You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 24, 2017

PLC Doing Business in … Global Guide 2017 – Thailand Chapter

Practical Law Company in Association with Lex Mundi

The 2017 edition of Doing Business In…, a Q&A-style guide published by Practical Law Company in collaboration with Lex Mundi, presents an overview of recent legal developments affecting doing business in 51 jurisdictions worldwide. The Thailand chapter of the guide was written by attorneys from Tilleke & Gibbins and presents an overview of Thailand’s legal system and key laws applicable to foreign companies doing business in the Kingdom. The chapter specifically covers the following main topics:

  • Legal System: Thailand’s codified legal system and hierarchy of laws including Constitutional Acts, Organic Acts, Royal Ordinances, Royal Decrees, and Ministerial Regulations.
  • Foreign Investment: Lists of reserved business activities, restrictions on doing business with certain jurisdictions, exchange controls and currency regulations, and grants and incentives—including merit-based incentives—available to investors.
  • Business Vehicles: Ordinary partnerships, registered ordinary partnerships, limited partnerships, private limited companies, and public companies.
  • Employment: Laws, employment contract requirements, work permits, and termination and redundancy.
  • Tax: Taxes on employment, tax and nontax resident employees and businesses, corporate income tax, value added tax, special business tax, municipal tax, stamp duty, dividends, interest, intellectual property royalties.
  • Competition: The existing and new draft version of Thailand’s Trade Competition Act, as well as merger control.
  • Intellectual Property: Patents, trademarks, registered and unregistered designs, and copyright.
  • Advertising: Thailand’s Consumer Protection Act and role of the Consumer Protection Board and Food and Drug Administration.
  • Product Liability: The Unsafe Goods Liability Act and the Consumer Case Procedure Act.

To read the Thailand chapter, please visit the PLC website or click on the PDF below.

RELATED INSIGHTS​ 

June 24, 2025
Insurance specialists from Tilleke & Gibbins in Bangkok have contributed the Thailand chapter to the newly released 2025 edition of Thomson Reuters’ Practical Law guide to insurance and reinsurance. The Thailand chapter offers a comprehensive Q&A-style overview of the legal and regulatory framework governing insurance and reinsurance in the country. It provides key insights for businesses, insurers, reinsurers, and intermediaries operating in or entering the Thai market. Key topics covered include: Market structure and common types of insurance; Regulatory framework and oversight by the Office of Insurance Commission (OIC); Authorisation requirements for insurers, reinsurers, and intermediaries; Ownership restrictions and foreign investment rules; Corporate governance, capital requirements, and solvency obligations; Reinsurance arrangements, including fronting, risk transfer, and common contractual clauses; Policy content requirements, standard clauses, and consumer protections; Claims procedures, statutory time limits, and subrogation rights; Dispute resolution mechanisms, including OIC arbitration and court proceedings; Insolvency protections for policyholders; Tax treatment of insurance and reinsurance businesses in Thailand; Recent legal developments, including pending amendments to the Life and Non-Life Insurance Acts and updated OIC regulations on reinsurance and investment activities. The 2025 edition reflects Thailand’s evolving regulatory environment, including proposed legislative reforms to strengthen corporate governance, risk-based capital requirements, and financial stability in the insurance sector. It also highlights practical considerations for foreign insurers, reinsurers, and intermediaries seeking to participate in Thailand’s insurance market. Tilleke & Gibbins contributes regularly to the Practical Law series of guides for various jurisdictions in Southeast Asia, providing trusted legal insight for multinational companies. To access the latest Thailand chapter of the insurance and reinsurance guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
June 19, 2025
The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices. The BOT is accepting public comments on the draft guidelines until June 30, 2025. Scope and Application The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct. The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching. Key Risk Management Principles The guidelines lay out two main principles in managing AI risk. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows: Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management
June 19, 2025
Thailand’s Electronic Transactions Development Agency (ETDA) has announced plans for increased enforcement of the Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022). The ETDA outlined a comprehensive enforcement framework and review process during an online meeting with digital platform service operators on June 11, 2025. The ETDA’s enhanced enforcement approach includes systematic reviews of notification submissions, formal correction orders, and potential criminal penalties for noncompliance. Digital platform operators should immediately assess their current notification status and prepare for increased regulatory scrutiny. Review and Amendment of Previously Submitted Notification Data The ETDA will begin reviewing operation notification forms and annual reports submitted by digital platform service operators to assess each platform’s risk level and develop tailored regulatory obligations. In this comprehensive review process, the ETDA will: Examine the accuracy and completeness of submitted notification data; Request additional information as needed by phone or email; and Issue formal orders as needed requiring operators to correct or complete missing information. Operators who fail to comply with ETDA orders may face suspension of operations, revocation of their notification receipt, and public disclosure of their noncompliant status on the ETDA’s website. The ETDA will conduct follow-up workshops in July 2025 for operators whose data remains unclear or incomplete. Enforcement Framework and Penalties The ETDA outlined a three-tiered enforcement framework with escalating consequences for different types of violations, as follows: Failure to notify before commencing operations: Operators who begin services without proper notification may face criminal penalties under the Electronic Transactions Act, including up to one year of imprisonment, fines of up to THB 100,000 (approx. USD 3,070), or both. Additional consequences include suspension of operations and potential liability for company directors. Failure to correct or comply with official orders: Noncompliance with ETDA correction
June 13, 2025
In today’s digital age, cyberattacks have become a real threat to organizations worldwide. These attacks can range from phishing and malware to ransomware and distributed denial of service (DDoS) attacks. As the frequency and sophistication of these attacks increase, so does the importance of cybersecurity compliance. In the corporate world, compliance refers to the process of ensuring that a company and its employees adhere to all relevant laws, regulations, standards, and ethical practices—but it should not stop there. Compliance should also encompass asset recovery and disciplinary measures, which can both help organizations address incidents effectively and promote good governance. Cyberattacks are malicious attempts to access or damage a computer system or network, often carried out for financial gain, for political activism, or simply to cause disruption. For instance, a successful attack might involve an attacker creating an email address that closely resembles a legitimate one, perhaps by changing only one or two characters. That email address is then inserted into an existing conversation thread, making it appear as if the user with this email address was already part of the discussion. This tactic can easily deceive a recipient into believing the email was sent from a trusted source, thereby leading them to click on malicious links, provide sensitive information, or even make payments in accordance with the attacker’s request or instructions. Phishing attacks like these are particularly dangerous and can have a serious impact on the ongoing business of a corporation because they exploit the trust and familiarity established in the original email chain. Effective Mitigation Approaches Mechanisms for addressing the aftermath of a crisis provide important recourse to affected organizations, but effective compliance mechanisms can minimize the risk of such crises ever occurring. Companies should therefore prioritize preventative measures and implementation of effective crisis management schemes. Various legal