You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 7, 2020

Bank of Thailand Introduces Digital Personal Loans

Informed Counsel

With technological advancements, business operators are able to access more varieties of data than ever before, and are able to use that data to assess the terms on which loans are provided. This means that they can provide services to consumers more efficiently and with lower operating costs. More importantly, however, it allows them to provide financial services to a broader range of consumers who would otherwise not be able to access vital funds.

To facilitate this, on September 15, 2020, the Bank of Thailand (BOT) introduced a new type of personal loan—the digital personal loan—under BOT Circular Re: Rules, Procedures and Conditions for the Undertaking of Digital Personal Loan Business. Sometimes known as “quick loans” or “easy loans” in other jurisdictions, this new type of loan instrument is intended to promote Under the circular, a digital personal loan is defined as a personal loan for which business operators utilize digital technology and alternative data (e.g., utility and mobile phone bill payment records) to assess the borrower’s ability and willingness to repay. The digital personal loans do not include loans for which car registration is used as collateral.

The key requirements for undertaking a digital personal loan business are as follows:

  1. Business operators are expected to use technology and alternative data to determine the customer’s risk profile, based on their ability or willingness to repay. The alternative data that is used must be from a trusted source and use a sensible hypothesis in assessing the customer’s credit profile. Such business operators may comply with the BOT’s information-based lending guidelines.
  2. Business operators must use electronic channels for both the provision and repayment of the loans. This may include disbursing and repaying by bank transfer, direct debit, or e-money to create a digital footprint in the financial sector for the customers.
  3. Business operators must disclose relevant information to customers, including interest rates, fines, service fees, operating fees, outstanding loan tables, and any other fees relating to the Digital Personal Loan. This information must also be easily accessible for customers through electronic means (for example, by being hosted and easily accessible on the loan providers website).
  4. The maximum loan amount is THB 20,000 with a tenure of not more than six months.
  5. Business operators are prohibited from charging additional interest rates, fines, service fees, operating fees, or any other fees to customers for early repayment of a loan.
  6. Business operators are required to have IT security risk management measures in place. This includes measures to protect data from unlawful collection, processing, use, and destruction. Business operators also have an obligation to business continuity management, which they must satisfy by having a business continuity plan and an IT Disaster Recovery Plan. If the business operator will outsource their IT systems or connect their IT systems to third party services in a way that will involve the transfer of sensitive data (e.g. by using a cloud computing service), the third party must also have risk management and cybersecurity processes in place to the same standards.

Personal loan license holders that wish to offer digital personal loans must submit an application and supporting documents, including information on their minimum viable product, for BOT consideration at least 30 business days prior to the date on which they plan to begin offering digital personal loans. However, this application requirement is waived if the provision of digital personal loans only uses traditional methods of assessing customers’ ability or willingness to repay their loans (such as the National Credit Bureau).

Business operators who would like to issue digital personal loans but do not currently have a personal loan license must first apply for one from the BOT in accordance with the requirements of BOT Notification SorNorSor. 12/2563 Re: Regulations, Procedures and Conditions for Undertaking Business of Personal Loan under Supervision. In practice, these business operators may apply for a personal loan license and simultaneously apply for BOT approval of their plan to issue digital personal loans.

While digital personal loans look set to become a major offering in Thai consumer banking, they are also of particular interest to non-traditional loan operators—especially e-money operators, large-scale casual employers (such as ride-share operators and delivery services), and even retailers, as has been the case with similar “quick loan” systems in other jurisdictions.

RELATED INSIGHTS​ 

November 8, 2024
On October 31, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) opened a public consultation period on its draft notifications—one directed at data controllers and another at data processors—regarding exemptions from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft notification for data controllers aims to amend and revoke certain aspects of the first ROPA exemption notification issued in June 2022 and outlines the criteria for data controllers to be exempted from the obligation to prepare and maintain such records. Although it is officially titled “Notification of the Personal Data Protection Committee on Exemption from Record-Keeping Requirements for Small Business Data Controllers,” this draft notification applies to all types of exempted data controllers (see list below), and not only small businesses. The draft notification for data processors is new and does not replace any prior notification. The criteria under both draft notifications exempt certain data controllers and data processors from the obligation to maintain ROPAs, but exempted data controllers are not free from the obligation to retain information on the rejection of data subjects’ requests to exercise certain rights under the PDPA. While these criteria remain consistent with the June 2022 ROPA exemption notification, there are a few key takeaways from the notifications, as detailed below. Types of Exempted Parties The draft notification on data controllers adds condominium and housing estate juristic persons, as well as individuals, to the list of parties eligible for an exemption, while removing internet cafes from the list. The new draft notification for data processors mirrors the corresponding list in the draft notification for data controllers. The complete list of parties eligible for ROPA exemptions under the draft notifications is as follows: SMEs according to the law on
October 8, 2024
On October 1, 2024, the Thai cabinet acknowledged the recommendations proposed by the National Anti-Corruption Commission (NACC) to prevent corruption related to online gambling. The Ministry of Digital Economy and Society (MDES) has been assigned as the lead agency to collaborate with various relevant agencies to reach a consensus on the necessary amendments and updates to laws related to online gambling. In assigning the MDES this role, the cabinet emphasized the importance of the following key items: Establishment of a national committee. The national committee will be chaired by a minister and will comprise relevant agencies, including policymaking bodies, technology agencies, frequency management agencies, law enforcement agencies, and other experts. The committee’s primary responsibility will be to consider amending and updating laws related to online gambling. Urgent action on online gambling. As online gambling has been deemed a serious issue requiring urgent action, joint policies will be developed among relevant agencies such as the Royal Thai Police, the Bank of Thailand, and the Anti-Money Laundering Office to elevate the importance of online gambling issues. Public awareness and law enforcement. Public awareness campaigns are to be conducted to educate the public about the risks and legal consequences of online gambling, and laws against online gambling and related financial crimes are to be strictly enforced. Compliance with the Cybersecurity Act. It is necessary to ensure strict compliance with the Cybersecurity Act B.E. 2562 (2019). At the same time, government data systems are to be moved to cloud computing for enhanced data security. Next Steps The MDES is tasked with summarizing the results of the related discussions, actions taken, and overall opinions and submitting the summary to the cabinet secretariat for further presentation to the cabinet. These measures aim to address and mitigate the risks associated with online gambling and related corruption.
October 8, 2024
Thailand’s Electronic Transactions Development Agency (ETDA) issued guidelines for managing advertisements on digital platform services (DPSs) earlier this year. These guidelines aim to prevent fraud, illegal product or service offerings, and inducements to commit illegal acts, and are likely to provide a basis for greater regulation of this issue in the future. Key obligations for DPS business operators under the guidelines are detailed below. Advertiser Screening and Data Collection Verification and collection: Business operators must establish processes for verifying and collecting advertiser data. This includes steps, methods, and required information for advertiser registration. Identity verification: Business operators should follow identity verification requirements for advertiser registration. This may include using identity verification results from other identity providers or conducting their own identity verification processes with a minimum identity assurance level (IAL) of IAL2. Data storage: Advertiser data must be stored in a machine-readable format. Business operators must maintain records for watchlists, blacklists, and whitelists. Prepublication Advertisement Review Review process: Business operators should review advertisements before publication. This review should consider factors such as prohibited or restricted advertisements, required permissions, and avoiding sensitive user data. Postpublication Monitoring Advertisement monitoring: Business operators must monitor published advertisements using automated systems, staff, or contracted personnel. Criteria for prioritizing reviews should be established. Reporting channels: Business operators must provide channels for users to report illegal or inappropriate advertisements. Reports must be promptly addressed, prioritizing cases involving intellectual property owners or multiple credible reports. Advertiser account monitoring: Business operators must monitor advertiser accounts. This includes considering factors such as the number of reports/flags received and compliance with service agreements and community standards. For more information on this initiative from the ETDA, or on any aspect related to Thailand’s regulations for DPSs, please contact Athistha (Nop) Chitranukroh at [email protected], Thammapas Chanpanich at [email protected], Pornpan Wichawut at [email protected],
October 2, 2024
The first draft of Vietnam’s new Personal Data Protection Law (“Draft PDPL”) was released for public consultation on September 24, 2024, and is open for comments until November 24, 2024. (See further details here.) It is expected that the draft will be presented to the National Assembly before the end of 2024 and will be submitted for adoption in May 2025, with a tentative entry into force on January 1, 2026. As the Draft PDPL incorporates most of the provisions of Decree No. 13/2023/ND-CP on Personal Data Protection (“PDPD”), which has been the primary legal instrument on personal data protection since it took effect on July 1, 2023, it is likely that it will supersede the PDPD when it takes effect. [Please contact our Vietnam data protection team to request a detailed comparison of the Draft PDPL to the PDPD.] Noting that there might be further changes to the draft once the public consultation period closes, the Draft PDPL proposes new specific requirements for a number of services. Some highlights of the current version include the following: Marketing services: Although marketing services are already regulated under the PDPD, the Draft PDPL now recognizes that the use of personal data for marketing must comply with anti-spam regulations. The current draft does not clarify whether organizations are exempted from the consent requirement for the purpose of the initial call or message under the anti-spam regime. Marketing service providers are not allowed to outsource the services to another organization to perform or support the implementation of marketing business, which may prevent the sharing of personal data. Behavioral advertising: Behavioral advertising (targeted personalized advertising based on a user’s activity or personal data) requires the consent of the data subject in a modifiable manner that allows the data subject to refuse to share data