You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 23, 2015

IT Law Update (Part 1): The Cybersecurity Bill

Bangkok Post, Corporate Counsellor Column

Earlier this month, the cabinet approved a series of bills related to information technology, personal data, cybersecurity, and telecommunications. One such bill would recast the Information and Communication Technology Ministry as the Digital Economy and Information Technology Ministry to reflect the importance of IT in Thailand’s economy—the same rationale behind the entire set of bills. This article focuses on one of these bills, the Cybersecurity Bill. Next week in a follow-up article, we will discuss another one of these bills, the Bill to Amend the Computer Crimes Act.

Given recent events, governments around the world are focusing on threats occurring over the Internet, as well as attacks using computing equipment and networks and how to counteract these threats to improve overall security. Thailand is no different. The Cybersecurity Bill, as approved by the cabinet, would establish a National Cybersecurity Committee and a new state agency, the Office of the National Cybersecurity Committee, to focus on these issues.

The committee would have the responsibility to determine how to respond to serious cyberthreats, effectively to serve as the center of operations in the event of an IT calamity (save for matters of military security) and cooperate with other state bodies and private entities for this purpose, among related responsibilities. The Office of the National Cybersecurity Committee would be responsible for implementing the committee’s policies, as well as related responsibilities specified in law.

The Bill also features a reporting mechanism for state agencies and/or designated persons in each agency to provide information to the secretary of the committee so it could determine what further actions to take in response to particular cyberthreats. Further, where maintaining cybersecurity is necessary—for example, in a case where there may be an effect on financial and commercial stability or national security—the committee may even order a state agency to take particular actions and report as the committee may instruct.

It is envisaged that the minister overseeing the committee would appoint officials to perform certain roles. These officials, in turn, may be authorized by the secretary of the office to request a state agency or any person to give testimony, submit a written explanation, or submit materials for inspection or information—all within the scope of the Act—or request state agencies or private entities to facilitate the committee’s performance of its duties.

The Bill also would empower officials to access communications information, be it in the form of posts, telegrams, telephones, faxes, computers, or any mechanism or device for electronic communication or telecommunications, for the purpose of cybersecurity. However, it also contemplates that the cabinet would specify rules for officials to follow in accessing such information, presumably for the purpose of addressing privacy concerns.

The law also contains provisions to protect such information and to prevent its disclosure, except in cases of prosecution under the Act, abuse of power, or as otherwise authorized by a court.

The most controversial provision of the Bill relates to accessing personal communications content. Indeed, commentators around the world have expressed concerns about access to personal communications by state agencies of various countries. These concerns are understandable and legitimate. Nevertheless, current public discourse seems to reflect that policymakers’ concerns about terrorism and national security are outweighing traditional concerns about personal privacy.

In Thailand, the practical reality is state agencies already have access to communications content under a variety of other laws. Hence, the provisions in the Cybersecurity Bill do not substantially expand the state’s ability to access such information. Rather, in the larger picture, the Bill would seem to envisage the establishment of a framework for such access.

All countries need to focus on cybersecurity, and the Cybersecurity Bill lays out a framework for this in Thailand. The reality is that it is impossible to predict all possible cyberthreats that may arise, which is why the Bill gives effect to plans and policies to be adopted by the National Cybersecurity Committee. In that regard, the success of the Bill will ultimately depend on those plans and policies, which would be expected to undergo continual adjustment and updates to meet current threats.

In next Friday’s article, we will discuss the proposed changes to the Computer Crimes Act—changes that may be a cause for concern for some.

RELATED INSIGHTS​ 

April 10, 2026
Thailand has introduced new regulatory guidance requiring digital platform operators to adopt structured, transparent, and fair fee practices. On March 16, 2026, the Electronic Transactions Development Agency (ETDA) published Announcement No. DPS 2/2569, titled “Guidelines for Transparency and Fairness in Digital Platform Service Fee Determination,” issued under the Royal Decree on Digital Platform Service Business Operations B.E. 2565 (2022). The guidelines establish a framework governing how digital platform operators should set, disclose, and adjust fees charged to users and related service providers such as logistics and payment providers. Although framed as best-practice guidance rather than legally binding rules with explicit penalties, the guidelines carry regulatory weight under the royal decree and represent a significant step toward structured governance of digital platform fee practices in Thailand. The guidelines establish various transparency principles and divide fees into two distinct categories—compulsory and additional—with specific governance principles for each. Transparency Principles The guidelines recommend that digital platform operators adopt several transparency measures to ensure that users can fully understand the costs of using a platform. Fee catalog. All fees should be consolidated into a single, accessible location, which should include the fee name, definition, scope of covered services, calculation methodology, rate, billing period, and calculation examples. Minimum service disclosure. Operators should disclose the minimum service that users can expect, such as baseline visibility, product listing capabilities, access to transaction data, and back-end dashboard access. Price structure disclosure. Operators should disclose the categories of costs underlying their fees, such as system maintenance, cybersecurity, and operational costs. While exact cost figures need not be made public, operators should be able to provide numerical data to regulators upon request. Clear fee formulas. Fee calculations should be simple and easy to understand—for example, percentage of net sales, cost per order, or cost per product listing. Operators should
April 10, 2026
As digital commerce continues to reshape consumer behavior in Thailand, the Office of the Consumer Protection Board (OCPB) has been taking steps to review and update key regulations for online platforms. The OCPB has had a particular focus on addressing the risks posed by e-marketplace businesses—from misleading product information to fraudulent online transactions. Some of the regulator’s current legislative efforts related to Thailand’s labeling regulations as well as potential changes to the country’s law on direct sales and marketing. Proposed Changes to Consumer Protection Labeling Regulations On February 24, 2026, the OCPB convened a public hearing to review the Notification of the Committee on Labels re: Specification of Goods as Controlled Label Goods B.E. 2565 (2022) and its annex issued under the Consumer Protection Act. The closed-door session, which started the OPCD’s process of seeking feedback on the proposed changes, brought together representatives from government agencies, business operators, and consumer groups. The OCPB explained that its review of the labeling regulations aims to address regulatory gaps arising from evolving commercial practices, particularly the expansion of e-commerce and cross-border transactions. Authorities highlighted recurring issues involving product information that is unclear, incomplete, or potentially misleading in digital sales channels. The proposed revisions are intended to improve consumers’ access to accurate and complete product information, ensure that label disclosures remain relevant amid the growth of e-commerce, and strengthen protections against deceptive or misleading digital advertising. The review is being undertaken pursuant to the Consumer Protection Act B.E. 2522 (1979). As part of the initiative, the OCPB signaled a potential update to the categories of “controlled label products” as well as enhanced disclosure obligations for business operators, with the broader aim of promoting greater transparency, reinforcing operator accountability, and aligning Thailand’s labeling framework with current market conditions. The OCPB secretary general emphasized that
April 9, 2026
As part of its ongoing public consultation process for the development of new practical guidelines under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), Thailand’s Personal Data Protection Committee (PDPC) held a two‑day public hearing on April 1–2, 2026. The hearing followed an online questionnaire and stakeholder engagement activities conducted in March 2026 and reflects the PDPC’s continued efforts to develop guidance that aligns international regulatory standards with Thai operational realities. The public hearing provided a forum for participants from both the public and private sectors to exchange views with the PDPC on the proposed guidance so that it responds to the needs of the business community while supporting effective and balanced enforcement of the PDPA. The PDPC emphasized that the consultation process is part of a wider policy objective to build trust in the convenient, secure, and internationally aligned exchange of data. Structure of the Consultation Process According to the PDPC, the initiative to develop the draft PDPA guidelines is being implemented through three core phases: Review of international best practices. The PDPC has conducted a comparative review of data protection guidance and regulatory approaches in jurisdictions with internationally recognized standards, including Singapore, the United Kingdom, the European Union (EU), and Japan. These materials are intended to serve as a reference point for developing practical recommendations across key subject areas under the PDPA. Identification of practical issues and challenges. To ensure that the guidelines respond to real‑world compliance challenges in Thailand, the PDPC has gathered views from a broad range of stakeholders across the public sector, the private sector, and the general public. This phase included focus group discussions and questionnaires aimed at identifying areas to provide organizations with greater clarity and consistency on regulatory expectations. Preparation of draft guidelines. Insights from the comparative study and stakeholder
April 3, 2026
On March 16, 2026, Vietnam’s Ministry of Public Security released a draft version of a new Decree on the Prevention and Combating of Cybercrime and High-Tech Crime to replace the currently effective Decree 25/2014/ND-CP. In the draft, the ministry has proposed a comprehensive regulatory framework aimed at addressing violations occurring within the cybersecurity domain, including measures related to intellectual property. Acts of Online IP Infringement Article 9 of the draft decree notably introduces specific provisions addressing online intellectual property infringement, with detailed lists of acts considered to constitute infringement in the online environment. Copyright and related rights infringement includes: Uploading or sharing works, performances, sound recordings, video recordings, broadcasts, computer programs, software, research, documents, theses, or other intellectual creations on digital platforms without the consent of the rights holder. Unauthorized livestreaming of copyrighted television programs, sporting events, or artistic performances. Uploading, sharing, storing, transmitting, or providing links to infringing works or digital content via websites, social networks, applications, or digital platforms. Providing or using software, tools, devices, or access codes to circumvent technological protection measures or evade lawful control mechanisms implemented by rights holders. Using artificial intelligence (AI) tools to replicate the ideas or structure of another person’s work without significant new creativity or without proper attribution, thereby causing damage to the original author. Industrial property infringement includes: Manufacturing, trading, advertising, or distributing counterfeit goods bearing counterfeit trademarks, geographical indications, or industrial designs, as well as goods infringing industrial property rights through online platforms. Unauthorized registration, appropriation, or use of domain names, account names, or digital identifiers that create confusion regarding the rights holder or the origin of goods or services. Producing, using, or offering for sale products containing all or part of a patented invention via online platforms. Advertising or introducing products with technical features or characteristics identical