You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 30, 2024

Thailand Issues Draft Platform Economy Act

Thailand has made its draft Platform Economy Act (the “Draft PEA”) available to relevant entities in certain industries. The Draft PEA aims to regulate and standardize digital platform service business operations and protect consumers and other stakeholders.

Once the Draft PEA becomes law, the Royal Decree on the Operation of Digital Platform Service Businesses that are subject to Prior Notification B.E. 2565 (2022) and the relevant provisions under the Electronic Transactions Act B.E. 2544 (2001), as amended, will cease to have effect.

The key provisions of the Draft PEA are summarized below.

Definitions

The definitions of the key terms under the Draft PEA are substantially similar to the definitions of the key terms under the royal decree mentioned above. According to the Draft PEA, “digital platform services” refers to the provision of electronic intermediary services that manage data to facilitate connection, through computer networks, between business users, consumers, or users, regardless of whether remuneration is charged.

Exemption

The Draft PEA does not apply to digital platform services (DPSs) that are regulated by specific laws and have rules guaranteeing transparency and fairness, or that follow operational standards no less stringent than those required in the Draft PEA. Nonetheless, the Electronic Transactions Development Agency (ETDA) can request or link data relating to exempted DPSs from the relevant supervisory authorities.

Extraterritorial Effect

Offshore DPSs with certain characteristics are also subject to the obligations under the Draft PEA and will have to appoint a coordinating person in Thailand. However, offshore DPSs will not have to establish a business in Thailand.

General Responsibilities and Obligations

The Draft PEA sets out the following requirements:

  • DPSs with (1) at least THB 100 million (approx. USD 2.8 million) in annual revenue from providing the DPSs in Thailand before deducting expenses, or (2) more than 10,000 monthly users in Thailand (calculated from the average monthly usage pursuant to the rules of the ETDA) must report their operations to the ETDA within 30 days of becoming aware that they fall within either of the criteria.
  • Upon any changes in the name, type, channel, or other details of a DPS provider or the DPSs, or in the details of the local coordinator, the ETDA must be notified of the relevant information within 30 days from the date of the change. Any changes must also be included in an annual report due 60 days from the end of each calendar year for individuals or from the end of each fiscal year for legal entities.
  • DPS providers are responsible for the lawfulness of their users’ data and any other data transmitted through the DPS, unless it can be proved or evidence can be shown in court that the DPS acts only as an intermediary for the transmission of the data and does not store it, or that the DPS does not have access to the data.
  • DPSs that do not only act as intermediaries for the transmission of data, or for which the provider can access users’ data or other transmitted data, must implement a system, mechanism, or procedure enabling other persons to report illegal acts or noncompliance. Upon receiving such a report, the DPS must delete or block the illegal data. If the DPS determines that there is no illegal data or noncompliance, the finding must be promptly reported to the ETDA.
  • Measures for the alleviation of injuries, compensation, and remediation must be in place.

Additional Obligations for Certain DPSs

Additional obligations are imposed on two categories of DPSs that have specific characteristics.

A “specific type of DPS” is one that provides all of the following services:

  • Sending and receiving data of users and other persons;
  • Storing data of users and other persons; and
  • Matching different categories of users to facilitate electronic transactions or for the benefit of selling and purchasing goods or services through the DPS.

These specific types of DPSs are obligated to notify users of the laws relating to the purchasing of goods or services and the associated risks; implement a notification system for products that are required by law to have an expiry date; monitor and ensure that the DPS will not be used for illegal activities and immediately report any suspicious activities to the ETDA; implement an identity verification system; and submit an annual report to the ETDA on the DPSs’ transparency, among other obligations.

A “large DPS” is one that:

  • Has over THB 1 billion in annual revenue, before deducting expenses, from the provision of a DPS in Thailand;
  • Has over 100,000 monthly users in Thailand; or
  • Poses a high risk to Thailand’s economy and social stability, or a high risk of potential damage to the public.

Large DPSs are obligated to engage external experts to assess risks at least once a year; arrange for IT audits; appoint a chief compliance officer to liaise with the ETDA and other competent authorities; disclose factors and methods used for processing data to offer goods or services as well as the ranking of those goods or services; and implement channels to enable users to exercise the right not to receive advertisements, among other obligations.

DPS Cessation

In cases of DPS cessation, notification of the cessation must be made to the ETDA at least 60 days prior to the date of cessation. For large DPSs, the cessation notification must be submitted at least 120 days in advance, along with a plan and measures for taking care of users after the cessation. A DPS only ceases once a receipt of notification for the cessation has been issued by the competent official.

Blockage of the Transmission of Data

If there is a transmission of illegal data through a DPS, the ETDA may order that the transmission of data by or to a user be blocked. If the order is not complied with, the ETDA may file a petition with the court requesting an order to block the transmission of data on the DPS.

Whistleblowers and Trusted Flaggers

The ETDA has the duty to recruit, examine, and certify whistleblowers or trusted flaggers and announce the list of certified whistleblowers on its electronic channel. Providers of specific types of DPSs or large DPSs must collaborate with the whistleblowers on certain aspects, such as by having a channel for whistleblowers to register their accounts and so on.

Agreements between DPSs and Users

Operators must clearly declare terms and conditions to users before and during service usage, addressing certain required items such as terms of service, suspension or termination of services, and service fees.

Competition Supervision

The ETDA and the Office of Trade Competition Commission (OTCC) will collaboratively establish criteria for determining the list of gatekeeping platforms and will publish it within six months of the criteria coming into effect.

The ETDA and the OTCC may issue regulations on behaviors, service conditions, and any other activities that are deemed to be an unfair exercise of gatekeeping platforms’ business power (ex-ante regulations).

Next Steps

The Draft PEA will be disclosed for a hearing involving relevant stakeholders and the public before the first draft is finalized.

For more details on digital platform services in Thailand, or on other aspects of the country’s technology-related laws, please contact Athistha (Nop) Chitranukroh at [email protected], Gvavalin Mahakunkitchareon at [email protected], Pornpan Wichawut at [email protected], Thammapas Chanpanich at [email protected], or Rada Lamsam at [email protected].

RELATED INSIGHTS​ 

June 25, 2025
Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption. The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight. For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues. The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks. Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully. Risks of GenAI Use The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant: Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training.
June 19, 2025
The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices. The BOT is accepting public comments on the draft guidelines until June 30, 2025. Scope and Application The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct. The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching. Key Risk Management Principles The guidelines lay out two main principles in managing AI risk. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows: Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management
June 19, 2025
Thailand’s Electronic Transactions Development Agency (ETDA) has announced plans for increased enforcement of the Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022). The ETDA outlined a comprehensive enforcement framework and review process during an online meeting with digital platform service operators on June 11, 2025. The ETDA’s enhanced enforcement approach includes systematic reviews of notification submissions, formal correction orders, and potential criminal penalties for noncompliance. Digital platform operators should immediately assess their current notification status and prepare for increased regulatory scrutiny. Review and Amendment of Previously Submitted Notification Data The ETDA will begin reviewing operation notification forms and annual reports submitted by digital platform service operators to assess each platform’s risk level and develop tailored regulatory obligations. In this comprehensive review process, the ETDA will: Examine the accuracy and completeness of submitted notification data; Request additional information as needed by phone or email; and Issue formal orders as needed requiring operators to correct or complete missing information. Operators who fail to comply with ETDA orders may face suspension of operations, revocation of their notification receipt, and public disclosure of their noncompliant status on the ETDA’s website. The ETDA will conduct follow-up workshops in July 2025 for operators whose data remains unclear or incomplete. Enforcement Framework and Penalties The ETDA outlined a three-tiered enforcement framework with escalating consequences for different types of violations, as follows: Failure to notify before commencing operations: Operators who begin services without proper notification may face criminal penalties under the Electronic Transactions Act, including up to one year of imprisonment, fines of up to THB 100,000 (approx. USD 3,070), or both. Additional consequences include suspension of operations and potential liability for company directors. Failure to correct or comply with official orders: Noncompliance with ETDA correction
June 13, 2025
In today’s digital age, cyberattacks have become a real threat to organizations worldwide. These attacks can range from phishing and malware to ransomware and distributed denial of service (DDoS) attacks. As the frequency and sophistication of these attacks increase, so does the importance of cybersecurity compliance. In the corporate world, compliance refers to the process of ensuring that a company and its employees adhere to all relevant laws, regulations, standards, and ethical practices—but it should not stop there. Compliance should also encompass asset recovery and disciplinary measures, which can both help organizations address incidents effectively and promote good governance. Cyberattacks are malicious attempts to access or damage a computer system or network, often carried out for financial gain, for political activism, or simply to cause disruption. For instance, a successful attack might involve an attacker creating an email address that closely resembles a legitimate one, perhaps by changing only one or two characters. That email address is then inserted into an existing conversation thread, making it appear as if the user with this email address was already part of the discussion. This tactic can easily deceive a recipient into believing the email was sent from a trusted source, thereby leading them to click on malicious links, provide sensitive information, or even make payments in accordance with the attacker’s request or instructions. Phishing attacks like these are particularly dangerous and can have a serious impact on the ongoing business of a corporation because they exploit the trust and familiarity established in the original email chain. Effective Mitigation Approaches Mechanisms for addressing the aftermath of a crisis provide important recourse to affected organizations, but effective compliance mechanisms can minimize the risk of such crises ever occurring. Companies should therefore prioritize preventative measures and implementation of effective crisis management schemes. Various legal