You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 19, 2016

Regulation of Domestic Debit Card Transactions in Thailand

Asian Banking & Finance

Back in 2012, Thailand’s Electronic Transactions Commission issued regulations that mandated domestic processing of domestic debit card transactions with debit cards issued in Thailand. It granted a grace period of one year for service providers to meet the new requirements. This was a policy goal that had been discussed and pursued for some time, with policymakers highlighting the cost savings that would be yielded by domestic processing, rather than offshore processing.

New regulations were issued in March 2016, which were published in the Government Gazette  in April. The changes in those regulations in relation to processing domestic debit card transactions mainly provided greater specificity and rules around outsourcing and requests for temporary exemptions from parts of the regulations.

More recently, in July, amendments were made to the regulations, and these were published in the Government Gazette  in August. Among other things, the new regulations refer to a chip card standard for debit cards, and they state that the standard is to be issued and imposed by the Bank of Thailand through discussions with the Thai Bankers’ Association, the Association of International Banks in Thailand, and the Council of State-Owned Financial Institutions.

Financial institutions that issue debit cards will be required to issue cards meeting this chip card standard, and the cards must be issued to use debit card networks in Thailand, unless an issuer utilizes its own system for processing the transactions. The regulations also affect consumer protection, in that they require issuers to provide users with information and details about the costs of each type of debit card that is sufficient, clear, and correct, so that users can use the service properly for their own purposes.

Where an issuer issues a card that is accepted on more than one network, at least one of those networks must be a domestic debit card network. In working with multiple networks, regulations require an issuer to observe its agreements and take account of the principle of equality.

The regulations also impose new obligations on acquirers. Specifically, they are required to have equipment and systems to accept debit cards that meet the aforementioned chip card standard and that utilize local debit card networks. Importantly, acquirers are prohibited from restricting the rights of merchants to use any debit card networks. They are also required to provide merchants with clear and accurate information on fees and services. In addition, where multi-network cards are processed, an acquirer must not charge any additional fees other than those for the network that is actually used.

Aside from issuers and acquirers, the regulations also set out additional requirements for service providers that provide switching service, clearing service, and settlement service. These service providers are required to arrange their systems to support debit cards on all debit card networks or to connect their systems with those of other service providers that provide switching, clearing, and settlement. In relation to cards that can be accepted on multiple networks, a service provider must not interfere with a merchant’s right to select a debit card network.

The new requirements are to be enforced from February next year. Consistent with earlier regulations, if an issuer or acquirer is unable to meet the new requirements, it can apply to the Bank of Thailand for additional time to come into compliance—up to an additional 180 days.  Also, for those cards issued prior to enforcement of the new requirements, they can continue to be used, but the issuer will eventually need to replace them with cards meeting the chip card standard by December 31, 2019.

These regulations follow an earlier announcement by the Bank of Thailand in May of this year that commercial banks in Thailand would, from May 16 onward, issue cards in conformity with the “Thai Bank Chip Card Standard,” which was established by the Thai Bankers’ Association. Last year, China UnionPay issued press releases about entering into a Chip Card Standard License Agreement with the Thai Bankers’ Association, which contemplated the adoption of China UnionPay’s chip card standard as “the standard of Thailand’s banking industry.” China UnionPay became a member of EMVCo in 2013, thus joining Visa, MasterCard, American Express, JCB, and Discover in the consortium that manages EMV standards (the technical standard for such chips). However, much has also been written about the compatibility problems between China UnionPay’s version of EMV, and the versions of EMV used by other card schemes such as MasterCard and Visa.

In referring to the chip card standard, the new regulations do not make specific reference to the China UnionPay standard, or any particular standard, for that matter. Moreover, in referring to the development of the chip card standard, the regulations make reference not only to discussions with the Thai Bankers’ Association, but also to the Association of International Banks in Thailand and the Council of State-Owned Financial Institutions, which is quite broad consultation.

China UnionPay is a major shareholder in Thailand Payment Network Co., Ltd. (TPN), established in 2014, which is one of the small number of companies that have been granted licenses necessary for providing switching and clearing services for domestic debit card transactions in Thailand. One can now see some debit cards issued by Bangkok Bank—the other major shareholder in TPN—that bear TPN branding, together with China UnionPay branding. In essence, TPN will compete with National ITMX Co., Ltd., which is owned by ten major banks in Thailand and has been providing local debit card switching services for some years.

As it now stands, most banks in Thailand issue Visa and MasterCard debit cards, each with EMV chips. It remains to be seen whether TPN and China UnionPay will become popular.  Customers like Visa and MasterCard because of their ease of acceptance, particularly when traveling overseas. In contrast, TPN has positioned itself as a low-cost provider for local transactions, which it says should enable merchants to accept TPN branded-cards for small transactions. Ultimately, more competition in the processing of domestic debit card transactions is good for merchants. Indeed, this has already prompted several banks to reduce their fees for debit card transactions. Thailand’s electronic payments landscape continues to excite.

RELATED INSIGHTS​ 

February 17, 2025
Thailand’s draft Emergency Decree on Technology Crimes Suppression, which we covered in a client alert in January 2025 primarily addressed to telecom operators and financial institutions, is expected to have significant implications for a wide range of business operators.  The draft emergency decree has already been approved by the cabinet but may undergo further developments as it continues in the legislative process. In this article, we will highlight the material impacts of the draft emergency decree on overseas and local fintech operators. Expanded Definition of “Technology Crimes” The definition of “technology crimes” now includes the following acts of forgery or alteration: Forging or altering the identity of individuals and biometric characteristics by utilizing computer or communication systems or other electronic means to commit offenses. Forging or altering symbols, trademarks, or seals of groups (e.g., foundations, community enterprises) or juristic persons, including acts by juristic persons using individuals or juristic persons as nominal directors or shareholders, regardless of whether such individuals or legal juristic persons reside in Thailand. Forging or altering digital or online platforms, regardless of the platform’s location or legal status. Individuals who conspire, utilize, assist, or support the commission of these offenses will face the same penalties as the principal offender. Business Operator Definition The scope of “business operators” is now expanded to cover various fintech and digital asset operators beyond those under the Payment Systems Act (PSA). The draft emergency decree now includes the following operators, whether they are legally authorized or not: Business operators under the PSA and business operators who operate “as if” they are payment system operators Business operators under the Royal Decree on Digital Asset Businesses or business operators who operate “as if” they are digital asset business operators. Foreign exchange business operators. Disclosure and Exchange of Information Business operators must disclose
January 30, 2025
The Thai cabinet has approved a draft amendment of the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes as proposed by the Ministry of Digital Economy and Society to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Following the Council of State’s review, the emergency decree will be become effective immediately upon its enactment and publication in the Government Gazette. While the draft amendment is not yet publicly available, the government recently indicated that the emergency decree aims to empower authorities with decisive measures to combat cybercrime effectively. It underscores the shared responsibility among various sectors, including banking, telecommunications, and online platforms, in safeguarding against technological crimes. Key provisions of the draft amendment of the emergency decree include: Telecommunications provider obligations: Telecommunications service providers must suspend SIM cards associated with criminal activities. The National Broadcasting and Telecommunications Commission and mobile service providers themselves are authorized to temporarily suspend mobile phone numbers if there is reasonable suspicion of involvement in criminal activities. Banking responsibilities: Financial institutions are required to promptly report mule accounts to the Anti-Money Laundering Office to facilitate quick restitution to victims. The Anti-Money Laundering Transaction Committee is empowered to order the return of funds to victims without requiring a final court ruling. Penalties for noncompliance: The amended emergency decree introduces penalties for noncompliance by regulated entities that fail to prevent criminal activities for offenses related to technology crimes in the following cases: Digital asset services: Those engaged in the buying, selling, or exchanging of digital assets, such as cryptocurrencies and digital tokens, as well as digital asset businesses that launder money obtained from online crimes by converting it into digital currency, will be subject to imprisonment for up to one year, a fine of up to THB 100,000,
January 22, 2025
Tasked with implementing the Politburo’s policy outlined in Notice No. 47-TB/TW dated November 15, 2024, the prime minister of Vietnam issued Decision No. 1718/QD-TTg on December 31, 2024, appointing himself as the head of a steering committee dedicated to the establishment of an international financial center in Ho Chi Minh City and a regional financial center in Da Nang by 2025. The Ministry of Planning and Investment has subsequently drafted an outline for the National Assembly’s Resolution on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Resolution”). This Draft Resolution introduces two key policy groups: (i) policies governing the quantity, location, structure, organization, functions, and responsibilities of the financial centers; and (ii) policies applicable to various areas and matters within the financial centers. Notably, under the Draft Resolution, fintech has been identified as a key sector, with a specific focus on the implementation of a “controlled sandbox” policy for business models involving virtual assets and cryptocurrencies. Under this framework, transactions related to virtual assets and cryptocurrencies will be permitted from July 1, 2026, subject to licensing, management, impact assessment, and risk oversight by the financial centers’ Management and Operations Committee. Scope of Application and Key Principles The Draft Resolution applies to a wide range of stakeholders, including investors, regulatory agencies, organizations, and individuals involved in the establishment, organization, and operation of regional and international financial centers in Vietnam. These financial centers will have clearly defined geographical boundaries and specific locations, which will be further specified and detailed by the People’s Committees of Ho Chi Minh City and Da Nang. Companies successfully registered as members of these financial centers will benefit from special investor-friendly policy principles, which may differ from the general legal and regulatory framework applicable in other parts of Vietnam. Most notably, the state will
January 13, 2025
The State Bank of Vietnam’s Circular No. 50/2024/TT-NHNN regulating safety and security for the provision of online services in the banking sector (“Circular 50”), issued on October 31, 2024, took effect on January 1, 2025, with delayed effectiveness for certain provisions on (i) network, communication, and security systems, online banking application software, and mobile banking application software (July 1, 2025); (ii) transaction confirmation for payment transactions conducted via the straight-through processing method (January 1, 2026); and (iii) authentication forms and reporting obligations (July 1, 2026). The cybersecurity situation in Vietnam is complicated, and the banking and finance sector has been one of the top targets of high-tech criminals. Circular 50 seeks to enhance user protection by expanding the technical requirements to more services in the banking sector as well as standardizing how transactions are authenticated. Expanded Scope of Services Covered Previous regulations on safety and security of online services in the banking sector only covered banking services and intermediary payment services. Circular 50 expands the scope to include other services of credit institutions and foreign bank branches such as credit information services, foreign exchange services, securities depository services, and services related to factoring and letters of credit, which now need to comply with technical requirements and standards for online services such as firewalls and DMZ network barriers. Risk-Based Approach to Authentication Circular 50 sets out standards for payment transactions and card transactions by: Classifying various online transactions based on the type of client, the purpose of the transfer, the value of the specific transaction, and the total value of certain transactions during the day; and Applying various types of authentication for the corresponding types of online transactions, e.g., using passwords or PINs for small-value online transactions, and using OTPs (through SMS, voice, or email), biometric matching, or e-signatures for