You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 10, 2024

Fintech Insights: E-payments in Thailand

In recent years, Thailand has witnessed a significant transformation in its financial landscape, particularly in the rapid adoption of financial technology (fintech). At the forefront of this evolution are electronic payment systems and services, which have revolutionized how individuals and businesses conduct financial transactions.

This transformation has been driven by both traditional financial institutions and alternative financial service operators. Overseeing this dynamic landscape are two primary regulators: the Bank of Thailand (BOT) and the Securities and Exchange Commission (SEC).

This article explores the development of electronic payment systems in Thailand, with a particular focus on the Payment Systems Act (PSA) of 2017 and its role in shaping the fintech ecosystem.

Payment Systems Act

In October 2017, Thailand took a significant step forward in regulating its burgeoning electronic payment sector by adopting the Payment Systems Act. This landmark legislation was designed to create and ensure electronic payment system stability and enhance consumer protection in the digital financial realm. The PSA establishes a comprehensive framework by categorizing electronic payment businesses into two main categories: payment systems and payment services.

Electronic Payment Systems under the PSA

The PSA recognizes two types of electronic payment systems that require specific licenses or registration:

  • Central or network systems. These include systems that act as a center or network between service users for fund transfers, clearing, or settlement. Examples include:
    • Inter-institution Fund Transfer System
    • Payment card networks
    • Settlement systems
  • Systems of public interest. This category encompasses any other payment systems that may affect public interest, public confidence, or the stability and security of the payment infrastructure.

Electronic Payment Services under the PSA

The PSA also identifies several electronic payment services that require specific licenses or registration:

  • Credit cards, debit cards, and ATM cards
  • Electronic money
  • E-payments
    • Acquisition
    • Payment facilitation
    • Receipt of payment on behalf of others
  • Electronic fund transfer
  • Other payment services that may affect financial systems or public interest

Looking Ahead

As Thailand continues to embrace digital transformation in its financial sector, the PSA serves as a solid foundation for future developments in payment technologies. The regulatory framework established by this law provides a structure for the ongoing evolution of electronic payment systems in the country.

The BOT and SEC continue to play pivotal roles in shaping the future of electronic payments in Thailand. Their ongoing efforts to balance innovation with stability and consumer protection will be crucial in maintaining Thailand’s position as a fintech leader in Southeast Asia.

For businesses operating in or looking to enter the Thai fintech space, understanding and navigating the PSA is essential. As the electronic payment landscape continues to evolve, companies should stay informed about regulatory updates and be prepared to adapt their services to comply with the PSA’s requirements. This proactive approach will not only ensure regulatory compliance but also position businesses to capitalize on the growing opportunities in Thailand’s evolving electronic payment ecosystem.

RELATED INSIGHTS​ 

October 19, 2021
On September 9, 2021, Laos announced a new pilot program to allow the mining and trading of cryptocurrency. Notification No. 1158, issued by the Prime Minister’s Office, provides for an electricity sale-purchase agreement with six companies involved in the pilot program. Under the notification, the six companies authorized by the prime minister to mine and trade cryptocurrency in Laos will pay a capped fee for energy they use in data processing or mining cryptocurrency. This effectively establishes a sandbox in which these six companies may mine and trade cryptocurrency—including on international cryptocurrency exchanges. The Ministry of Technology and Communications (MTC) is in charge of coordinating the program, together with the Ministry of Finance, the Bank of the Lao PDR, the Ministry of Planning and Investment, the Ministry of Energy and Mines, the Ministry of Public Security, and Électricité du Laos. The MTC is also charged with drafting the rules of the pilot program and setting the conditions on which the participating companies can mine, sell, and purchase cryptocurrency in Laos. One of the six selected companies will also act as a coordinator for the other companies and report to the government on any benefits of cryptocurrency observed during the pilot program. The next step is for the MTC to compile data analysis from each of the other government agencies and submit the conclusions to a meeting of the prime minister and the deputy prime ministers before the pilot program is implemented. The pilot program was originally scheduled to start in September, but there has not yet been any update on the implementation of the program, which nonetheless is expected to start in the near future.
October 19, 2021
In September 2021, the Bank of Thailand (BOT) issued its Guidelines on Data Governance to provide financial institutions with recommendations on how to ensure that their data governance will be in compliance with accepted international principles. While there are no penalties for noncompliance, financial institutions should view the recommendations as minimum standard expectations for their data governance in Thailand. The BOT guidelines set forth five main data governance principles: Data Governance Policy Financial institutions should set forth their data governance policy in writing in accordance with their business size, business operations, business complexity, and data risk. The policy should cover all types of data, including data related to services from third parties or business partners, as well as provide information on the data governance structure, data lifecycle management, protection of data security and data privacy, and incident management. Financial institutions should inform their employees and other relevant parties of the policy to ensure their compliance. In addition, the data governance policy must be approved by the designated board or committee of the financial institution, and be reviewed and revised in response to significant changes. Data Governance Structure Financial institutions should establish a data governance structure with three lines of defense, supervised by an oversight committee. The first line of defense comprises data management personnel, a data approver, and data users; the second comprises a risk management unit and a compliance unit; and the third is an audit unit. While the chosen data governance structure can be tailored to the characteristics of the institution, the structure should cover all of these roles and duties, and must not contravene the principle of checks and balances. The data governance structure should also be supported by sufficient personnel and equipment, as well as a clear plan—reviewed and revised as necessary—for building awareness at