You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 20, 2017

New Computer Crimes Act to Tackle Cybercrime amid Public Concerns over Online Freedom

Bangkok Post, Corporate Counsellor Column

The Thai government’s attempts to revamp the 2007 Computer Crimes Act (CCA) and grant authorities more power to investigate and apprehend perpetrators of increasingly diverse cybercrimes has raised consternation among internet users who fear the new and more stringent law may impinge on human rights and place restrictions on online activity in the country.

Thailand’s National Legislative Assembly (NLA) passed draft amendments to the 2007 Computer Crimes Act (CCA) on December 16, 2016, and it is now awaiting publication in the Government Gazette. The law will come into effect 120 days after its publication date.

According to a report issued by the NLA committee responsible for drafting the CCA, the amendments are intended to:

  • Enhance and update the 2007 CCA, which is outdated due to rapid changes in the nature of cybercrimes;
  • Introduce new committees; and
  • Adjust and rationalize the authority of officials under the new law.

However, the public appears not to share the government’s thinking behind this rationale, and before the law was passed, more than 340,000 people signed a petition objecting to the amendments as they believe the new CCA gives excessively broad authority to government agencies to act against online content containing information that is deemed inappropriate.

The activists fear abuse of the new enhanced powers under the new law could adversely affect the rights of people both inside and outside the country, and particular attention is focused on Sections 14, 18, and 20 of the CCA.

Under the new NLA-approved CCA, Section 14 introduces more offenses and offers more room for interpretation. Under this controversial section, the public are prohibited from entering (or knowingly sharing) a computer system that causes “damage to the public, creates panic, or causes harm to public infrastructure, national security, public security, or economic security.”

The broad scope of the new Section 14 operates as a catch-all for a wide range of offenses, thus compelling online users—including businesses—to be more discrete and mindful of publicly sharing information. Some argue this will force users to be more responsible in disseminating content online, while others contend that it serves to restrict freedoms for internet users.

Section 18 has also been severely criticized, as it broadly empowers officers investigating an offense under the CCA or other laws to enquire, request, access, seize, duplicate, and unlock computer systems to obtain the data in question. However, a court order is specifically required for the access, seizure, duplication, or hacking (unlocking) of computer systems that are not in the possession of the officers.

Although no mechanism is prescribed under the law detailing how the courts should exercise their judicial discretion in granting or declining an order, the wording of this section appears intended to limit questions about whether officers are deliberately or excessively exercising their broad authority over the unpossessed computer data.

But Section 18 does not require officers to obtain a court order if they wish to request Service Providers, such as online access providers or social media platforms, to provide “traffic data” information to facilitate an investigation into an offense under the CCA or other laws. Although the public has questioned why a court order is not required, these new powers will undoubtedly cause businesses and other public users to be more mindful of handling their “traffic data,” which could also be interpreted to include data messages sent through work or personal devices and computers.

Section 20 of the new CCA requires the formation of a new Computer Data Screening Committee to be appointed by the Digital Ministry, wherein three out of nine members must be representatives from the private sector, including human rights, media, and other related fields.

This new committee will have the authority to consider and provide second-tier approval to censor “inappropriate” computer data (i.e., defined as against good morals or public order) before the request to censor the “inappropriate” computer data can be submitted for court approval. The subsequent granting of a court approval will result in such data being censored. However, the public have questioned whether authorities need this type of oversight of all inappropriate computer data.

Public attention is now focused squarely on the Digital Ministry, the authority charged with ensuring the smooth implementation of the new CCA. The NLA drafting committee has recommended that the ministry conduct training and educate officials so they have a better understanding of cybercrime investigations and computer data evidence collection, to ensure enforcement of the CCA complies with their intentions.

It is hoped that correct and efficient enforcement by authorities will ease public concerns over the new Computer Crimes Act, although undoubtedly, concerns will remain as the public continues to debate whether the new act is wholly appropriate for computer and online users in Thailand. All business operators in Thailand will need to closely monitor the CCA’s implementation and enforcement to ensure compliance.

RELATED INSIGHTS​ 

April 10, 2026
Thailand has introduced new regulatory guidance requiring digital platform operators to adopt structured, transparent, and fair fee practices. On March 16, 2026, the Electronic Transactions Development Agency (ETDA) published Announcement No. DPS 2/2569, titled “Guidelines for Transparency and Fairness in Digital Platform Service Fee Determination,” issued under the Royal Decree on Digital Platform Service Business Operations B.E. 2565 (2022). The guidelines establish a framework governing how digital platform operators should set, disclose, and adjust fees charged to users and related service providers such as logistics and payment providers. Although framed as best-practice guidance rather than legally binding rules with explicit penalties, the guidelines carry regulatory weight under the royal decree and represent a significant step toward structured governance of digital platform fee practices in Thailand. The guidelines establish various transparency principles and divide fees into two distinct categories—compulsory and additional—with specific governance principles for each. Transparency Principles The guidelines recommend that digital platform operators adopt several transparency measures to ensure that users can fully understand the costs of using a platform. Fee catalog. All fees should be consolidated into a single, accessible location, which should include the fee name, definition, scope of covered services, calculation methodology, rate, billing period, and calculation examples. Minimum service disclosure. Operators should disclose the minimum service that users can expect, such as baseline visibility, product listing capabilities, access to transaction data, and back-end dashboard access. Price structure disclosure. Operators should disclose the categories of costs underlying their fees, such as system maintenance, cybersecurity, and operational costs. While exact cost figures need not be made public, operators should be able to provide numerical data to regulators upon request. Clear fee formulas. Fee calculations should be simple and easy to understand—for example, percentage of net sales, cost per order, or cost per product listing. Operators should
April 10, 2026
As digital commerce continues to reshape consumer behavior in Thailand, the Office of the Consumer Protection Board (OCPB) has been taking steps to review and update key regulations for online platforms. The OCPB has had a particular focus on addressing the risks posed by e-marketplace businesses—from misleading product information to fraudulent online transactions. Some of the regulator’s current legislative efforts related to Thailand’s labeling regulations as well as potential changes to the country’s law on direct sales and marketing. Proposed Changes to Consumer Protection Labeling Regulations On February 24, 2026, the OCPB convened a public hearing to review the Notification of the Committee on Labels re: Specification of Goods as Controlled Label Goods B.E. 2565 (2022) and its annex issued under the Consumer Protection Act. The closed-door session, which started the OPCD’s process of seeking feedback on the proposed changes, brought together representatives from government agencies, business operators, and consumer groups. The OCPB explained that its review of the labeling regulations aims to address regulatory gaps arising from evolving commercial practices, particularly the expansion of e-commerce and cross-border transactions. Authorities highlighted recurring issues involving product information that is unclear, incomplete, or potentially misleading in digital sales channels. The proposed revisions are intended to improve consumers’ access to accurate and complete product information, ensure that label disclosures remain relevant amid the growth of e-commerce, and strengthen protections against deceptive or misleading digital advertising. The review is being undertaken pursuant to the Consumer Protection Act B.E. 2522 (1979). As part of the initiative, the OCPB signaled a potential update to the categories of “controlled label products” as well as enhanced disclosure obligations for business operators, with the broader aim of promoting greater transparency, reinforcing operator accountability, and aligning Thailand’s labeling framework with current market conditions. The OCPB secretary general emphasized that
April 9, 2026
As part of its ongoing public consultation process for the development of new practical guidelines under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), Thailand’s Personal Data Protection Committee (PDPC) held a two‑day public hearing on April 1–2, 2026. The hearing followed an online questionnaire and stakeholder engagement activities conducted in March 2026 and reflects the PDPC’s continued efforts to develop guidance that aligns international regulatory standards with Thai operational realities. The public hearing provided a forum for participants from both the public and private sectors to exchange views with the PDPC on the proposed guidance so that it responds to the needs of the business community while supporting effective and balanced enforcement of the PDPA. The PDPC emphasized that the consultation process is part of a wider policy objective to build trust in the convenient, secure, and internationally aligned exchange of data. Structure of the Consultation Process According to the PDPC, the initiative to develop the draft PDPA guidelines is being implemented through three core phases: Review of international best practices. The PDPC has conducted a comparative review of data protection guidance and regulatory approaches in jurisdictions with internationally recognized standards, including Singapore, the United Kingdom, the European Union (EU), and Japan. These materials are intended to serve as a reference point for developing practical recommendations across key subject areas under the PDPA. Identification of practical issues and challenges. To ensure that the guidelines respond to real‑world compliance challenges in Thailand, the PDPC has gathered views from a broad range of stakeholders across the public sector, the private sector, and the general public. This phase included focus group discussions and questionnaires aimed at identifying areas to provide organizations with greater clarity and consistency on regulatory expectations. Preparation of draft guidelines. Insights from the comparative study and stakeholder
April 3, 2026
On March 16, 2026, Vietnam’s Ministry of Public Security released a draft version of a new Decree on the Prevention and Combating of Cybercrime and High-Tech Crime to replace the currently effective Decree 25/2014/ND-CP. In the draft, the ministry has proposed a comprehensive regulatory framework aimed at addressing violations occurring within the cybersecurity domain, including measures related to intellectual property. Acts of Online IP Infringement Article 9 of the draft decree notably introduces specific provisions addressing online intellectual property infringement, with detailed lists of acts considered to constitute infringement in the online environment. Copyright and related rights infringement includes: Uploading or sharing works, performances, sound recordings, video recordings, broadcasts, computer programs, software, research, documents, theses, or other intellectual creations on digital platforms without the consent of the rights holder. Unauthorized livestreaming of copyrighted television programs, sporting events, or artistic performances. Uploading, sharing, storing, transmitting, or providing links to infringing works or digital content via websites, social networks, applications, or digital platforms. Providing or using software, tools, devices, or access codes to circumvent technological protection measures or evade lawful control mechanisms implemented by rights holders. Using artificial intelligence (AI) tools to replicate the ideas or structure of another person’s work without significant new creativity or without proper attribution, thereby causing damage to the original author. Industrial property infringement includes: Manufacturing, trading, advertising, or distributing counterfeit goods bearing counterfeit trademarks, geographical indications, or industrial designs, as well as goods infringing industrial property rights through online platforms. Unauthorized registration, appropriation, or use of domain names, account names, or digital identifiers that create confusion regarding the rights holder or the origin of goods or services. Producing, using, or offering for sale products containing all or part of a patented invention via online platforms. Advertising or introducing products with technical features or characteristics identical