2560 [Constitution of the Kingdom of Thailand B.E. 2560]. (2560, 6 เมษายน). ราชกิจจานุเบกษา, 134(40 ก).
สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล. (2567). แผนแม่บทการคุ้มครองข้อมูลส่วนบุคคลของประเทศไทย พ.ศ. 2567–2570. สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล.
สำนักงานคณะกรรมการดิจิทัลเพื่อเศรษฐกิจและสังคมแห่งชาติ. (2565). แนวปฏิบัติจริยธรรมด้านปัญญาประดิษฐ์ (Thailand AI Ethics Guideline). สำนักงานคณะกรรมการดิจิทัลเพื่อเศรษฐกิจและสังคมแห่งชาติ.
สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์. (2566). แนวทางธรรมาภิบาลปัญญาประดิษฐ์สำหรับผู้บริหารองค์กร (AI Governance Guideline for Executives). สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์.
สำนักงานสภานโยบายการอุดมศึกษา วิทยาศาสตร์ วิจัยและนวัตกรรมแห่งชาติ และศูนย์เทคโนโลยีอิเล็กทรอนิกส์และคอมพิวเตอร์แห่งชาติ. (2565). แผนปฏิบัติการด้านปัญญาประดิษฐ์แห่งชาติเพื่อการพัฒนาประเทศไทย ระยะที่ 1 (พ.ศ. 2565–2570). กระทรวงการอุดมศึกษา วิทยาศาสตร์ วิจัยและนวัตกรรม.
Alqodsi, E., & Gura, D. (2025). Reflections on the data protection compliance of AI systems under the EU AI Act. Cogent Social Sciences, Article 2560654.
Court of Justice of the European Union. (2023, December 7). Case C-634/21, OQ v. Land Hessen (SCHUFA Holding – Scoring), ECLI:EU:C:2023:957.
Court of Justice of the European Union. (2025, February 27). Case C-203/22, CK v. Dun & Bradstreet Austria GmbH, ECLI:EU:C:2025:131.
European Data Protection Board. (2018). Guidelines on automated individual decision-making and profiling (WP251 rev.01). EDPB.
European Data Protection Board. (2024). Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models. EDPB.
European Union. (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation). Official Journal of the European Union, L 119, 1–88.
European Union. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act). Official Journal of the European Union, L, 2024/1689, 1–144.
Felzmann, H., Fosch-Villaronga, E., Lutz, C., & Tamo-Larrieux, A. (2019). Transparency you can trust: Transparency requirements for artificial intelligence between legal norms and best practices. Social Media + Society, 5(2), 1–14.
Kaminski, M. E., & Malgieri, G. (2020). Algorithmic impact assessments under the GDPR: Producing multi-layered explanations. International Data Privacy Law, 11(2), 125–144.
Malgieri, G., & Comandé, G. (2017). Why a right to legibility of automated decision-making exists in the General Data Protection Regulation. International Data Privacy Law, 7(4), 243–265.
Pasquale, F. (2015). The Black Box Society: The secret algorithms that control money and information. Harvard University Press.
Selbst, A. D., & Powles, J. (2017). Meaningful information and the right to explanation. International Data Privacy Law, 7(4), 233–242.
Tilleke & Gibbins. (2023). AI, privacy, and data protection: Legal considerations in Southeast Asia. Tilleke & Gibbins International Ltd. สืบค้นจาก https://www.tilleke.com/resources/ai-privacy-and-data-protection-legal-considerations-in-southeast-asia/
UNESCO. (2025). Global AI ethics and governance observatory: Thailand country profile. United Nations Educational, Scientific and Cultural Organization. สืบค้นจาก https://www.unesco.org/ethics-ai
van Kolfschooten, H. B. (2024). A health-conformant reading of the GDPR's right not to be subject to automated decision-making. Medical Law Review, 32(3), 373–391.
Veale, M., & Zuiderveen Borgesius, F. (2021). Is that your final decision? Multi-stage profiling, selective effects, and Article 22 of the GDPR. International Data Privacy Law, 11(4), 319–332.
Wachter, S., Mittelstadt, B., & Floridi, L. (2017). Why a right to explanation of automated decision-making does not exist in the General Data Protection Regulation. International Data Privacy Law, 7(2), 76–99.
Zweigert, K., & Kötz, H. (1998). An introduction to comparative law (3rd ed.). Oxford University Press.