You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 23, 2015

IT Law Update (Part 1): The Cybersecurity Bill

Bangkok Post, Corporate Counsellor Column

Earlier this month, the cabinet approved a series of bills related to information technology, personal data, cybersecurity, and telecommunications. One such bill would recast the Information and Communication Technology Ministry as the Digital Economy and Information Technology Ministry to reflect the importance of IT in Thailand’s economy—the same rationale behind the entire set of bills. This article focuses on one of these bills, the Cybersecurity Bill. Next week in a follow-up article, we will discuss another one of these bills, the Bill to Amend the Computer Crimes Act.

Given recent events, governments around the world are focusing on threats occurring over the Internet, as well as attacks using computing equipment and networks and how to counteract these threats to improve overall security. Thailand is no different. The Cybersecurity Bill, as approved by the cabinet, would establish a National Cybersecurity Committee and a new state agency, the Office of the National Cybersecurity Committee, to focus on these issues.

The committee would have the responsibility to determine how to respond to serious cyberthreats, effectively to serve as the center of operations in the event of an IT calamity (save for matters of military security) and cooperate with other state bodies and private entities for this purpose, among related responsibilities. The Office of the National Cybersecurity Committee would be responsible for implementing the committee’s policies, as well as related responsibilities specified in law.

The Bill also features a reporting mechanism for state agencies and/or designated persons in each agency to provide information to the secretary of the committee so it could determine what further actions to take in response to particular cyberthreats. Further, where maintaining cybersecurity is necessary—for example, in a case where there may be an effect on financial and commercial stability or national security—the committee may even order a state agency to take particular actions and report as the committee may instruct.

It is envisaged that the minister overseeing the committee would appoint officials to perform certain roles. These officials, in turn, may be authorized by the secretary of the office to request a state agency or any person to give testimony, submit a written explanation, or submit materials for inspection or information—all within the scope of the Act—or request state agencies or private entities to facilitate the committee’s performance of its duties.

The Bill also would empower officials to access communications information, be it in the form of posts, telegrams, telephones, faxes, computers, or any mechanism or device for electronic communication or telecommunications, for the purpose of cybersecurity. However, it also contemplates that the cabinet would specify rules for officials to follow in accessing such information, presumably for the purpose of addressing privacy concerns.

The law also contains provisions to protect such information and to prevent its disclosure, except in cases of prosecution under the Act, abuse of power, or as otherwise authorized by a court.

The most controversial provision of the Bill relates to accessing personal communications content. Indeed, commentators around the world have expressed concerns about access to personal communications by state agencies of various countries. These concerns are understandable and legitimate. Nevertheless, current public discourse seems to reflect that policymakers’ concerns about terrorism and national security are outweighing traditional concerns about personal privacy.

In Thailand, the practical reality is state agencies already have access to communications content under a variety of other laws. Hence, the provisions in the Cybersecurity Bill do not substantially expand the state’s ability to access such information. Rather, in the larger picture, the Bill would seem to envisage the establishment of a framework for such access.

All countries need to focus on cybersecurity, and the Cybersecurity Bill lays out a framework for this in Thailand. The reality is that it is impossible to predict all possible cyberthreats that may arise, which is why the Bill gives effect to plans and policies to be adopted by the National Cybersecurity Committee. In that regard, the success of the Bill will ultimately depend on those plans and policies, which would be expected to undergo continual adjustment and updates to meet current threats.

In next Friday’s article, we will discuss the proposed changes to the Computer Crimes Act—changes that may be a cause for concern for some.

RELATED INSIGHTS​ 

July 8, 2026
On July 7, 2026, the Trade Competition Commission of Thailand (TCCT) issued a press release announcing the establishment of two new subcommittees designed to intensify oversight of digital platforms and modern trade businesses. The formation of the digital platform subcommittee marks a significant escalation in competition enforcement following the TCCT’s Guidelines on Multi-Sided Platforms and E-Commerce Businesses, which took effect on March 25, 2026. Platform operators, sellers, and related service providers should expect heightened regulatory scrutiny and potential investigations into practices already flagged under the March guidelines. Two Dedicated Enforcement Bodies The first new body is the digital platform subcommittee—formally the Subcommittee on Supervision, Monitoring, and Prevention of Trade Conduct in Digital Platform Business. It is tasked with driving intensive oversight of digital platform businesses. It will coordinate with government agencies, the private sector, business operators, and other relevant stakeholders to supervise and prevent trade conduct that may affect competition, and to promote free and fair competition in the digital platform sector. The subcommittee will be composed of TCCT members and representatives from the Department of Internal Trade. The second body—the Subcommittee on Determining Guidelines and Action Plans Concerning Competition Conditions in Modern Wholesale and Retail Business—will study, analyze, and monitor market structure in modern wholesale and retail businesses, compile databases to analyze retail business concentration, assess impacts on small-scale operators, and propose supervisory measures for the retail sector. TCCT members will serve on the subcommittee alongside experts from government and private organizations, including the Office of Industrial Economics, the Office of Small and Medium Enterprises Promotion, the Thai SME Federation, and the Thai SME Council. Operational Impact for Industry Participants These subcommittees provide the TCCT with a focused mechanism to investigate various trade practices deemed unfair, and the TCCT has authority under the Trade Competition Act to issue cease-and-desist
July 6, 2026
Vietnam has introduced an official list of high-risk AI systems, triggering more stringent compliance obligations for developers, suppliers, and deployers operating in the country. On June 30, 2026, the prime minister issued Decision No. 33/2026/QD-TTg (Decision 33), which establishes the List of High-Risk AI Systems under the Law on Artificial Intelligence (AI Law) and Decree No. 142/2026/ND-CP (Decree 142). Decision 33 takes effect on August 15, 2026. Decision 33 is significant because only AI systems included on the list will be subject to the heightened compliance obligations applicable to high-risk AI systems under the AI Law and Decree 142. These include, among others, local presence requirements for foreign providers, mandatory conformity assessment before deployment, comprehensive risk management and data quality documentation, and strict liability for damages even when the provider is fully compliant. Decision 33 also specifies the applicable conformity assessment pathway for each listed system, indicating whether the system must undergo mandatory third-party conformity certification before being placed into use, or whether the provider may self-assess conformity or voluntarily engage a registered or recognized conformity assessment body. Which AI Systems Are Covered? Decision 33 identifies high-risk AI systems across six sectors—the key attributes of which are summarized below. Education: AI systems used for automated assessment, learner ranking, behavioral monitoring, or generating educational content from uncontrolled data sources. Ethnic affairs and religion: AI systems used to automatically score, classify, or rank applications for government ethnic policies; approve or reject regulatory applications; suspend benefits on suspicion of fraud; allocate budgets; or infer and classify individuals by ethnicity or religion for administrative purposes. Healthcare: AI-assisted surgical systems and autonomous AI-powered surgical robots. Banking: AI systems that autonomously conduct electronic banking transactions or make credit approval decisions. Judicial proceedings: Certain large-scale biometric identification systems used in public-interest civil proceedings. Transport: Thirty-one categories
July 6, 2026
Indonesia’s regulation on reporting online intellectual property (IP) infringement provides comprehensive procedural guidance for IP rights holders and their licensees in reporting online infringement complaints. Issued in December 2025 by the Ministry of Law as Regulation No. 47 of 2025 regarding Handling of Intellectual Property Infringement Reports in Electronic Systems, this regulation covers all types of IP rights. It also specifies documentation when reporting infringement, and lays out the procedures for examination, verification, and enforcement actions. Submission of Complaints Complainants may submit reports through the online system of the Directorate General of Intellectual Property (DGIP) or in person at the DGIP office. Complaints may also be filed through an authorized proxy. Under the regulation, complainants are required to provide the following information and documents: Personal details of the complainant; Brief description of the protected work or subject matter (i.e., type of IP and name or address of the infringing website, portal, account, or application, or a link to the location of the infringing content); Complete description of the alleged infringement; Certificate of registration or recordal of the relevant IP; Recordal of IP license agreement, if any; and Other supporting evidence. Verification and Examination Process Upon receiving a complaint, the responsible formality officer may request clarification or additional supporting documents. In the latter case, the complainant must then submit the necessary administrative documents within 14 days of the notification date. Once the documentation is deemed complete and sufficient, the case will be formally registered. Subsequently, the DGIP will establish a verification team to handle online IP violations, which will include the Civil Servant Investigator (PPNS), the Ministry of Communication and Digital Affairs, experts with relevant expertise in IP, and representatives from related associations such as AVISI (Indonesian Video Streaming Association). After examining the report, the team will prepare the Minutes
July 6, 2026
Tilleke & Gibbins has contributed the Vietnam chapter to Data Protection & Privacy 2027, a global guide published by Lexology Panoramic that provides comparative insights into data protection and privacy regimes across multiple jurisdictions. The Vietnam chapter offers a comprehensive overview of the country’s data protection framework, addressing both regulatory structure and practical compliance considerations for businesses operating in or engaging with Vietnam. Topics covered include: Law and the regulatory authority: Legislative framework; data protection authority; cooperation with other data protection authorities; breaches of data protection law; judicial review of data protection authority orders Scope: Exempt sectors and institutions; interception of communications and surveillance laws; other laws; personal information formats; extraterritoriality; covered uses of personal information Legitimate processing of personal information: Lawful bases for processing; grounds for legitimate processing; types of personal information Data handling responsibilities of owners of personal information: Transparency; exemptions from transparency obligations; data accuracy; data minimization; data retention; purpose limitation; automated decision-making Security: Security obligations; notification of data breaches; internal controls Accountability: Data protection officer requirements; record-keeping; risk assessment; design of personal information processing systems Registration and notification: Registration requirements; other transparency duties Sharing and cross-border transfers of personal information: Sharing with processors and service providers; restrictions on third-party disclosures; cross-border transfers; further transfers; localization requirements Rights of individuals: Right of access; other statutory rights; compensation Enforcement: Enforcement mechanisms; exemptions, derogations, and restrictions; further exemptions and restrictions Specific data processing: Cookies and similar technologies; electronic communications marketing; targeted advertising; sensitive personal information; profiling; cloud services The chapter concludes with an update on key legal and regulatory developments over the past year and emerging trends in Vietnam’s data protection landscape. The full Vietnam chapter is available as a PDF through the button below. Readers can also gain 30 days of complementary access to the full Data