You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 11, 2021

Thailand Enacts Law Imposing VAT on Foreign e-Services and e-Platforms

On February 10, 2021, the Act Amending the Revenue Code (No.53) B.E. 2564 (2021) was published in the Thai Government Gazette, amending and introducing new provisions under the Revenue Code with respect to value added tax (VAT) on services provided online (sometimes called e-Services—see definition below). The act will come into effect on September 1, 2021.

The key elements of the act are as follows.

Definitions of e-Services, e-Platforms, and Goods

The act defines an “e-Service” as “a service that includes incorporeal property delivered through the internet or other electronic means, where the service is, in essence, performed automatically, and where the service cannot be performed without information technology”.

The act also defines an “e-Platform” as “a market, channel, or any other process or method that multiple service providers can use to provide e-Services.”

The act amends the definition of “Goods” for VAT purposes to explicitly exclude “e-Services.” Once the act takes effect, the definition of “Goods” will therefore be “corporeal and incorporeal property susceptible to having a value, and of being appropriated, whether or not for sale, use, or any purposes, and shall include every imported item, but shall not include incorporeal property that is delivered through internet system or other electronics means” (italics denote new wording added to the Revenue Code by the act).

E-Service Providers and e-Platform Operators Will Be Subject to VAT

Business operators providing e-Services from abroad and used in Thailand by users who are not VAT registrants will now be required to register for VAT, and will be liable to pay VAT without deducting any output tax (VAT pay-only). A VAT return must be filed, and the corresponding VAT must be paid, on a monthly basis.

If business operators provide e-Services through an e-Platform, which supports the continual process from service proposal, service payment, service delivery, and other processes (to be prescribed by the Director-General of Revenue Department), the operator of the e-Platform shall be liable to pay VAT on behalf of every foreign provider of e-Services, without the need to separate the details of each service provided by each provider. The duty and liability of an e-Platform operator will be the same as that of the foreign provider of e-Services.

E-Service and e-Platform providers are prohibited from issuing tax invoices to their users.

The methods by which foreign e-Service providers and e-Platform operators must register for VAT, file VAT returns, and pay VAT under this new act are yet to be prescribed.

Electronic Communication Between the Revenue Department and Taxpayers

Communication between the Revenue Department and taxpayers, including summonses, tax assessment letters, forms, tax invoices, reports, documents, and any other letters that must be prepared or used in accordance with the Revenue Code, can now be done electronically.

The criteria and methods for electronic communications are yet to be prescribed by ministerial regulations. When such regulations are released, they will be in line with the law concerning electronic transactions.

Any notification issued under the current law (which does not allow communication via electronic means) will continue to be in effect only to the extent that it does not contradict with the new law.

Other matters

Provisions which are repealed or amended by this act will continue to be in effect on tax collection that is already due, or will become due, for income or expenses that occurred before September 1, 2021.

RELATED INSIGHTS​ 

January 13, 2026
On January 9, 2026, Thailand’s Securities and Exchange Commission (SEC) filed a criminal complaint with the Economic Crime Suppression Division (ECD) against five individuals for unauthorized operation of a digital-asset dealer business under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This precedent-setting case signals that the regulator is willing to pursue crypto enforcement against natural persons even in the absence of a licensed platform entity. Background and Implications The case follows the SEC’s October 2025 public warning about the use of iris-scanning technology in exchange for certain digital tokens. In its warning, the SEC cautioned that exchanging or trading these specific tokens with unlicensed service providers exposes users to heightened fraud, scam, and money laundering risks. Unlike prior regulatory enforcement matters, which involved platform-level administrative fines for operational or compliance failures, this case targets misconduct by individuals who may not be professional traders but openly advertised their willingness to buy these tokens from the public, opened individual over-the-counter (OTC) trade channels for these tokens, and facilitated off-exchange transactions in a manner resembling ordinary commercial dealing. This enforcement action establishes a clear precedent that natural persons engaging in public-facing digital-asset dealing may face criminal liability under Thai law, even without operating through a corporate or licensed platform structure. Outlook The alleged offenders may not settle this crime by payment of fines. Following the SEC’s referral, the ECD will undertake further investigation, after which prosecutors may review the case and proceed to court. The SEC has stated that it will cooperate fully with enforcement agencies throughout the criminal enforcement process.
January 9, 2026
Vietnam has taken a decisive step into the global artificial intelligence regulatory landscape with the promulgation of the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law), adopted on December 10, 2025, and effective from March 1, 2026. As one of the earliest comprehensive, standalone AI statutes in Southeast Asia, the AI Law signals Vietnam’s ambition to position itself as both an innovation-friendly and governance-conscious AI market. In doing so, the legislature has also streamlined Vietnam’s AI regulatory architecture. The AI Law repeals most AI-related provisions previously embedded in the Law on Digital Technology Industry No. 71/2025/QH15, consolidating AI governance under a single, unified legal framework. This structural move underscores an intent to provide greater regulatory clarity and coherence for businesses operating across the AI value chain. Against this backdrop, the key question for AI developers, providers, deployers, and governance teams is how the new risk-based framework will shape compliance expectations, operational decisions, and governance design in practice. This article examines the new AI Law through that practical lens, focusing on what it means for AI businesses operating in or into Vietnam. Scope of Application The AI Law applies broadly to Vietnamese organizations and individuals, as well as foreign entities that participate in AI-related activities within Vietnam. The law expressly excludes AI activities conducted solely for national defense, security, and cryptography purposes. A defining feature of the AI Law is that it regulates by role, not by industry. It distinguishes between: Developers, who design, build, train, test, or fine-tune AI models and have direct control over the technical methods, training data, or model parameters; Providers, who place AI systems on the market or put them into use under their own names; Deployers, who use AI systems under their control in professional, commercial, or service-provision activities; Users, who interact with AI
January 9, 2026
Thailand continues to advance its legal and regulatory framework for the technology sector, with several key laws undergoing review and proposed amendments. These developments reflect Thailand’s broader efforts to ensure that its regulatory landscape keeps pace with rapid technological change and aligns more closely with international standards and best practices. The following are key legal developments and proposed legislative reforms in 2026 that are expected to impact businesses operating in the technology sector and the broader Thai business landscape. Data Privacy and Cybersecurity Personal Data Protection Act B.E. 2562 (2019) Following the full enforcement of Thailand’s Personal Data Protection Act (PDPA) in June 2022, businesses and practitioners have identified practical implementation challenges and interpretative issues. These challenges were reflected in an effectiveness assessment conducted by the Personal Data Protection Committee (PDPC) in late 2024. The PDPC published a set of principles for public consultation to identify issues and directions for potential amendments to the PDPA. Key issues: Emerging issues include clarifying the definitions of “data controller,” “data processor,” and “criminal record”; revisiting the scope of sensitive personal data to better reflect Thailand’s context; proposing amendments to the hierarchy of legal bases to avoid misconceptions of consent as the default legal basis; and clarifying the required level of expressiveness for explicit consent, as well as rules for collecting personal data from other sources. Current status: The first round of public consultation has concluded. Next steps: The proposed amendments are proceeding to a revised draft following the consultation outcomes. Cybersecurity Act B.E. 2562 (2019) Thailand is moving forward with proposed amendments to enhance the effectiveness of its national cybersecurity framework, as evolving digital technologies bring new risks such as misinformation, system intrusions, and attacks on critical infrastructure, making cybersecurity a national priority. Key issues: The amendments aim to clarify and strengthen
January 8, 2026
Thailand’s Digital Government Development Agency (DGA) has proposed new standards that would require government agencies to select cloud services exclusively from a preapproved shortlist of providers. The draft Digital Government Standards re: Cloud Service Provider Standards aims to strengthen procurement confidence and reduce risks associated with selecting cloud service providers that do not meet the required standards. A public hearing period on these standards concluded on December 27, 2025. The DGA will now review submitted comments and consider revising the standards accordingly. Shortlisted Cloud Service Provider Tiers The draft standards establish three tiers of cloud service providers based on their assessed service capability levels, core qualifications, and certifications. The DGA sets qualification requirements for each tier, and it is at the discretion of each agency to select the tier of cloud service provider that best suits its operational needs, as follows: Tier 1 cloud service providers are suitable for providing services involving disclosable official data. Tier 2 cloud service providers are suitable for handling official data and protected data, such as personal data, which requires a high-security public cloud (e.g., virtual private cloud). Tier 3 cloud service providers are suitable for providing services to agencies with specific regulatory and security requirements that handle highly protected data, such as the national security system. These providers must offer sovereign or hybrid cloud as stipulated by the Ministry of Digital Economy and Society. All tiers of cloud service providers must be legal entities incorporated under Thai law and can be authorized distributors of offshore cloud service providers. However, each tier will be subject to different requirements, including infrastructure obligations. Government agencies are encouraged to select a cloud service provider appropriate for their intended use. For example, if a government agency intends to procure cloud services for operating applications that process personal data,