You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 19, 2024

DNA: How the Use of Artificial Intelligence Is Regulated in Southeast Asia

Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to How the Use of Artificial Intelligence Is Regulated in Southeast Asia, a comparative resource published by Drew Network Asia (DNA). The guide provides an accessible introduction to artificial intelligence (AI) and examines how ASEAN member states are approaching governance, regulation, and responsible deployment of AI technologies.

The publication begins by outlining core AI concepts and summarizing the ASEAN Guide on AI Governance and Ethics, which reflects the region’s collective approach to promoting innovation while addressing risks. It then presents a comparative overview of nine ASEAN jurisdictions, highlighting emerging national strategies, regulatory developments, and institutional frameworks.

Each country chapter responds to a consistent set of ten practical questions. These cover whether a national AI strategy has been issued; the extent to which dedicated AI laws or sectoral regulations apply; the existence of relevant judicial decisions; available guidelines and government support schemes; regulators responsible for AI oversight; approaches to liability, copyright, and data protection; and key considerations for organizations deploying AI technologies.

By consolidating developments across the region, the guide serves as a useful reference for businesses exploring AI-related opportunities or compliance obligations in Southeast Asia. As regulatory approaches continue to evolve, readers seeking jurisdiction-specific advice are encouraged to contact the practitioners listed in each chapter.

The full guide is available for download using the button below or directly from the DNA website.

RELATED INSIGHTS​ 

November 27, 2023
Thailand’s Electronic Transaction Development Agency (ETDA) has released two new subordinate regulations under the Royal Decree on Digital Platform Services: one detailing the assessment of digital platform services (DPSs) that will be deemed “high-risk” and subject to additional obligations, and another setting guidelines on user verification and authentication for all DPSs. The two subordinate regulations are summarized below. Impact Assessment of DPS Operations Under the Royal Decree on Digital Platform Services, DPS operations that have the risk of seriously impacting financial and commercial security, reliability and credibility of data message systems, or the general public are subject to additional obligations. The first subordinate regulation mentioned above (officially titled Notification of the Electronic Transactions Commission Re: Criteria for Impact Assessment on Operation of Digital Platform Services) outlines the criteria for the ETDA to determine which DPSs are “high-risk.” DPSs falling under this designation include: DPSs whose total value of transactions conducted through the platform in Thailand exceeds THB 100 million (approx. USD 2.8 million) per year; DPSs whose operators have not registered their entities with the Department of Business Development (DBD)—notably overseas operators—and that have 100 or more merchants or business users in Thailand or total users in Thailand between 5 and 10 percent of the country’s population (i.e., approx. 3.3–6.1 million users, calculated using official 2022 figures); DPSs that allow their users to freely post certain messages, or do certain acts, that may affect the public in certain cases, such as: (1) unlawful messages or acts; (2) messages or acts that may affect a child’s rights or people’s fundamental rights; and (3) messages or acts that may negatively affect political opinions of Thai citizens (whether before or after an election) or statements or actions likely to negatively affect other individuals due to gender differences or sexual violence. After considering
November 23, 2023
On November 14, 2023, Thailand’s Personal Data Protection Committee (PDPC) published a draft notification on collection of personal data regarding criminal records. The draft notification aims to provide clarifications and prescribe further criteria for processing criminal record data under the Personal Data Protection Act (PDPA), which generally requires the processing of criminal records to be carried out under the control of the relevant official authority under the law or under a data protection measure implemented according to rules prescribed by the PDPC. After its eventual passage, the draft notification will have important implications for businesses’ recruitment and human resources activities in relation to individuals with criminal records. Key aspects of the draft notification include the following: “Personal data regarding a criminal record” and “criminal record data” denote personal data related to the investigations of criminal offenses, criminal prosecution, or criminal punishment that is official information or certified by the relevant supervisory authority, regardless of whether that action is connected to a final judgment. Under the draft notification, data controllers may process criminal record data for the purpose of a recruitment process, checking the qualifications of personnel, and considering the suitability of a person for a position if the processing activities are required by law or when a data controller obtains explicit consent from the data subject. Furthermore, the necessity of processing the criminal record data must be announced at the beginning of the recruitment process. Data controllers’ requests for explicit consent to collect a data subject’s criminal record data must also notify the data subject of the consequences of not providing consent or withdrawing consent. The draft notification sets the allowable retention period for criminal record data at a maximum of six months from the end of the processing activities specified above. After the retention period ends, the criminal
November 17, 2023
On October 3, 2023, Thailand’s Board of Investment (BOI) issued a new regulation clarifying the eligibility criteria for investment promotion under the BOI category “5.10 Development of software, platforms for digital services, or digital content.” To be eligible for BOI promotion under the digital activity category, projects must meet criteria related to local development, minimum investment amount, machinery and equipment, and development processes. These criteria for category 5.10 activities, along with the latest clarifications from the BOI, are detailed in the table below. Tax Incentives The BOI also clarified the method for calculating corporate income tax (CIT) exemptions. The CIT cap amount is calculated on an annual basis from the prescribed expenses incurred after applying for BOI promotion and occurring during the year for which the CIT exemption is claimed. The allowances include 100% of expenses for salaries for newly hired Thai IT personnel, technology-related training, and obtaining quality standards (such as ISO 29110). The revenue of projects that qualify for CIT exemption must be from sales or services directly related to software, platforms for digital services, or digital content developed as promoted by the BOI, including licensing fees, subscription fees, pay-per-use expenses, in-app purchase fees, usage fees, revenue sharing, advertising fees, and so on. For more details on BOI promotion for digital activities, or on any aspect of investment promotion in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected] or +66 2056 5600, Napassorn Lertussavavivat at [email protected] or +66 2056 5662, or Thammapas Chanpanich at [email protected] or +66 2056 5561.
November 15, 2023
Four decisions from the Expert Committee under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) indicate that there will no longer be any relaxation of PDPA enforcement. The enforcement of Thailand’s seminal data protection law had been relaxed for more than a year when, on October 18, 2023, the Personal Data Protection Committee (PDPC) published the first decision made by the Expert Committee on the imposition of administrative measures against a company pursuant to authority granted to it under the Notification of the PDPC Re: Rules for the Consideration of the Imposition of Administrative Penalties by the Expert Committee B.E. 2565 (2022), which was one of the first subordinate regulations issued under the PDPA. Shortly thereafter, on October 19, October 25, and November 15, three additional Expert Committee decisions were published. These three decisions made by the Expert Committee are summarized below. October 18 Decision The complainant in this case lodged a complaint with the Expert Committee alleging that an insurance company contacted him to offer the company’s products without his consent. The complaint further claimed that when the complainant requested the company to disclose how his personal data had been acquired and asked the company to stop contacting him through any channel, the company did not take any action on the requests. The insurance company appeared to have obtained the personal data of the complainant from another source prior to the PDPA becoming fully effective (i.e., June 1, 2022). As the Expert Committee explained in its order, the company failed to comply with its obligations under the PDPA regarding the collection of personal data from another source, which requires consent as a legal basis; failed to comply with the grandfather provision by not publicizing opt-out procedures to enable the data subject to withdraw his consent easily; and