You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 15, 2024

Thailand Issues Draft Cybersecurity Standards for Cloud Services

On May 1, 2024, Thailand’s National Cyber Security Committee (NCSC) published the draft NCSC Notification Re: Cloud Cybersecurity Standards for a public hearing period, which was open until May 14, 2024. These standards have been drafted to drive the country’s cloud-first policy with the aim of minimizing risks from cyber threats to cloud services utilized by government agencies, supervising or regulating organizations, and critical information infrastructure (CII) organizations.

The key points of the draft Cloud Cybersecurity Standards are below.

Scope

  • The standards apply to government agencies, supervising or regulating organizations, and CII organizations under the Cybersecurity Act B.E. 2562 (2019), as well as cloud service providers (defined below).
  • The standards prescribe cloud system cybersecurity measures for cloud service customers (defined below) and providers only to the extent that the service is provided to the in-scope organizations outlined above.

Definitions

  • Cloud service customers (CSCs): In-scope organizations that have a formal contractual agreement to use cloud services provided by a cloud service provider.
  • Cloud service providers (CSPs): Persons who enable cloud services to be used by a cloud service customer, responsible for maintaining infrastructure, platforms, and software that enable provision of the cloud services and for managing these resources to ensure their accessibility, security, and scalability for their cloud service customers.

Application

  • In-scope organizations that will use or have been using cloud services must comply with the Cloud Cybersecurity Standards by taking into account their data or technology information systems’ level of impact, as specified in the previously issued Notification of the NCSC Re: Standards for Defining the Security Category for Data and Information Systems B.E. 2566 (2023).
  • The impact level related to personal data is to be rated as being at least at the medium level, and the minimum standards for that level specified in the draft Cloud Cybersecurity Standards must be adopted.
  • In-scope organizations must report their implementation of the Cloud Cybersecurity Standards to the National Cyber Security Agency (NCSA) within 30 days of completing the implementation.
  • The draft Cloud Cybersecurity Standards will come into force one year from their publication in the Government Gazette.

Structure

The requirements in the Cloud Cybersecurity Standards are divided into two areas, (1) cloud security governance and (2) cloud infrastructure and operations:

Requirement Area 1: Cloud Security Governance

  • Information security policies
  • Organization of information security
  • External supplier relationships
  • Compliance

Requirement Area 2: Cloud Infrastructure Security and Operations  

  • Human resource security
  • Asset management
  • Access control
  • Cryptography
  • Physical and environmental security
  • Operational security
  • Communication security
  • System acquisition, development, and maintenance
  • External supplier relationships
  • Information security incident management

Impact Levels and Requirements

The stipulations of the Cloud Cybersecurity Standards vary depending on the data or information systems’ level of impact. The requirements for each level are summarized in the table below.

For more information on the draft Cloud Cybersecurity Standards, or on any aspect of cybersecurity and cloud-related laws in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected] and Thammapas Chanpanich at [email protected].

RELATED INSIGHTS​ 

May 28, 2025
Tilleke & Gibbins attorneys in Vietnam have contributed the 2025 edition of Doing Business in Vietnam, a comprehensive Q&A-style resource from Thomson Reuters Practical Law that provides essential insights for companies navigating business operations in Vietnam. The guide presents a detailed overview of the country’s legal framework and regulatory environment, reflecting recent updates in Vietnamese legislation and practice. This annually updated guide offers key information on the following areas: Legal system: Structure of the Vietnamese judiciary and the role of codified law. Foreign investment: Conditions for market access, licensing requirements, foreign ownership restrictions, and investment incentives. Business vehicles: Formation and operation of legal entities, including limited liability companies, joint-stock companies, and representative offices. Employment: Employment contracts, social insurance, labor rights, and procedures for hiring foreign nationals. Tax: Overview of corporate income tax, personal income tax, value-added tax, and other tax obligations. Intellectual property: Procedures for protecting and enforcing patents, trademarks, copyrights, and other IP rights. Data protection: Compliance requirements under Vietnam’s data privacy laws, including the Personal Data Protection Decree. Competition law: Antitrust rules and regulatory oversight under the Law on Competition. Anti-bribery and corruption: Legal framework and enforcement practices aimed at curbing corrupt activities. E-commerce and digital business: Regulations governing online platforms, digital content, and cross-border services. Marketing and advertising: Laws and guidelines on advertising standards and consumer protection. Product regulation and liability: Safety requirements, product liability issues, and roles of relevant authorities. Doing Business in Vietnam is part of Practical Law’s global series of legal guides designed to support international practitioners and businesses. To access the most recent edition of the Vietnam guide, visit the Practical Law website and sign up for a free trial.
May 28, 2025
Thailand’s Food and Drug Administration (FDA) has launched a strategic collaboration with leading e-commerce platforms Lazada and Shopee to strengthen regulatory oversight of health-related products sold online. This partnership is part of a broader initiative to enhance consumer protection, enforce compliance with Thai health regulations, and foster a safer digital marketplace for health products. As part of this initiative, the Thai FDA is urging all sellers—particularly cross-border vendors—to secure proper FDA registration for their products before market entry. The objective is to ensure that only legally authorized, safe, and quality-assured healthcare products are available to Thai consumers. In pursuit of this goal, the FDA has been working closely with Lazada and Shopee to implement proactive surveillance mechanisms aimed at identifying and removing noncompliant, substandard, or unregistered products. This collaboration has already yielded measurable results. Between September 2023 and 2024, Lazada supported regulatory enforcement by removing 9,454 noncompliant listings and delisting 30 vendors. In addition, 134 sellers were subjected to legal proceedings for regulatory violations. Shopee has taken a similarly rigorous stance, committing to the immediate removal of products found to be in breach of FDA regulations. The platform has also provided educational materials for merchants and implemented consumer complaint mechanisms to enhance accountability. Looking ahead, the Thai FDA plans to roll out a data integration system utilizing API technology, enabling seamless and secure exchange of regulatory data between the agency and e-commerce platforms. This system will be supported by comprehensive training for both Thai FDA officials and e-commerce staff, with a particular focus on the use of the Thai government’s Law Enforcement Request Portal, a secure communication channel for coordinating enforcement actions between government agencies and platform operators. Additionally, a joint product inspection framework is currently under development in partnership with Lazada and Shopee. This framework will incorporate strict
May 26, 2025
On May 21, 2025, the Trade Competition Commission of Thailand (TCCT) published a press release signaling heightened regulation of digital platforms in response to the influx of products from foreign countries being sold in Thailand via e-commerce platforms. In recent years, the rapid expansion of cross-border multi-sided e-commerce platforms has unlocked unprecedented growth, but it has also flooded Thailand’s digital marketplaces with low-cost imports sold by unregulated foreign vendors via these platforms, unfairly undercutting local merchants’ market share and exposing consumers to uneven product quality. According to the press release, the TCCT announced progress on drafting new guidelines on unfair trade practices, monopolistic conduct, and competition restraint by multi-sided e-commerce platforms at a recent meeting of the Management Committee for Addressing Issues of Foreign Goods and Businesses Violating Laws. This regulatory push is part of a broader governmental effort to tackle issues stemming from the foregoing that create uneven playing fields and undermine consumer welfare. The draft guidelines are designed to regulate platform operators and their complex and multidimensional trade relations that cause network effects and distort competition. The forthcoming guidelines, to be issued under the Trade Competition Act B.E. 2560 (2017), will undergo public consultation to ensure platform operators, the public, and other stakeholders will have an opportunity to provide input before they are finalized and enforced. The guidelines are seen as an important priority, with the minister of commerce urging swift implementation of the measures to achieve the government’s objectives. In addition to the legislative advancement, one of the TCCT commissioners has been appointed to advise a subcommittee on preventing nominee arrangements by foreign investors and a subcommittee dedicated to promoting Thai SMEs and eliminating poor-quality imports. The appointee will also support the nationwide task force against illegal foreign products in overseeing proactive field operations and comprehensive
May 22, 2025
While digital technologies have significantly enhanced communication and information sharing, they have also created new opportunities for misuse, particularly for children, who are especially vulnerable to online abuse and exploitation. These risks are often difficult for parents and guardians to detect or prevent in a timely manner. To address these concerns, Thailand has drafted an amendment to the Criminal Code to introduce new provisions targeting offenses against children committed via online platforms. The objective is to close existing legal gaps and to provide more robust protections for children in the digital environment. The draft amendment focuses primarily on addressing online offenses against children and enhancing legal protections for children. The draft amendment proposed changes regarding the following issues: Jurisdiction and media misuse Expanding Thailand’s jurisdiction to cover sexual and liberty-related offenses committed against children outside the country. Adding offenses for misuse of media, including recording, publishing, or transmitting text, images, or sounds for unlawful or exploitative purposes. Offenses involving child exploitation Adding penalties for persuading, luring, or enticing children to engage in sexual or indecent conduct. Imposing harsher penalties for aggravated cases relating to child exploitation that result in serious harm or death. Adding penalties for sending or forwarding inappropriate sexual content to children with exploitative intent. Adding penalties for using threats involving sexual conduct to pressure or coerce victims. Removing ignorance of a child’s age as a possible defense for certain offenses (e.g., luring children or sending inappropriate content) when the child is under 13 years old. Special protections for vulnerable individuals Imposing harsher penalties for offenses committed against parents, persons under legal guardianship or parental authority, or individuals unable to protect themselves. Adding penalties to offenses such as luring children, sending inappropriate content, and cases involving serious harm or death. Child pornography Increasing liability for possession and