You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 26, 2025

Thailand Extends Compliance Deadline for Ride-Sharing Platforms

Thailand has granted ride-sharing platforms additional time to comply with new regulatory requirements, extending the compliance deadline to March 31, 2026 (replacing the previous deadline of October 2, 2025). The postponement was made official on December 18, 2025, when Thailand’s Electronic Transactions Development Agency (ETDA) published the second Notification Regarding Supervision of Ride-Hailing Platforms Classified as High-Impact Digital Platform Services under the Royal Decree on Digital Platform Service Businesses.

The notification provides additional time for ride-sharing platforms and drivers to transition to full regulatory compliance. The extension replaces the effective date provision of the earlier notification and applies specifically to ride-hailing activities.

Background

The postponement responds to feedback from operators and driver groups regarding challenges converting private vehicles into legally registered public vehicles, including complex registration procedures, high compliance costs, and operational delays. The Department of Land Transport (DLT) is concurrently reforming its vehicle registration and driver verification processes to streamline operations. Given these issues, the Electronic Transactions Committee has deferred enforcement to provide an adjustment period for operators and drivers to meet compliance requirements.

Ongoing Obligations

While the effective date has been deferred, the substantive obligations imposed on ride-sharing platforms remain fully intact. Operators must continue preparing to comply with the additional duties applicable to high-impact digital platform services, beyond the general requirements under the digital platform services framework.

Operators are expected to use the extended transition period to finalize operational and compliance readiness ahead of enforcement on March 31, 2026. Key focus areas include:

  • Integration with DLT vehicle-registration systems
  • Deployment of robust driver and passenger identity verification mechanisms
  • Updates to platform terms of service, driver-onboarding standards, and internal operational policies
  • Preparation for ETDA reporting obligations and future audit and review processes

Next Steps

While the postponement replaces the previous effective date with the new March 31, 2026, deadline, operators should anticipate increased regulatory scrutiny as the revised effective date approaches and proactively align their operations with the strengthened regulatory framework.

RELATED INSIGHTS​ 

September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 22, 2025
On September 15, 2025, Vietnam’s Ministry of Science and Technology announced that the country will issue an updated version of its National AI Strategy (first issued in 2021) and its first-ever AI Law by the end of this year. The ministry emphasized that the AI strategy is not just a legal framework, but a commitment to embracing AI to drive Vietnam into a new era. The AI adoption plan is set as a priority of the country, and marks a significant step in shaping Vietnam’s AI governance and innovation landscape. Highlights of the plan include the following: Strategic vision. Vietnam’s ambition is to leverage AI for economic growth, social development, and global competitiveness, under the guiding principle “AI for humans – safe, autonomous, cooperative, inclusive, and sustainable.” AI as national infrastructure. The updated strategy positions AI as core national infrastructure, comparable to electricity or the internet, aiming to provide every citizen with a “personal digital assistant.” Core principles for AI legislation. The AI Law will be built around the following six core principles: Risk-based regulation Transparency and accountability Human-centric development Domestic AI autonomy AI as a driver of sustainable growth Digital sovereignty, with data, infrastructure, and AI technology being three strategic pillars Ethics and openness. A National AI Ethics Code will accompany the upcoming law, aligned with international standards but tailored to the Vietnamese context. The government emphasizes open standards and open-source development. Market development and incentives. The government plans to expand domestic AI adoption, particularly in public services and key industries. The National Technology Innovation Fund (NATIF) will allocate at least 40% of its budget to AI projects, prioritizing SMEs through vouchers for locally developed AI solutions. Background on AI Law Development Regulations on AI are found in various Vietnamese laws and regulations, notably the recently adopted Law
September 19, 2025
Over the past two years—particularly since Thailand announced incentives for EVs, including tax exemptions and reductions—there has been a clear trend of manufacturers relocating their facilities to Thailand. This shift is reshaping the country’s industrial landscape and creating significant opportunities in the real estate sector for companies looking to establish or expand EV manufacturing operations in Southeast Asia. Incentive-Driven Market Transformation The government’s tax exemptions and reductions have proven effective in attracting foreign investment, with Chinese manufacturers currently dominating the market. Most EV parts and car manufacturers operating in Thailand are from China, reflecting the prominence of Chinese EV brands that have already established a presence in the country. The sector encompasses manufacturers of electrical equipment as well as companies seeking to establish facilities for producing electric vehicle components, parts, and accessories. The surge in activity is evident across Thailand’s EV manufacturing sector, with legal practices handling these transactions experiencing unprecedented demand. Industrial Real Estate Framework and Market Dynamics Thailand’s industrial real estate framework provides compelling advantages for foreign manufacturers, who typically face restrictions on foreign land ownership under the Land Code. However, foreign investors can benefit from exemptions to these restrictions if the land is located within industrial real estate zones designated by the Industrial Estate Authority of Thailand (IEAT) or they obtain investment promotion from the Board of Investment (BOI) if the land is located outside an industrial estate area governed by the IEAT. Both the IEAT and BOI provide special tax and nontax incentives, including foreign land ownership, with even greater incentives available for land situated within the country’s Eastern Economic Corridor (EEC). This regulatory advantage has sparked a parallel trend in land development. Industrial real estate developers in the EEC are actively consolidating land into large plots to develop new industrial estate projects, recognizing that
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.