You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 5, 2026

Thai SEC Heightens Enforcement Against Cross-Border Digital Asset Platforms

Thailand’s Securities and Exchange Commission (SEC) has filed a criminal complaint against a licensed digital asset broker, its overseas trading platform, and its executives for allegedly operating an unlicensed digital asset exchange targeting Thai customers. The case marks an escalation in the SEC’s enforcement efforts against unlicensed offshore platforms that attempt to serve Thai users through local licensed entities.

Criminal Complaint

On February 20, 2026, the SEC filed a criminal complaint with the Economic Crime Suppression Division against a local licensed digital asset broker, its overseas global trading platform, and its executives. The SEC alleges that the parties violated the Digital Asset Business Emergency Decree B.E. 2561 (2018) by cooperatively operating a digital asset exchange business on a cross-border basis since 2023 without the required SEC license.

According to the SEC, the local broker promoted the overseas platform’s services to the public through Thai-language posts on social media channels, with services available exclusively to customers residing in Thailand. Access to the global platform was provided through the local broker’s website and mobile application. Customers who registered for the local broker’s services were automatically granted access to the global platform without having to undergo a separate identity verification process. The SEC also found that the local broker provided back-office system support services to the global platform.

The SEC considers these activities to constitute joint operation of an unlicensed digital asset exchange. The former executives of the local broker are being held liable as the responsible persons during the relevant period. The SEC emphasized that the complaint initiates the criminal process, and the decision to prosecute or convict the accused parties will ultimately be made by law enforcement authorities and the criminal courts.

Platform Blocking

The SEC has also coordinated with the Ministry of Digital Economy and Society to block public access to the global platform under the Emergency Decree on Measures for the Prevention and Suppression of Technology Crime (No. 2) B.E. 2568 (2025). Access is expected to be restricted beginning March 22, 2026. The SEC has cautioned current users in Thailand to take appropriate steps regarding their digital assets held on the platform before the blocking date and reiterated its warning against using the services of unlicensed digital asset operators.

Key Takeaway

This enforcement action reflects the SEC’s heightened scrutiny of unlicensed offshore digital asset platforms and demonstrates that such platforms may not rely on local licensed entities to offer cross-border trading services targeting Thai users.

RELATED INSIGHTS​ 

January 10, 2023
The National Assembly of Vietnam promulgated a new Law on Cinema in June 2022 with an effective date of January 1, 2023. To guide the implementation of the new law and the sanctioning of administrative violations thereof, the government of Vietnam issued two related decrees in the final days of 2022. Cinema Decree On December 31, 2022, the government issued Decree No. 131/2022/ND-CP elaborating a number of articles of the Cinema Law (“Cinema Decree”), which took effect with the new law on January 1, 2023. Among the many issues under the Cinema Law guided by the Cinema Decree, one that is critical to over-the-top (OTT) media service providers is the set of conditions for performing the mandatory self-rating of films to be disseminated in cyberspace. According to the Cinema Law, meeting the film self-rating conditions is one of the prerequisites for online dissemination of films. If a film disseminator does not meet these conditions, it would be required to request the Ministry of Culture, Sports and Tourism (MOCST) to perform the rating. The conditions for online disseminators to self-rate their films have now been set out under Article 12 of the Cinema Decree. Accordingly, these conditions include: Having a film rating council or technical software or a mechanism to rate the films according to Vietnamese regulations on film rating and taking responsibility for the results of film rating. Having a plan to amend and update film rating results at the request of the cinematography authority (for most providers, this is the Cinematography Department under the MOCST). Having an administrative tool to support the rating of films according to each of the rating criteria and to flexibly display the updated rating immediately after the rating is changed. Having a technical plan and process for suspending and removing films at the
January 5, 2023
Data protection in Vietnam has been an ever-changing area of law in the last few years, with many legislative and practical developments. From its initiative to build the very first comprehensive Personal Data Protection Decree to meet international standards, to its actions to tackle widespread illegal data processing and trading, the Vietnamese government has shown its determination to strengthen the protection of data, which it has recognized as one of the national key tasks in the Prime Minister’s Strategy for Development of E-Government. The year 2023 is expected to be another year of many important changes made to the law and practices in this area. This article discusses what we anticipate to be the key upcoming developments in Vietnam’s data protection regime that businesses may wish to keep a close eye on to ensure compliance. Tightened Rules on Data Collection and Data Transfer The conditions for personal data processing under the current law are rather sketchily outlined. In general, the data subject’s consent to the scope and purposes of the data processing may be considered sufficient for any collection, use, retention, or sharing of personal data. Explicit consent is not clearly required, except when the data is collected in e-commerce, used for direct marketing purposes, or for other strictly controlled activities. This leads to the practice where data controllers usually do not treat consent as a serious matter. In addition, once consent has been obtained, data controllers tend to comfortably collect whatever data they want, since the law does not require the collection to be “proportionate.” This situation is expected to change in 2023 with more stringent regulations on personal data processing underway. The first and most influential set of rules on data protection to come out early this year will likely be the much talked-about Personal Data Protection
December 27, 2022
Thailand has issued the Royal Decree on Digital Platforms, which was published in the Government Gazette on December 22, 2022. The royal decree provides a grace period of 240 days from its publication for digital platform providers to take the actions necessary to ensure compliance. The key requirements are outlined below. Definitions After going through various amendments in its draft stages, the published royal decree’s definition of “digital platform” refers to the provision of an electronic intermediary platform that manages information to create connections between “merchants,” “consumers,” and “users” via a computer network in order to create electronic transactions—regardless of whether payment is actually made. However, this does not include digital platforms that offer goods or services of the digital platform operator or an affiliated company acting as its representative, regardless of whether the goods or services are offered to third parties or to affiliated companies. Notification Exemption Under the royal decree, a digital platform provider under the supervision of other authorities, such as the Bank of Thailand and the Securities and Exchange Commission, or falling under the Electronic Transactions Commission’s list of exempted digital platform providers is exempted from the requirement to notify the Electronic Transactions Development Agency (ETDA) of the operation of its digital platform. The commission may also exempt any other digital platform service as it sees fit. Extraterritorial Effect Certain digital platforms located outside Thailand are subject to the royal decree and must appoint a coordinating person in Thailand. This requirement to appoint a local coordinator does not mean that overseas digital platforms have to establish their business in Thailand. Digital Platform Certification Mark The royal decree introduces an ETDA certification mark for digital platforms. Display of the mark appears not to be mandatory, but more specific rules, procedures, and other details will be prescribed
December 23, 2022
On December 15, 2022, Thailand’s Personal Data Protection Committee (PDPC) issued the Notification on the Criteria and Procedures for Handling Personal Data Breaches. What Constitutes a “Data Breach”? A “personal data breach” refers to a breach of security measures that causes unlawful or unauthorized loss, access, use, modification, or disclosure of personal data, resulting from an intentional, willful, negligent, accidental, unauthorized, or unlawful act, or an act related to computer crimes, cyber threats, mistakes or accidents, or any other act. The notification also classifies personal data breaches into three categories: confidentiality breach, integrity breach, and availability breach. Upon being informed of an actual or suspected personal data breach, a data controller must take the following actions: To the extent possible, assess the reliability of the information and investigate the facts related to the personal data breach, including all aspects concerning security measures, such as organizational measures, technical measures, and physical measures; Conduct a data breach assessment to consider whether the personal data breach is likely to result in a risk to an individual’s rights and freedom; Notify the Office of the PDPC, any affected data subjects, or both as required; and Take necessary and appropriate action to prevent further consequences resulting from the personal data breach. Breach Assessment When conducting a data breach assessment, the following factors must be taken into account if there is a risk to an individual’s rights and freedom. Nature and the type of data breach; Nature, type, and volume of personal data involved; Nature, type, and status of the affected data subject; Severity of the consequences of the personal data breach for any affected data subjects, and the effectiveness of the measures taken to prevent the data breach; Impact of the data breach on the operation of the business or on the public; Storage