← Atlas Theme · spans 1 topics

Privacy enforcement now lands harder on processors than on the controllers who hire them.

APAC regimes are attaching direct — and often larger — liability to the vendors that process data on controllers' behalf, from Thailand's six-to-one fine ratio to Malaysia's criminal exposure for processors.

1
Topics it spans
2
Findings citing it
—
Evidence window
The convergence

The same conclusion keeps arriving from across the workspace's research — 1 topics independently instantiate this theme. Filter the evidence by where it came from:

APAC Data Residency
Thailand: PDPA Enforcement Escalates with THB 21.5M in Fines and Tightened Cross-Border Transfer Rules

Thailand's PDPC fined the processor six times its controller, establishing that vendors handling data directly bear the heavier penalty.

APAC Data Residency
Malaysia Implements Major PDPA Overhaul and Launches Risk-Based Cross-Border Transfer Guidelines

Malaysia's amendment gives processors independent criminal liability regardless of the controller relationship, formalizing direct vendor exposure.