You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 26, 2025

Thailand Extends Compliance Deadline for Ride-Sharing Platforms

Thailand has granted ride-sharing platforms additional time to comply with new regulatory requirements, extending the compliance deadline to March 31, 2026 (replacing the previous deadline of October 2, 2025). The postponement was made official on December 18, 2025, when Thailand’s Electronic Transactions Development Agency (ETDA) published the second Notification Regarding Supervision of Ride-Hailing Platforms Classified as High-Impact Digital Platform Services under the Royal Decree on Digital Platform Service Businesses.

The notification provides additional time for ride-sharing platforms and drivers to transition to full regulatory compliance. The extension replaces the effective date provision of the earlier notification and applies specifically to ride-hailing activities.

Background

The postponement responds to feedback from operators and driver groups regarding challenges converting private vehicles into legally registered public vehicles, including complex registration procedures, high compliance costs, and operational delays. The Department of Land Transport (DLT) is concurrently reforming its vehicle registration and driver verification processes to streamline operations. Given these issues, the Electronic Transactions Committee has deferred enforcement to provide an adjustment period for operators and drivers to meet compliance requirements.

Ongoing Obligations

While the effective date has been deferred, the substantive obligations imposed on ride-sharing platforms remain fully intact. Operators must continue preparing to comply with the additional duties applicable to high-impact digital platform services, beyond the general requirements under the digital platform services framework.

Operators are expected to use the extended transition period to finalize operational and compliance readiness ahead of enforcement on March 31, 2026. Key focus areas include:

  • Integration with DLT vehicle-registration systems
  • Deployment of robust driver and passenger identity verification mechanisms
  • Updates to platform terms of service, driver-onboarding standards, and internal operational policies
  • Preparation for ETDA reporting obligations and future audit and review processes

Next Steps

While the postponement replaces the previous effective date with the new March 31, 2026, deadline, operators should anticipate increased regulatory scrutiny as the revised effective date approaches and proactively align their operations with the strengthened regulatory framework.

RELATED INSIGHTS​ 

February 18, 2021
As you will no doubt know, on February 1, 2021, the Myanmar military declared a state of emergency in Myanmar for a period of one year. State Counsellor Daw Aung Sang Su Kyi was detained, as were the president and various significant political and civil leaders. Min Aung Hlaing, commander-in-chief of the Tatmadaw (Myanmar armed forces) has installed himself as chairman of the State Administration Council, the current administration. New sanctions The reaction of the Biden administration has been swift. On February 10, 2021, President Biden issued Executive Order 14014, which provides bases to impose sanctions on individuals and companies deemed by the US to, among other things: operate in the defense sector of Myanmar; be responsible for policies that undermine democratic processes in Myanmar; have taken actions to undermine democratic processes or institutions, or prohibit, limit, or penalize the exercise of free speech, in Myanmar; or be a spouse or child of the foregoing. On the next day, February 11, the US Office of Foreign Assets Control (OFAC), imposed sanctions under the new executive order on ten individuals—including General Min Aung Hlaing—and three companies, including Cancri Gems & Jewelry Co, Myanmar Imperial Jade Co, and Myanmar Ruby Enterprise.  All such individuals and companies have now been designated on the US list of specially designated nationals (SDNs). Effect of sanctions As a result of such sanctions, the property of these individuals or companies that is located in the US or is under the possession or control of US companies and citizens is frozen, and US companies and citizens are generally prohibited from dealing deal with any such property.  Reportedly, roughly USD 1 billion of funds belonging to the individuals and companies blocked on February 11 are located in the US and thus now frozen. The SDN list As many
February 11, 2021
After approximately a decade drafting general personal data protection laws and formulating a regime to protect personal data and privacy rights, Thailand finally issued the country’s first unified personal data protection legislation in 2019. The public was surprised when the draft Personal Data Protection Act (PDPA) was published for the final round of hearings. The draft PDPA largely adopted the preeminent personal data protection standards as expressed in the European Union’s General Data Protection Regulation (GDPR). The government expressed its objective to enhance personal data protection standards in Thailand to meet international standards, which would permit cross border transfers of personal data to Thailand, without any material limitations. The PDPA, which was finally published in the Government Gazette in May 2019, also established a new independent regulator, the Personal Data Protection Commission (PDPC), tasked with enforcing the PDPA. All members of the commission must possess the qualifications required by the PDPA. The PDPA was enacted with a grace period of one year for the requirements relating to the processing of personal data—which would provide businesses with sufficient time to adjust their practices to ensure compliance with the new requirements. It is a significant undertaking for businesses to adjust from having no general law on data protection to being required to meet high international data protection standards comparable to those in the GDPR. GPDR concepts that were incorporated into the PDPA include (1) purpose limitation, (2) transparency, (3) lawfulness and fairness, and (4) data minimization. When collecting personal data, data controllers are required to establish a lawful basis to allow for such collection and processing of personal data. The lawful bases for general personal data are also similar to those under the GDPR, with concepts such as contractual necessity, legal obligation, legitimate interest, vital interest, and consent. Special types of
February 2, 2021
On February 1, 2021, through Thailand’s Ministry of Digital Economy and Society, the Office of Personal Data Protection Commission announced that it will arrange public hearing sessions for the first set of subordinate regulations under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). Subordinate regulations on the following topics will be covered during the consultations: Consent Privacy notices Responsibilities of data controllers Cross-border data transfers Data protection officers Security measures Compliance processes Sensitive personal data It is anticipated that the draft subordinate regulations will be circulated (in Thai) to registered attendees ahead of the sessions. Participation by video conferencing will be available. In addition, at the First ASEAN Digital Ministers’ Meeting on January 21 and 22, 2021, the ASEAN Data Management Framework (DMF) and the Model Contractual Clauses for Cross Border Data Flows (MCCs) were approved in order to promote the secure free flow of data between ASEAN countries, including Thailand. The development of the Thai PDPA is expected to factor into these DMF and MCC initiatives, potentially allowing businesses in Thailand to transfer data between neighboring countries within the region, in addition to the permitted transfer between countries whitelisted under the European General Data Protection Regulation (GDPR). These initiatives were led by the Singapore Personal Data Protection Commission, and more details are expected in due course. Prior to the PDPA effective date on June 1, 2021, substantial further developments are expected to give further clarification and guidance for businesses, and to ease their compliance concerns. For more information on this development, or any other aspect of data protection in Thailand, please contact Tilleke & Gibbins’ data protection team led by Athistha (Nop) Chitranukroh ([email protected]).