You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 20, 2015

Challenges of Protecting Intellectual Property in the Software Industry

Bangkok Post, Corporate Counsellor Column

In the fast-evolving and highly competitive technology industry, software developers and owners should exercise strong vigilance to ensure that their creations are properly guarded within the ambit of intellectual property rights. Protecting software, however, involves complex, interrelated issues that encompass a mix of copyright, patent, trademark, and trade secrets law.

In this article, we will examine what people in the software industry should know to adequately protect their creations and operate their business with fewer hitches.

Software as a Copyrighted Literary Work

Copyright protection applies to computer source code and is not limited to any particular language. The protection is automatic—i.e. no registration is required—but owners can still record their software as a copyrighted work with the Department of Intellectual Property to better prove ownership, should the need arise. The process, known as recordation, is free and uncomplicated.

Newly developed source code can be filed for recordation at any time. Important documents required include a copy of the first five pages and the last five pages of the source code, or a CD containing the relevant software.

Functions and Features of Software

Copyright law does not protect ideas about functions and features of software, nor does it protect functional user interfaces. For this reason, rival companies can develop the same kind of software and will not be considered to have committed copyright infringement, so long as the software has its own source code.

Ideas about software functions and features may, however, be protected under patent law. Currently, software is not patentable in Thailand, but in some countries, including the United States, it is. Thailand may be moving in this direction, as certain hardware or devices programmed with functions that are novel and involve an inventive step would be deemed patentable under Thai law, but these are considered on a case-by-case basis.

Source Code

Normally, after software has been commercially distributed, the source code is kept confidential and is only disclosed in necessary cases. If the source code is kept under appropriate security measures, it may be protectable under trade secret law, which imposes serious penalties on those who intentionally disclose, deprive, or use another party’s trade secrets without that party’s consent.

Copyright Ownership

The copyright of software developed by an employee under an employment contract is owned by the employee, unless agreed otherwise in writing. By contrast, the copyright of software developed under a specially commissioned contract will belong to the commissioning party. However, developers for other parties and their commissioners may agree that the copyright shall be owned by the developers.

License Agreements

If a customer requires a software developer to deliver source code, the parties should make it clear whether the customer wants to own the source code or merely customize or update the software in the future. This is because a software sale agreement or an agreement to assign copyright to the source code is significantly different from a license agreement.

If the parties agree to a software license agreement, under which the source code is required to be disclosed for the purposes of customizing or updating the software, the developer may include a provision under which the customer is obligated to keep the source code confidential.

Software license agreements do not bar copyright owners from granting licenses to other parties. As copyright is alienable, licensable, and divisible, many types of software license agreements exist, for example:

  • Exclusive Licenses: Only the licensee has the right to make use of the software. The licensor is not allowed to make use of it, nor grant any additional licenses.
  • Sole Licenses: Only the licensee is allowed to make use of the software. The licensor agrees to not grant any additional licenses, but retains the right to make use of the software.
  • Nonexclusive Licenses: The copyright owner may grant licenses to several users simultaneously and the licensor can also make use of the software. General software programs and mobile applications are normally licensed non-exclusively.

Copyright can be licensed to multiple users, unless expressly prohibited, such as under exclusive or sole license agreements. If the licensee does not want the copyright owner to grant licenses to other parties, the copyright license agreement must include a clause to this effect.

Registering Software Brands or Logos as Trademarks

Developers should create a brand name or trademark, for the purpose of internal reference, as well as for copyright recordation and licensing. Words or devices used as trademarks must not directly describe the nature or characteristics of the goods or services—otherwise, the trademark will not be registrable. Words or devices used as trademarks should be distinctive and must not be identical or similar to other parties’ registered trademarks.

Granting a software copyright license to a foreign company does not require registration. Many software products, however, bear widely known trademarks. Therefore, in addition to a software copyright license, a copyright owner may have to grant a trademark license to its customer—such as a distributor appointed in a foreign country. In such a case, the trademark should also be registered in that foreign country.

Products and services relating to software change rapidly, and sometimes existing protection may not completely cover all aspects of a new, innovative piece of software. Therefore, developers, government bodies and lawyers should regularly exchange ideas and opinions and keep themselves up-to-date to be able to deal with new problems effectively.

RELATED INSIGHTS​ 

February 26, 2026
Thailand is preparing to offer new tools for intellectual property enforcement as the Electronic Transactions Development Agency (ETDA) recently released for public consultation a draft notification requiring social media platforms to verify user identities and conduct know-your-customer (KYC) checks on advertisers. The draft Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers, which is to be issued under the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023), as amended in 2025, primarily aims to combat online fraud and technology-related crimes. However, its new obligations also provide IP owners with valuable tools to identify anonymous infringers. Key Regulatory Mandates The draft notification imposes several verification requirements on social media platforms operating in Thailand. These requirements also strengthen IP rights holders’ ability to identify anonymous infringers, as platforms must: Verify user identities through registered phone numbers and link all accounts to verifiable identities. Conduct KYC checks on advertisers, including individuals, companies, and any third-party payers. Perform heightened identity checks for high-risk or repeat offenders before publishing advertisements. Promptly remove content flagged by the Anti-Technology Crime Division and prescreen advertisements for prohibited or high-risk content. How IP Owners Can Use This Notification for Enforcement The phone number–based verification requirement enables IP owners to work more effectively with enforcement authorities in tracing individuals or entities responsible for infringing content. The comprehensive advertiser KYC obligations, including mandatory disclosure of third-party payment sources, create a clear audit trail even when bad actors attempt to obscure their identity through intermediaries or shell accounts. This traceability is essential for pursuing damages and dismantling organized counterfeit operations. The ETDA is now considering adjustments to the draft notification after receiving comments during the public consultation period, which ended on February 2, 2026. Following finalization
February 23, 2026
On February 17, 2026, Thailand’s Personal Data Protection Committee (PDPC) released its draft Guidelines on Personal Data Protection in the Development and Use of Artificial Intelligence. The draft guidelines, which translate data controller and data processor compliance obligations under the Personal Data Protection Act (PDPA) into measures tailored to AI development and deployment, are open for public comment until February 25, 2026. At a public hearing session on the draft guidelines held on February 19, the PDPC emphasized that its approach to AI is not to hinder innovation but to develop practical guidance supporting safe deployment while ensuring data protection. Although the guidelines are not legally binding, they indicate the regulator’s expectations and the likely direction of interpretation and enforcement. Scope of Application and Role of Stakeholders The guidelines will apply to all data controllers and data processors in Thailand, and to overseas data controllers and data processors whose data processing falls within the extraterritorial scope of the PDPA. The draft guidelines distinguish the roles of parties involved in AI deployment. Users of AI who determine the purpose of use and designate the input data, and retain outputs generated by the AI, are considered data controllers. In contrast, AI model providers or system integrators that process personal data under the instructions of the data controller are generally regarded as data processors. However, if an AI model provider utilizes user data for its own purposes, such as model fine-tuning or training, it may instead be classified as a data controller. Key Obligations for AI Data Collection and Use The basic principles of data processing under the PDPA must be maintained throughout the AI implementation lifecycle, from design to decommissioning, emphasizing accountability and privacy-by-design principles. The draft guidelines also stipulate the following: Data processing agreements (DPAs) should include model training prohibitions,
February 10, 2026
Data center and cloud investments are forming a major focus of private-sector investment in Thailand, with tech giants like Amazon, Google, Microsoft, and TikTok, as well as numerous telecom and data center companies, committing significant outlays to data center and cloud development. The country’s Board of Investment (BOI) approved projects worth THB 1.87 trillion in 2025, and THB 746 billion of this was from planned data center investments—by far the largest amount from any single industry. Thailand’s swift rise as a regional data center hub is fueled by surging demand for cloud, AI, and digital services, as well as large-scale investments from global tech firms. The country’s strategic location, competitive power costs, robust fiber infrastructure, expanding IT talent, and supportive government policies—including BOI incentives and streamlined approvals—have made it an attractive destination for scalable and sustainable digital infrastructure investments. The BOI’s proactive approach in updating promoted categories and providing both tax and non-tax incentives further ensures Thailand’s continued growth in this sector. 2025 BOI Changes for Data Centers In the middle of 2025, the BOI responded to the remarkable trend by updating investment‑promotion categories across various sectors (e.g., machinery and electrical equipment, public utilities, digital and innovative industries) to accommodate growing investment in data‑center projects. Before the change, which was detailed in a notification that has applied to investment promotion applications submitted from July 1, 2025, onward, data‑center projects under BOI promotion were granted a single A1 incentive (an eight‑year corporate income‑tax exemption) and subject to one uniform set of conditions. The July 2025 notification restructured promotion for data centers into two categories based on power‑usage efficiency: high‑efficiency data centers and other data centers. Under these rules, qualified high‑efficiency data centers are eligible for an eight‑year corporate income tax (CIT) exemption, while for other data centers this exemption is
February 4, 2026
On November 18, 2025, Vietnam’s Ministry of Finance released for public consultation a draft decree on administrative sanctions in the field of crypto assets and crypto asset markets (the “Draft Decree”), intended to implement Resolution No. 05/2025/NQ-CP dated September 9, 2025, on the pilot crypto asset market in Vietnam (“Resolution 05”). While Resolution 05 sets out who may participate and under what conditions, the Draft Decree addresses a more practical question for market participants, i.e., what happens if those conditions are not met. In doing so, the Draft Decree offers important insight into how Vietnamese regulators intend to supervise, discipline, and ultimately shape the crypto market during the pilot phase. Regulatory Scope and Overall Sanctions Architecture The Draft Decree applies to both domestic and foreign organizations and individuals engaging in crypto-related activities in Vietnam’s market. Covered entities include: (i) crypto asset issuers; (ii) crypto asset service providers, including trading platforms and market operators; (iii) Vietnamese and foreign investors participating in the pilot market; and (iv) other organizations involved in the offering, issuance, or provision of crypto-related services in Vietnam. The breadth of this scope is deliberate. It appears to reflect a regulatory view that cross-border structures, offshore platforms, and indirect participation may not necessarily insulate market actors from compliance obligations once they operate within the pilot framework. For the crypto industry, this may mark a shift from regulatory ambiguity toward a more explicit articulation of jurisdictional reach. At first glance, the Draft Decree’s monetary penalties appear restrained. The maximum fine per administrative violation is capped at VND 200 million (approx. USD 7,700) for organizations and VND 100 million (approx. USD 3,800) for individuals. However, focusing solely on fine levels risks missing the point. The Draft Decree also places great regulatory weight on supplementary sanctions and corrective measures, including: (i)