You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 6, 2014

Ensuring Compliance with the Thai Computer-Related Crimes Act

The Link: Magazine of the British Chamber of Commerce Thailand

The Computer-Related Crimes Act (CCA) of Thailand came into force in July 2007. It was followed a month later with the publication of a Notification of the Ministry of Information and Communications Technology providing more detail relative to the scope and application of the law.

The law has attracted a certain amount of controversy particularly with regard to freedom of speech issues. That is not the focus of this article. The purpose here is to introduce the basic content of the law and consider what businesses and their staff need to do to comply with its requirements—and, of course, to avoid committing any offenses.

First, a word about context. It is now obvious that the internet is transforming society and the business world to a far greater extent than was imaginable a mere 15 years ago. Gutenberg’s printing press pales in comparison in terms of impact. From a lawyer’s point of view this dramatic online evolution (which is ongoing) creates, at a very high level, two primary areas of concern:

  • The internet as a new “venue” for committing unlawful acts
  • The internet as means to expand the reach of acts which are already classed as unlawful

Between these two poles, a vast number of issues stand to be regulated, including such issues as  contract, service responsibilities, security, consumer protection and fraud and, of course, jurisdiction. The list is extensive.

In Europe, there is a growing corpus of law aimed at making the internet safe for social interaction and commerce. The CCA in Thailand seems perhaps more stark in terms of its remit because it forms part, for the present, of a smaller body of computer-related law. Its genesis and objectives are however both recognisable and logical.

Scope

The key parts of the CCA for the purposes of this article can be broken down as follows:

  • Definitions: important, particularly in relation to who may be considered a “service provider”
  • Cybercrimes: they track for the most part the crimes enumerated in Title 1—Offences against the confidentiality, integrity and availability of computer data and systems of the 2001 Convention on Cybercrime
  • Content crimes: these relate to unlawful activities already dealt with under Thai law as they may be conducted online. This includes defamation, offences against the honour, dignity and reputation of the Royal Family and its institutions (lèse-majesté), and the dissemination of pornography or indecent information
  • Enforcement: primary responsibility lies with the Ministry of Information and Communications Technology
  • Service provider responsibilities: maintaining computer traffic data

Foreign entities conducting business in Thailand through local subsidiaries are of course subject to the provisions of the law. And importantly, a content crime does not have to be committed in Thailand to constitute an offence under the CCA. In 2011 a Thai-born U.S. citizen published online, from the U.S., a translation of Thai text that was judged offensive to the Royal Family. On his next visit to Thailand, the U.S. citizen was arrested, charged, and convicted under the CCA. (He subsequently received a Royal pardon.)

Impact of the Law

So what should foreign businesses worry about with regard to the law? Essentially, three things:

  • Doing something that may be held to constitute a crime under the CCA.
  • Being held liable as a service provider for a crime committed by an employee—or a guest in a hotel or a customer (for example, using the Wi-Fi connection in a coffee shop). CCA s.15 provides that a service provider who intentionally supports or consents to a content offence under s.14 shall be liable to the same penalty as the primary offender.
  • Failing to comply with traffic data retention requirements: a hefty fine of up to THB 500,000 can be imposed for each instance of non-compliance.

In response, prudent managers should consider the following:

  • Read the CCA—it’s widely available in translation online. Consider the content offences in particular. Act accordingly and sensitively, particularly in relation to online expression of matters touching on the dignity of the Royal Family, public morality or local politics.  Avoid defamatory statements regardless of truthfulness/veracity.  
  • Understand that the definition of service provider includes any entity which provides internet access, a local area network or server facilities. Ensure the necessary workplace, estate or occupancy policies are in place. Be alert as managers: individuals from directors to webmasters could be personally liable under the CCA if they have actual knowledge of any offense committed through the system they manage but do nothing about it.
  • Review the computer traffic data retention requirements thoroughly with the CIO or an appropriate external advisor. They are extensive yet non-exhaustive as set out in the regulations.
  • If in doubt, have no doubt: seek the advice of expert Thai counsel. This is a serious matter.

Service Provider Requirements

The basic structure of the service provider traffic data retention requirements is as follows:

  • CCA s.3 defines the service provider to include any entity which provides internet access, services for communicating between computers or computer data storage whether in its own name or via a third party.
  • CCA s.26 stipulates that a service provider shall retain computer traffic data for not less than 90 days (or up to 1 year if so ordered by a competent official) relating to identified, individual users from the start to the end of the use of the service.
  • The regulations provide further details about what data to store and how to store it.

The regulations are in three parts: the body of the regulatory text and two annexes. First, through Annex A they identify different categories of service providers, offering examples within each category. Then, in Annex B, the regulations set out the particular data that must be retained by the different categories of service providers. The lists of data are extensive but, reportedly, not exhaustive.

Finally, as general provisions, the regulations stipulate arrangements for maintaining the integrity of the data, storing it securely and in a way that makes it readily deliverable to competent officers who require it. They also require the setting of equipment to a single international reference time.

Conclusion

Surprisingly, given the importance of the law, information regarding its application in practice remains somewhat limited. This may be partly due to the fact that, in addition to the Ministry of Information and Communications Technology, a number of different enforcement agencies have been involved in enforcement of the law, including the Technology Crime Suppression Division of the police and the Department of Special Investigation. What is known is that the number of prosecutions for both cybercrime and content offences is growing—confirming both our increasing reliance on the internet and our growing need to know about its regulation as a matter of basic prudent business practice.

RELATED INSIGHTS​ 

May 22, 2026
On May 8, 2026, the Thai government held a press conference to announce a coordinated, multiagency initiative to strengthen oversight and enforcement over products sold on online platforms. The initiative involves the Office of the Consumer Protection Board, the Thai Industrial Standards Institute, the Electronic Transactions Development Agency, the Thailand Consumers Council, the Consumer Protection Police Division, and major online platform operators. With this appointment, the government has signaled a deliberate shift from a predominantly reactive enforcement framework toward a more proactive regulatory and monitoring approach for online commerce and digital platform services. Legal and Regulatory Reform The government is accelerating a proposed Product Liability Law that would introduce new statutory frameworks for defective or substandard products, along with amendments to food safety and consumer protection legislation. The draft law has already been approved by the cabinet; the Council of State and relevant authorities will further draft the law and subsequently issue it for public hearings prior to enactment. Authorities also plan to expand enforcement measures against noncompliant businesses and distributors. In particular: The implementation of stricter “know your merchant” (KYM) identity verification requirements for online sellers. Expanded mandatory standards and regulatory oversight for high-risk products, such as power banks, electrical appliances, food products, and household goods. Increased monitoring of online product listings, and coordination with platform operators to remove unsafe, counterfeit, misleading, or otherwise noncompliant products. Additional monitoring and enforcement measures targeting online scams and illegal goods distributed through digital platforms, including e-cigarettes, which authorities identified as a growing concern due to increasing online distribution channels and potential health impact on young consumers. Strengthening Consumer Complaint Mechanisms The government announced increased cooperation with the Thailand Consumers Council and other agencies to facilitate complaint handling, market monitoring, and policy recommendations. Enhanced interagency coordination will aim to ensure that consumer
May 19, 2026
Thailand’s telecommunications regulator has introduced a range of new compliance obligations for telecom licensees aimed at preventing and suppressing technology crime. On May 15, 2026, the National Broadcasting and Telecommunications Commission (NBTC) published in the Government Gazette Notification on Measures for Prevention and Suppression of Technology Crime No. 2, which amends the original NBTC notification dated August 24, 2025. The amendment derives its authority from the Emergency Decree on Measures for Prevention and Suppression of Technology Crime B.E. 2566 (2023), as amended in 2025, and took effect on May 16, 2026. SIM Card Registration Cap for Non-Thai Nationals Persons without Thai nationality are now limited to a maximum of three SIM cards per person per service provider. Identity verification must be done primarily via passport. For those without a passport, acceptable alternatives include travel documents or certificates of identity issued by foreign governments, accompanied by additional Thai government-issued documents, as well as pink ID cards (for persons without Thai nationality) and white ID cards (for persons without registration status). Registration must be done in person at a branch or authorized dealer. Service providers must develop their identity verification systems and obtain NBTC approval before deployment. SIM Activation Deadline and SIM Box Prohibition Both Thai and non-Thai service users must activate their registered SIM within 60 days of registration. If they fail to do so, they must re-verify their identity in person before activation, confirming they are the same person who originally registered. Service providers must prohibit SIM box and gateway devices capable of supporting four or more SIMs from connecting to their mobile networks unless the device has received a license under the Radio Communications Act. Blacklist Enforcement Service providers must refuse registration of additional mobile numbers for persons listed on a technology crime-related database maintained by the Royal
May 6, 2026
Thailand has introduced new requirements for online social media platforms to verify the identity of paying advertisers before publishing their advertisements. On May 5, 2026, the Electronic Transactions Commission published the Notification on Measures for Prevention of Technology Crime for Online Social Media (No. 2) in the Government Gazette. The notification, which aims to prevent technology crimes such as fraud and scams, takes effect 180 days after publication (i.e., on November 1, 2026). Mandatory Advertiser Identity Verification Online social media service providers must verify the identity of every advertiser before publishing an advertisement. Verification remains valid for up to one year from the most recent verification date. The notification requires social media providers to use either of the following methods when verifying advertisers: Document-based verification: Examine government-issued identity documents (e.g., national ID, passport, or juristic person registration certificate), cross-check the connection between the advertiser and the identity documents (e.g., facial comparison with photo ID), and ensure that the identity documents are verifiable against reliable sources. Digital identity verification: Use an identity verification system with a level of assurance no lower than that prescribed by the Electronic Transactions Commission. Advertiser Data Collection and Retention Service providers must collect and retain certain data—including name, identification number, and contact details—from the start of the advertising service and for a minimum of 90 days after the end of the advertising service relationship. The same requirements apply where there is a third-party payer, such as an ad agency. Implications for Affected Businesses The notification raises two key areas of concern for affected businesses: Social media platforms must implement know-your-advertiser (KYA) onboarding as described above, including document upload and identity matching processes. The 180-day implementation window requires immediate technical and operational planning. The collection and retention of national ID cards, passport copies, and other personal
April 30, 2026
Vietnam’s Decree No. 134/2026/ND‑CP, which took effect on 9 April 2026, plays an important role in detailing and implementing Vietnam’s Intellectual Property (IP) Law in the context of rapid digital transformation and the growing application of artificial intelligence (AI). The new decree provides comprehensive guidance on the application of copyright and related‑rights regulations, addressing key issues such as authorship, ownership, statutory exceptions and limitations, registration procedures, and enforcement mechanisms. Through these measures, Decree 134 seeks to achieve an appropriate balance between safeguarding the legitimate interests of rightsholders and fostering innovation, research, and technological advancement, thereby strengthening the state’s framework for the effective management, protection, and exploitation of intellectual property in the digital and AI‑driven environment. Some notable aspects of Decree 134 are discussed below. Copyright for AI-Created Works Decree 134 provides important guidance on the determination of copyright and related rights in works created with the assistance of AI. Article 5a reaffirms the principle that human creativity remains central to copyright protection, clarifying that copyright or related rights arise only where a human makes a substantial and decisive intellectual contribution, exercises effective control over the creative outcome, and assumes responsibility for the content and its legality. At the same time, the provision confirms that AI is regarded solely as a technological tool rather than a rights‑holding subject, thus ensuring consistency with the fundamental concepts of authorship and ownership under the IP Law. By introducing requirements on transparency, proof of human contribution, and compliance with AI‑specific labelling and technical marking obligations, Decree 134 establishes a clear and enforceable legal framework for the responsible use of AI in creative activities. Lawful Use of Copyrighted Texts and Data Article 37a of Decree 134 sets out the specific conditions under which copyrighted texts and data may be lawfully used for scientific research, experimentation,