You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 14, 2021

New Digital Asset Business Requirements for Businesses in Thailand

On November 26, 2020, the Notification of the Ministry of Finance Re: Addition to Other Business Relating to Digital Assets B.E. 2563 (2020) (the Digital Asset Business Notification) and the Notification of the Ministry of Finance Re: Licensing of Digital Asset Business No. 2 B.E. 2563 (2020) (the Digital Asset Business Licensing Notification) were published in the Thai Government Gazette.

Additional Digital Asset Businesses

The new Digital Assets Business Notification adds two new categories of digital assets business to the list prescribed in the Royal Decree on Digital Asset Businesses B.E. 2561 (2018).

  • Digital Asset Fund Manager is defined as a person who manages funds from digital assets for another person for benefits, or holds themselves out to the general public as being ready to do so, in the ordinary course of business. It does not include the management of digital assets as prescribed by the Securities and Exchange Commission (SEC).
  • Digital Asset Advisory Service is defined as a person who provides consultations to other people, directly or indirectly, regarding the value of digital assets; the suitability of investment in digital assets; or the buying, selling, or exchanging of any digital assets in the ordinary course of business in return for service fees or other compensation. However, this does not include consultations as a part of or relating to a digital asset exchange, digital asset broker, digital asset dealer, digital asset fund manager, or other personal consultation as prescribed by the SEC.

Additional Digital Asset Licensing Requirements

The Digital Asset Business Licensing Notification amends the definition of “License Applicant” to include cryptocurrency exchanges, digital token exchanges, cryptocurrency brokers, digital token brokers, cryptocurrency dealers, digital token dealers, cryptocurrency fund managers, digital token fund managers, cryptocurrency advisory services, and digital token advisory services.

Additional requirements for granting licenses have also been added in the new Digital Asset Business Licensing Notification, including:

  • the licensee must never have been denied a license or had a license revoked in the last six months from the date of the application submission;
  • the licensee’s application must not be a replacement of a previous application that has been withdraw by the licensee; and,
  • the licensee must not currently be under any legal proceedings for any violation of law.

The digital assets business must commence within 180 days after receiving licensing approval.

Digital Asset Fund Managers and Digital Asset Advisory Services already in operation are required to apply for a license from the SEC within 90 days after this Digital Asset Business Licensing Notification comes into force (i.e. by February 25, 2021). Once an application has been filed with the SEC, the applicant is allowed to continue operating their business until the SEC issues an order to decline the application.

The Digital Asset Business Licensing Notification also updates the application fees.

For more details on these notifications, or on any aspect of Thai law relating to digital assets or currencies, please contact Charuwan Charoonchitsathian at [email protected], Nopparat Lalitkomon at [email protected] or Teelada Rujirawanichtep at [email protected].

 

RELATED INSIGHTS​ 

August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with
August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention
July 30, 2025
Artificial intelligence (AI) model training and data scraping are essential processes in the development of modern AI systems. AI model training involves using large datasets to teach machine learning algorithms to recognize patterns, make predictions, or generate new content. Data scraping refers to the automated extraction of information from websites or digital sources, often to assemble the vast datasets required for effective AI training. As these practices become more widespread, questions about the legality of using third-party content—especially copyrighted works—have become increasingly important. In Thailand, the legal landscape for AI developers is shaped primarily by the Copyright Act, which presents unique challenges due to the absence of a fair-use exception. This article examines the copyright-related risks and legal uncertainties facing AI developers under Thailand’s current copyright law and practices, offering strategic guidance for navigating this complex environment. Copyright Risks in AI Scraping and Training Thailand’s Copyright Act does not provide a broad fair use or fair dealing exception, unlike some other jurisdictions, such as the United States. This absence has significant consequences for AI developers: No general defense for AI training: Any use of copyrighted material for AI model training is presumed to be infringing unless a specific, narrow statutory exception applies or explicit permission is obtained from the rights holder. There is no general legal basis for using copyrighted works in AI training without authorization. Increased rights clearance burden: Developers must identify and secure licenses for every copyrighted work included in their training datasets. Given the scale and diversity of data required for effective AI models, this process can be both impractical and costly. Legal ambiguity and litigation risk: The lack of clear statutory guidance or case law leaves developers in a legal gray area. There is no established precedent clarifying whether certain uses of copyrighted material for
July 24, 2025
Thai authorities have escalated efforts to block unlawful cross-border digital asset business operators. On June 19, 2025, the Ministry of Digital Economy and Society (MDES) issued a notification empowering it to ban internet access to operations or services offered by digital asset business operators who lack licenses from the Thailand Securities and Exchange Commission (SEC) under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This ban, issued under the 2023 Royal Decree on Measures for the Prevention and Suppression of Technology Crime, particularly aims to block Thai users’ access to services offered by unlicensed offshore digital asset providers via their own apps or websites or through public social media platforms. Compliance Requirements The notification requires internet service providers and social media platforms selected by MDES to immediately impose internet access restrictions on identified apps, websites, and IP addresses of illegal operators upon receiving MDES orders. Takedown Orders There are two tracks for competent officials at MDES to issue orders to operators: If the competent official is notified by the SEC of licensing noncompliance by a particular digital asset business operator, the competent official can issue a takedown order to the operator upon approval from the permanent secretary of MDES. If the competent official independently discovers, or receives a complaint from any third party other than the SEC, that a digital asset business operator may have violated licensing requirements, the competent official can ask the SEC to verify and confirm the relevant facts and noncompliance before seeking approval from the permanent secretary of MDES to issue the takedown order. Streamlined Enforcement Prior to this notification, the SEC could obtain takedown orders only from Thai courts under the 2007 Computer Crime Act to take down or block access to unlicensed digital asset platforms and apps. This was a relatively