You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 5, 2017

Thailand: Amendments to Computer Crimes Act

On December 16, 2016, Thailand’s National Legislative Assembly passed draft amendments to the 2007 Computer Crimes Act (the “Act”). When it takes effect, the new Act will broaden the powers and reach of the Ministry of Digital Economy and Society. Competent officials under the Act may carry out investigations or confiscations if the crime (falling under the Computer Crimes Act or other criminal offenses) was committed using computer systems, computer data, or equipment for storing computer data. The Act will also extend the powers of inquiry officials by granting them power to instruct competent officials under the Act without the need for a court order and to carry out any investigation or confiscation process, as listed in the Act.

The following is a brief snapshot of the amendments made to the Act:

  • Among the committees appointed under the new Act, a Computer Data Screening Committee will have the power to permit officials to request a court order to block or destroy any data which is contrary to the stability or good morals of the people, even if the data does not violate any criminal laws.
  • The Ministry’s powers have been expanded to include offences or acts which relate to “national security, public safety, national economic stability, or the infrastructure for public benefit,” including hacking into systems relating to these broad criteria.
  • Crimes relating to the importation of forged data into a computer system now include the requirement of dishonesty and deceit, and separate penalties have been set for offenses against individuals.
  • Of particular interest to companies, the new Act will also criminalize the sending of emails or data which cannot be unsubscribed by the recipient and which disturbs the recipient. This can be read as criminalizing spam, which has never previously been included in the Act. However, the definition and criteria for “disturbs” is not stipulated and will be set out in ministerial regulations.
  • A service provider may prevent themselves from being deemed criminally liable for crimes committed by an individual using their service by restraining the dissemination of computer data. Importantly, however, the relevant details of these terms will be set out later in regulations to be passed by the Ministry.
  • Furthermore, the new Act maintains the previous Act’s requirement to retain general traffic data for not less than 90 days, while the period within which a service provider may be ordered to store traffic data has been extended from one year to two in special cases. But the Act now gives service providers the right to appeal such an order.

The Act is now awaiting royal endorsement and is expected to come into effect later this year.

RELATED INSIGHTS​ 

December 4, 2024
Thailand Legal Basics, a valuable primer for foreign investors, explores all aspects of living and doing business in Thailand. Written by specialists at Tilleke & Gibbins in Bangkok, it is the only comprehensive English-language guide to the Thai legal system with a focus on the concerns of foreign business and investment.
November 25, 2024
Thailand has released the set of principles that will form the official draft Platform Economy Act (PEA) for a public hearing period that runs until December 15, 2024. The PEA is likely to be positioned as a general or overarching law for digital intermediary services and digital platform service businesses. In January 2024, an early, unofficial version of the proposed law had been circulated among a limited group of operators in certain industries to get comments for the working group charged with the PEA’s development. Now, however, the proposed principles that will underpin the official draft PEA have been released publicly to gather comments, feedback, and suggestions from any interested stakeholders. The principles of the draft PEA cover two main areas: user protection and fair competition. The key details in these two areas are outlined below. User Protection The main regulator supervising the law’s user protection elements will be the Electronic Transactions Development Agency (ETDA). The draft PEA is expected to impose user protection obligations on service providers based on their nature, size, and risk level. The principles set out a three-tiered classification system for service providers that will be covered under the draft PEA, as detailed below, ordered from fewest obligations to most: Intermediary Service Provider: This describes a service provider acting as an intermediary between a sender and recipient of information on a computer network, the internet, or a telecommunications network. Service providers likely to fall under this category include cloud service providers and web hosting providers. Intermediary service providers may be further categorized into the following subtypes: Mere conduit service providers; Caching service providers; Hosting service providers; and Other service providers as prescribed in ministerial regulations. Online Platform: This refers to an intermediary service provider offering data storage services that connect various types of users to
November 15, 2024
Vietnam’s new Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (“Decree 147”), which will come into effect on December 25, 2024, replacing Decree No. 72/2013/ND-CP (“Decree 72”), introduces several changes to the regime for domain name dispute resolution. The new decree aims to clarify the legal framework and address some longstanding inconsistencies between Vietnam’s laws on intellectual property and information technology. The main changes related to domain name dispute resolution under Decree 147 are summarized below. Removal of Prescriptive Actions Decree 147 no longer lists specific actions for resolving domain name disputes. Decree 72 had outlined three methods: negotiation/mediation, arbitration, and court. However, IP practitioners had long criticized this approach, arguing it conflicted with the IP Law, which additionally allows administrative action. By omitting these methods, the new decree implies an acceptance of administrative action as provided in the IP Law. However, Decree 147 remains silent on establishing a dispute resolution forum aligned with the CPTPP’s requirement for a UDRP-like model. Currently, Vietnam’s available forums do not fully conform to the UDRP framework. An anticipated circular may provide further guidance on this aspect. Deactivation of Domain Names Decree 72 does not have any provision on the deactivation of a domain name. However, Decree 147 has stipulated some situations where domain names will be deactivated, such as when there is a request from an authority, or when it is discovered that incorrect information was used for registration. Clearer Criteria for Dispute Resolution Article 16 of Decree 147 sets out three clear criteria that must be met for domain name dispute resolution to proceed: (i) confusing similarity with the plaintiff’s trademark, trade name, or personal name; (ii) the defendant’s lack of legitimate rights or interests in the domain name; and (iii) bad faith. Previously,
November 15, 2024
On November 9, 2024, the government of Vietnam promulgated Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (“Decree 147”). This decree supersedes the previous Decree No. 72/2013/ND-CP dated July 15, 2013, on the same topic (“Decree 72”) and its amending regulations, and will take effect on December 25, 2024. Spanning over 200 pages, with an appendix of 62 forms, Decree 147 addresses a wide range of key internet and online topics, including internet services; domain names; cross-border information provision; social network services; aggregated information websites; online game services; app store services; information content services on mobile telecom networks; responsibilities of telecom, internet, web hosting, data center, and telecom application service providers; and measures to handle illegal content. This decree is expected to have a significant impact on both onshore and offshore service providers in the respective fields, and will potentially tighten the regulatory landscape for internet services and online information provision in Vietnam. Some highlights from the new Decree 147 compared to its predecessor are detailed below. Cross-Border Information Provision Offshore service providers, including offshore social network service providers and offshore app store service providers, who provide services on a cross-border basis and either lease data storage in Vietnam or meet a threshold of 100,000 or more total visits per month from Vietnam for six consecutive months must adhere to stricter requirements than other providers. Notable obligations of these regulated cross-border providers include: Notifying the Authority of Broadcasting and Electronic Information (ABEI) of their contact information. Monitoring and removing illegal content. Storing and managing user data as required. Authenticating social network user accounts using Vietnamese mobile number or ID number. Reporting to the ABEI annually as well as on an ad hoc Handling user complaints. Only cross-border providers who have notified the