You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 3, 2026

Bank of Thailand Proposes New Digital Channel Security Standards

On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026.

Background

The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements.

Expanded Scope of Regulated Entities and Channels

The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking.

Strengthened Customer Authentication

The draft introduces enhanced authentication requirements in three areas:

  • Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits.
  • Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases.
  • Secure authentication factors. Key requirements include the following:
    • “What-you-know” factors must protect against brute-force attacks.
    • “What-you-have” factors must use secure methods such as a registered mobile application with device binding or hard/soft tokens.
    • SMS OTPs must be discontinued for transaction authentication.
    • Biometric factors must use effective antispoofing technology, such as facial scanning, in compliance with the BOT’s guidelines on biometric technology in financial services.

Providers must cease sending SMS messages and emails containing embedded links and must establish incident response processes for counterfeit applications or websites.

Mobile Application Security Controls

Providers must ensure application integrity and block remote-access applications. Facial comparison with antispoofing technology is required for transfers exceeding THB 50,000 (approx. USD 1,490) per transaction or THB 200,000 (approx. USD 5,960) per day.

Next Steps

Affected financial service providers should assess their current systems against the draft requirements and consider submitting comments to the BOT by August 24, 2026.

RELATED INSIGHTS​ 

November 7, 2023
Under Thailand’s Royal Decree on Digital Platform Services, domestic and in-scope overseas digital platform operators that are required to notify the Electronic Transactions Development Agency (ETDA) of their operations must do so by November 18, 2023 (or by August 20, 2024, for small or low-impact platforms). This step is one of the essential requirements of the royal decree. Other key information on complying with the royal decree is as follows: The royal decree aims to regulate the operation of “digital platform services,” which refers to the provision of electronic intermediary services that create a connection between consumers, merchants or businesses, or other types of users in order to create an electronic transaction in whole or in part, regardless of whether a service fee is charged. The regulated digital platform services do not include digital platform services intended for offering the goods or services of a single digital platform service operator or an affiliated company that is an agent of the operator, irrespective of whether the goods or services are offered to third persons or to affiliated companies. The royal decree has extraterritorial effect, whereby overseas operators targeting the Thailand market are subject to the royal decree if their services are accessible in Thailand. Overseas operators are required to appoint a local coordinator in Thailand to coordinate with the ETDA. Compliance and Enforcement The ETDA released nine subordinate regulations under the royal decree; these took effect on August 21, 2023 (except for rules on platforms’ terms and conditions, which will take effect on January 3, 2024). Some important points on compliance and enforcement in the subordinate regulations, along with procedural guidance, are listed below. The ETDA has been emphasizing that both domestic and overseas digital platform operators need to notify the ETDA of their operations within the specified timeline (i.e.,
October 25, 2023
One significant development in the health sector in Indonesia is the use of information technology and communication in the implementation of health efforts—particularly digital health services such as telehealth and telemedicine integrated into the country’s National Health Information System. This development was addressed in a major new piece of legislation for the healthcare sector in Indonesia. Enacted in August 2023, Law No. 17 of 2023 concerning Health (the “Health Law”) provides the updates needed to support the development of healthcare services in Indonesia. Under the Health Law, health information system (HIS) providers must: Carry out processing of data and health information in the territory of Indonesia, except for certain limited and specific processing activities that may be conducted outside Indonesia when permitted by the relevant authorities and in compliance with relevant regulations. Ensure the reliability of its HIS, including availability, security, maintenance, and integration with Indonesia’s National Health Information System. Provide quality health data and information. Process data and health information, which includes planning, collection, storage, inspection, transfer, utilization, and destruction. Record its data- and information-processing history. Protect every person’s data and health information. Obtain approval from the relevant personal data subject or comply with relevant regulations if the processing of data and health information involves an individual’s health data. Inform the data owner if there is a failure to protect data and individual health information. The Health Law’s personal data protection requirements listed above appear to be aligned with the provisions in Law No. 27 of 2022 concerning Personal Data Protection (the “PDP Law”). Under this law, data and information relating to health are identified as “specific personal data,” the processing of which carries a high potential risk of impacting the relevant personal data subject. In the implementation of digital health services, patients’ personal data or medical records
October 25, 2023
Thailand has released a notification adding new consumer protection provisions related to the collection of prepaid telecom service fees and combining several disparate regulations and resolutions. The Notification on the Criteria Relating to the Collection of Prepaid Telecommunications Service Fees was issued on September 4, 2023, and came into effect on September 21, 2023. The notification will be enforced as a general regulation and guideline for all telecom services other than fixed broadband services, which already fall under a comparable regulation.   Previously, Thailand’s National Broadcasting and Telecommunications Commission (NBTC) had issued several regulations to regulate the collection of prepaid telecom service fees. These include the NBTC Notification on Contract Standards, the NBTC Notification on the Maximum Service Fee Rate and Collection of Prepaid Telecommunications Service Fees, and the NBTC Notification on the Criteria Relating to the Collection of Prepaid Fixed High-Speed Broadband Service Fees. These are now subsumed by the new notification. Key requirements of the new notification on prepaid telecom fee collection are described below. Collection Approval Requirement Before collecting prepaid telecom service fees, service providers (SPs) must apply to the NBTC for approval by submitting the required forms and supporting documents. Changes to the criteria and methods of prepaid telecom service fee collection must also be reapproved. This provision aims to protect against fraud and money-laundering transactions. The NBTC will consider whether to approve an SP’s proposal for the maximum period to be covered by the prepaid service fees on a case-by-case basis. After the collection criteria and methods are approved by the NBTC, SPs must inform their users individually. SPs must also report to the NBTC by the 15th of every month after receiving the NBTC’s approval to collect prepaid service fees. Approvals of prepaid service fee collection granted by the NBTC prior to the
October 17, 2023
On June 20, 2023, Vietnam’s new Law on Protection of Consumers’ Rights (“CPL 2023”) was officially promulgated, followed two days later by a new Law on E-Transactions (“LOET 2023”). The new laws, which will both take effect from July 1, 2024, replacing the CPL 2010 and the LOET 2005, respectively, provide new regulations for e-commerce platforms and will impact e-commerce activities in Vietnam. Some of the more significant changes are outlined below. Law on Protection of Consumers’ Rights Regulation of offshore entities: Previously, the CPL 2010 regulated only organizations and individuals in the territory of Vietnam. Under the CPL 2023, both onshore and offshore agencies, organizations, and individuals related to protecting consumers’ rights are regulated. In other words, Vietnam intends to monitor and manage activities of platforms with no legal presence in Vietnam. Remote transactions: Previously, the laws on consumer protection regulated “remote contracts.” The CPL 2023 introduces and defines “remote transactions” as transactions made online, by electronic means or by other means wherein consumers cannot check or have direct contact with products, goods or services before participating in the transaction. In addition, the CPL 2023 also provides for additional responsibilities of business entities offering remote transactions such as adequately and precisely providing consumers with information when entering into these remote transactions, including the rights of consumers in case of incomplete or inaccurate provision of information and complaint handling mechanisms. Online businesses: The CPL 2023 introduces “online businesses,” which are defined as (i) those trading products, goods, and services via their self-established platforms or digital platforms or (ii) those establishing or operating intermediary digital platforms. According to the Vietnam Competition Commission in a recent workshop, the definitions of “digital platforms” and “intermediary digital platforms” can be referred to in the LOET 2023 (see below). Under this new category, online