What does data protection actually protect? Is it really about data — or about the person behind the record, and how far a brand can go with their preferences once a campaign leaves the home market? Across Southeast Asia, six markets share familiar privacy labels but ask different questions of the same customer journey. The data at stake is ordinary campaign material: email addresses, tracking cookies, purchase histories, and the preference flags that decide who sees the next offer.
Most recently, in July 2026, Thailand’s Personal Data Protection Committee released consultation drafts on lawful bases and on marketing and direct marketing. Summaries of the draft say digital marketing, profiling and AI-assisted personalisation sit as distinct consent questions — separate from core service consent. Here is a look at how data protection is being regulated in the ASEAN region.
What happened
There is no unified ASEAN privacy law. Across Singapore, Thailand, Indonesia, Malaysia, Vietnam and the Philippines, regional marketing teams need to follow each country’s rules on marketing consent, profiling and how customers can withdraw permission.
Singapore’s Personal Data Protection Act remains the baseline many regional headquarters use for internal policy language, including Do Not Call Registry interaction. Thailand’s July 2026 consultation drafts push the timely question further. Summaries say marketing consent should stay separate from the primary service relationship — the consent needed to open an account or complete an order should not automatically allow promotions or marketing profiles. They also warn against preselected boxes and bundled consent when profiling or AI-driven marketing is involved: for example, a signup form that already ticks “send me offers,” or that rolls newsletter, partner ads and behavioural targeting into one yes. The final PDPC marketing guidance will determine how strictly those lines apply.
A second split sits in how markets treat legitimate interest — a legal basis that lets a company process personal data for a real business purpose, such as promoting similar products to existing customers, when that purpose is not overridden by the person’s rights. Indonesia’s Personal Data Protection Law, fully enforced since 17 October 2024, allows more than one legal basis for marketing, including legitimate interest — but withdrawal workflows still decide when promotional use must stop. Those workflows are the steps that remove someone from lists, pause CRM tags and stop ad tools from using their data after they opt out. In the Philippines, NPC Circular No. 2023-04 says direct marketing may rely on legitimate interest for ordinary personal information after assessment, or on consent where processing would significantly affect a person’s rights. Once consent is withdrawn, a company cannot keep emailing or targeting that person by switching to legitimate interest instead.
A third split covers profiling and purpose-specific consent. Malaysia’s Personal Data Protection Commissioner issued April 2026 guidelines on automated decision-making and profiling: data-protection officers should engage early and run a data-protection impact assessment where ADMP — including AI-enabled personalisation — is introduced. That means checking privacy risks before a system starts scoring customers or deciding offers automatically — for example, an AI model that ranks who gets a discount based on browsing and purchase history. Vietnam’s Personal Data Protection Law is targeted to take effect in 2026, with consent as the default basis and separate consents expected for specific processing purposes rather than one bundled approval at sign-up. Processing purposes are the stated reasons for using the data — account setup, order delivery, email marketing, partner sharing — each needing its own clear yes where the rules require it.
What it means
Implementing a one-consent-fits-all approach across ASEAN will not work. For brands with a Singapore HQ, the PDPA can be used for establishing internal policies; however, operating across the other five markets means translating that wording into six paths: what must be consented separately, when profiling needs a risk check, and what happens after someone opts out.
WE Interactive’s SEA Data Privacy Guide for Marketers (15 July 2026) suggests the same friction — granular opt-ins, preference centres and tools configured by market — and says a single regional privacy policy is generally insufficient.
Regional campaigns therefore need consent built market by market: separate opt-ins, clear purpose tags, AI personalisation checks, easy withdrawal, and records that show which rule applied in which country. Otherwise a customer’s stated preference will not survive the hand-off between systems.
What to watch
• Thailand’s final marketing guidance: Whether the July 2026 draft’s rules on profiling and AI personalisation stay in the final PDPC guidance — and how strictly brands must separate marketing opt-ins from account signup.
• Vietnam’s new privacy law in practice: Once the 2026 Personal Data Protection Law takes effect, how clearly regulators require a separate yes for marketing versus other uses of the same customer data.
• After opt-out: In the Philippines, once consent is withdrawn, the brand cannot keep marketing by switching to legitimate interest — watch whether email, CRM and ad tools actually stop. Indonesia’s multiple legal bases make the same workflow test relevant when promotional use must end.



