You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 26, 2011

Clouds Looming Over New Computer Crimes Act

Bangkok Post, Corporate Counsellor Column

The proposed new Computer Crimes Act, which will supersede the 2007 Computer Crimes Act, has been introduced in an attempt to fill loopholes in the current legislation.

The new draft is aimed at those who perpetrate offenses and who have previously evaded liability. But there are concerns over whether the new law would be overly zealous in handing out harsh punishment to all offending parties, regardless of the severity of the crime involved.

Although the draft Act has similarities to the current Computer Crimes Act, there are new key sections that have been introduced, including definitions for “system administrator” and “Board” under Section 4. There have also been important additions to Sections 16 and 25 of the law, which detail offenses relating to any person who is found to be copying another person’s computer data and the penalties for possessing child pornography.

Section 16 of the draft has caused particular concern among the media, service providers, webmasters, companies, and even students, university professors, and other users because it stipulates that “copying” another person’s computer data will now be deemed a criminal offense.

This article analyzes Section 16 and highlights the possible repercussions of the proposed additions.

Section 16 of the draft provides that “any person who copies another person’s computer data illegally, in a manner that is likely to cause damage to such other person, shall be punished with imprisonment of not more than three years, or a fine not more than 50,000 baht, or both”.

The definition of “computer data” refers to data, statements, or sets of instructions (including electronic data) that are contained in a computer system, the output of which may be processed by a computer system, according to the Law of Electronic Transactions.

But the draft does not provide a definition for “copying”. As a result, “copying” could be interpreted to mean copying data, materials, or downloading a file from the internet, regardless of whether such material is copyrighted. Even accessing the internet and having temporary storage caches in a computer without consent could be deemed an offense. Such copying offenses will carry a maximum penalty of three years’ imprisonment.

The provision of Section 16 in regard to “illegally copying another person’s computer data, in a manner that is likely to cause damage to another person” is relatively broad in terms of its interpretation of the scope of an act that is “likely to cause damage”.

Copying or downloading text materials or images from the internet would seem to be a common everyday occurrence. Under the Thai Copyright Act, if materials or images are copyrighted, any copying or downloading of such materials or images from the internet will be regarded as reproduction, which requires permission from the copyright owner. Otherwise, it will be regarded as an infringement of the exclusive rights of the copyright owner.

But the Thai Copyright Act acknowledges certain exceptions, including the fair use exception for infringements such as “research or study of the work, which is not for profit” or “reproduction, adaption, exhibition, or making available such materials by a teacher for teaching purposes, when not done for profit”. The fair use exception can be applied provided that:

  1. Such use of the copyrighted work does not conflict with normal exploitation of such work by the copyright holder; and
  2. 2. It does not unreasonably prejudice the legitimate interests of the copyright holder.

The definition of a “system administrator” in the draft Act refers to a person “who has the right to access computer systems which provide services to permit others to access the internet, or to enable parties to connect by means of a computer system, regardless of whether this administration is for his or her own benefit or for the benefit of other persons.”

Internet service providers usually set up their automatic backup proxy servers when providing internet services to users. When accessing web browsers, the servers or computers will temporarily store information to allow quicker access to the internet. By having the information stored temporarily in such caches, the system administrator can unknowingly cause damage to other persons, and thus could face liability under Section 16, even without intending to use or knowing that the information is stored in the caches. The system administrator that is responsible for the computer system would face half the penalty under Section 16, which is an imprisonment term of 18 months, a fine of 25,000 baht, or both.

Under the provisions of Section 16 and the definition of “system administrator”, any user, internet service provider, or system administrator who has previously enjoyed copyright exemption could now be held liable under the new proposed draft.

It is likely that Section 16 will require further clarification before its promulgation, particularly the definition of the term “copying“ and the scope of actions that will be specifically deemed an offense under the new Computer Crimes Act.

RELATED INSIGHTS​ 

March 30, 2026
On March 24, 2026, the Trade Competition Commission of Thailand (TCCT) published its long-anticipated Guidelines on Multi-Sided Platforms and E-Commerce Businesses in the Government Gazette, following the conclusion of a public hearing conducted last year. The guidelines entered into force on March 25, 2026, and significantly expand the application of Thai competition law to digital platform ecosystems. These rules introduce targeted restrictions on platform conduct, such as price-ranking algorithms and tying and bunding, that leverages network effects, and will have far-reaching implications across Thailand’s digital economy—affecting not only platform operators but also platform participants, including sellers, logistics providers, advertisers, and payment service providers operating on or alongside such platforms. The guidelines clarify how existing prohibitions under the Trade Competition Act B.E. 2560 (2017) (TCA)—including abuse of market dominance, cartel conduct, and unfair trade practices—apply in the context of platform-based business models. While many provisions reflect earlier draft guidelines, the final version delivers more precise definitions and clearer enforcement parameters, increasing regulatory certainty while also raising compliance expectations. Applicability The guidelines introduce core definitions that determine their coverage: Multi-sided platform: A platform that acts as an intermediary connecting two or more groups of users, enabling them to have direct interaction in order to exchange or rely on services from one another. Examples include digital platforms for trading goods or services (e-commerce), as defined below. Digital platform for trading goods or services (e-commerce): A platform that acts as an intermediary connecting the distribution, purchase, sale, or exchange of goods or services. This includes operations carried out to facilitate transactions or interactions between business operators through an electronic transaction system, regardless of whether a service fee is charged. Operator of a digital platform business for trading goods or services: A provider of digital platform services for trading goods or services, as described
March 27, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has publicly indicated that it is preparing a new regulatory framework for data center operators that may introduce foreign-ownership restrictions. In particular, the NBTC is considering reclassifying data center operations from a type 1 telecommunications business license to a type 3 license. If implemented, this change would subject data center operators to a significantly more stringent regulatory regime, especially in relation to foreign ownership and control. The NBTC has indicated that it intends to propose a draft framework to the NBTC board. This would be followed by a public hearing process, with a view to implementing the new rules within 2026. Under the Telecommunications Business Act B.E. 2544 (2001), as amended, telecommunications businesses operating under type 3 licenses are subject to foreign ownership restrictions, including a requirement that less than 50% of the total issued shares be held by foreign shareholders. In addition, type 3 licensees are subject to foreign dominance restrictions, which prohibit arrangements that allow foreigners to dominate the business. These foreign dominance restrictions are broad in scope and may capture various forms of direct and indirect control or influence. This includes circumstances in which a foreign national is able to influence or control the formulation of policy, management, or business operations, or the appointment of directors or senior executives. At this stage, the exact scope of the proposed rules remains unclear. Businesses with existing or planned data center operations in Thailand should therefore monitor upcoming NBTC developments in this regard and prepare for the expected public hearing process.
March 27, 2026
Vietnam’s emerging governance framework for artificial intelligence (AI) is developing through a multi-layered structure comprising three components: Policy instruments setting national priorities for AI development; Regulatory framework governing development, provision, deployment and use of AI; and Technical standards and voluntary guidelines. Policy level. At policy level, the foundation for a strategic framework for AI development and governance was laid in 2021 by the National Strategy for Research, Development and Application of AI until 2030, aimed at strengthening the national AI ecosystem and positioning Vietnam as a regional AI innovation hub. Subsequently, resolution No.57-NQ/TW (2024) identified AI as a key driver of science, technology, innovation and national digital transformation. AI was also designated as a strategic technology under decision No.1131/QD-TTg (2025) listing priority technologies across sectors. Regulatory framework. At the legislative level, the new Law on Artificial Intelligence took effect on 1 March 2026, establishing the core regulatory framework governing development, provision, deployment and use of AI systems. Controlled testing for emerging AI technologies is implemented under the Law on Science, Technology and Innovation. The AI Law is expected to be further operationalised through implementing instruments, most notably a draft decree guiding the AI Law, and draft decision of the prime minister identifying high-risk AI systems (both published in February 2026). A decision establishing priority datasets for AI development is also anticipated. Compliance obligations may also arise under sectoral regulatory regimes, including data protection, cybersecurity, banking, consumer protection, e-commerce and intellectual property, particularly where AI systems are used in automated decision-making or data-driven services. Technical standards and non-binding guidelines. Vietnam’s AI governance framework is also supported by technical standards and voluntary guidelines. A key instrument is decision No.1290/QD-BKHCN (2024), providing guidelines for responsible research and development of AI systems, and represents Vietnam’s first national AI ethics code. The Ministry of Science and Technology
March 27, 2026
In response to the rapid advancement of artificial intelligence (AI) and evolving global digital trends, Thailand has undertaken significant efforts to establish a comprehensive national policy framework aimed at fostering an AI ecosystem. This framework seeks to promote the responsible development and deployment of AI technology to enhance Thailand’s economic competitiveness and improve quality of life, with targeted implementation by 2027. In furtherance of this national AI policy, regulatory authorities have initiated efforts to develop and refine the applicable legal framework, including the drafting of Thailand’s first unified AI legislation. Pending the composing and enactment of such comprehensive legislation, sector-specific regulators have proactively issued guidelines applicable to regulated entities within their respective jurisdictions, including financial institutions, banks, insurance companies, securities and derivatives business operators, and digital asset service providers. Concurrently, cross-sectoral regulatory bodies, notably the Personal Data Protection Committee (PDPC) and the National Cyber Security Agency (NCSA), have promulgated guidelines applicable to all business operators within their regulatory purview. While unified AI legislation has not been enacted, the design, development and use of AI in Thailand in various industries is still subject to existing sector-specific legislation. National AI policy The Thai cabinet approved the Thailand National AI Strategy and Action Plan (2022-2027) in July 2022, aiming to establish an AI development and application ecosystem by 2027. The strategy is built around five pillars: Preparing social, ethical, legal and regulatory readiness for AI; Developing national infrastructure; Increasing human capability and AI education; Driving AI technology and innovation; and Promoting AI adoption in public and private sectors. The above-mentioned national AI committee, under the National Digital Economy and Society Committee (NDESC), was established in August 2022, chaired by the prime minister. Comprehensive legislation Following the national AI strategy, the government has been developing comprehensive AI legislation to govern and promote AI