You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 17, 2025

Fintech Operators and Thailand’s Draft Emergency Decree on Technology Crimes Suppression

Thailand’s draft Emergency Decree on Technology Crimes Suppression, which we covered in a client alert in January 2025 primarily addressed to telecom operators and financial institutions, is expected to have significant implications for a wide range of business operators.  The draft emergency decree has already been approved by the cabinet but may undergo further developments as it continues in the legislative process.

In this article, we will highlight the material impacts of the draft emergency decree on overseas and local fintech operators.

Expanded Definition of “Technology Crimes”

The definition of “technology crimes” now includes the following acts of forgery or alteration:

  • Forging or altering the identity of individuals and biometric characteristics by utilizing computer or communication systems or other electronic means to commit offenses.
  • Forging or altering symbols, trademarks, or seals of groups (e.g., foundations, community enterprises) or juristic persons, including acts by juristic persons using individuals or juristic persons as nominal directors or shareholders, regardless of whether such individuals or legal juristic persons reside in Thailand.
  • Forging or altering digital or online platforms, regardless of the platform’s location or legal status.

Individuals who conspire, utilize, assist, or support the commission of these offenses will face the same penalties as the principal offender.

Business Operator Definition

The scope of “business operators” is now expanded to cover various fintech and digital asset operators beyond those under the Payment Systems Act (PSA). The draft emergency decree now includes the following operators, whether they are legally authorized or not:

  • Business operators under the PSA and business operators who operate “as if” they are payment system operators
  • Business operators under the Royal Decree on Digital Asset Businesses or business operators who operate “as if” they are digital asset business operators.
  • Foreign exchange business operators.

Disclosure and Exchange of Information

Business operators must disclose or exchange information on accounts and transactions linked to technology crimes and notify a centralized system for relevant government agencies to access. In this regard, the lead regulator (e.g., Bank of Thailand, the Securities and Exchange Commission) of the business operator can mandate this within a set timeline.

Customers’ accounts related to technology crimes are publicly disclosable. Moreover, activities involving personal data sharing or processing under the draft emergency decree are exempt from the Personal Data Protection Act.

Transaction and Account Suspension

When there is a reasonable suspicion that the customer’s account is used or may be used for technology crimes or the victim reports that a deposit or e-money account of a business operator’s customer was used for a technology crime-related act, that business operator must (1) suspend the relevant customer’s account and business relationship, (2) notify other entities (i.e., financial institutions, other business operators, and telecom operators) in the transaction chain to ensure coordinated action, (3) input information into a system for disclosure or exchange, and (4) report the situation to the relevant authorities.

If an account holder is found to have multiple accounts without a valid reason, the business operator must (1) immediately suspend all related accounts, (2) notify account holders, and (3) report the situation to the relevant authorities.

Accounts can only be reinstated (1) upon notification by the relevant officer or (2) if the account holder provides face-to-face verification and evidence that the account is not related to technology crime. Failure to provide verification and clarification within 30 days will result in a presumption that the money is related to technology crime. Consequently, money will be transferred back to the original source, with the original account owner notified.

Victim Compensation

Business operators, including financial institutions and telecom operators, are required to share the burden of compensating victims of technology crimes. If a business operator is found to have neglected their duties or facilitated technology crimes, they are obligated to compensate the victims for their losses.

Penalties for Business Operators

Financial institutions, business operators, and network service providers involved in technology crimes face significant penalties. This includes fines and imprisonment for those who facilitate or support technology crimes, including employees of the business operators.

Adoption and Compliance

Once the decree is issued, there is no transition period for business operators to comply with the requirements under the decree. It is expected that this decree will be issued in the very near future.

RELATED INSIGHTS​ 

August 18, 2026
The Bank of Thailand (BOT) is seeking public comment on proposed amendments that would significantly expand know-your-customer (KYC) and customer due diligence (CDD) requirements for cash-related transactions at financial institutions (FIs) and specialized financial institutions (SFIs). Released on August 5, 2026, the proposed regulation would supersede BOT Notification No. 16/2569, which focused primarily on cash withdrawal transactions. The public comment period is open through September 3, 2026. The amendments reflect concerns that FIs and SFIs may be used to facilitate the movement, concealment, and conversion of criminal proceeds, potentially damaging institutional operations and public confidence in the financial system. Expanded Scope of Covered Transactions The most significant change is the broadening of the definition of “cash-related transactions.” Previously, the regulation covered only cash withdrawals and uncrossed check withdrawals. The amended regulation extends coverage to include: Cash deposits, check deposits, or receipt of funds from the public not in the form of deposit accounts; Thai baht (THB) banknote exchange (different denominations); Receipt of cash for issuing checks and drafts; and Purchase, sale, or exchange of foreign banknotes. Mandatory Identity Verification and Risk Management For all cash-related transactions, FIs and SFIs must require customers, or authorized or delegated persons, to present identification or verify their identity before every transaction, including one-time (walk-in) transactions. Specific identification requirements vary by transaction type, customer nationality, and channel (branch vs. electronic). FIs and SFIs must also establish comprehensive risk management processes and procedures for cash-related transactions. These requirements include identifying customers or authorized representatives in accordance with transaction-specific verification standards, analyzing customer behavior, implementing risk-management measures proportionate to the customer’s risk profile, and recording abnormal behavior in relevant systems. The BOT also encourages institutions to proactively guide customers toward transaction channels that offer greater traceability than cash. For corporate customers in high-risk business sectors—including foreign
August 14, 2026
Thailand’s Office of the Insurance Commission (OIC) has issued guidelines clarifying the boundaries between permissible and prohibited activities for unlicensed individuals—including influencers, bloggers, and content creators—when communicating about insurance products on social media. The Good Practice Guidelines for Persons Not Licensed as Insurance Agents or Brokers Regarding the Dissemination of Insurance Content Through Digital Media B.E. 2569 (2026) took effect on July 24, 2026. Activities Requiring a License The guidelines reserve the following activities for licensed agents and brokers: Soliciting or facilitating insurance contracts. Providing personalized advice on product suitability. Recommending policy cancellation to purchase promoted products. Creating links that facilitate contract formation. Receiving performance-based compensation tied to policies or premiums generated. Importantly, boilerplate disclaimers such as “this is not a recommendation to buy insurance” will not shield individuals from liability if the OIC views the content as personalized advice or solicitation. Permitted Activities Unlicensed persons may present general educational content about insurance—such as explaining terminology, sharing industry statistics, reporting news, or sharing personal experiences—provided the content does not target specific individuals to purchase from specific companies. The guidelines also set out best practices for communication, including presenting information in a fair and balanced manner that covers both benefits and limitations, encouraging consumers to read policy terms and consult licensed professionals, verifying information from credible sources before dissemination, and exercising special care when the audience may include vulnerable groups such as persons aged 60 and older. Prohibited Practices Prohibited practices include fear-based marketing, creating artificial urgency, omitting material limitations, making exaggerated claims, falsely claiming professional credentials, using fake engagement mechanisms, and sharing false or misleading content. The guidelines also reinforce the prohibitions under section 83 of the Life Insurance Act B.E. 2535 and section 78 of the Non-Life Insurance Act B.E. 2535 against soliciting insurance contracts with foreign operators
August 13, 2026
On August 6, 2026, the National Bank of Cambodia (NBC) issued a notice calling on business owners that issue electronic money, such as e-wallet accounts and stored-value membership cards, to notify the central bank within 90 days. The notice targets businesses that are not licensed banking or financial institutions or payment service providers, but have been issuing e-money to facilitate payments within their own networks. Failure to notify the NBC may result in legal action. Background and Regulatory Basis The NBC has observed that certain businesses, including cafes, restaurants, transportation companies, entertainment centers, and gas stations, have been issuing e-money through e-wallet accounts in mobile apps or membership cards to facilitate customer payments for products or services within their own networks. Customers create e-wallet accounts and load balances to pay for goods or services at the issuing business. The NBC describes this as “single-purpose e-money.” Under the 1999 Law on Banking and Financial Institutions, providing payment facilities to customers forms part of the operations of banking and financial institutions and requires an NBC license. In addition, article 20 of the 2017 Prakas on the Management of Payment Service Institutions further prohibits legal entities other than banking and financial institutions and payment service institutions from issuing e-money. However, article 20 also provides that issuing e-money in certain limited cases does not require a license, but the NBC must be notified in advance in writing. A business may issue single-purpose e-money without a payment service institution license provided it meets all the following conditions and submits written notice to the NBC: The maximum balance per account is KHR 200,000 (approximately USD 50) or equivalent. The total aggregate balance across all accounts does not exceed KHR 800 million (approximately USD 200,000) or equivalent. The e-money is used to pay for products or
August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public