You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 15, 2019

Bank of Thailand Issues First Peer-to-Peer Lending Regulations

On April 29, 2019, the Bank of Thailand issued Notification 4/2562 Re: The Determination of Rules, Procedures, and Conditions for Peer-to-Peer (P2P) Lending Businesses and Platforms. The notification took effect the following day. 

The notification lays out a number of guidelines for P2P platform providers and P2P lenders. A P2P platform provider is defined as a person who provides an electronic system or network for P2P lending, while a lender is a natural person or juristic person who offers a loan through an electronic system or network (excluding crowdfunding providers). Key provisions are summarized below. 

P2P Platform Provider

A P2P platform provider must:

  • not be a financial institution (including banks, although subsidiaries of banks are permitted);
  • be a private company or public company incorporated in Thailand;
  • have paid-in capital of at least THB 5 million; and
  • have at least 75% of its total shares held by Thai citizens.

Directors of a platform provider must not have been involved in, or accused of, fraud or corruption; must not demonstrate a lack of qualifications or professional standards; and must be financially sound.

Custodians

  • A qualified custodian is required, as platform providers are prohibited from holding the money, property, and securities of lenders and borrowers themselves.
  • Custodians must either be authorized custodians under SEC regulations or authorized commercial banks (for escrow accounts) under BOT regulations.

Borrowers

Under this notification, borrowers must be natural persons who:

  • have the capability to incur debts;
  • are not P2P platform providers;
  • are not directors, authorized persons, or major shareholders of the provider; and,
  • have not already obtained personal loans from three lenders.

The notification also prescribes credit limits for loans. Loans for consumer purposes are limited based on the borrowers’ average monthly income as follows.

  • For borrowers whose average monthly income is below THB 30,000, the credit limit must not exceed 1.5 times their average monthly income.
  • For borrowers whose average monthly income is THB 30,000 or more, the credit limit must not exceed 5 times their average monthly income.

Borrowers can obtain loans for business purposes up to a maximum of THB 50 million.

Lenders

Unlike borrowers, lenders (who must not also be P2P platform providers) can be either natural or juristic persons. They must conduct client suitability assessments before providing loans to ensure adequate knowledge and understanding of each loan and the associated risks.

The notification also prescribes credit limits for providing loans as follows.

  • There is no limit for loans provided by institutional investors, private equity trusts, or venture capital businesses under the Securities and Exchanges Act.
  • All other lenders can provide loans that do not exceed THB 500,000 in a period of 12 months.

Interest

The interest rate for loans offered through a P2P lending platform must not exceed 15% per year, in accordance with the Civil and Commercial Code of Thailand. 

For more information on the notification, or on any aspect of the P2P lending business in Thailand, please contact our Bangkok office at [email protected] or +66 2056 5555.

RELATED INSIGHTS​ 

January 8, 2026
Thailand has enacted comprehensive sexual harassment legislation that significantly expands criminal penalties and creates new compliance obligations for online platform operators. The Act Amending the Penal Code (No. 30) B.E. 2568 (2025), enacted on December 29, 2025, and taking effect the following day, introduces a comprehensive definition of sexual harassment, establishes new criminal offenses with graduated penalties, and imposes content removal obligations on social media platforms and computer system service providers. The amendment, which establishes a comprehensive framework for addressing sexual harassment in both physical and digital environments, significantly expands legal exposure for online service operators. It also grants courts authority to order takedowns of violating data accessible to the public. Definition of Sexual Harassment The law introduces “sexual harassment” as a distinct statutory concept covering physical conduct, verbal conduct, sounds, gestures, expressions, postures, communications, surveillance, stalking, and acts committed through computer systems or electronic devices. Conduct qualifies as sexual harassment when it is sexual in nature and likely to cause the victim distress, annoyance, embarrassment, humiliation, fear, or a sense of sexual insecurity. Criminal Offenses and Penalties The amended Penal Code establishes graduated penalties based on the severity and context of the harassment—including enhanced penalties for public or online conduct. For instance: Basic sexual harassment is punishable by imprisonment for up to one year, a fine of up to THB 20,000, or both. Continuous or repeated harassment that prevents normal life escalates penalties to imprisonment for up to two years, a fine of up to THB 40,000, or both. Critically for online operators, harassment committed in public places, in the presence of the public, or through computer systems accessible to the general public triggers imprisonment for up to three years, a fine of up to THB 60,000, or both. Acts of harassment committed by supervisors, employers, or others
January 6, 2026
On December 30, 2025, Thailand’s Electronic Transactions Development Agency (ETDA) notified digital marketplace operators of a consolidated list of “high‑risk products” that are subject to strict monitoring on digital platforms. The list was jointly prepared by the Thai Industrial Standards Institute (TISI) and the Food and Drug Administration (FDA) to guide platform compliance in the initial phase of implementation of the Electronic Transaction Committee’s Notification on Other Measures for Marketplace for Goods with Specific Characteristics under Section 18(2) of the 2022 Royal Decree on Digital Platform Businesses Requiring Notification B.E.2568 (2025). The notice is addressed to operators of digital platform services that function as product marketplaces with specific characteristics laid out in the notification. The ETDA states that the TISI and the FDA are closely monitoring the high‑risk product categories on digital platforms, and the published list serves as the baseline reference for platform screening during the initial phase of the notification’s implementation. High‑Risk Product List The list aggregates categories of products that are illegal to sell online or are otherwise tightly regulated under Thai law, with an emphasis on health-related products, controlled substances, medical devices, and a wide range of industrial products that require certification or compliance with specified Thai Industrial Standards, as detailed below. Prohibited and tightly controlled health products. This includes all categories of modern medicines subject to control other than general household remedies; all categories of controlled herbal products except for over-the-counter herbal products; narcotics; psychotropic substances; and medical devices requiring use in medical facilities or a physician’s prescription. Selected industrial products requiring heightened controls. The list highlights dozens of TISI-regulated items commonly sold online. Examples include pacifiers, rice cookers, electrical wire, food wrap film, crayons, washing machines and dryers, air conditioners, electric cookers and air fryers, water heaters, microwave ovens, LED luminaires, hair dryers
January 5, 2026
On December 31, 2025, the government of Vietnam promulgated Decree No. 356/2025/ND-CP detailing and guiding the implementation of the new Personal Data Protection Law (PDPL) that was issued in June 2025. The new decree, like the PDPL, entered into force on January 1, 2026, with the previous Decree No. 13/2023/ND-CP on personal data protection ceasing effect on the same day. Some key points of the new decree include the following: Comprehensive lists of basic and sensitive personal data are provided, which will require companies to review again their existing documents and data type classification to ensure compliance. New timelines are established for responding to specific data subject requests. These timelines are more reasonable and longer than the previous 72-hour requirements. Additional consent guidelines are provided, prohibiting default consent or ambiguous instructions that confuse data subjects about giving or withholding consent. Mandatory content for data transfer agreements/clauses in particular cases is provided. This covers, among other things, (i) the legal basis for the transfer of personal data; (ii) responsibilities for personal data protection during the transfer and processing of personal data; (iii) responsibilities for ensuring the exercise of the rights of personal data subjects; and (iv) responsibilities for coordination and compliance of the parties in cases where violations of personal data protection regulations are detected. The qualifications and responsibilities of data protection officers (DPOs) and data protection departments include, among others, having been trained and fostered in legal knowledge and professional skills regarding personal data protection. There are no specific provisions governing the qualifications or requirements for organizations that provide data protection training or education. New mandatory templates and requirements are provided in relation to data processing impact assessment and data transfer impact assessment, and for cases in which companies need to re-submit assessments to the regulator. Stricter requirements are
December 30, 2025
On December 17, 2025, Laos’ Ministry of Industry and Commerce (MOIC) issued a notice introducing a new digital system that allows e-commerce businesses to obtain required certificates and licenses through an online, application-based platform. Notice No. 3988, which will take effect on February 1, 2026, introduces the E-Trust platform, a downloadable application that allows e-commerce businesses to remotely obtain acknowledgement certificates and business operating licenses. New Digital Registration Options Under the previous framework established by the Decree on E-commerce (2021), businesses were required to complete registration exclusively through paper-based submissions. The new system now offers businesses two registration options: Traditional paper-based process at the Division of E-commerce Management within the MOIC; or Electronic registration and renewal through the E-Trust platform. This change is expected to streamline procedures, reduce administrative burdens, and enhance accessibility for businesses operating outside Vientiane. The E-Trust platform facilitates compliance for both individuals and legal entities required to submit applications and renewals for required certificates and licenses. The development is particularly beneficial for businesses located in remote provinces, as it eliminates the need for physical travel and significantly accelerates processing times. Compliance Requirements and Penalties Businesses must obtain or renew the required certificates and licenses to avoid sanctions under the Decision on Fines and Other Measures for Violation of the Decree and Regulations on E-commerce (No. 2828/MOIC, dated November 11, 2025). Penalties for noncompliance may include monetary fines and other enforcement measures.