You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 18, 2025

Thailand Amends Emergency Decree on Technology Crime

On April 12, 2025, Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes in the Government Gazette, with the regulation taking effect the following day.

Drafts of the amendment had been shared in recent months, and the final amendment of the decree contains some additional key revisions, such as narrowing the business operators subject to the decree’s requirements, reducing operators’ obligations, and establishing collaboration between relevant stakeholders to tackle technology crime.

These key revisions to the amendment are detailed below.

  • Business operators subject to the decree: The business operators covered under the decree now include only payment service providers under the Payment System Act and digital asset operators under the Royal Decree on Digital Asset Businesses. Digital platform services under the Royal Decree on Digital Platform Service Businesses That Are Subject to Prior Notification are no longer within the scope of the decree.
  • Definition of technology crime: The final version of the amendment removed the expanded definition of technology crime that had been included in a previous draft, leaving the decree’s existing definition unchanged.
  • Telecommunications provider obligations: Mobile and telecommunications service providers now have an obligation to monitor and screen for content that may be related to technology crime and suspend SIM cards when instructed to do so by the National Broadcasting and Telecommunications Commission (NBTC).
  • Transaction and account suspension: The amendment removes the decree’s complex transaction suspension procedures and leaves room for business-specific regulators (e.g., Bank of Thailand, Securities and Exchange Commission, NBTC) to impose various technology crime suspension requirements on business operators under their supervision. The newly established Center for Prevention and Suppression of Technology Crimes can also notify financial institutions and business operators of names or digital asset wallet addresses that may be related to technology crime, triggering an obligation to suspend the accounts.
  • Shared liability: Although digital platform service providers are not in the scope of business operators under the amended decree, online social media platform operators are still jointly accountable with other operators (i.e., financial institutions, business operators, and related service providers) for damages from technology crime. To be released from this liability, operators have to prove their compliance with the technology crime standards and measures stipulated by their regulators (safe harbor rules).

Business operators will need to wait and see how their sector-specific regulators impose requirements to combat technology crime. Online social media platforms should closely monitor the safe harbor rules, which are expected to be issued soon.

RELATED INSIGHTS​ 

December 11, 2024
On November 30, 2024, the National Assembly of Vietnam issued a new Law on Data (“Data Law”), the first of its kind in the country. Initiated by a legislative proposal in February 2024, the Data Law underwent an accelerated preparation process and was officially promulgated just nine months later. It is worth noting that the Data Law is not the same as the Personal Data Protection Law, which is still in draft form and is expected to be submitted to the National Assembly in November 2025. The scope of application of the Data Law is broader, including not only personal data but also other types of data. The Data Law governs digital data, the National Data Center, the National General Database, digital data products and services, digital data management, and the rights, obligations, and responsibilities of agencies, organizations, and individuals related to digital data activities. Set to take effect on July 1, 2025, the Data Law is expected to have a significant impact on businesses involved in data-processing activities. Below are some key takeaways from this pivotal legislation. Cross-Border Data Transfer and Processing The Data Law recognizes and protects the freedom of cross-border data transfer and processing, as well as the legitimate rights and interests of relevant agencies, organizations, and individuals. The government is assigned the responsibility to provide detailed regulations on cross-border data transfer and processing activities, including the transfer of offshore data into Vietnam. National Data Center Resolution No. 175/NQ-CP issued by the Vietnamese government in October 2023 set out ambitious goals for a new National Data Center, which will integrate and manage human-related data from the national database, databases of ministries and central and local authorities, and other databases. The National Data Center is expected to be a core platform to provide data-related services, support policy
December 11, 2024
Thailand has released a draft amended Electronic Transactions Act (ETA), which aims to overhaul the current version of the law from 2001 to correct its enforcement limitations and update the ETA to be consistent with current electronic transactions practice. The draft ETA is open for public comment until December 20, 2024. The draft ETA introduces a new supervisory scheme that (1) recognizes electronic transactions executed by both current and future technologies without having to enact regulations recognizing the technology, (2) replaces the licensing, registration, and notification scheme for electronic transaction service providers with a trust-mark scheme, and (3) introduces a new mechanism to regulate electronic transaction service providers. The major amendments under the draft ETA address: Relationship with other relevant laws. The draft ETA is designated as the primary law governing electronic transactions, whether between private parties or between private parties and the state. However, if specific laws—including those on electronic administrative procedures—prescribe methods for conducting particular electronic transactions, those laws will prevail. Definitions. The draft ETA revises some existing terms, such as “transaction,” which is now more clearly defined as “any act relating to civil or commercial activities, including administrative procedures, administrative contracts, and any other actions by government agencies or officials.” It also introduces new definitions, such as “biometric data,” “automated system,” and “electronic seal.” Electronic transaction reliability. The draft ETA now clearly provides that electronic transactions executed using a method or an electronic method stipulated by the Electronic Transactions Development Agency (ETDA) as reliable are themselves presumed to be “reliable.” In case of a challenge over the implementation of a certified method or certified service, the challenging party bears the burden of proof and related expenses. Electronic transferable instruments. The draft ETA adopts the UNCITRAL Model Law on Electronic Transferable Records (ETRs) in recognizing ETRs (e.g.,
December 4, 2024
On October 28, 2024, Indonesia officially amended its existing Patent Law when the president ratified Law Number 65 of 2024. This comprehensive update—the third such amendment in the history of Indonesia’s Patent Law—introduces several key changes that will significantly impact patent protection and application processes in Indonesia. Key highlights and changes are outlined below. Definition of Invention The new law broadens the definition of “invention” to explicitly include systems, methods, and uses. Additionally, the law introduces formal definitions for traditional knowledge and genetic resources. Patentability Criteria Notable changes include: Computer programs are now excluded, with an exception for computer-implemented inventions. Theories and methods in science and mathematics are added to the list of excluded inventions. Previous restrictions on new uses of existing products are removed. Grace Periods The grace periods for some patent-related actions have been adjusted: The grace period for disclosures has been extended to 12 months (from 6 months previously), providing inventors with more flexibility in filing patent applications after initial disclosure. A newly introduced item is the grace period for a conventional patent application claiming priority rights, which is 4 months after the 12-month filing deadline under the Paris Convention. The grace period for annuity payments is 6 months (from 12 months previously) with a fine for late payments of 100% of the annual fee payable. Patent Holder Rights and Obligations Patent holders can now grant permissions to enforce patents. There is a new requirement for patent holders to submit annual statements on patent implementation in Indonesia. Compulsory Licensing Significant changes to compulsory licensing include: Establishment of licenses based on the principle of expediency. Limitations on license scope and transferability. Prioritization of domestic market needs. New provisions for technical improvements and economic significance. Government Patent Exploitation The new law contains specific provisions for the government’s implementation
December 4, 2024
Thailand Legal Basics, a valuable primer for foreign investors, explores all aspects of living and doing business in Thailand. Written by specialists at Tilleke & Gibbins in Bangkok, it is the only comprehensive English-language guide to the Thai legal system with a focus on the concerns of foreign business and investment.