You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 5, 2021

Stablecoin Policy Guidelines Issued by Bank of Thailand

On March 19, 2021, the Bank of Thailand (BOT) issued policy guidelines on how stablecoins are to be regulated. These were issued following the BOT’s recent ruling that stablecoins pegged to the Thai baht violate the Currency Act B.E. 2501 (1958).

Stablecoins were developed to offer a more price-stable alternative to traditional cryptocurrencies, which are defined under Thai law as digital units created to serve as means of exchange for goods, services, or any other rights. As traditional cryptocurrencies (such as Bitcoin) have no underlying assets, they are subject to such extreme fluctuations in value, and therefore people often hold them as investments rather than spend them as currency.

Some stablecoins are pegged to the value of a specific fiat currency, such as the Thai baht, and are sometimes even intentionally created to mirror that fiat currency in name, denomination, and value.  The BOT reasoned that such stablecoins—seemingly created to replace Thai baht currency—violate the Currency Act B.E. 2501 (1958), because the public might incorrectly consider them a parallel baht currency.

The BOT’s subsequent policy guidelines on how stablecoins are to be regulated address both baht-pegged stablecoins and those pegged to other currencies or assets.

Stablecoins pegged to the Thai baht (or “baht-backed stablecoins”) that are intended to be used as a means of payment may be considered electronic money (e-money) under the Payment Systems Act B.E. 2560 (2017), which is regulated by the BOT. This type of stablecoin has similar characteristics and risk factors to existing e-money, for which the BOT has issued regulations governing various aspects such as settlement, money laundering, cybersecurity, and consumer protection. Consequently, business operators who intend to launch baht-backed stablecoins in the Thai market should consult with the BOT before doing so. To support their determination on this issue, the BOT notes that their position is consistent with those of other countries, such as Singapore, the UK, and Japan.

The BOT confirmed that stablecoins pegged to foreign currencies or other assets, including those with value backed by a digital mechanism rather than an asset (i.e., algorithmic stablecoins) are currently unregulated. However, the BOT is studying this topic and is open to receiving comments and feedback before deciding whether and how these stablecoins should be regulated.

The BOT itself is developing a cryptocurrency called a retail-type central bank digital currency (CBDC), similar to Digital Yuan of the People’s Bank of China and other government-developed digital currencies, to be freely used by the general public as a stable exchange of value for goods and services. The BOT believes that, when compared to privately issued stablecoins, a CBDC will be more secure and efficient and can meet the demands of all users and business operators.

Cryptocurrency and stablecoins are now at a regulatory crossroads, with Thai regulators set to determine their future. Conceptually, neither traditional cryptocurrency nor stablecoins are regulated under the Emergency Decree on Digital Asset Business Operation B.E. 2561 (2018), but businesses related to them are. The recent BOT rulings indicate some skepticism by Thai regulators toward stablecoins—especially those pegged to the Baht—and the possibility that their widespread introduction into Thailand could create a new and unregulated financial ecosystem that adversely impacts the stability of the financial sector, and by extension the country’s economic development. Nevertheless, the BOT well recognizes this technological development and is therefore actively engaging with it.

RELATED INSIGHTS​ 

July 1, 2025
Now halfway through 2025, Thailand continues to advance in the realm of data privacy, with the ambitious goal of achieving zero data breaches. The Personal Data Protection Committee (PDPC), an independent government body established by the Personal Data Protection Act (PDPA), is taking a more proactive approach, having published several rulings and orders to enhance data protection measures and clarify compliance expectations for businesses. Here is a look back at Thailand’s data privacy developments in the first half of the year. Strengthening Law Enforcement and New Guidance for Compliance Enforcement of existing data protection laws and regulations has taken a step forward this year. Some of the specific initiatives include: Increased enforcement by the PDPC. A key trend to watch from the first half of 2025 is the PDPC’s active enforcement of the PDPA as it intensifies oversight through compliance orders and public warnings against noncompliant organizations while ramping up efforts to prevent and halt the illegal trading of personal data by actively monitoring emerging societal issues. Call center scams and cyber fraud control. Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Orders from the Expert Committee. Several orders issued by the Expert Committee under the PDPA were announced in the first half of this year. These include directives for data controllers to take corrective actions to comply with the PDPA, as well as initiatives to raise awareness of data privacy within organizations, reflecting the regulator’s focus on promoting organizational awareness and compliance. A guideline report summarizing the Expert Committee’s decisions and orders was also published to serve as a reference for compliance. Public issue monitoring. The PDPC has been taking a more proactive approach
June 27, 2025
Three American giants are actively protecting their intellectual property rights against generative AI, as two legal battles commence on both sides of the Atlantic. In the UK, Seattle-based media company Getty Images accuses UK-based Stability AI of multiple IP infringements. In the US, The Walt Disney Company and Universal Studios are teaming up against Midjourney, an AI startup, with their main ground being copyright infringement. Both cases are centered around questions legal minds have been posing since the introduction of generative AI: Is the output of generative AI an infringement? And who is ultimately responsible for the output, the platform or the user? Getty Images v. Stability AI Getty initially filed a claim in the High Court in 2023, which resulted in Stability applying for reverse summary judgment on the grounds that Getty had no real prospect of success, arguing that their operations took place outside the UK. However, the High Court judge hearing the case decided that the claims brought by Getty did have a real prospect of succeeding in court. Despite this, Stability saw a small victory when the court ruled that the representative action brought by Getty would not succeed due to the difficulties in identifying who qualified for the class. The proposed class was comprised of 50,000 rightsholders who alleged their rights were also infringed. Stability was successful in arguing that identifying these individuals would be challenging due to the unclear definition of the class. This current trial is centered around four main grounds: Copyright infringement. Getty accuses Stability of using content that Getty owns or has an exclusive license for when training their model, Stable Diffusion, resulting in the generated output containing substantial parts of that content. Getty is also alleging secondary copyright infringement, arguing that Stability is importing an article into the UK
June 26, 2025
Vietnam’s new Personal Data Protection Law (PDPL) was passed by the National Assembly on June 26, 2025, and will enter into force on January 1, 2026. The PDPL introduces several new concepts, exemptions, and obligations in comparison with the current Decree No. 13/2023/ND-CP on personal data protection (PDPD), while other contents remain essentially the same. The relationship between the PDPD and the PDPL has not been clearly addressed; however, it is expected that the government will issue a new decree providing necessary guidance on certain requirements under the PDPL, and the PDPD will remain in effect until it is replaced by this new decree. Some key points of the new PDPL include the following: Personal data will be further defined by lists of basic personal data and sensitive personal data to be issued by the government. The consent-centric approach of the PDPD remains in place, along with additional exemptions for certain data processing activities. The requirements for the data processing impact assessment (DPIA) and transfer impact assessment (TIA) remain unchanged. However, there are new exemptions for the TIA, including for the processing and storing in the cloud of employee data, and when the data subject is the person sending its own data outside of Vietnam. Consent obtained under the PDPD remains valid under the PDPL. DPIAs and TIAs submitted under the PDPD are valid under the PDPL but may need to be updated to be in line with the requirements of the PDPL. Administrative fines depend on the type of violation. The fine for sale and purchase of personal data will be 10 times the revenue from the sale or VND 3 billion (about USD 115,000), whichever is higher. The fine for cross-border transfer violations is 5% of the violator’s revenue of the preceding year or VND 3 billion,
June 25, 2025
Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption. The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight. For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues. The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks. Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully. Risks of GenAI Use The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant: Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training.