You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 3, 2017

Copyright Protection in Virtual Reality

Informed Counsel

Virtual reality (VR) describes a computer-generated simulation of a three-dimensional (3D) space, which allows users to feel as if they are exploring a physical environment. To achieve this effect, a user wears a headset that performs the dual functions of displaying the 3D images and blocking out physical reality. By tracking the movements of the user’s head, the displayed images may be adjusted to create the sense of being able to view an environment in 360 degrees.

The year 2016 was a watershed moment for virtual reality due to the release of several new VR systems for consumer purchase. Ranging from high-end systems, such as Oculus Rift, to inexpensive cardboard headsets designed to work with smartphones, there are now multiple options available for those interested in experiencing virtual reality firsthand.

While the rise of virtual reality thus far has been driven mostly by video games—exemplified by the recent release of the PlayStation VR headset—the investments currently being made by prominent tech companies signal that virtual reality will soon change the way we surf the Internet and engage with social media.

In addition, creative programs like Tilt Brush already offer artists new and unique ways to create genre-defying works in VR environments. As VR tools continue to improve and the number of VR adopters increases, there will be a marked proliferation of creative works in the VR context. For example, the Internet platform Second Life is a virtual world in which users explore and interact using avatars. Second Life has its own internal currency and a large market for “in-world” digital goods, including real estate, artwork, avatar clothing, and even pets. Strong protection for VR works will ensure that creators are incentivized to innovate in this new area.

This article discusses the applicability of copyright to virtual reality and some of the novel issues presented by intellectual property protection of VR works.

Copyright Protection

While virtual reality is still in its infant stages, artists are already finding that creating works in a virtual 3D space allows them to do things that were previously impossible. Virtual reality allows artists to “paint” using color and light, and incorporate motion and sound to create three-dimensional works that appear to float in the air. These creations defy categorization because they may combine elements of illustration, sculpture, music, and cinematography. In addition, the VR context allows users to interact with works in ways not possible in physical reality, such as by walking through an object to examine multiple layers.

The Thai Copyright Act B.E. 2537 (1994) was designed to be adaptable so that it could encompass new types of works. However, the Act does not explicitly provide for protection of creative works in virtual reality, which raises the question of whether such works are protected under copyright.

Section 6 of the Copyright Act specifies that a “[c]opyright work under this Act means a work of authorship in the form of a literary, dramatic, artistic, musical, audiovisual, cinematographic, sound recording, sound and video broadcasting work or any other work in the literary, scientific or artistic field whatever the mode or form of  its expression” (emphasis added).

The above language demonstrates that the Copyright Act is not limited to the technologies that were in existence at the time of drafting. As long as a new work can be classified as part of the literary, scientific, or artistic fields, and the work satisfies the other requirements of the Act, it will be protectable by copyright. Further, Thailand protects software under copyright law as a literary work. As VR works are represented by software, they will be protected by copyright regardless of the form they take.

While works are automatically protected by copyright upon their creation, rights holders should undertake recordation of their works with Thailand’s Department of Intellectual Property to establish prima facie evidence of copyright ownership and subsistence in the event they need to take legal action against an infringer.

Infringement

Copyright provides an associated bundle of exclusive rights for copyright owners, such as the right to reproduce, rent, assign, license, communicate to the public, and create adaptations or derivative works. Because VR works are protected under copyright, other parties may not make the above uses of a work without the permission of the copyright owner. The flip side of this is that a VR reproduction of a real-world work will also be considered infringement as a derivative work.

While we are still in the early days of virtual reality adoption, VR platforms should create clear Terms of Service stating that users may not use the platform to infringe the intellectual property rights of other parties. Users who violate these terms by creating infringing content may be blocked or removed from the service.

As adoption of virtual reality grows, VR platforms will also need to be protected against infringing uses of their services, much as user-generated content sites are today. If VR platforms allow users to interact with one another in virtual space via the Internet, VR platforms will fall under the broad definition of internet service providers (ISPs) found in the Copyright Act. Section 32/3 of the Copyright Act grants immunity to ISPs against infringing content placed on their services by other parties, provided that they comply with court orders to remove such content. This immunity should encourage VR platforms to allow robust innovation by their users without fear of being held liable for any infringing activity their users may undertake.

Enforcement

The intangible nature of VR works will make enforcement against infringing uses difficult, just as the Internet has presented numerous challenges for creators seeking to enforce their IP rights against online infringers. Jurisdiction over VR disputes will likely be tested early, and courts will have to determine whether to make jurisdiction dependent on the location of the creator, infringer, infringement, or servers hosting the virtual reality. These locations may be on opposite sides of the world, and each one will create different enforcement issues.

VR platforms can assist content owners by creating internal notification and removal procedures for infringing content. Creating these internal procedures will demonstrate the goodwill of the VR platform and encourage content creators to participate in virtual reality. Additionally, by creating dependable methods for removal of infringing content, content owners may protect their works while avoiding costly and lengthy litigation.

Outlook

Due to its ability to create the impression of visiting new worlds, virtual reality has the potential to transform areas as disparate as entertainment, education, and tourism. While we cannot predict the path that virtual reality will eventually take, the innovative ways that virtual reality is already being used demonstrate that new markets for creative VR works will continue to proliferate. VR works need to receive strong protection under intellectual property laws in order to encourage creators to adopt virtual reality as their medium of choice.

RELATED INSIGHTS​ 

August 10, 2026
On July 31, 2026, Thailand’s Big Data Institute (BDI) launched a public consultation on the principles of a proposed new data-sharing law, with comments accepted until August 31, 2026. If enacted, the law would establish Thailand’s first comprehensive framework for government and private-sector data sharing, creating a systematic, secure, and transparent regime to support analytics, policymaking, research, and innovation. Central Data-Sharing Platform The draft law establishes a central system for data sharing, managed by the BDI. Government agencies would be required to connect to the BDI’s Data Integration and Intelligence Platform (also referred to as D2), in accordance with the BDI’s rules and procedures. Five Dimensions of Data Sharing The draft law covers five key types of data sharing between government (G), businesses (B), and consumers (C): G2B: Private organizations may request government data specifically for research and development purposes. The BDI will assess the applicant’s data governance, security, and privacy capabilities whether such measures meet prescribed standards before forwarding the request to the relevant government agency within 90 days. Any dispute may be escalated to a newly established Data-Sharing Promotion Committee for final determination. G2G: Government agencies may request data from other agencies through the central system. The data-holding agency must respond within 90 days, taking legality, necessity, proportionality, public interest, and personal data protection into account. Disputes may be referred to the Data-Sharing Promotion Committee for adjudication. B2G: In emergency situations involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society may require private entities to provide data through the central data-sharing system. Government agencies must specify the data requested, demonstrate its necessity and expected benefits, and request only data reasonably available to the data holder. Requests for personal data must be limited to the minimum amount necessary. B2C: Royal decrees may
August 10, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) recently released draft guidance on records of processing activities (ROPA) for personal data controllers and processors under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft guidance, which was presented to the public on July 7, 2026, addresses both controller records of collection, use, and disclosure of personal data and processor records of processing activities carried out on behalf of controllers. If implemented, the guidance will significantly expand organizational expectations for ROPA preparation, maintenance, and use across all sectors. Key Takeaways The draft guidance contains several important implications for organizations subject to the PDPA: ROPA reframed as a core accountability tool. The guidance elevates ROPA from an administrative record to a central accountability mechanism, connecting controller duties with recordkeeping obligations. ROPA as a source for privacy notices and governance documents. ROPA should serve as the primary source for privacy notices and align with consent management, retention schedules, DPIAs, incident response plans, and vendor contracts. Expanded scope across all activities. ROPA must cover all processing activities across the organization—including security, finance, HR, and external contractors—with correct controller or processor classification for each. Ongoing maintenance and auditability. ROPA must be updated for any change to systems, purposes, or processors, reviewed at least annually, and maintained with version control and a designated owner. Enhanced vendor, processor, and cross-border transfer requirements. Organizations must document all processors, external recipients, and cross-border transfers, specifying purposes, access scope, and destination countries. Linkage with risk assessment, DPIAs, and LIAs. ROPA should assign risk levels to each activity and identify when data protection impact assessments (DPIAs) or legitimate interests assessments (LIAs) are required, functioning as a risk-management tool. ROPA and data breach readiness. Incomplete ROPA can delay breach response and notification. Organizations should map data flows, vendors,
August 4, 2026
Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) could soon see some important changes, as a draft bill to amend the PDPA has been introduced in the House of Representatives. The draft amendment is currently in the public consultation phase, with comments accepted from July 16 to August 15, 2026. If enacted in its current form, the amendment would make three key changes: expanding the government exemption to cover anticorruption operations, introducing a statutory definition of “government agency,” and restructuring the lawful bases for personal data processing to align with international standards. Background The PDPA has encountered several enforcement challenges since its implementation, including three core problems identified by the bill’s sponsors: (1) the current exemptions for government agencies do not cover anticorruption and misconduct-prevention operations; (2) the PDPA lacks a clear statutory definition of “government agency,” causing legal uncertainty as to which entities are covered; and (3) the existing framework for lawful bases of data processing does not align with international standards—particularly the multiple-lawful-bases system in the EU’s General Data Protection Regulation (GDPR)—making compliance inflexible for both government and private sector entities. Expanded Government Exemption The current PDPA exempts government agencies performing duties related to national security (including fiscal security), public safety, anti-money laundering, forensic science, and cybersecurity. The proposed amendment adds “prevention and suppression of corruption and misconduct” to this list of exempted functions. This would allow anticorruption bodies—most notably the National Anti-Corruption Commission (NACC), which is identified as a directly affected party—to collect, use, and disclose personal data without being subject to PDPA requirements when carrying out their duties. New Statutory Definition of “Government Agency” Notably, while the current PDPA use the term “government agency” in several provisions, the term is not comprehensively defined, creating potential uncertainty as to its scope. The draft bill therefore
August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must