You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 3, 2026

Bank of Thailand Proposes New Digital Channel Security Standards

On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026.

Background

The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements.

Expanded Scope of Regulated Entities and Channels

The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking.

Strengthened Customer Authentication

The draft introduces enhanced authentication requirements in three areas:

  • Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits.
  • Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases.
  • Secure authentication factors. Key requirements include the following:
    • “What-you-know” factors must protect against brute-force attacks.
    • “What-you-have” factors must use secure methods such as a registered mobile application with device binding or hard/soft tokens.
    • SMS OTPs must be discontinued for transaction authentication.
    • Biometric factors must use effective antispoofing technology, such as facial scanning, in compliance with the BOT’s guidelines on biometric technology in financial services.

Providers must cease sending SMS messages and emails containing embedded links and must establish incident response processes for counterfeit applications or websites.

Mobile Application Security Controls

Providers must ensure application integrity and block remote-access applications. Facial comparison with antispoofing technology is required for transfers exceeding THB 50,000 (approx. USD 1,490) per transaction or THB 200,000 (approx. USD 5,960) per day.

Next Steps

Affected financial service providers should assess their current systems against the draft requirements and consider submitting comments to the BOT by August 24, 2026.

RELATED INSIGHTS​ 

November 27, 2023
Thailand’s Electronic Transaction Development Agency (ETDA) has released two new subordinate regulations under the Royal Decree on Digital Platform Services: one detailing the assessment of digital platform services (DPSs) that will be deemed “high-risk” and subject to additional obligations, and another setting guidelines on user verification and authentication for all DPSs. The two subordinate regulations are summarized below. Impact Assessment of DPS Operations Under the Royal Decree on Digital Platform Services, DPS operations that have the risk of seriously impacting financial and commercial security, reliability and credibility of data message systems, or the general public are subject to additional obligations. The first subordinate regulation mentioned above (officially titled Notification of the Electronic Transactions Commission Re: Criteria for Impact Assessment on Operation of Digital Platform Services) outlines the criteria for the ETDA to determine which DPSs are “high-risk.” DPSs falling under this designation include: DPSs whose total value of transactions conducted through the platform in Thailand exceeds THB 100 million (approx. USD 2.8 million) per year; DPSs whose operators have not registered their entities with the Department of Business Development (DBD)—notably overseas operators—and that have 100 or more merchants or business users in Thailand or total users in Thailand between 5 and 10 percent of the country’s population (i.e., approx. 3.3–6.1 million users, calculated using official 2022 figures); DPSs that allow their users to freely post certain messages, or do certain acts, that may affect the public in certain cases, such as: (1) unlawful messages or acts; (2) messages or acts that may affect a child’s rights or people’s fundamental rights; and (3) messages or acts that may negatively affect political opinions of Thai citizens (whether before or after an election) or statements or actions likely to negatively affect other individuals due to gender differences or sexual violence. After considering
November 23, 2023
On November 14, 2023, Thailand’s Personal Data Protection Committee (PDPC) published a draft notification on collection of personal data regarding criminal records. The draft notification aims to provide clarifications and prescribe further criteria for processing criminal record data under the Personal Data Protection Act (PDPA), which generally requires the processing of criminal records to be carried out under the control of the relevant official authority under the law or under a data protection measure implemented according to rules prescribed by the PDPC. After its eventual passage, the draft notification will have important implications for businesses’ recruitment and human resources activities in relation to individuals with criminal records. Key aspects of the draft notification include the following: “Personal data regarding a criminal record” and “criminal record data” denote personal data related to the investigations of criminal offenses, criminal prosecution, or criminal punishment that is official information or certified by the relevant supervisory authority, regardless of whether that action is connected to a final judgment. Under the draft notification, data controllers may process criminal record data for the purpose of a recruitment process, checking the qualifications of personnel, and considering the suitability of a person for a position if the processing activities are required by law or when a data controller obtains explicit consent from the data subject. Furthermore, the necessity of processing the criminal record data must be announced at the beginning of the recruitment process. Data controllers’ requests for explicit consent to collect a data subject’s criminal record data must also notify the data subject of the consequences of not providing consent or withdrawing consent. The draft notification sets the allowable retention period for criminal record data at a maximum of six months from the end of the processing activities specified above. After the retention period ends, the criminal
November 17, 2023
On October 3, 2023, Thailand’s Board of Investment (BOI) issued a new regulation clarifying the eligibility criteria for investment promotion under the BOI category “5.10 Development of software, platforms for digital services, or digital content.” To be eligible for BOI promotion under the digital activity category, projects must meet criteria related to local development, minimum investment amount, machinery and equipment, and development processes. These criteria for category 5.10 activities, along with the latest clarifications from the BOI, are detailed in the table below. Tax Incentives The BOI also clarified the method for calculating corporate income tax (CIT) exemptions. The CIT cap amount is calculated on an annual basis from the prescribed expenses incurred after applying for BOI promotion and occurring during the year for which the CIT exemption is claimed. The allowances include 100% of expenses for salaries for newly hired Thai IT personnel, technology-related training, and obtaining quality standards (such as ISO 29110). The revenue of projects that qualify for CIT exemption must be from sales or services directly related to software, platforms for digital services, or digital content developed as promoted by the BOI, including licensing fees, subscription fees, pay-per-use expenses, in-app purchase fees, usage fees, revenue sharing, advertising fees, and so on. For more details on BOI promotion for digital activities, or on any aspect of investment promotion in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected] or +66 2056 5600, Napassorn Lertussavavivat at [email protected] or +66 2056 5662, or Thammapas Chanpanich at [email protected] or +66 2056 5561.
November 15, 2023
Four decisions from the Expert Committee under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) indicate that there will no longer be any relaxation of PDPA enforcement. The enforcement of Thailand’s seminal data protection law had been relaxed for more than a year when, on October 18, 2023, the Personal Data Protection Committee (PDPC) published the first decision made by the Expert Committee on the imposition of administrative measures against a company pursuant to authority granted to it under the Notification of the PDPC Re: Rules for the Consideration of the Imposition of Administrative Penalties by the Expert Committee B.E. 2565 (2022), which was one of the first subordinate regulations issued under the PDPA. Shortly thereafter, on October 19, October 25, and November 15, three additional Expert Committee decisions were published. These three decisions made by the Expert Committee are summarized below. October 18 Decision The complainant in this case lodged a complaint with the Expert Committee alleging that an insurance company contacted him to offer the company’s products without his consent. The complaint further claimed that when the complainant requested the company to disclose how his personal data had been acquired and asked the company to stop contacting him through any channel, the company did not take any action on the requests. The insurance company appeared to have obtained the personal data of the complainant from another source prior to the PDPA becoming fully effective (i.e., June 1, 2022). As the Expert Committee explained in its order, the company failed to comply with its obligations under the PDPA regarding the collection of personal data from another source, which requires consent as a legal basis; failed to comply with the grandfather provision by not publicizing opt-out procedures to enable the data subject to withdraw his consent easily; and