You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 27, 2026

Thailand Considers Restricting Foreign Ownership of Data Centers

Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has publicly indicated that it is preparing a new regulatory framework for data center operators that may introduce foreign-ownership restrictions. In particular, the NBTC is considering reclassifying data center operations from a type 1 telecommunications business license to a type 3 license. If implemented, this change would subject data center operators to a significantly more stringent regulatory regime, especially in relation to foreign ownership and control.

The NBTC has indicated that it intends to propose a draft framework to the NBTC board. This would be followed by a public hearing process, with a view to implementing the new rules within 2026.

Under the Telecommunications Business Act B.E. 2544 (2001), as amended, telecommunications businesses operating under type 3 licenses are subject to foreign ownership restrictions, including a requirement that less than 50% of the total issued shares be held by foreign shareholders. In addition, type 3 licensees are subject to foreign dominance restrictions, which prohibit arrangements that allow foreigners to dominate the business.

These foreign dominance restrictions are broad in scope and may capture various forms of direct and indirect control or influence. This includes circumstances in which a foreign national is able to influence or control the formulation of policy, management, or business operations, or the appointment of directors or senior executives.

At this stage, the exact scope of the proposed rules remains unclear. Businesses with existing or planned data center operations in Thailand should therefore monitor upcoming NBTC developments in this regard and prepare for the expected public hearing process.

RELATED INSIGHTS​ 

March 18, 2025
On February 6, 2025, the prime minister of Vietnam, Pham Minh Chinh, chaired an online meeting to review the progress of Vietnam’s digital transformation agenda. The meeting assessed achievements under the National Digital Transformation Program and Project 06 on the development and application of population data, electronic identification, and authentication for national digital transformation for the period 2022-2025, with a vision to 2030, approved by the prime minister in 2022. The meeting also outlined key legislative and regulatory priorities for 2025, as set forth in Notice No. 56/TB-BPCP issued by the Government Office on February 23, 2025 (Notice 56). One of the central focuses of the 2025 digital transformation agenda is the development and issuance of laws and regulations governing digital technology, data management, and cybersecurity. Below are the key legal developments provided in Notice 56 that stakeholders should anticipate in the coming months. 1. Law on Digital Technology Industry The Ministry of Information and Communications (MIC) has been tasked with finalizing the draft Law on Digital Technology Industry (DTI Law) for submission to the National Assembly at its 9th session in May 2025. This law is expected to establish a comprehensive legal framework for the digital technology sector, addressing regulatory gaps in emerging fields such as artificial intelligence (AI), Internet of Things (IoT), cloud computing, big data and platform services to promote innovation, ensure data security, and support the growth of the digital economy in Vietnam. Concurrently, the MIC will expedite the issuance of guiding decrees to ensure the swift implementation of the DTI Law once enacted. 2. Law on Personal Data Protection and regulations guiding implementation of Data Law The Ministry of Public Security (MPS) is making efforts to finalize the long-anticipated Law on Personal Data Protection (PDPL)—data protection is currently governed by Decree No. 13/2023/ND-CP on
March 17, 2025
Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to Data Protection and Cybersecurity Regulation in Southeast Asia, a wide-ranging guide published by Drew Network Asia (DNA). The resource provides a comprehensive overview of data protection and cybersecurity laws across the region, offering practical insight into compliance requirements and regulatory developments affecting organizations that handle personal data or operate digital services in Southeast Asia. The guide begins with a regional overview, including the broader ASEAN context and cooperation initiatives. Jurisdiction-specific chapters follow a consistent structure—covering data privacy and governance obligations, security requirements and breach notification, outsourcing and cross-border data transfers, and broader accountability and compliance measures. This format allows readers to compare regulatory approaches across markets such as Brunei, Indonesia, Malaysia, the Philippines, Singapore, and others. In addition to the country chapters, the publication addresses cybersecurity and privacy engineering challenges, providing guidance for organizations and outlining obligations applicable to data controllers, processors, and intermediaries. A dedicated section on data breach management across ASEAN examines notification requirements, response considerations, and practical steps for managing incidents in a regional or global context. The guide is intended to serve as a practical reference, and the authors note that specific legal requirements may vary depending on sector, processing activity, or evolving legislation. Readers seeking more detailed advice can contact the practitioners listed in each chapter. The full guide is available for download using the button below or directly from the DNA website.
March 13, 2025
Vietnam’s Ministry of Finance has released a draft Decree on Tax Administration for E-Commerce and Digital Platforms (“Draft Decree”), introducing significant tax compliance obligations that could reshape how digital platforms, and individuals and business households conducting business through the platforms, manage their tax responsibilities. Aimed at strengthening tax enforcement, the Draft Decree requires e-commerce and digital platforms to actively track and withhold taxes from business households and individual sellers, and remit payments to tax authorities. While it has not yet been promulgated, the Draft Decree is expected to take effect on April 1, 2025, leaving platforms with a limited window to prepare for compliance. Who Is Affected by the New Tax Rules? The Draft Decree significantly broadens the tax administration scope beyond traditional e-commerce platforms to cover a wide range of digital economy participants. Specifically, the Draft Decree places direct tax-related responsibilities on two major categories (collectively, “Regulated Operators”): E-commerce and digital platforms with payment functions (e.g., platforms that process buyer payments via e-wallets, bank transfers, cards, or cash-on-delivery); and Other digital-economy players that enable e-commerce transactions, including (i) intermediary service platforms connecting service providers with consumers, (ii) digital content platforms, (iii) online advertising providers, (iv) cloud computing and data storage providers, (v) social media platforms engaged in business activities (e.g., live-stream, in-app transactions), (vi) online education, gaming, and digital entertainment platforms generating revenue from digital transactions, (vii) Vietnam-based partners of foreign digital service providers facilitating local payments for overseas platforms, and (viii) intermediary payment service providers handling financial transactions for e-commerce activities. Under the Draft Decree, Regulated Operators will be required to track, report, and enforce tax compliance for both resident and nonresident individuals and households conducting business through their platforms (“Sellers”). What New Tax Obligations Do Platforms Face? Onshore platforms For the first time, Regulated Operators will
March 10, 2025
Thailand’s Securities and Exchange Commission (SEC) will officially add USD Coin (USDC) and Tether (USDT) to its list of approved cryptocurrencies for use in digital asset transactions on March 16, 2025. The addition is a significant move that expands Thailand’s digital asset market, aiming to enhance market flexibility and provide more payment options for investors and traders in Thailand’s digital asset ecosystem. Under the SEC regulations, digital asset operators, including digital token issuers, ICO portals, and digital asset exchanges, are only permitted to accept, conduct transactions with, and use “approved cryptocurrencies” as trading pairs. After the addition of USDC and USDT, the full list of approved cryptocurrencies will include: Bitcoin (BTC) Ethereum (ETH) Ripple (XRP) Stellar (XLM) Tether (USDT) USD Coin (USDC) Other cryptocurrencies used for testing programmable payments under the enhanced regulatory sandbox in accordance with the Bank of Thailand’s rules and conditions. For more information on these new additions, or on any aspect of digital assets and cryptocurrency in Thailand, please contact Kobkit Thienpreecha at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].