You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 14, 2021

Lex Mundi Guide to Doing Business in Thailand 2021

Tilleke & Gibbins and Lex Mundi

As part of its membership in Lex Mundi, Tilleke & Gibbins has published an updated edition of its Guide to Doing Business in Thailand for 2021. This guide outlines all of the key factors for starting and operating a business in the Thai market. Issues covered include:

  • Investment incentives
  • Financial facilities
  • Exchange controls
  • Import and export regulations
  • Structures for doing business
  • Requirements for the Establishment of a Business
  • Operation of the Business
  • Cessation or Termination of the Business
  • Labor legislation, relations, and supply
  • Tax
  • Immigration requirements

This publication is part of Lex Mundi’s Guides to Doing Business series prepared by member firms in more than 100 jurisdictions worldwide. The guides serve as a useful resource when planning an international business strategy or researching a new market.

RELATED INSIGHTS​ 

June 5, 2026
On May 25, 2026, Vietnam’s Ministry of Health issued Circular No. 16/2026/TT-BYT governing free-of-charge medicine support programs for medical establishments (Circular 16). Circular 16 will take effect on July 10, 2026, replacing Circular No. 31/2018/TT-BYT, which currently regulates the same subject matter. Circular 16 introduces several significant changes compared to the existing legal framework. Removal of Prior Approval Requirement Under the current regulations, free-of-charge medicine support programs are divided into two categories: (1) entirely free-of-charge provision of medicines for all types of drugs and (2) partially free-of-charge provision applicable only to brand-name drugs under patent protection or drugs whose generic products with identical active ingredients and dosage forms are available in Vietnam. Under the current regulations, partially free-of-charge programs are subject to mandatory registration with the competent authority, while entirely free-of-charge programs could be implemented without prior approval. A key reform under Circular 16 is that it stipulates only entirely free-of-charge medicine support programs applicable to all types of medicines, thereby eliminating the partially free-of-charge category. In addition, free-of-charge medicine support programs may be carried out solely based on a written agreement between the pharmaceutical company and the medical establishment, without any requirement for prior approval from competent authorities prior to implementation. Written Agreement Requirements Circular 16 requires the pharmaceutical company and medical establishment to enter into a written agreement in accordance with a prescribed template. This agreement must include the following compulsory information: Information on the supported medicines Form of support (entirely free-of-charge provision to patients) Quantity of medicines provided Target patient groups and applicable indications Duration of the program Rights and obligations of each party Transitional provisions on the protection of patients’ rights upon completion of the program The agreement may contain other contents as agreed by the parties, provided that these do not contradict applicable laws.
June 5, 2026
Thailand’s Office of Insurance Commission (OIC) has opened a public hearing on proposed amendments to the OIC Notification on Criteria for Information Technology Risk Governance and Management for Life Insurance and Non-Life Insurance Companies B.E. 2563 (2020) via the centralized Law platform. The public consultation period runs from May 8, 2026, to June 9, 2026. The proposed amendments aim to elevate the IT risk governance and cybersecurity risk management framework to be more modern and aligned with international standards, with a focus on strengthening cyber resilience, enhancing the role of IT audits, and establishing data governance and data quality controls. The parties affected by these amendments include life insurance companies, non-life insurance companies, and external IT auditors. Key Changes Elevated Role of Board of Directors The proposed notification requires the company’s board of directors to oversee data governance, cybersecurity, and the responsible use of AI. Additionally, the board should include at least one director with IT knowledge or experience. Companies are also required to designate a head of security responsible for information security. The board’s duties are expanded to include oversight of data governance and AI usage, including establishing relevant policies and committees. Enhanced IT Security and Cybersecurity The revised notification consolidates the existing chapters on IT project management, IT security and cybersecurity to reduce redundancy, and introduces significant new measures. These include mandatory multi-factor authentication for material systems, enhanced data security measures such as data masking and data leakage prevention, security hardening requirements, web filtering, and mandatory vulnerability assessment and penetration testing at least annually. New requirements are also introduced for mobile application security, API security, and security measures for emerging technologies such as cloud computing and post quantum cryptography. The cybersecurity framework now encompasses identification, protection, detection, response, and recovery. The draft also introduces source code review
June 5, 2026
Vietnam’s AI regulatory framework has reached an important milestone. While the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law) established the foundation for AI governance, many practical compliance requirements were left to implementing regulations. On April 30, 2026, the government issued Decree No. 142/2026/ND-CP (Decree 142), which took effect on May 1, 2026, and provides the first detailed guidance on the implementation of the AI Law. Although an official list of high-risk AI systems is still pending from the prime minister, Decree 142 provides valuable insight into how Vietnam’s risk-based AI regulatory framework will operate in practice. Risk Classification Framework The AI Law adopts a risk-based approach under which AI systems are classified as high-risk, medium-risk, or low-risk. Decree 142 builds on this framework by providing detailed guidance on how these classifications are determined. High-risk AI systems are determined based on factors such as (i) their potential impact on life, health, property, human rights, public interests, or national security; (ii) the sector in which they are deployed; and (iii) the scale of affected users or integration with critical infrastructure. The latest draft list of high-risk AI systems appears to follow these same principles. Medium-risk AI systems generally include systems that may mislead, influence, or manipulate users, particularly where users may not realize they are interacting with AI or AI-generated content. The focus is therefore on transparency and authenticity risks rather than broader societal or safety concerns. Low-risk AI systems are those that do not meet the criteria for either high-risk or medium-risk classification. Importantly, Decree 142 seeks to avoid over-classification. Certain systems may fall outside the high-risk or medium-risk regimes, including internal-use systems, office-support tools, technical editing applications, certain back-end processing systems, and AI systems used in artistic, gaming, cinematic, or other creative contexts. Providers must also review and
June 5, 2026
On May 11, 2026, Thailand’s Ministry of Social Development and Human Security released a draft Child Protection Act (“CPA”) for public review. The draft CPA would completely repeal and replace the current Child Protection Act B.E. 2546 (2003). This represents the most comprehensive overhaul of Thailand’s child protection framework in over two decades, reflecting the government’s stated objective of modernizing the law to address evolving social challenges—including those arising from digital technology—and to promote greater coordination among government agencies, local authorities, and civil society. The public review period closes on June 9, 2026. Key changes introduced by the draft CPA that could have significant implications for businesses, particularly online platform providers, media companies, and entities operating child-related services in Thailand, are set out below. Expanded Definition of “Child” Under the current CPA, a “child” is defined as a person under the age of 18, excluding those who have attained legal majority through marriage. The draft CPA removes the marriage exception entirely, broadening the scope of the law’s protections to include all individuals under 18 without exception. Replacement of “Abuse” with Broader Concept of “Violence” The current CPA uses the term “abuse/cruelty,” which covers acts causing harm to a child’s liberty, body, or mind; sexual offenses against children; and using children in harmful or immoral activities. The draft CPA replaces this with the broader concept of “violence,” which encompasses any act or omission causing harm to a child’s body, mind, or development; abandonment or neglect; improper exploitation; and sexual abuse. Notably, the new definition adds developmental harm as a recognized category of injury and captures all forms of misconduct regardless of the child’s consent. New Standalone Definition of Sexual Abuse, Including Online Conduct One of the most significant additions in the draft CPA is the introduction of a standalone definition