You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 6, 2019

The Compliance Framework for Online Content in Thailand

Informed Counsel

With the growing power and influence wielded by online content, concerns have been raised in Thailand (as in many other countries) that online channels, which facilitate free and easy exchange of information across a variety of forums, could be used to conduct illegal activities that will incite discontent and conflict within the country. This is especially true of information exchanged and shared through social media and Over-the-Top (OTT) services.    

In a bid to exercise a degree of control over online content, a number of laws and regulations have been prescribed focusing specifically on types of information that should be restricted, or prohibited, from being disseminated online. The following is an overview of Thai laws and regulations relating to online content.

Computer Crimes Act    

The Computer Crimes Act (CCA) is used by the government as a tool to control, restrict, and prohibit the dissemination of specific information by computer. The CCA also authorizes authorities to monitor internet traffic and suppress content that falls within the scope of the following criteria:

  • Distorted, false, or partially false content which is likely to cause damage to the general public with malicious intent.
  • False content which is likely to cause damage to national security, public safety, national economic stability, or infrastructure for the public benefit, or cause panic to the general public.
  • Content that constitutes a criminal offense relating to national security or terrorism, the royal family, or relationships with foreign nations, as prescribed under the Penal Code.
  • Content that constitutes a criminal offense under the laws relating to intellectual property.
  • Content which, by itself, is contrary to Thai public order or good morals.
  • Obscene or pornographic content.
  • Computer data or emails which could be regarded as a disturbance to the recipients, wherein there is no option for them to easily opt out or unsubscribe.

The provisions of the CCA also provide enforcement measures aimed at tackling intellectual infringement through online platforms. These measures provide the possibility of imposing a permanent injunction, which allows for the suspension or blocking of websites that contain content, or disseminate any data, that is deemed to infringe intellectual property. The provisions also allow for the removal of such data from computer systems. 

Child Protection Act     .

The Child Protection Act prohibits the dissemination of any information relating to a child with the intention of causing damage to the mind, reputation, prestige, or any other interests of that child, or which seeks benefit for oneself or others in an unlawful manner.

Copyright Act   

With millions of people spending an increasing proportion of their time online in order to enjoy online content and services, several types of infringing digital content (e.g., movies, songs, or games) can easily be illegally disseminated and consumed through online platforms, increasing the risk of copyright infringements. Notably, an amendment to the Copyright Act that came into force in 2015 provides alternative relief for copyright infringement in the form of a preliminary injunction, allowing the injured parties to have infringing content removed from the internet.

NCPO Orders   

In addition to these attempts to curb widespread distribution of unregulated online content, Thailand’s interim government, the National Council for Peace and Order (NCPO), has attempted to exert additional controls over digital rights by imposing extensive prohibitions on the dissemination and broadcasting of information via various forms of media.   

These NCPO orders empower authorities to prohibit the dissemination and broadcasting of any information that falls within the confines of the following criteria:

  • False content that could cause defamation or have a negative impact on the royal family.
  • News or information that could be harmful to national security.
  • Criticism of the NCPO’s operation which is provided in bad faith, or any false information that could impair the NCPO’s credibility.
  • Voices, photos, and videos relating to the confidential operation of government agencies.
  • Information which could cause controversy or polarization within the country.
  • Information that invites people, or leads to the assembly of people, in order to oppose NPCO officials, or people associated with the NCPO.
  • A threat to commit an act of violence against other people, or which causes panic or fear among the general public.

On top of these extensive restrictions, the NCPO orders also further prohibit individuals and media from inviting academics, or former civil servants, for interviews or to express opinions that are deemed to be in a manner that could exacerbate conflicts, or which distort information and cause confusion amongst the public.

Moving Forward   

The extensive restrictions and prohibitions cited above have not been initiated without concerns being raised in some quarters, and there is consternation that the drive to enforce the law could also result in a reduction in individual rights to freedom of expression.    

Therefore, finding a balance and suitable resolutions for these issues appears to be a crucial challenge for Thailand’s regulatory authorities, and ultimately, the country’s next government, which will come to power after the widely anticipated elections are held in March 2019. In the meantime, and whatever the outcome, it is imperative that both individuals and corporations understand the laws relating to online content, and exercise caution when engaging in any online transactions or businesses, in order to mitigate their exposure to potential penalties that may be imposed for transgressions.

RELATED INSIGHTS​ 

August 14, 2026
Thailand’s Office of the Insurance Commission (OIC) has issued guidelines clarifying the boundaries between permissible and prohibited activities for unlicensed individuals—including influencers, bloggers, and content creators—when communicating about insurance products on social media. The Good Practice Guidelines for Persons Not Licensed as Insurance Agents or Brokers Regarding the Dissemination of Insurance Content Through Digital Media B.E. 2569 (2026) took effect on July 24, 2026. Activities Requiring a License The guidelines reserve the following activities for licensed agents and brokers: Soliciting or facilitating insurance contracts. Providing personalized advice on product suitability. Recommending policy cancellation to purchase promoted products. Creating links that facilitate contract formation. Receiving performance-based compensation tied to policies or premiums generated. Importantly, boilerplate disclaimers such as “this is not a recommendation to buy insurance” will not shield individuals from liability if the OIC views the content as personalized advice or solicitation. Permitted Activities Unlicensed persons may present general educational content about insurance—such as explaining terminology, sharing industry statistics, reporting news, or sharing personal experiences—provided the content does not target specific individuals to purchase from specific companies. The guidelines also set out best practices for communication, including presenting information in a fair and balanced manner that covers both benefits and limitations, encouraging consumers to read policy terms and consult licensed professionals, verifying information from credible sources before dissemination, and exercising special care when the audience may include vulnerable groups such as persons aged 60 and older. Prohibited Practices Prohibited practices include fear-based marketing, creating artificial urgency, omitting material limitations, making exaggerated claims, falsely claiming professional credentials, using fake engagement mechanisms, and sharing false or misleading content. The guidelines also reinforce the prohibitions under section 83 of the Life Insurance Act B.E. 2535 and section 78 of the Non-Life Insurance Act B.E. 2535 against soliciting insurance contracts with foreign operators
August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public
August 10, 2026
Thailand has finalized its social media KYC (“know your customer”) rules under Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers (No. 2), which was published in the Government Gazette on May 5, 2026, and will take effect on November 1, 2026. While an early draft of the notification proposed requiring social media platforms to arrange identification of every user account, the final notification is significantly more targeted, focusing on paid online advertising and advertiser identity verification. Though the regulatory initiative primarily aims to combat online fraud and technology-related crimes, it also has important consequences for intellectual property enforcement, because the verified platform records that will be generated under the new requirements can help IP rights holders to identify anonymous online infringers. Key Regulatory Mandates The notification requires social media service providers to verify the identity of advertisers before their paid advertisements are published and disseminated in Thailand through social media, regardless of whether the advertising fees come from the advertisers or third parties. Verification of an advertiser is valid for one year, after which verification would have to be performed again before the platform could publish additional paid advertisements from the advertiser. Permitted verification methods are specified under the notification. A platform may verify an advertiser by checking identity evidence and confirming the connection between the advertiser and that identity evidence, with the notification giving facial comparison against certain government-issued identity documents as an example. Alternatively, platforms may verify advertisers through a digital identity verification and authentication system with an identity-proofing assurance level not lower than the level prescribed by Thailand’s Electronic Transactions Commission. The notification further requires platforms to retain only the advertiser’s information necessary to identify the advertiser, beginning from the start of the advertising activity and for
August 10, 2026
On July 31, 2026, Thailand’s Big Data Institute (BDI) launched a public consultation on the principles of a proposed new data-sharing law, with comments accepted until August 31, 2026. If enacted, the law would establish Thailand’s first comprehensive framework for government and private-sector data sharing, creating a systematic, secure, and transparent regime to support analytics, policymaking, research, and innovation. Central Data-Sharing Platform The draft law establishes a central system for data sharing, managed by the BDI. Government agencies would be required to connect to the BDI’s Data Integration and Intelligence Platform (also referred to as D2), in accordance with the BDI’s rules and procedures. Five Dimensions of Data Sharing The draft law covers five key types of data sharing between government (G), businesses (B), and consumers (C): G2B: Private organizations may request government data specifically for research and development purposes. The BDI will assess the applicant’s data governance, security, and privacy capabilities whether such measures meet prescribed standards before forwarding the request to the relevant government agency within 90 days. Any dispute may be escalated to a newly established Data-Sharing Promotion Committee for final determination. G2G: Government agencies may request data from other agencies through the central system. The data-holding agency must respond within 90 days, taking legality, necessity, proportionality, public interest, and personal data protection into account. Disputes may be referred to the Data-Sharing Promotion Committee for adjudication. B2G: In emergency situations involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society may require private entities to provide data through the central data-sharing system. Government agencies must specify the data requested, demonstrate its necessity and expected benefits, and request only data reasonably available to the data holder. Requests for personal data must be limited to the minimum amount necessary. B2C: Royal decrees may