You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 10, 2026

Thailand Expands “Major Shareholder” Definition for Securities and Digital Asset Businesses

Thailand’s Ministry of Finance and Securities and Exchange Commission (SEC) have issued regulations broadening the criteria for determining who qualifies as a “major shareholder” of licensed securities and digital asset business operators. Under relevant SEC regulations, major shareholders of a regulated entity must obtain regulatory approval and undergo screening by the SEC. The revised framework introduces both shareholding-based and control-based tests to determine which shareholders require regulatory approval for a wider range of indirect ownership structures and de facto control. The Ministry of Finance notification took effect on February 21, 2026, while the SEC’s clarifying rules took effect on March 4, 2026. These changes aim to enhance transparency around beneficial ownership and strengthen regulatory oversight of entities operating in Thailand’s capital markets.

Expanded Definition

Under the revised framework, a “major shareholder” now includes persons who directly or indirectly hold more than 10% of the voting rights in a regulated company, as well as persons who exercise control over the regulated company or its shares. This system of two separate tests, based on both shareholding and control, differs from the prior regime, which focused primarily on shareholding thresholds and applied a more limited method for determining indirect shareholdings. The two tests (detailed below) operate independently of each other, and any person identified by either of the tests will be deemed a major shareholder.

Shareholding-Based Test Broadens Indirect Ownership Attribution

For the shareholding-based test, the SEC recognizes two existing methods for identifying indirect ownership, together with a new proportional attribution method. Any person captured under these methods, which are described below, will be regarded as a major shareholder of the regulated company and must obtain SEC approval as a major shareholder.

First, the existing framework continues to apply to both first-tier and chain ownership structures. Approval is required for (1) first-tier shareholders of an entity that directly holds more than 10% of the voting rights in a regulated company (or where an entity holds 100% or nearly 100% in the layer above), and (2) ultimate shareholders holding more than 50% of the voting rights at each level of an unbroken ownership chain. These approaches reflect the previous application of the shareholding-based test.

Second, the SEC will apply a pro rata calculation to identify ultimate beneficial owners whose effective economic interests in the regulated entity exceed 10%, even where no single tier holds more than 50% of the voting rights. This proportional attribution method increases transparency in complex multilayered ownership structures and reduces the risk of circumvention through dispersed shareholdings. The calculation method will significantly broaden the pool of persons deemed major shareholders under the new rules.

Control-Based Test Adds New Trigger

In addition to the shareholding-based test, the amendments introduce a separate control-based test under which a person may qualify as a major shareholder.

Under the separate control-based test, shareholders will be deemed “major” if they possess the authority to appoint or remove at least half of the company’s board of directors or control a majority of votes at shareholder meetings, regardless of the basis for such authority. This provision captures persons who may hold relatively small equity stakes but nevertheless exercise significant influence over the company’s management or decision-making.

Attribution to Related Persons

In determining whether the major shareholder threshold is met, the SEC will aggregate shareholdings and control among spouses (including de facto partners), minor children, and persons acting in concert. Licensed operators must exercise reasonable efforts to review relevant relationships and identify such arrangements to ensure that all shareholders and controlling persons captured under the new framework are submitted for SEC approval.

Transition and Compliance Timeline

Persons who were approved as major shareholders under the previous regulations are deemed approved under the revised framework. However, where a person newly falls within the expanded definition, the licensed operator must file an application with the SEC for approval of that person as a major shareholder within 180 days of February 21, 2026 (conservatively, August 19, 2026).

For changes involving major shareholders by any action rather than as a result of these amendments, the application must be filed no later than 14 days after the licensed operator becomes aware, or has reason to know, that the person qualifies as a major shareholder under the expanded definition. For newly issued shares, licensed operators must submit the application before a person becomes a major shareholder.

Practical Implications

Securities firms and digital asset business operators should review their shareholding structures and governance arrangements to identify persons who may now qualify as major shareholders. This includes:

  • Mapping multi-tier corporate chains and calculating effective ownership percentages;
  • Examining board nomination and removal rights under shareholder agreements or bylaws; and
  • Documenting spousal and family relationships as well as potential acting-in-concert arrangements.

Operators should prioritize compliance for persons captured under the transitional provisions. Failure to obtain approval within the prescribed 180-day period will result in regulatory enforcement.

RELATED INSIGHTS​ 

June 19, 2024
On June 14, 2024, the Personal Data Protection Committee (PDPC) released a draft notification under the Personal Data Protection Act 2019 (PDPA), setting out criteria for how data controllers must delete, destroy, and de-identify personal data. According to the PDPA, a data subject can request that a data controller delete, destroy, or de-identify their personal data in any of the following circumstances: The personal data is no longer necessary for the purposes for which it was collected, used, or disclosed. The data subject has withdrawn their consent for the processing of the personal data, and no other lawful basis for processing remains. The data subject has objected to the processing of their personal data on grounds of legitimate interests or official tasks, the data controller has no other compelling grounds to refuse the request, and the data is not needed for legal claims. The data subject objects to the processing of their personal data for direct marketing purposes. The processing of personal data is unlawful. The draft stipulates that data controllers respond to a data subject’s request to delete, destroy, or de-identify personal data immediately, and within 60 days of receiving the request. If the data controller cannot fulfill the request immediately, they must take interim measures to ensure that the personal data is made difficult to collect, use, or disclose. This includes implementing measures such as preventing access to the data and applying appropriate security measures to protect the data from unauthorized use or disclosure. De-identification or Anonymization of Personal Data In certain circumstances, a data controller may opt to de-identify or anonymize personal data, rather than delete or destroy it. If doing so, the data controller must satisfy the following criteria: There must be a structured process to remove or eliminate all direct identifiers linked to the
May 15, 2024
On May 1, 2024, Thailand’s National Cyber Security Committee (NCSC) published the draft NCSC Notification Re: Cloud Cybersecurity Standards for a public hearing period, which was open until May 14, 2024. These standards have been drafted to drive the country’s cloud-first policy with the aim of minimizing risks from cyber threats to cloud services utilized by government agencies, supervising or regulating organizations, and critical information infrastructure (CII) organizations. The key points of the draft Cloud Cybersecurity Standards are below. Scope The standards apply to government agencies, supervising or regulating organizations, and CII organizations under the Cybersecurity Act B.E. 2562 (2019), as well as cloud service providers (defined below). The standards prescribe cloud system cybersecurity measures for cloud service customers (defined below) and providers only to the extent that the service is provided to the in-scope organizations outlined above. Definitions Cloud service customers (CSCs): In-scope organizations that have a formal contractual agreement to use cloud services provided by a cloud service provider. Cloud service providers (CSPs): Persons who enable cloud services to be used by a cloud service customer, responsible for maintaining infrastructure, platforms, and software that enable provision of the cloud services and for managing these resources to ensure their accessibility, security, and scalability for their cloud service customers. Application In-scope organizations that will use or have been using cloud services must comply with the Cloud Cybersecurity Standards by taking into account their data or technology information systems’ level of impact, as specified in the previously issued Notification of the NCSC Re: Standards for Defining the Security Category for Data and Information Systems B.E. 2566 (2023). The impact level related to personal data is to be rated as being at least at the medium level, and the minimum standards for that level specified in the draft Cloud Cybersecurity Standards
May 13, 2024
On May 2, 2024, Vietnam’s Ministry of Justice published on its online platform the most recent version of the draft decree on administrative sanctions for violations in the field of cybersecurity (“Draft Sanction Decree”) to gather feedback and contributions from the community and stakeholders. After receiving the Ministry of Justice’s assessment, the Ministry of Public Security (“MPS”), in charge of drafting the Draft Sanction Decree, may make further revisions before submitting it to the government for review and final decision on enactment. The decree is expected to have an effective date of June 1, 2024. The stringent penalties for infringements involving personal data of the previous draft version remain in this Draft Sanction Decree—a sign of the proactive stance of the MPS in enforcing the Personal Data Protection Decree (“PDPD”). Effective Date and Transitional Provisions It is important to note that the Draft Sanction Decree does not impose any new obligations on organizations or individuals, and only sets out the administrative sanctions that could be imposed on violators as soon as June 1, 2024, which is indicated as the effective date in Article 49. This signals the MPS’s eagerness to begin taking enforcement actions against recalcitrant organizations and individuals that have not complied with the various obligations imposed on them under the Law on Network Information Security (enacted in 2015), the Law on Cybersecurity (enacted in 2018) and its guiding decree (Decree 53 – enacted in 2022), and the most recent PDPD (enacted in 2023). Article 50.1 of the Draft Sanction Decree outlines the transitional provisions regarding administrative violations in the cybersecurity field. It clarifies that the decree does not have retroactive effect, by stating that violations occurring before its effective date, but discovered or under review after such effective date will be subject to the regulations on administrative
May 9, 2024
As non-cash payments continue to surge in Vietnam, the requirement for strong security standards and a clear legislative framework for intermediary payment services (“IPS”) is becoming more and more critical. Recognizing this, the State Bank of Vietnam (“SBV”) has been working on a draft decree to supersede the outdated Decree No. 101/2012/ND-CP dated November 22, 2012, on non-cash payments (“Draft Non-Cash Payment Decree”), which will lay the groundwork for non-cash payments in general and the provision of IPS in particular. Building upon this, the SBV recently issued a draft circular to replace Circular No. 39/2014/TT-NHNN dated December 11, 2014, on IPS (“Circular 39”) (“Draft IPS Circular”), which will offer more detailed guidance on the provision of IPS in Vietnam on top of the Draft Non-Cash Payment Decree. The Draft IPS Circular will be applicable to (i) IPS providers; (ii) foreign organizations providing IPS in Vietnam; and (iii) organizations and individuals involved in the provision of IPS. Some key updates regarding the Draft IPS Circular are as follows: Scope of Application The Draft IPS Circular sets out further guidance for the provision of IPS as listed under the Draft Non-Cash Payment Decree, including: (i) electronic clearing services; (ii) electronic wallet (“e-wallet”) services; (iii) collection and payment support services; (iv) financial switching services; (v) international financial switching services; and (vi) electronic payment gateway services. Notably, the Draft IPS Circular has explicitly excluded from its scope of application the provision of accounts by goods/service providers to their customers solely for the purpose of payment within the systems of such providers (e.g., cards/coupons or service/transaction accounts of online game service providers, transportation service providers, or securities companies, etc.). Requirements on the Provision of IPS Electronic Clearing Services: The Draft IPS Circular introduces regulations to cover certain elements of electronic clearing services that have