You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 24, 2024

IAPP Global Legislative Predictions 2024 – Thailand

International Association of Privacy Professionals

Thailand’s Personal Data Protection Act came into full effect on 1 June 2022 and various subordinate regulations have since been issued by the Personal Data Protection Committee. These include regulations on security measures to be implemented by data controllers, data breach notification requirements, a mandatory obligation to appoint a data protection officer when the processing activity requires regular monitoring of personal data or a system due to the large scale of personal data, administrative measures and data processors’ record of processing activities.

As some areas under the PDPA still require further clarifications, a series of public consultations for the remaining draft subordinate regulations is anticipated in 2024. Potential areas include data protection impact assessments and cross-border transfers of personal data, which are crucial for organizations and particularly for entities with establishments in other jurisdictions.

PDPA enforcement by Thai regulators was silent until the last quarter of 2023, when the PDPC published details about complaints that have been lodged to the Expert Committee. The committee is designated by virtue of the PDPA and has the power to make determinations related to imposing administrative fines and other penalties. Enforcement in 2024 is expected to become more active and potentially more serious, which means organizations should pay closer attention to ensure compliance with the PDPA.

Similar to the GDPR, the PDPA also has extraterritorial effect. Once the subordinate regulation on international cooperation has been issued by the PDPC, this should clarify how PDPA enforcement against organizations located outside of Thailand will be conducted by Thai regulators.

With respect to sector-specific data protection legislation, in September 2023, Thailand’s National Broadcasting and Telecommunications Commission issued the Notification of the NBTC Re: Measures to Protect Telecommunications Service Users’ Rights in regard to Personal Data, Privacy Rights, and Freedom of Telecommunications, which replaces the previous notification. The notification aims to enhance the protection of personal data and privacy rights for telecommunication users and to align its data protection requirements with the provisions of the PDPA. The development of specific data protection laws for other sectors is still silent.

 

Athistha (Nop) Chitranukroh and Gvavalin Mahakunkitchareon provided this update as part of the “IAPP Global Legislative Predictions 2024” from the International Association of Privacy Professionals. Tilleke & Gibbins also provided the Vietnam update.

RELATED INSIGHTS​ 

March 15, 2024
Vietnam’s fintech industry is booming, and the rapid emergence of tech startups and non-bank institutions offering innovative financial services has been outpacing existing regulations. This regulatory gap not only creates uncertainty for both innovators and consumers, but also poses a number of imminent risks in areas such as consumer protection, data privacy, cybersecurity, and anti-money laundering, among others. The State Bank of Vietnam (SBV) is stepping up to tackle these challenges by accelerating the promulgation of a long-awaited Fintech Sandbox Decree with the issuance of an updated draft (“Draft Fintech Sandbox Decree”) on March 4, 2024. The Draft Fintech Sandbox Decree establishes a controlled environment where fintech companies and financial institutions can test solutions that do not fall squarely within the parameters of existing regulations. The pilot activities will be limited in scope, scale, and duration, with a number of precautionary measures in place. The SBV will supervise this “sandbox” closely, effectively mitigating risks and gathering valuable data to inform future regulations. Who Can Participate in the Sandbox? Traditional financial institutions (credit institutions): Banks and other institutions licensed to provide financial services can participate in the sandbox to test new offerings or refine existing ones. Independent fintech companies: Startups and established companies specializing in fintech solutions can leverage the sandbox to pilot innovative ideas before seeking wider market adoption. Other relevant organizations involved in the pilot: Depending on the specific solution being tested, other entities may also be involved in the sandbox. Geographical scope: Limited to Vietnamese territory; cross-border testing is not allowed. Focusing on Three Solution Categories Earlier versions of the Draft Fintech Sandbox Decree included categories like blockchain technology and other innovative business models, but these were removed in the latest version. To allow the SBV to assess the associated risks and work on the solutions more
March 12, 2024
Thailand’s Ministry of Finance has issued the Notification re: Criteria, Methods and Conditions for Applying for and Issuing Licenses to Operate Virtual Bank Business, which was published in the Government Gazette on March 4, 2024. This notification opens an opportunity for qualified experts in technology, digital services, and diverse data usage fields to apply for virtual bank licenses to provide financial services through new digital channels. The main goal is to serve the financial needs of target groups that may not have received sufficient or tailored financial services from the traditional banking system. Licensing Timeline Application submission period: 6 months (March 20–September 19, 2024). Announcement of successful applicants: Mid-2025 (approx. 9 months–1 year from the end of the submission period) After the announcement, successful licensees must demonstrate their readiness to commence virtual bank operations within 1 year (extendable for up to 1 additional year) via the following: Having paid-up registered capital of THB 5 billion and plans to increase the paid-up registered capital to at least THB 10 billion after the initial business period; Establishment or adjustment of a financial business group; Procurement of human resources, IT systems, and relevant risk management tools. Number of Licenses to be Issued No written or specified limit, subject to the discretion of the Bank of Thailand (BOT). Key Qualifications Applicants must have the following: Experience and resources to support virtual banking operations according to the business model and plan. Expertise and experience in conducting business that utilizes technology and provides services through digital channels. Experience demonstrating the ability to obtain, access, manage, and utilize data, including development of systems or data connections to facilitate user activities, allowing them to use their data to conduct transactions with other providers. Criteria In assessing applicants’ qualifications for a virtual bank license, the BOT will consider
February 27, 2024
Thailand’s National Cyber Security Committee (NCSC) released three notifications under the Cybersecurity Act on January 18, 2024, setting cybersecurity-related requirements for key organizations and assets. While one of these notifications already took effect, the two most notable will take effect on January 18, 2025 (i.e., one year from their publication in the Government Gazette). These two are the NCSC Notification Re: Standards for Defining the Security Category for Data or Information Systems B.E. 2566 (2023) (“Notification on Security Category”) and the NCSC Notification Re: Minimum Standards for Data and Information Systems B.E. 2566 (2023) (“Notification on Minimum Standards”). These notifications apply to: State agencies; Supervising or regulating organizations (i.e., state organizations, private organizations, or persons designated by law to regulate or supervise the affairs of state organizations or critical information infrastructure organizations); and Critical information infrastructure organizations (i.e., organizations related to or providing national security, significant public services, banking and finance, information technologies and telecommunications, transportation and logistics, energy and public utilities, and public health). Collectively these are defined as “Organizations” under the notifications. Notification on Security Category The Notification on Security Category sets forth risk-based security classifications—or “security categories”—for Organizations’ data or information systems. For security category assessment purposes, Organizations are required to perform a self-assessment of their data or information systems based on three key security objectives: confidentiality, integrity, and availability. Each of these objectives is further categorized into three risk levels (low, medium, and high), taking into account the assessment of potential impact in the following areas: Organizations’ financial value or reputation; Organizations’ number of service users; Organizations’ ability to perform their duties; State stability or public order. The risk levels for the three objectives are determined by considering whether there are “minimal,” “severe,” or “serious severe” effects, as described below: Confidentiality (not including data classified
February 2, 2024
The pervasive global issue of illicit personal data trading has extended its reach into Vietnam, where such sensitive information is being sold at minimal costs. A 2023 report from the Ministry of Public Security revealed that over two-thirds of the Vietnamese population has fallen victim to unlawful data collection and distribution. In the past two years, authorities have pressed charges on five criminal cases involving the buying and selling of billions of items of personal data, encompassing a wide range of sensitive information such as names, phone numbers, email addresses, and more. Notably, a person’s profile can be acquired for just USD 1, while profiles of millions of business customers can be obtained for a mere USD 100. Recognizing the severity of the problem, Vietnam has made serious efforts to combat illicit personal data trading by criminal means, encompassing both the legal framework and practical implementation.   Understanding the Criminal Legal Framework Vietnam’s 2015 Criminal Code, as amended in 2017, functions as a pivotal legal instrument delineating offenses and their corresponding punishments. Under Section 2 of Chapter XXI of the Criminal Code (“Offenses Against Regulations on Information Technology and Telecommunications Networks”), individuals engaging in the illicit trading of personal data, depending on the nature of the data (e.g., information about phone number, address, or—more dangerously—bank account) and the nature of the infringing acts, may be charged under different crimes. The sanctions can include monetary fines; non-custodial reform; imprisonment; and/or prohibition from holding certain positions, practicing certain professions, or doing certain jobs. For example, for the illicit trade of private information of an individual on a computer or telecommunications network, Article 288 of the Criminal Code specifies penalties including a monetary fine of up to VND 1 billion (equivalent to around USD 41,000); non-custodial reform of up to three years;