You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 30, 2026

Thailand Issues New Competition Guidelines for Multi-Sided and E-commerce Platforms

On March 24, 2026, the Trade Competition Commission of Thailand (TCCT) published its long-anticipated Guidelines on Multi-Sided Platforms and E-Commerce Businesses in the Government Gazette, following the conclusion of a public hearing conducted last year. The guidelines entered into force on March 25, 2026, and significantly expand the application of Thai competition law to digital platform ecosystems.

These rules introduce targeted restrictions on platform conduct, such as price-ranking algorithms and tying and bunding, that leverages network effects, and will have far-reaching implications across Thailand’s digital economy—affecting not only platform operators but also platform participants, including sellers, logistics providers, advertisers, and payment service providers operating on or alongside such platforms.

The guidelines clarify how existing prohibitions under the Trade Competition Act B.E. 2560 (2017) (TCA)—including abuse of market dominance, cartel conduct, and unfair trade practices—apply in the context of platform-based business models. While many provisions reflect earlier draft guidelines, the final version delivers more precise definitions and clearer enforcement parameters, increasing regulatory certainty while also raising compliance expectations.

Applicability

The guidelines introduce core definitions that determine their coverage:

  • Multi-sided platform: A platform that acts as an intermediary connecting two or more groups of users, enabling them to have direct interaction in order to exchange or rely on services from one another. Examples include digital platforms for trading goods or services (e-commerce), as defined below.
  • Digital platform for trading goods or services (e-commerce): A platform that acts as an intermediary connecting the distribution, purchase, sale, or exchange of goods or services. This includes operations carried out to facilitate transactions or interactions between business operators through an electronic transaction system, regardless of whether a service fee is charged.
  • Operator of a digital platform business for trading goods or services: A provider of digital platform services for trading goods or services, as described above, operating by receiving purchase orders for goods or services transacted via electronic systems, whether in the form of an electronic marketplace, social media marketplace, or any other format that connects purchase orders for business operators’ goods or services through an electronic system.

The scope of the guidelines is intentionally broad and extends to sellers, carriers, digital media advertisers, payment channels, and platform operators that use algorithms to rank, match, or display goods or services.

Restriction of Practices

The guidelines do not adopt a per se illegality standard but rather apply a rule-of-reason principle to various price-related practices and other conduct, as described below. The conduct may still be acceptable—or in other words, not considered unfair or unreasonable—if it meets specific criteria for exemption, such as being supported by sound economic, business, or technological reasoning, or aligning with established trade practices and market customs intended to enhance or maintain competition.

The conduct must not significantly harm overall market competition, nor should it result in excessive restriction, distortion, or the imposition of an unfair burden on other business operators. Regulatory assessment may also take into account external factors such as contractual relationships and other legal limitations.

Price-Related Practices Under Scrutiny

The price-related practices now within the TCCT’s enforcement focus include:

  • Below-cost pricing: Setting prices for goods or services below their total average cost, including charging fees, expenses, or other benefits at a rate lower than the average total cost.
  • Predatory pricing: Charging fees, expenses, or other benefits at a rate lower than the average variable cost from sellers, carriers, digital media advertisers, and payment channels with the objective of foreclosing competitors. Predatory pricing requires demonstrable or foreseeable recoupment to offset previous losses and maximize long-term profits.
  • Rate parity clauses: Requiring sellers to match the platform’s prices across other channels or preventing sellers from offering lower prices elsewhere.
  • Resale price maintenance: Dictating the resale price at which sellers offer goods or services.
  • Refusal to deal: Refusing to deal with sellers who do not comply with specified pricing requirements.
  • Excessive or unreasonable pricing: Charging commissions, advertising fees, logistics fees, promotional fees, or payment-processing fees that are not reasonably justified or proportionate.
  • Price discrimination: Charging different prices or fees to similarly situated sellers or service providers.
  • Price-ranking algorithms: Using algorithms that systematically prioritize or deprioritize goods or services based on pricing in a manner that harms fair competition.

Nonprice Conduct Under Scrutiny

The guidelines also impose extensive restrictions on nonprice conduct common in platform operations, including:

  • Visibility reductions: Lowering the search ranking or display prominence of sellers’ products.
  • Self-preferencing: Favoring the platform’s own goods or services over third-party offerings.
  • Exclusionary conduct toward carriers: Refusing to allow goods delivery by seller-chosen carriers or setting default carrier assignments that prevent sellers from selecting alternative logistics providers.
  • Mandatory sales promotions: Compelling participation in sales promotion activities for an extended and continuous period, such as recurring monthly “double-date” sales promotions.
  • Mandatory payment channels: Requiring the use of payment services provided or designated exclusively by the platform.
  • Coercion to purchase: Requiring the purchase or use of any services without reasonable justification—such as utilizing a designated media advertiser.
  • Exclusive dealing arrangements: Requiring sellers to list or sell goods exclusively through the platform, or prohibiting sellers from offering products on competing platforms.
  • Refusal to deal: Banning seller accounts, delisting products, or refusing to transact with sellers.
  • Restriction of alternatives: Forcing sellers to purchase unrelated services or agree to unrelated contract terms as a condition of platform access (tying and bundling), anticompetitive use of third-party data, limiting seller choice and delisting carriers
  • Discrimination: Ranking discrimination and quantity discrimination against certain carriers.
  • Abusive data leveraging: Using competitively sensitive data obtained from third-party sellers to benefit the platform’s own competing products.
  • Self-preferencing through data use: Exploiting proprietary data to advantage the platform’s offerings.
  • Collusive conduct: Platforms colluding with one another on competitive terms, including keyword-bidding collusion.

Next Steps

The TCCT has enforcement authority to investigate, issue cease-and-desist orders, and impose penalties for violations. Platform operators and participants should review their commercial terms, algorithms, pricing policies, and contractual arrangements to ensure compliance with the new restrictions. Companies should also consider conducting internal compliance assessments and seeking legal guidance to address any potentially problematic practices before enforcement actions commence.

RELATED INSIGHTS​ 

August 6, 2025
Thailand’s Digital Government Development Agency (DGA) has released drafts of two pivotal documents to guide Thai government agencies in adopting cloud technology and classifying data for cloud usage. These draft guidelines, open for public hearing through August 12, 2025, are part of the national “Go Cloud First” policy, which aims to accelerate digital transformation, improve efficiency, and ensure robust data security across the public sector. The new standards will have significant implications for both government agencies and cloud service providers operating in Thailand. Highlights of the draft guidelines are presented below. Government Cloud Usage Guidelines Cloud-first transformation: All government agencies are directed to prioritize cloud solutions for new IT projects, in line with the cabinet’s “Go Cloud First” policy. Cloud model selection: Agencies must assess their needs and select the most appropriate cloud deployment model—public, private, hybrid, or community cloud—based on the sensitivity of the data and operational requirements. Service types: The guidelines provide criteria for choosing between Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS), emphasizing the importance of using standard, non-customized services where possible. Cost management: Agencies are required to plan and separate cloud-related expenses, ensuring transparency and efficient budget allocation. Cloud migration: The guidelines outline the steps for migrating to the cloud and highlight the role of cloud service providers in facilitating the process, including supporting innovation and enabling smooth exit strategies. Procurement compliance: All cloud procurement must comply with public sector procurement laws and regulations. Only providers meeting government-mandated standards can be selected. Security and shared responsibility: The guidelines clarify the division of security responsibilities between cloud providers and government agencies. While providers manage infrastructure security, agencies remain responsible for data, application, and access controls. Legal framework: Agencies must comply with the Digital Government Administration Act, Cybersecurity
August 1, 2025
Thailand’s Personal Data Protection Committee (PDPC) announced to the press on August 1, 2025, that it had issued eight new administrative fines under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) in five cases of noncompliance by public and private entities. The enforcement actions reflect a growing commitment by the PDPC to penalize noncompliance across all sectors, regardless of organizational type or size. The total amount imposed to date was approximately THB 21.5 million (approx. USD 654,690), underscoring the financial risks tied to PDPA violations. The five cases—one involving a state agency and the remainder in the private sector—are summarized below. Case 1: State Agency Providing Online Services to the Public The order in this case stemmed from a cyberattack on a state agency’s web app, resulting in personal data of 200,000 data subjects being leaked to and sold on the dark web. The software developer was also found to have implemented no privacy by design, lacked an access control system, had no data breach prevention measures, and failed to conduct risk assessments or review existing security measures. Key noncompliance identified: Lack of appropriate security measures Weak password protection No risk assessment or ongoing review of security measures No data processing agreement with software developer that acted as data processor The state agency and the developer were each fined THB 153,120 (approx. USD 4,670). Case 2: Private Hospital This case involved a hospital that engaged an individual contractor to destroy patient medical record documents. However, the contractor stored the documents at their own premises, failed to follow the required destruction protocols, and ultimately used the medical records to wrap sweets, resulting in the leak of over 1,000 records during the destruction process. The contractor also failed to notify the hospital of the data breach. Although there was a
August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with
August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention