You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 26, 2011

Clouds Looming Over New Computer Crimes Act

Bangkok Post, Corporate Counsellor Column

The proposed new Computer Crimes Act, which will supersede the 2007 Computer Crimes Act, has been introduced in an attempt to fill loopholes in the current legislation.

The new draft is aimed at those who perpetrate offenses and who have previously evaded liability. But there are concerns over whether the new law would be overly zealous in handing out harsh punishment to all offending parties, regardless of the severity of the crime involved.

Although the draft Act has similarities to the current Computer Crimes Act, there are new key sections that have been introduced, including definitions for “system administrator” and “Board” under Section 4. There have also been important additions to Sections 16 and 25 of the law, which detail offenses relating to any person who is found to be copying another person’s computer data and the penalties for possessing child pornography.

Section 16 of the draft has caused particular concern among the media, service providers, webmasters, companies, and even students, university professors, and other users because it stipulates that “copying” another person’s computer data will now be deemed a criminal offense.

This article analyzes Section 16 and highlights the possible repercussions of the proposed additions.

Section 16 of the draft provides that “any person who copies another person’s computer data illegally, in a manner that is likely to cause damage to such other person, shall be punished with imprisonment of not more than three years, or a fine not more than 50,000 baht, or both”.

The definition of “computer data” refers to data, statements, or sets of instructions (including electronic data) that are contained in a computer system, the output of which may be processed by a computer system, according to the Law of Electronic Transactions.

But the draft does not provide a definition for “copying”. As a result, “copying” could be interpreted to mean copying data, materials, or downloading a file from the internet, regardless of whether such material is copyrighted. Even accessing the internet and having temporary storage caches in a computer without consent could be deemed an offense. Such copying offenses will carry a maximum penalty of three years’ imprisonment.

The provision of Section 16 in regard to “illegally copying another person’s computer data, in a manner that is likely to cause damage to another person” is relatively broad in terms of its interpretation of the scope of an act that is “likely to cause damage”.

Copying or downloading text materials or images from the internet would seem to be a common everyday occurrence. Under the Thai Copyright Act, if materials or images are copyrighted, any copying or downloading of such materials or images from the internet will be regarded as reproduction, which requires permission from the copyright owner. Otherwise, it will be regarded as an infringement of the exclusive rights of the copyright owner.

But the Thai Copyright Act acknowledges certain exceptions, including the fair use exception for infringements such as “research or study of the work, which is not for profit” or “reproduction, adaption, exhibition, or making available such materials by a teacher for teaching purposes, when not done for profit”. The fair use exception can be applied provided that:

  1. Such use of the copyrighted work does not conflict with normal exploitation of such work by the copyright holder; and
  2. 2. It does not unreasonably prejudice the legitimate interests of the copyright holder.

The definition of a “system administrator” in the draft Act refers to a person “who has the right to access computer systems which provide services to permit others to access the internet, or to enable parties to connect by means of a computer system, regardless of whether this administration is for his or her own benefit or for the benefit of other persons.”

Internet service providers usually set up their automatic backup proxy servers when providing internet services to users. When accessing web browsers, the servers or computers will temporarily store information to allow quicker access to the internet. By having the information stored temporarily in such caches, the system administrator can unknowingly cause damage to other persons, and thus could face liability under Section 16, even without intending to use or knowing that the information is stored in the caches. The system administrator that is responsible for the computer system would face half the penalty under Section 16, which is an imprisonment term of 18 months, a fine of 25,000 baht, or both.

Under the provisions of Section 16 and the definition of “system administrator”, any user, internet service provider, or system administrator who has previously enjoyed copyright exemption could now be held liable under the new proposed draft.

It is likely that Section 16 will require further clarification before its promulgation, particularly the definition of the term “copying“ and the scope of actions that will be specifically deemed an offense under the new Computer Crimes Act.

RELATED INSIGHTS​ 

June 5, 2026
Vietnam’s AI regulatory framework has reached an important milestone. While the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law) established the foundation for AI governance, many practical compliance requirements were left to implementing regulations. On April 30, 2026, the government issued Decree No. 142/2026/ND-CP (Decree 142), which took effect on May 1, 2026, and provides the first detailed guidance on the implementation of the AI Law. Although an official list of high-risk AI systems is still pending from the prime minister, Decree 142 provides valuable insight into how Vietnam’s risk-based AI regulatory framework will operate in practice. Risk Classification Framework The AI Law adopts a risk-based approach under which AI systems are classified as high-risk, medium-risk, or low-risk. Decree 142 builds on this framework by providing detailed guidance on how these classifications are determined. High-risk AI systems are determined based on factors such as (i) their potential impact on life, health, property, human rights, public interests, or national security; (ii) the sector in which they are deployed; and (iii) the scale of affected users or integration with critical infrastructure. The latest draft list of high-risk AI systems appears to follow these same principles. Medium-risk AI systems generally include systems that may mislead, influence, or manipulate users, particularly where users may not realize they are interacting with AI or AI-generated content. The focus is therefore on transparency and authenticity risks rather than broader societal or safety concerns. Low-risk AI systems are those that do not meet the criteria for either high-risk or medium-risk classification. Importantly, Decree 142 seeks to avoid over-classification. Certain systems may fall outside the high-risk or medium-risk regimes, including internal-use systems, office-support tools, technical editing applications, certain back-end processing systems, and AI systems used in artistic, gaming, cinematic, or other creative contexts. Providers must also review and
June 5, 2026
On May 11, 2026, Thailand’s Ministry of Social Development and Human Security released a draft Child Protection Act (“CPA”) for public review. The draft CPA would completely repeal and replace the current Child Protection Act B.E. 2546 (2003). This represents the most comprehensive overhaul of Thailand’s child protection framework in over two decades, reflecting the government’s stated objective of modernizing the law to address evolving social challenges—including those arising from digital technology—and to promote greater coordination among government agencies, local authorities, and civil society. The public review period closes on June 9, 2026. Key changes introduced by the draft CPA that could have significant implications for businesses, particularly online platform providers, media companies, and entities operating child-related services in Thailand, are set out below. Expanded Definition of “Child” Under the current CPA, a “child” is defined as a person under the age of 18, excluding those who have attained legal majority through marriage. The draft CPA removes the marriage exception entirely, broadening the scope of the law’s protections to include all individuals under 18 without exception. Replacement of “Abuse” with Broader Concept of “Violence” The current CPA uses the term “abuse/cruelty,” which covers acts causing harm to a child’s liberty, body, or mind; sexual offenses against children; and using children in harmful or immoral activities. The draft CPA replaces this with the broader concept of “violence,” which encompasses any act or omission causing harm to a child’s body, mind, or development; abandonment or neglect; improper exploitation; and sexual abuse. Notably, the new definition adds developmental harm as a recognized category of injury and captures all forms of misconduct regardless of the child’s consent. New Standalone Definition of Sexual Abuse, Including Online Conduct One of the most significant additions in the draft CPA is the introduction of a standalone definition
May 25, 2026
After several years of policy discussion and continued efforts led by the Ministry of Commerce (MOC) to relax the list of reserved businesses under the Foreign Business Act B.E. 2542 (1999) (FBA), the reform process has now reached a significant milestone. On May 12, 2026, the Thai cabinet approved in principle two draft subordinate legislative instruments aimed at delisting certain reserved business activities under the FBA and reducing licensing requirements for foreign business operators. These developments signal a renewed and concrete effort by the government to modernize Thailand’s business regulatory framework in order to attract foreign investment and boost Thailand’s competitiveness in the global market. Nine Businesses Set for FBA Delisting Below is a list of the nine businesses that are being targeted for delisting from the FBA’s restrictions. A draft ministerial regulation would delist the first eight reserved businesses, while a royal decree has been drafted to delist the ninth business: Telecommunications services (Type 1 license only, covering operators without their own telecommunications infrastructure), under the supervision of the Office of the National Broadcasting and Telecommunications Commission. Treasury center services subject to the Foreign Exchange Control Act B.E. 2485 and under the supervision of the Bank of Thailand. Securities-collateralized lending, pursuant to the laws governing securities and exchange and derivatives regulated by the Securities and Exchange Commission. Agency, dealer, advisory, or fund management services relating to derivatives where the underlying assets fall outside the scope of the Derivatives Act B.E. 2546 (2003) Intra-group shared services, including administrative, human resources, and IT functions Intra-group domestic debt guarantee services Leasing of partial space for installation of financial service machines and automatic vending machines for employee use Petroleum drilling services Trading of agricultural product derivatives through a futures exchange, with physical delivery or receipt of agricultural products at a futures exchange–designated
May 25, 2026
Thailand published new rules on May 1, 2026, establishing clear procedures for how the Anti-Money Laundering Office (AMLO) handles digital assets seized during criminal and money laundering investigations. Taking effect the following day, the Regulation of the Anti-Money Laundering Board on the Custody and Management of Seized or Frozen Assets (No. 3) B.E. 2569 applies to digital asset businesses, cryptocurrency holders, and anyone subject to asset seizure under Thailand’s anti-money laundering laws. For the first time, authorities now have a detailed roadmap for transferring seized digital property from private or foreign control into secure state custody. Digital asset businesses holding customer assets under investigation must be prepared to comply with these rules compelling repatriation of such assets in enforcement actions. Expanded Definition of Digital Assets The regulation defines digital assets to include not only those covered by Thailand’s existing digital asset business law but also any other property that can be stored using the same methods as digital assets. This broad formulation means the custody rules will apply to emerging blockchain-based assets and tokenized property that may not yet fall within the statutory definition of a digital asset business, giving authorities flexibility as the technology evolves. Mandatory Transfer to Domestic Custody When digital assets are held with service providers outside Thailand, AMLO will first attempt to transfer them to an account the office maintains with a licensed domestic digital asset business operator. If the domestic operator does not support that particular asset, the office will instead move the assets to its own cold wallet (offline, internet-isolated storage system). If neither option is feasible, the seizing official will report the situation to the Anti-Money Laundering Committee for alternative instructions. A similar hierarchy governs assets held in an accused party’s private wallet or by any third party that is not a