Module 5/5 · Weeks 13–15 · 27 h

Ethics and the PDPA

DRT 343 Regulations, Safety, Risk Management and Ethics for Unmanned Aircraft Systems

About 90 minDraft, awaiting reviewLast updated 26 September 2026

Lesson

By the end of this module you will be able to

  1. Explain the key provisions of Thailand's Personal Data Protection Act 2019 relevant to drone imagery
  2. Determine the lawful basis for collecting imagery in case studies
  3. Calculate the deadline for notifying a personal data breach
  4. Design collection, use and deletion of imagery using privacy by design
  5. Analyse ethical issues in autonomous systems using the IEEE and UNESCO frameworks

Prerequisites: DRT 343 module 1

Why this matters

A camera drone sees what people on the ground cannot: back gardens behind high walls, rooftops and swimming pools. A single image may show faces, number plates and houses whose owners can be identified. Well-intended work can invade privacy without anyone noticing, and erode public trust in the whole drone industry.

The 2015 MOT notification forbids violating other people’s privacy, and Thailand’s Personal Data Protection Act 2019 (PDPA) sets clear duties for those who collect and use data. But the law is only the minimum. Ethics asks further: even if it is legal, should we do it?

A simple comparison: a photographer standing on a public street is different from someone climbing a fence to photograph inside a house. Drones blur that line, so pilots must ask the question themselves every time.

The PDPA in brief for drone work

The PDPA was published in the Royal Gazette on 27 May 2019. Its main chapters were postponed and it has been fully enforced since 1 June 2022.

SectionRelevance to drone work
6Personal data is data that identifies a person directly or indirectly, excluding data of deceased persons
4Does not apply in certain cases, such as purely personal or household use, and mass media, art or literature under professional ethics; exempted parties must still keep data secure
24Collection requires consent or another basis: archives, research or statistics; protecting life, body or health; contract; public task or official authority; legitimate interest not overridden by the data subject’s rights; legal obligation
26Sensitive data, such as race, beliefs, health, disability and biometric data, requires explicit consent unless an exception in this section applies
37(4)A breach must be notified to the Personal Data Protection Office within 72 hours of becoming aware of it, and to data subjects too if the risk is high
77–90Civil liability (punitive damages up to twice actual damages), criminal penalties for sensitive data, and administrative fines of up to 1, 3 or 5 million baht depending on the violation

Is drone imagery personal data?

It depends on whether a person can be identified. An image of rice fields from 90 m with no people is usually not personal data. Images showing faces, number plates, or houses that can be matched to their owners are personal data. Thermal imagery used to assess whether people are ill may be health data, which is sensitive.

Decision chart: if the data does not identify a person, it is outside the PDPA but privacy should still be respected; if it does and a section 4 exemption applies, the PDPA does not apply but security is still required; if not exempt and not sensitive, a section 24 basis is needed; if sensitive, explicit consent or a section 26 exception is needed
Figure 1 Deciding the PDPA lawful basis for drone imagery

Example 1 Determining the lawful basis (for learning, not legal advice)

  1. A municipality hires a canal survey for drainage planning. Images include people and houses along the canal. The municipality is the data controller; a possible basis is a public task or official authority under section 24. The contractor processes on instruction and should blur faces and plates in published images
  2. Filming a wedding for hire. For the couple, contract is a basis. For guests, inform them in advance and consider legitimate interest or consent, giving those who do not want to appear an option
  3. Using a thermal camera to screen body temperatures at a public gathering. The data may be health data, which is sensitive under section 26, requiring explicit consent or a specific exception; the flight also runs into the 2015 condition against flying over gatherings of people

Example 2 Breach notification deadline

An unencrypted hard drive with community survey imagery goes missing from the team’s vehicle. The data controller becomes aware at 14:30 on Monday 28 September 2026.

  1. Deadline to notify the Office hours
  2. 72 hours is exactly 3 days, so notify by 14:30 on Thursday 1 October 2026
  3. The images show faces and house numbers, so the risk to data subjects is high; they should be notified too, with remedial guidance

Encrypting storage media from the start greatly reduces the severity of incidents like this.

Privacy by design

Guidance from several bodies, such as the US NTIA voluntary best practices (2016), the EU Article 29 Working Party opinion (2015) and the UK Information Commissioner’s Office (ICO), shares common principles: inform others, assess impact before collecting (data protection impact assessment, DPIA), collect only what is necessary, keep it secure, limit use and sharing, and delete it when no longer needed. The ICO stresses that recording should not be continuous without strong justification, and that collateral intrusion must be managed.

A five-stage cycle around purpose and DPIA at the centre: collect only what is needed, store securely, use for the stated purpose, share only with a basis, and delete when no longer needed
Figure 2 Life cycle of drone imagery data

Design choices in real work:

  • Collect: set flight lines and camera angles to avoid private areas unrelated to the job; record only when needed
  • Store: encrypt media, restrict access, log who accesses it
  • Use: use only for the stated purpose; no reuse without a basis
  • Share: blur faces and plates before publication; share only with entitled recipients
  • Delete: set a retention period in the contract and actually delete when it ends

Ethics of autonomous systems

As drones make more decisions themselves, such as choosing targets to follow with AI, the question “who is responsible?” becomes more important. Useful frameworks:

  • IEEE Ethically Aligned Design (2019) sets out 8 general principles: human rights, well-being, data agency, effectiveness, transparency, accountability, awareness of misuse and competence
  • The UNESCO Recommendation on the Ethics of Artificial Intelligence (2021) has 4 core values, such as respecting human dignity and human rights, and 10 principles, such as proportionality and do no harm, privacy, transparency and explainability, human oversight and determination, and fairness

Questions every drone professional should keep asking:

  1. Proportionality: is the mission’s benefit worth the intrusion? Is there a less intrusive way?
  2. Human in the loop: do decisions that significantly affect people have a human who reviews and is accountable?
  3. Dual use: the same technology can find disaster victims or conduct surveillance; developers must consider misuse
  4. Social responsibility: does our work build or destroy trust in drones across the industry?

Class activity

Activity: A short DPIA and data cycle

Use core lesson G03 “Planning the data cycle before collecting drone imagery” from the drone knowledge hub.

  1. Choose a case from Example 1. Write the purpose, necessary data, who has access, sharing and retention period.
  2. Identify possible lawful bases and what still needs a legal expert’s opinion.
  3. Propose measures to reduce intrusion, such as camera angles, flight times and blurring.
  4. Discuss an ethics case: a company asks you to use drones to track its field staff. Should you take the job? Use the UNESCO framework.

Common mistakes

Watch out

  • Thinking anything may be filmed when flying over public space
  • Keeping all imagery “just in case” with no deletion date
  • Claiming a section 4 exemption for commercial work
  • Counting 72 hours from the incident or in working days instead of from awareness
  • Sending raw images with faces to a client who does not need them
  • Treating ethics as management’s job when the pilot is the first to see the problem

Summary

  • Personal data is data that identifies a person directly or indirectly; drone imagery is personal data when people can be identified
  • Collection needs consent or another basis under section 24; sensitive data under section 26 needs explicit consent or an exception
  • Breaches must be notified to the Office within 72 hours of awareness under section 37(4)
  • Privacy by design covers every stage of the data cycle, from collection to deletion
  • Ethics asks more than the law: proportionality, a human in the loop, misuse and social responsibility

Check your understanding

  1. A rooftop image from 80 m that can be matched to the house register: is it personal data? Why?
  2. Biometric data from face recognition is which type of data under the PDPA?
  3. You become aware of a breach at 09:00 on a Friday. When must you notify the Office?
  4. Give two privacy-by-design measures for drone work.
  5. How does UNESCO’s principle of “human oversight and determination” relate to autonomous drones?
Answers
  1. Yes, because a person can be identified indirectly when it is combined with other data
  2. Sensitive data under section 26
  3. By 09:00 the following Monday (72 continuous hours, including weekends)
  4. For example: set camera angles to avoid private areas, record only when needed, encrypt media, blur faces before publication, and set a deletion period
  5. Decisions that significantly affect people must have a human who reviews them and is accountable, not be left entirely to the autonomous system

Key formulas

Breach notification deadline to the Office (section 37(4))

Key references

  1. พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562. ราชกิจจานุเบกษา, 136(69 ก), 52–95. link
  2. National Telecommunications and Information Administration. (2016). Voluntary best practices for UAS privacy, transparency, and accountability. link
  3. Information Commissioner’s Office. Unmanned aerial systems (UAS) / drones. In Guidance on video surveillance (including CCTV). link
  4. Article 29 Data Protection Working Party. (2015). Opinion 01/2015 on privacy and data protection issues relating to the utilisation of drones (WP 231). link
  5. IEEE Global Initiative on Ethics of Autonomous and Intelligent Systems. (2019). Ethically aligned design (1st ed.). IEEE.
  6. UNESCO. (2021). Recommendation on the ethics of artificial intelligence. link
  7. กระทรวงคมนาคม. (2558). ประกาศกระทรวงคมนาคม เรื่อง หลักเกณฑ์การขออนุญาตและเงื่อนไขในการบังคับหรือปล่อยอากาศยานซึ่งไม่มีนักบิน ประเภทอากาศยานที่ควบคุมการบินจากภายนอก พ.ศ. 2558. ราชกิจจานุเบกษา, 132(86 ง), 6–12. link

Further reading

Study the assigned knowledge units in advance, review media and take the module quiz

In class / field

Lecture, case discussion and in-class problem solving

Learning evidence: Quiz results and submitted exercises

Module quiz

This is a formative self-check, not a graded exam

Knowledge domain: Law, safety and risk · Management, innovation and professional practice · Artificial intelligence and computer vision