You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 8, 2026

Thailand Intensifies Competition Enforcement in Specific Sectors

On July 7, 2026, the Trade Competition Commission of Thailand (TCCT) issued a press release announcing the establishment of two new subcommittees designed to intensify oversight of digital platforms and modern trade businesses. The formation of the digital platform subcommittee marks a significant escalation in competition enforcement following the TCCT’s Guidelines on Multi-Sided Platforms and E-Commerce Businesses, which took effect on March 25, 2026. Platform operators, sellers, and related service providers should expect heightened regulatory scrutiny and potential investigations into practices already flagged under the March guidelines.

Two Dedicated Enforcement Bodies

The first new body is the digital platform subcommittee—formally the Subcommittee on Supervision, Monitoring, and Prevention of Trade Conduct in Digital Platform Business. It is tasked with driving intensive oversight of digital platform businesses. It will coordinate with government agencies, the private sector, business operators, and other relevant stakeholders to supervise and prevent trade conduct that may affect competition, and to promote free and fair competition in the digital platform sector. The subcommittee will be composed of TCCT members and representatives from the Department of Internal Trade.

The second body—the Subcommittee on Determining Guidelines and Action Plans Concerning Competition Conditions in Modern Wholesale and Retail Business—will study, analyze, and monitor market structure in modern wholesale and retail businesses, compile databases to analyze retail business concentration, assess impacts on small-scale operators, and propose supervisory measures for the retail sector. TCCT members will serve on the subcommittee alongside experts from government and private organizations, including the Office of Industrial Economics, the Office of Small and Medium Enterprises Promotion, the Thai SME Federation, and the Thai SME Council.

Operational Impact for Industry Participants

These subcommittees provide the TCCT with a focused mechanism to investigate various trade practices deemed unfair, and the TCCT has authority under the Trade Competition Act to issue cease-and-desist orders and impose penalties.

Business operators in these sectors should anticipate that the subcommittees’ coordination mandates will translate into more frequent information requests for market studies and sector inquiries, industry consultations, stakeholder collaborations, and joint enforcement actions with other regulators. The subcommittees’ explicit charge to prevent conduct that may affect competition signals a proactive posture rather than reactive, complaint-based enforcement. All related parties in the modern trade sector (including department stores, hypermarkets, supermarkets, convenient stores, and specialty stores) and in the digital platform sector (including e-marketplaces, online sellers, carriers, advertisers, and payment service providers operating on or alongside platforms) will also fall within the subcommittee’s oversight remit.

Recommended Next Steps for Business Operators

Business operators in the digital platform and modern trade industries should consider conducting internal compliance assessments and updating policies before the subcommittee initiates enforcement proceedings. Given the TCCT’s stated commitment to keeping pace with rapidly changing business dynamics and fostering a free and fair competitive environment, early compliance steps will be important.

In particular, digital platform operators and participants should review the following against the restrictions detailed in the March guidelines:

  • Commercial terms and contractual arrangements
  • Algorithmic pricing and ranking mechanisms
  • Data-handling practices

More broadly, all businesses operating in the Thai market should take note of the TCCT’s move toward more sector-specific and proactive enforcement, and maintain operational preparedness to ensure that commercial practices are aligned with the latest guidance.

RELATED INSIGHTS​ 

June 27, 2025
Three American giants are actively protecting their intellectual property rights against generative AI, as two legal battles commence on both sides of the Atlantic. In the UK, Seattle-based media company Getty Images accuses UK-based Stability AI of multiple IP infringements. In the US, The Walt Disney Company and Universal Studios are teaming up against Midjourney, an AI startup, with their main ground being copyright infringement. Both cases are centered around questions legal minds have been posing since the introduction of generative AI: Is the output of generative AI an infringement? And who is ultimately responsible for the output, the platform or the user? Getty Images v. Stability AI Getty initially filed a claim in the High Court in 2023, which resulted in Stability applying for reverse summary judgment on the grounds that Getty had no real prospect of success, arguing that their operations took place outside the UK. However, the High Court judge hearing the case decided that the claims brought by Getty did have a real prospect of succeeding in court. Despite this, Stability saw a small victory when the court ruled that the representative action brought by Getty would not succeed due to the difficulties in identifying who qualified for the class. The proposed class was comprised of 50,000 rightsholders who alleged their rights were also infringed. Stability was successful in arguing that identifying these individuals would be challenging due to the unclear definition of the class. This current trial is centered around four main grounds: Copyright infringement. Getty accuses Stability of using content that Getty owns or has an exclusive license for when training their model, Stable Diffusion, resulting in the generated output containing substantial parts of that content. Getty is also alleging secondary copyright infringement, arguing that Stability is importing an article into the UK
June 26, 2025
Vietnam’s new Personal Data Protection Law (PDPL) was passed by the National Assembly on June 26, 2025, and will enter into force on January 1, 2026. The PDPL introduces several new concepts, exemptions, and obligations in comparison with the current Decree No. 13/2023/ND-CP on personal data protection (PDPD), while other contents remain essentially the same. The relationship between the PDPD and the PDPL has not been clearly addressed; however, it is expected that the government will issue a new decree providing necessary guidance on certain requirements under the PDPL, and the PDPD will remain in effect until it is replaced by this new decree. Some key points of the new PDPL include the following: Personal data will be further defined by lists of basic personal data and sensitive personal data to be issued by the government. The consent-centric approach of the PDPD remains in place, along with additional exemptions for certain data processing activities. The requirements for the data processing impact assessment (DPIA) and transfer impact assessment (TIA) remain unchanged. However, there are new exemptions for the TIA, including for the processing and storing in the cloud of employee data, and when the data subject is the person sending its own data outside of Vietnam. Consent obtained under the PDPD remains valid under the PDPL. DPIAs and TIAs submitted under the PDPD are valid under the PDPL but may need to be updated to be in line with the requirements of the PDPL. Administrative fines depend on the type of violation. The fine for sale and purchase of personal data will be 10 times the revenue from the sale or VND 3 billion (about USD 115,000), whichever is higher. The fine for cross-border transfer violations is 5% of the violator’s revenue of the preceding year or VND 3 billion,
June 25, 2025
Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption. The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight. For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues. The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks. Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully. Risks of GenAI Use The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant: Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training.
June 19, 2025
The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices. The BOT is accepting public comments on the draft guidelines until June 30, 2025. Scope and Application The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct. The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching. Key Risk Management Principles The guidelines lay out two main principles in managing AI risk. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows: Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management