You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 5, 2021

Stablecoin Policy Guidelines Issued by Bank of Thailand

On March 19, 2021, the Bank of Thailand (BOT) issued policy guidelines on how stablecoins are to be regulated. These were issued following the BOT’s recent ruling that stablecoins pegged to the Thai baht violate the Currency Act B.E. 2501 (1958).

Stablecoins were developed to offer a more price-stable alternative to traditional cryptocurrencies, which are defined under Thai law as digital units created to serve as means of exchange for goods, services, or any other rights. As traditional cryptocurrencies (such as Bitcoin) have no underlying assets, they are subject to such extreme fluctuations in value, and therefore people often hold them as investments rather than spend them as currency.

Some stablecoins are pegged to the value of a specific fiat currency, such as the Thai baht, and are sometimes even intentionally created to mirror that fiat currency in name, denomination, and value.  The BOT reasoned that such stablecoins—seemingly created to replace Thai baht currency—violate the Currency Act B.E. 2501 (1958), because the public might incorrectly consider them a parallel baht currency.

The BOT’s subsequent policy guidelines on how stablecoins are to be regulated address both baht-pegged stablecoins and those pegged to other currencies or assets.

Stablecoins pegged to the Thai baht (or “baht-backed stablecoins”) that are intended to be used as a means of payment may be considered electronic money (e-money) under the Payment Systems Act B.E. 2560 (2017), which is regulated by the BOT. This type of stablecoin has similar characteristics and risk factors to existing e-money, for which the BOT has issued regulations governing various aspects such as settlement, money laundering, cybersecurity, and consumer protection. Consequently, business operators who intend to launch baht-backed stablecoins in the Thai market should consult with the BOT before doing so. To support their determination on this issue, the BOT notes that their position is consistent with those of other countries, such as Singapore, the UK, and Japan.

The BOT confirmed that stablecoins pegged to foreign currencies or other assets, including those with value backed by a digital mechanism rather than an asset (i.e., algorithmic stablecoins) are currently unregulated. However, the BOT is studying this topic and is open to receiving comments and feedback before deciding whether and how these stablecoins should be regulated.

The BOT itself is developing a cryptocurrency called a retail-type central bank digital currency (CBDC), similar to Digital Yuan of the People’s Bank of China and other government-developed digital currencies, to be freely used by the general public as a stable exchange of value for goods and services. The BOT believes that, when compared to privately issued stablecoins, a CBDC will be more secure and efficient and can meet the demands of all users and business operators.

Cryptocurrency and stablecoins are now at a regulatory crossroads, with Thai regulators set to determine their future. Conceptually, neither traditional cryptocurrency nor stablecoins are regulated under the Emergency Decree on Digital Asset Business Operation B.E. 2561 (2018), but businesses related to them are. The recent BOT rulings indicate some skepticism by Thai regulators toward stablecoins—especially those pegged to the Baht—and the possibility that their widespread introduction into Thailand could create a new and unregulated financial ecosystem that adversely impacts the stability of the financial sector, and by extension the country’s economic development. Nevertheless, the BOT well recognizes this technological development and is therefore actively engaging with it.

RELATED INSIGHTS​ 

August 1, 2025
Thailand’s Personal Data Protection Committee (PDPC) announced to the press on August 1, 2025, that it had issued eight new administrative fines under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) in five cases of noncompliance by public and private entities. The enforcement actions reflect a growing commitment by the PDPC to penalize noncompliance across all sectors, regardless of organizational type or size. The total amount imposed to date was approximately THB 21.5 million (approx. USD 654,690), underscoring the financial risks tied to PDPA violations. The five cases—one involving a state agency and the remainder in the private sector—are summarized below. Case 1: State Agency Providing Online Services to the Public The order in this case stemmed from a cyberattack on a state agency’s web app, resulting in personal data of 200,000 data subjects being leaked to and sold on the dark web. The software developer was also found to have implemented no privacy by design, lacked an access control system, had no data breach prevention measures, and failed to conduct risk assessments or review existing security measures. Key noncompliance identified: Lack of appropriate security measures Weak password protection No risk assessment or ongoing review of security measures No data processing agreement with software developer that acted as data processor The state agency and the developer were each fined THB 153,120 (approx. USD 4,670). Case 2: Private Hospital This case involved a hospital that engaged an individual contractor to destroy patient medical record documents. However, the contractor stored the documents at their own premises, failed to follow the required destruction protocols, and ultimately used the medical records to wrap sweets, resulting in the leak of over 1,000 records during the destruction process. The contractor also failed to notify the hospital of the data breach. Although there was a
August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with
August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention
July 30, 2025
Artificial intelligence (AI) model training and data scraping are essential processes in the development of modern AI systems. AI model training involves using large datasets to teach machine learning algorithms to recognize patterns, make predictions, or generate new content. Data scraping refers to the automated extraction of information from websites or digital sources, often to assemble the vast datasets required for effective AI training. As these practices become more widespread, questions about the legality of using third-party content—especially copyrighted works—have become increasingly important. In Thailand, the legal landscape for AI developers is shaped primarily by the Copyright Act, which presents unique challenges due to the absence of a fair-use exception. This article examines the copyright-related risks and legal uncertainties facing AI developers under Thailand’s current copyright law and practices, offering strategic guidance for navigating this complex environment. Copyright Risks in AI Scraping and Training Thailand’s Copyright Act does not provide a broad fair use or fair dealing exception, unlike some other jurisdictions, such as the United States. This absence has significant consequences for AI developers: No general defense for AI training: Any use of copyrighted material for AI model training is presumed to be infringing unless a specific, narrow statutory exception applies or explicit permission is obtained from the rights holder. There is no general legal basis for using copyrighted works in AI training without authorization. Increased rights clearance burden: Developers must identify and secure licenses for every copyrighted work included in their training datasets. Given the scale and diversity of data required for effective AI models, this process can be both impractical and costly. Legal ambiguity and litigation risk: The lack of clear statutory guidance or case law leaves developers in a legal gray area. There is no established precedent clarifying whether certain uses of copyrighted material for