You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 10, 2026

Thailand Issues Guidelines on Digital Platform Fee Transparency and Fairness

Thailand has introduced new regulatory guidance requiring digital platform operators to adopt structured, transparent, and fair fee practices. On March 16, 2026, the Electronic Transactions Development Agency (ETDA) published Announcement No. DPS 2/2569, titled “Guidelines for Transparency and Fairness in Digital Platform Service Fee Determination,” issued under the Royal Decree on Digital Platform Service Business Operations B.E. 2565 (2022). The guidelines establish a framework governing how digital platform operators should set, disclose, and adjust fees charged to users and related service providers such as logistics and payment providers.

Although framed as best-practice guidance rather than legally binding rules with explicit penalties, the guidelines carry regulatory weight under the royal decree and represent a significant step toward structured governance of digital platform fee practices in Thailand.

The guidelines establish various transparency principles and divide fees into two distinct categories—compulsory and additional—with specific governance principles for each.

Transparency Principles

The guidelines recommend that digital platform operators adopt several transparency measures to ensure that users can fully understand the costs of using a platform.

  • Fee catalog. All fees should be consolidated into a single, accessible location, which should include the fee name, definition, scope of covered services, calculation methodology, rate, billing period, and calculation examples.
  • Minimum service disclosure. Operators should disclose the minimum service that users can expect, such as baseline visibility, product listing capabilities, access to transaction data, and back-end dashboard access.
  • Price structure disclosure. Operators should disclose the categories of costs underlying their fees, such as system maintenance, cybersecurity, and operational costs. While exact cost figures need not be made public, operators should be able to provide numerical data to regulators upon request.
  • Clear fee formulas. Fee calculations should be simple and easy to understand—for example, percentage of net sales, cost per order, or cost per product listing. Operators should avoid multilayered or stacked fee formulas that may mislead users.
  • Advance notice. Operators should notify users at least 15 days in advance of any fee change, disclosing the reason, scope, potential impact on users, and channels for inquiries and feedback.

Compulsory Fees

Compulsory fees cover services essential to basic platform operations, such as transaction processing, payment systems, identity verification, back-end systems, security, and basic customer service. Key recommendations include the following:

  • “1 activity = 1 fee” principle. Each fee should correspond to a clearly defined service scope, with no double-charging.
  • Cost-based logic. Fees should be justifiable by reference to cost categories, though detailed cost figures need not be publicly disclosed.
  • Minimum service guarantee. Users who pay compulsory fees are entitled to stable systems, baseline visibility, basic customer support, and access to essential data.
  • No conditional linkage. Basic rights should not be degraded if a user declines to purchase advertising or add-on services. For example, product visibility should not be reduced for users who do not purchase advertising.

Additional Fees

Additional fees include value-added services such as advertising, sales promotions, and subscription packages that enhance business performance beyond the baseline. Governance recommendations for additional fees include the following:

  • No impact on core benefits. Declining add-on services should not reduce baseline visibility or degrade basic system performance.
  • Value-based pricing. Fees should reflect measurable outcomes, such as impressions or search ranking improvement.
  • Optional, not mandatory. The purchase of add-on services should be voluntary, with no coercive bundling or pressure to purchase.
  • Unbundling principle. Basic and add-on services should not be mixed in ways that force users to purchase unnecessary bundles.

Common Principles for All Fee Types

Regardless of category, the guidelines recommend several overarching principles applicable to all fees:

  • Minimum service standards. Each fee type should be linked to clearly defined minimum service levels, including baseline data access, standard visibility, and appropriate service periods.
  • 15-day public consultation. Before any fee adjustment, operators should open a minimum 15-day consultation period, which should be accompanied by a summary of key issues, impacts, and the operator’s response to any feedback.
  • Fee challenge mechanism. Operators should maintain a formal process allowing users to dispute fees, with clear timelines, response procedures, and reasoning.
  • Fair exit. Cancellation procedures, especially for monthly or annual subscriptions, should be clear, reasonable, and free of excessive penalties.

Implications for Digital Platform Operators

Under the new guidelines, digital platform operators—particularly e-commerce marketplaces, food delivery apps, and similar intermediary platforms—may need to make significant operational and legal adjustments, and should review their current fee structures, disclosure practices, and terms of service for alignment with these guidelines. Key priorities include the following:

  • Preparing a consolidated fee catalog
  • Developing advance-notice and consultation procedures for fee changes
  • Implementing fee-dispute mechanisms
  • Ensuring internal cost-allocation records can be produced for regulators on request

In addition, the “1 activity = 1 fee” principle and unbundling requirements may force operators to unbundle existing combined fee packages and justify pricing with cost-based or value-based rationale. The prohibition on conditional linkage, such as suppressing product visibility for users who do not buy ads, directly limits a common monetization strategy and may affect revenue models.

RELATED INSIGHTS​ 

August 6, 2025
Thailand’s Digital Government Development Agency (DGA) has released drafts of two pivotal documents to guide Thai government agencies in adopting cloud technology and classifying data for cloud usage. These draft guidelines, open for public hearing through August 12, 2025, are part of the national “Go Cloud First” policy, which aims to accelerate digital transformation, improve efficiency, and ensure robust data security across the public sector. The new standards will have significant implications for both government agencies and cloud service providers operating in Thailand. Highlights of the draft guidelines are presented below. Government Cloud Usage Guidelines Cloud-first transformation: All government agencies are directed to prioritize cloud solutions for new IT projects, in line with the cabinet’s “Go Cloud First” policy. Cloud model selection: Agencies must assess their needs and select the most appropriate cloud deployment model—public, private, hybrid, or community cloud—based on the sensitivity of the data and operational requirements. Service types: The guidelines provide criteria for choosing between Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS), emphasizing the importance of using standard, non-customized services where possible. Cost management: Agencies are required to plan and separate cloud-related expenses, ensuring transparency and efficient budget allocation. Cloud migration: The guidelines outline the steps for migrating to the cloud and highlight the role of cloud service providers in facilitating the process, including supporting innovation and enabling smooth exit strategies. Procurement compliance: All cloud procurement must comply with public sector procurement laws and regulations. Only providers meeting government-mandated standards can be selected. Security and shared responsibility: The guidelines clarify the division of security responsibilities between cloud providers and government agencies. While providers manage infrastructure security, agencies remain responsible for data, application, and access controls. Legal framework: Agencies must comply with the Digital Government Administration Act, Cybersecurity
August 1, 2025
Thailand’s Personal Data Protection Committee (PDPC) announced to the press on August 1, 2025, that it had issued eight new administrative fines under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) in five cases of noncompliance by public and private entities. The enforcement actions reflect a growing commitment by the PDPC to penalize noncompliance across all sectors, regardless of organizational type or size. The total amount imposed to date was approximately THB 21.5 million (approx. USD 654,690), underscoring the financial risks tied to PDPA violations. The five cases—one involving a state agency and the remainder in the private sector—are summarized below. Case 1: State Agency Providing Online Services to the Public The order in this case stemmed from a cyberattack on a state agency’s web app, resulting in personal data of 200,000 data subjects being leaked to and sold on the dark web. The software developer was also found to have implemented no privacy by design, lacked an access control system, had no data breach prevention measures, and failed to conduct risk assessments or review existing security measures. Key noncompliance identified: Lack of appropriate security measures Weak password protection No risk assessment or ongoing review of security measures No data processing agreement with software developer that acted as data processor The state agency and the developer were each fined THB 153,120 (approx. USD 4,670). Case 2: Private Hospital This case involved a hospital that engaged an individual contractor to destroy patient medical record documents. However, the contractor stored the documents at their own premises, failed to follow the required destruction protocols, and ultimately used the medical records to wrap sweets, resulting in the leak of over 1,000 records during the destruction process. The contractor also failed to notify the hospital of the data breach. Although there was a
August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with
August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention