You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 10, 2026

Thailand Issues Guidelines on Digital Platform Fee Transparency and Fairness

Thailand has introduced new regulatory guidance requiring digital platform operators to adopt structured, transparent, and fair fee practices. On March 16, 2026, the Electronic Transactions Development Agency (ETDA) published Announcement No. DPS 2/2569, titled “Guidelines for Transparency and Fairness in Digital Platform Service Fee Determination,” issued under the Royal Decree on Digital Platform Service Business Operations B.E. 2565 (2022). The guidelines establish a framework governing how digital platform operators should set, disclose, and adjust fees charged to users and related service providers such as logistics and payment providers.

Although framed as best-practice guidance rather than legally binding rules with explicit penalties, the guidelines carry regulatory weight under the royal decree and represent a significant step toward structured governance of digital platform fee practices in Thailand.

The guidelines establish various transparency principles and divide fees into two distinct categories—compulsory and additional—with specific governance principles for each.

Transparency Principles

The guidelines recommend that digital platform operators adopt several transparency measures to ensure that users can fully understand the costs of using a platform.

  • Fee catalog. All fees should be consolidated into a single, accessible location, which should include the fee name, definition, scope of covered services, calculation methodology, rate, billing period, and calculation examples.
  • Minimum service disclosure. Operators should disclose the minimum service that users can expect, such as baseline visibility, product listing capabilities, access to transaction data, and back-end dashboard access.
  • Price structure disclosure. Operators should disclose the categories of costs underlying their fees, such as system maintenance, cybersecurity, and operational costs. While exact cost figures need not be made public, operators should be able to provide numerical data to regulators upon request.
  • Clear fee formulas. Fee calculations should be simple and easy to understand—for example, percentage of net sales, cost per order, or cost per product listing. Operators should avoid multilayered or stacked fee formulas that may mislead users.
  • Advance notice. Operators should notify users at least 15 days in advance of any fee change, disclosing the reason, scope, potential impact on users, and channels for inquiries and feedback.

Compulsory Fees

Compulsory fees cover services essential to basic platform operations, such as transaction processing, payment systems, identity verification, back-end systems, security, and basic customer service. Key recommendations include the following:

  • “1 activity = 1 fee” principle. Each fee should correspond to a clearly defined service scope, with no double-charging.
  • Cost-based logic. Fees should be justifiable by reference to cost categories, though detailed cost figures need not be publicly disclosed.
  • Minimum service guarantee. Users who pay compulsory fees are entitled to stable systems, baseline visibility, basic customer support, and access to essential data.
  • No conditional linkage. Basic rights should not be degraded if a user declines to purchase advertising or add-on services. For example, product visibility should not be reduced for users who do not purchase advertising.

Additional Fees

Additional fees include value-added services such as advertising, sales promotions, and subscription packages that enhance business performance beyond the baseline. Governance recommendations for additional fees include the following:

  • No impact on core benefits. Declining add-on services should not reduce baseline visibility or degrade basic system performance.
  • Value-based pricing. Fees should reflect measurable outcomes, such as impressions or search ranking improvement.
  • Optional, not mandatory. The purchase of add-on services should be voluntary, with no coercive bundling or pressure to purchase.
  • Unbundling principle. Basic and add-on services should not be mixed in ways that force users to purchase unnecessary bundles.

Common Principles for All Fee Types

Regardless of category, the guidelines recommend several overarching principles applicable to all fees:

  • Minimum service standards. Each fee type should be linked to clearly defined minimum service levels, including baseline data access, standard visibility, and appropriate service periods.
  • 15-day public consultation. Before any fee adjustment, operators should open a minimum 15-day consultation period, which should be accompanied by a summary of key issues, impacts, and the operator’s response to any feedback.
  • Fee challenge mechanism. Operators should maintain a formal process allowing users to dispute fees, with clear timelines, response procedures, and reasoning.
  • Fair exit. Cancellation procedures, especially for monthly or annual subscriptions, should be clear, reasonable, and free of excessive penalties.

Implications for Digital Platform Operators

Under the new guidelines, digital platform operators—particularly e-commerce marketplaces, food delivery apps, and similar intermediary platforms—may need to make significant operational and legal adjustments, and should review their current fee structures, disclosure practices, and terms of service for alignment with these guidelines. Key priorities include the following:

  • Preparing a consolidated fee catalog
  • Developing advance-notice and consultation procedures for fee changes
  • Implementing fee-dispute mechanisms
  • Ensuring internal cost-allocation records can be produced for regulators on request

In addition, the “1 activity = 1 fee” principle and unbundling requirements may force operators to unbundle existing combined fee packages and justify pricing with cost-based or value-based rationale. The prohibition on conditional linkage, such as suppressing product visibility for users who do not buy ads, directly limits a common monetization strategy and may affect revenue models.

RELATED INSIGHTS​ 

July 1, 2025
Now halfway through 2025, Thailand continues to advance in the realm of data privacy, with the ambitious goal of achieving zero data breaches. The Personal Data Protection Committee (PDPC), an independent government body established by the Personal Data Protection Act (PDPA), is taking a more proactive approach, having published several rulings and orders to enhance data protection measures and clarify compliance expectations for businesses. Here is a look back at Thailand’s data privacy developments in the first half of the year. Strengthening Law Enforcement and New Guidance for Compliance Enforcement of existing data protection laws and regulations has taken a step forward this year. Some of the specific initiatives include: Increased enforcement by the PDPC. A key trend to watch from the first half of 2025 is the PDPC’s active enforcement of the PDPA as it intensifies oversight through compliance orders and public warnings against noncompliant organizations while ramping up efforts to prevent and halt the illegal trading of personal data by actively monitoring emerging societal issues. Call center scams and cyber fraud control. Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Orders from the Expert Committee. Several orders issued by the Expert Committee under the PDPA were announced in the first half of this year. These include directives for data controllers to take corrective actions to comply with the PDPA, as well as initiatives to raise awareness of data privacy within organizations, reflecting the regulator’s focus on promoting organizational awareness and compliance. A guideline report summarizing the Expert Committee’s decisions and orders was also published to serve as a reference for compliance. Public issue monitoring. The PDPC has been taking a more proactive approach
June 27, 2025
Three American giants are actively protecting their intellectual property rights against generative AI, as two legal battles commence on both sides of the Atlantic. In the UK, Seattle-based media company Getty Images accuses UK-based Stability AI of multiple IP infringements. In the US, The Walt Disney Company and Universal Studios are teaming up against Midjourney, an AI startup, with their main ground being copyright infringement. Both cases are centered around questions legal minds have been posing since the introduction of generative AI: Is the output of generative AI an infringement? And who is ultimately responsible for the output, the platform or the user? Getty Images v. Stability AI Getty initially filed a claim in the High Court in 2023, which resulted in Stability applying for reverse summary judgment on the grounds that Getty had no real prospect of success, arguing that their operations took place outside the UK. However, the High Court judge hearing the case decided that the claims brought by Getty did have a real prospect of succeeding in court. Despite this, Stability saw a small victory when the court ruled that the representative action brought by Getty would not succeed due to the difficulties in identifying who qualified for the class. The proposed class was comprised of 50,000 rightsholders who alleged their rights were also infringed. Stability was successful in arguing that identifying these individuals would be challenging due to the unclear definition of the class. This current trial is centered around four main grounds: Copyright infringement. Getty accuses Stability of using content that Getty owns or has an exclusive license for when training their model, Stable Diffusion, resulting in the generated output containing substantial parts of that content. Getty is also alleging secondary copyright infringement, arguing that Stability is importing an article into the UK
June 26, 2025
Vietnam’s new Personal Data Protection Law (PDPL) was passed by the National Assembly on June 26, 2025, and will enter into force on January 1, 2026. The PDPL introduces several new concepts, exemptions, and obligations in comparison with the current Decree No. 13/2023/ND-CP on personal data protection (PDPD), while other contents remain essentially the same. The relationship between the PDPD and the PDPL has not been clearly addressed; however, it is expected that the government will issue a new decree providing necessary guidance on certain requirements under the PDPL, and the PDPD will remain in effect until it is replaced by this new decree. Some key points of the new PDPL include the following: Personal data will be further defined by lists of basic personal data and sensitive personal data to be issued by the government. The consent-centric approach of the PDPD remains in place, along with additional exemptions for certain data processing activities. The requirements for the data processing impact assessment (DPIA) and transfer impact assessment (TIA) remain unchanged. However, there are new exemptions for the TIA, including for the processing and storing in the cloud of employee data, and when the data subject is the person sending its own data outside of Vietnam. Consent obtained under the PDPD remains valid under the PDPL. DPIAs and TIAs submitted under the PDPD are valid under the PDPL but may need to be updated to be in line with the requirements of the PDPL. Administrative fines depend on the type of violation. The fine for sale and purchase of personal data will be 10 times the revenue from the sale or VND 3 billion (about USD 115,000), whichever is higher. The fine for cross-border transfer violations is 5% of the violator’s revenue of the preceding year or VND 3 billion,
June 25, 2025
Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption. The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight. For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues. The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks. Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully. Risks of GenAI Use The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant: Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training.