You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

//
INSIGHTS

Insights

We provide you with all of the latest legal developments in Southeast Asia, ensuring that you have the up-to-date knowledge you need to navigate the ever-changing legal landscape affecting your business. You can browse our entire library of publications below, and email [email protected] to sign up for updates that are relevant to your interests, delivered straight to your mailbox, as they emerge.

Search Insights

  • Order by
  • Reset

Search Results

0 results found

June 5, 2026
Thailand’s Office of Insurance Commission (OIC) has opened a public hearing on proposed amendments to the OIC Notification on Criteria for Information Technology Risk Governance and Management for Life Insurance and Non-Life Insurance Companies B.E. 2563 (2020) via the centralized Law platform. The public consultation period runs from May 8, 2026, to June 9, 2026. The proposed amendments aim to elevate the IT risk governance and cybersecurity risk management framework to be more modern and aligned with international standards, with a focus on strengthening cyber resilience, enhancing the role of IT audits, and establishing data governance and data quality controls. The parties affected by these amendments include life insurance companies, non-life insurance companies, and external IT auditors. Key Changes Elevated Role of Board of Directors The proposed notification requires the company’s board of directors to oversee data governance, cybersecurity, and the responsible use of AI. Additionally, the board should include at least one director with IT knowledge or experience. Companies are also required to designate a head of security responsible for information security. The board’s duties are expanded to include oversight of data governance and AI usage, including establishing relevant policies and committees. Enhanced IT Security and Cybersecurity The revised notification consolidates the existing chapters on IT project management, IT security and cybersecurity to reduce redundancy, and introduces significant new measures. These include mandatory multi-factor authentication for material systems, enhanced data security measures such as data masking and data leakage prevention, security hardening requirements, web filtering, and mandatory vulnerability assessment and penetration testing at least annually. New requirements are also introduced for mobile application security, API security, and security measures for emerging technologies such as cloud computing and post quantum cryptography. The cybersecurity framework now encompasses identification, protection, detection, response, and recovery. The draft also introduces source code review requirements for system development and mandates security controls
June 5, 2026
Vietnam’s AI regulatory framework has reached an important milestone. While the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law) established the foundation for AI governance, many practical compliance requirements were left to implementing regulations. On April 30, 2026, the government issued Decree No. 142/2026/ND-CP (Decree 142), which took effect on May 1, 2026, and provides the first detailed guidance on the implementation of the AI Law. Although an official list of high-risk AI systems is still pending from the prime minister, Decree 142 provides valuable insight into how Vietnam’s risk-based AI regulatory framework will operate in practice. Risk Classification Framework The AI Law adopts a risk-based approach under which AI systems are classified as high-risk, medium-risk, or low-risk. Decree 142 builds on this framework by providing detailed guidance on how these classifications are determined. High-risk AI systems are determined based on factors such as (i) their potential impact on life, health, property, human rights, public interests, or national security; (ii) the sector in which they are deployed; and (iii) the scale of affected users or integration with critical infrastructure. The latest draft list of high-risk AI systems appears to follow these same principles. Medium-risk AI systems generally include systems that may mislead, influence, or manipulate users, particularly where users may not realize they are interacting with AI or AI-generated content. The focus is therefore on transparency and authenticity risks rather than broader societal or safety concerns. Low-risk AI systems are those that do not meet the criteria for either high-risk or medium-risk classification. Importantly, Decree 142 seeks to avoid over-classification. Certain systems may fall outside the high-risk or medium-risk regimes, including internal-use systems, office-support tools, technical editing applications, certain back-end processing systems, and AI systems used in artistic, gaming, cinematic, or other creative contexts. Providers must also review and reclassify AI systems where significant changes materially alter
June 5, 2026
On May 11, 2026, Thailand’s Ministry of Social Development and Human Security released a draft Child Protection Act (“CPA”) for public review. The draft CPA would completely repeal and replace the current Child Protection Act B.E. 2546 (2003). This represents the most comprehensive overhaul of Thailand’s child protection framework in over two decades, reflecting the government’s stated objective of modernizing the law to address evolving social challenges—including those arising from digital technology—and to promote greater coordination among government agencies, local authorities, and civil society. The public review period closes on June 9, 2026. Key changes introduced by the draft CPA that could have significant implications for businesses, particularly online platform providers, media companies, and entities operating child-related services in Thailand, are set out below. Expanded Definition of “Child” Under the current CPA, a “child” is defined as a person under the age of 18, excluding those who have attained legal majority through marriage. The draft CPA removes the marriage exception entirely, broadening the scope of the law’s protections to include all individuals under 18 without exception. Replacement of “Abuse” with Broader Concept of “Violence” The current CPA uses the term “abuse/cruelty,” which covers acts causing harm to a child’s liberty, body, or mind; sexual offenses against children; and using children in harmful or immoral activities. The draft CPA replaces this with the broader concept of “violence,” which encompasses any act or omission causing harm to a child’s body, mind, or development; abandonment or neglect; improper exploitation; and sexual abuse. Notably, the new definition adds developmental harm as a recognized category of injury and captures all forms of misconduct regardless of the child’s consent. New Standalone Definition of Sexual Abuse, Including Online Conduct One of the most significant additions in the draft CPA is the introduction of a standalone definition of “sexual abuse” or “sexual harassment.” This
June 4, 2026
Indonesia’s Minister of Health has issued Decree No. HK.01.07/MENKES/301/2026 on the Affixation of Nutritional Labels and Health Information to Ready-to-Eat Processed Food Products. The decree came into force on April 14, 2026, and was issued to implement the Health Law and Minister of Health Regulation No. 3 of 2026 on Disease Control. The decree requires the inclusion of Nutri-Level labeling on the front-of-pack nutrition labeling (FOPNL) to indicate the product’s nutritional level based on the content of sugar, salt, and fat (“gula, garam dan lemak (GGL)”). Changes from 2024 Draft Regulation The Nutri-Level labeling was previously proposed in 2024 by the Indonesian FDA (BPOM) through a draft regulation concerning nutrition information. While the categories of Nutri-Level labeling remain the same in the issued decree, the content requirements of sugar, salt and fat in the decree are different from the earlier proposal introduced in the 2024 draft BPOM regulation. In addition, the decree has further specified that the content of fat in the Nutri-Level labeling is the content of saturated fat, not total fat as previously proposed in the 2024 draft. The decree requires Nutri-Level labeling to be implemented in beverage products, which is the same as previously proposed in the 2024 draft BPOM regulation. Other food products may gradually become subject to mandatory Nutri-Level labeling under future implementing regulations. Nutri-Level Labeling Food levels as shown by the Nutri-Level labeling are classified into four color-coded categories from A to D: Level A (lowest amount) in dark green Level B in light green Level C in yellow Level D (highest amount) in red The Nutri-Level labeling is represented by the following image. The requirements for each level for sugar, salt, and fat content, based on amounts per 100 milliliters of product in beverage form, are as follows. Nutri-Level information must be affixed as follows: Nutri-Level must be displayed in full, using all four letters
June 4, 2026
On May 19, 2026, the Cabinet of the Royal Thai Government approved, in principle, revisions to Thailand’s visa exemption scheme and visa on arrival (VOA) program, as proposed by the Ministry of Foreign Affairs and the Ministry of Tourism and Sports. The revisions represent a tightening of Thailand’s immigration framework and will affect a broad range of short-term visitors. Background On July 15, 2024, Thailand expanded its visa exemption scheme by increasing the permitted period of visa-exempt stay from 30 days to 60 days in order to promote tourism, support the country’s post-pandemic economic recovery, and facilitate international travel. Under this revised scheme, passport holders from 93 countries and territories (an increase from the previous 57 countries and territories) have been permitted to enter Thailand without a visa and remain in the country for up to 60 days per entry for purposes including tourism, business engagements, urgent work, and ad hoc assignments. In addition, eligible visitors may apply at the Thai Immigration Bureau for a further 30-day extension of stay. Key Changes The proposed revisions would revoke the current 60-day exemption and reinstate the previous stay period, thereby reducing the maximum permitted stay for eligible travelers to 30 days per entry. In addition, the number of countries and territories eligible under the 30-day visa-exemption scheme is expected to be reduced to 54. The scope of the VOA scheme would likewise be significantly narrowed, with the number of eligible countries reduced from 31 countries to just four (Azerbaijan, Belarus, Serbia, and India). Further, Thailand is expected to introduce a new 15-day visa exemption category for nationals of Seychelles, the Maldives, and Mauritius. The revised framework would also limit each country or territory to a single visa exemption privilege in order to simplify Thailand’s immigration framework and reduce overlapping immigration privileges. Overstay Penalties Foreign nationals are reminded that remaining in Thailand
May 29, 2026
Indonesia’s Food and Drug Authority (BPOM) has issued Regulation No. 7 of 2026 on Drug Promotion and Advertising, establishing an updated framework for promotional activities involving medicinal products in Indonesia. The regulation took effect on April 16, 2026, and supersedes BPOM Regulation No. 2 of 2021 on Drug Advertising Supervision. The new regulation maintains general principles for advertising content, including requirements that advertisements be objective, complete, and not misleading, as further detailed in its annex. It also confirms that advertisements for nonprescription drugs directed to the public must obtain prior approval from BPOM before publication and must be in Bahasa Indonesia. The regulation provides a more comprehensive framework governing how drug promotion is conducted, introducing several notable additions and changes, as described below. Procedure and Requirements for Drug Advertisement Approval To apply for a drug advertisement approval, applicants must create an online account through the dedicated portal SIAPIK. Advertisement approval is available only for registered drugs; unregistered drugs are not eligible for advertisement approval with BPOM. The application must include the advertisement design, along with a translation if the design contains any wording in a foreign language. The submission format varies by media type, requiring, for example, copies in the form of print advertisements for visual media, scripts for audio media, and storyboards for audiovisual media. For online media—including social media—submissions should include any captions, descriptions, and hashtags that form an integral part of the advertising material. The approval timeline takes approximately 3–4 months, as BPOM will generally request additional information or revisions during the verification and evaluation process. Applicants have 20 days to submit any such requested documents. BPOM may also conduct a reevaluation of advertisements that have already received approval, based on monitoring results or new information regarding the safety and quality of the advertised drug. This could result in BPOM issuing a correction
May 25, 2026
After several years of policy discussion and continued efforts led by the Ministry of Commerce (MOC) to relax the list of reserved businesses under the Foreign Business Act B.E. 2542 (1999) (FBA), the reform process has now reached a significant milestone. On May 12, 2026, the Thai cabinet approved in principle two draft subordinate legislative instruments aimed at delisting certain reserved business activities under the FBA and reducing licensing requirements for foreign business operators. These developments signal a renewed and concrete effort by the government to modernize Thailand’s business regulatory framework in order to attract foreign investment and boost Thailand’s competitiveness in the global market. Nine Businesses Set for FBA Delisting Below is a list of the nine businesses that are being targeted for delisting from the FBA’s restrictions. A draft ministerial regulation would delist the first eight reserved businesses, while a royal decree has been drafted to delist the ninth business: Telecommunications services (Type 1 license only, covering operators without their own telecommunications infrastructure), under the supervision of the Office of the National Broadcasting and Telecommunications Commission. Treasury center services subject to the Foreign Exchange Control Act B.E. 2485 and under the supervision of the Bank of Thailand. Securities-collateralized lending, pursuant to the laws governing securities and exchange and derivatives regulated by the Securities and Exchange Commission. Agency, dealer, advisory, or fund management services relating to derivatives where the underlying assets fall outside the scope of the Derivatives Act B.E. 2546 (2003) Intra-group shared services, including administrative, human resources, and IT functions Intra-group domestic debt guarantee services Leasing of partial space for installation of financial service machines and automatic vending machines for employee use Petroleum drilling services Trading of agricultural product derivatives through a futures exchange, with physical delivery or receipt of agricultural products at a futures exchange–designated warehouse These delistings were made on the basis that they would not adversely
May 25, 2026
Thailand published new rules on May 1, 2026, establishing clear procedures for how the Anti-Money Laundering Office (AMLO) handles digital assets seized during criminal and money laundering investigations. Taking effect the following day, the Regulation of the Anti-Money Laundering Board on the Custody and Management of Seized or Frozen Assets (No. 3) B.E. 2569 applies to digital asset businesses, cryptocurrency holders, and anyone subject to asset seizure under Thailand’s anti-money laundering laws. For the first time, authorities now have a detailed roadmap for transferring seized digital property from private or foreign control into secure state custody. Digital asset businesses holding customer assets under investigation must be prepared to comply with these rules compelling repatriation of such assets in enforcement actions. Expanded Definition of Digital Assets The regulation defines digital assets to include not only those covered by Thailand’s existing digital asset business law but also any other property that can be stored using the same methods as digital assets. This broad formulation means the custody rules will apply to emerging blockchain-based assets and tokenized property that may not yet fall within the statutory definition of a digital asset business, giving authorities flexibility as the technology evolves. Mandatory Transfer to Domestic Custody When digital assets are held with service providers outside Thailand, AMLO will first attempt to transfer them to an account the office maintains with a licensed domestic digital asset business operator. If the domestic operator does not support that particular asset, the office will instead move the assets to its own cold wallet (offline, internet-isolated storage system). If neither option is feasible, the seizing official will report the situation to the Anti-Money Laundering Committee for alternative instructions. A similar hierarchy governs assets held in an accused party’s private wallet or by any third party that is not a licensed domestic digital asset business operator.