You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 25, 2023

Thailand Issues New Regulation on Prepaid Telecom Service Fee Collection

Thailand has released a notification adding new consumer protection provisions related to the collection of prepaid telecom service fees and combining several disparate regulations and resolutions. The Notification on the Criteria Relating to the Collection of Prepaid Telecommunications Service Fees was issued on September 4, 2023, and came into effect on September 21, 2023.

The notification will be enforced as a general regulation and guideline for all telecom services other than fixed broadband services, which already fall under a comparable regulation.  

Previously, Thailand’s National Broadcasting and Telecommunications Commission (NBTC) had issued several regulations to regulate the collection of prepaid telecom service fees. These include the NBTC Notification on Contract Standards, the NBTC Notification on the Maximum Service Fee Rate and Collection of Prepaid Telecommunications Service Fees, and the NBTC Notification on the Criteria Relating to the Collection of Prepaid Fixed High-Speed Broadband Service Fees. These are now subsumed by the new notification.

Key requirements of the new notification on prepaid telecom fee collection are described below.

Collection Approval Requirement

Before collecting prepaid telecom service fees, service providers (SPs) must apply to the NBTC for approval by submitting the required forms and supporting documents. Changes to the criteria and methods of prepaid telecom service fee collection must also be reapproved. This provision aims to protect against fraud and money-laundering transactions.

The NBTC will consider whether to approve an SP’s proposal for the maximum period to be covered by the prepaid service fees on a case-by-case basis.

After the collection criteria and methods are approved by the NBTC, SPs must inform their users individually. SPs must also report to the NBTC by the 15th of every month after receiving the NBTC’s approval to collect prepaid service fees.

Approvals of prepaid service fee collection granted by the NBTC prior to the new notification are still effective, but SPs must obtain new approval for any changes or differences from the previously approved collection criteria and methods.

Consumer Protection

The new notification also includes several provisions aimed at protecting users of prepaid telecom services:

  • SPs must not set a time limit before which users have to complete their use of a prepaid telecom service except when approved by the NBTC, which may set conditions relating to transfers of remaining value, refunds of excess service fees, minimum terms for using the service, or registration of users’ names and addresses.
  • SPs must allow users to choose between prepaid and postpaid telecom service fee collection via similar channels, and must allow them to change their choice. If the service conditions prevent the collection of service charges after service usage or the end of the billing cycle, or if it creates an undue burden on the users, SPs may ask the NBTC for its approval to offer only postpaid collection. To obtain NBTC approval, SPs must justify their request with supporting evidence.
  • Any rewards or discounts offered to users for choosing prepaid collection must be reasonable, fair, and in proportion to the period for collecting the prepaid fee. SPs must inform users of the exact value of the rewards or discounts before they enter into service contracts.
  • SPs must set the service charges for prepaid services before giving rewards or discounts in a manner that does not differ significantly from the service charges for postpaid services with similar quality, volume, and service standards offered or provided in the market.
  • When collecting any other charges as specified in the service contract for both prepaid or postpaid services, SPs must inform users of the objective of collecting the charges and specify each charge separately in the telecom service statement. For example, if an SP charges a telecom service user for telecom equipment installation, the statement from the SP must show the installation charge as a separate item from the telecom service.

Refunds and Returns

The new notification on prepaid telecom fee collection assigns obligations to both SPs and users in relation to termination of a telecom service contract or change or cancellation of a service package.

In such a case, SPs must refund the prepaid service fee and any remaining unused balance, including VAT, in proportion to the remaining unused service. The SP must notify the user when the refund is complete.

To receive a refund from an SP, users must return any reward or discount received from the SP in proportion to the service that has already been used. However, if the cause of termination, change, or cancellation is the SP’s fault, the user does not need to return the reward or discount.

SPs must obtain approval from the NBTC regarding the details of service fee refunds and reward and discount returns before proceeding with prepaid collection.

For more information on the NBTC notification, or on any aspect of telecom activities in Thailand, please contact Charuwan Charoonchitsathian at [email protected], Napassorn Lertussavavivat at [email protected], or Nitcharat Siraprapasiri at [email protected].

RELATED INSIGHTS​ 

January 13, 2026
On January 9, 2026, Thailand’s Securities and Exchange Commission (SEC) filed a criminal complaint with the Economic Crime Suppression Division (ECD) against five individuals for unauthorized operation of a digital-asset dealer business under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This precedent-setting case signals that the regulator is willing to pursue crypto enforcement against natural persons even in the absence of a licensed platform entity. Background and Implications The case follows the SEC’s October 2025 public warning about the use of iris-scanning technology in exchange for certain digital tokens. In its warning, the SEC cautioned that exchanging or trading these specific tokens with unlicensed service providers exposes users to heightened fraud, scam, and money laundering risks. Unlike prior regulatory enforcement matters, which involved platform-level administrative fines for operational or compliance failures, this case targets misconduct by individuals who may not be professional traders but openly advertised their willingness to buy these tokens from the public, opened individual over-the-counter (OTC) trade channels for these tokens, and facilitated off-exchange transactions in a manner resembling ordinary commercial dealing. This enforcement action establishes a clear precedent that natural persons engaging in public-facing digital-asset dealing may face criminal liability under Thai law, even without operating through a corporate or licensed platform structure. Outlook The alleged offenders may not settle this crime by payment of fines. Following the SEC’s referral, the ECD will undertake further investigation, after which prosecutors may review the case and proceed to court. The SEC has stated that it will cooperate fully with enforcement agencies throughout the criminal enforcement process.
January 9, 2026
Vietnam has taken a decisive step into the global artificial intelligence regulatory landscape with the promulgation of the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law), adopted on December 10, 2025, and effective from March 1, 2026. As one of the earliest comprehensive, standalone AI statutes in Southeast Asia, the AI Law signals Vietnam’s ambition to position itself as both an innovation-friendly and governance-conscious AI market. In doing so, the legislature has also streamlined Vietnam’s AI regulatory architecture. The AI Law repeals most AI-related provisions previously embedded in the Law on Digital Technology Industry No. 71/2025/QH15, consolidating AI governance under a single, unified legal framework. This structural move underscores an intent to provide greater regulatory clarity and coherence for businesses operating across the AI value chain. Against this backdrop, the key question for AI developers, providers, deployers, and governance teams is how the new risk-based framework will shape compliance expectations, operational decisions, and governance design in practice. This article examines the new AI Law through that practical lens, focusing on what it means for AI businesses operating in or into Vietnam. Scope of Application The AI Law applies broadly to Vietnamese organizations and individuals, as well as foreign entities that participate in AI-related activities within Vietnam. The law expressly excludes AI activities conducted solely for national defense, security, and cryptography purposes. A defining feature of the AI Law is that it regulates by role, not by industry. It distinguishes between: Developers, who design, build, train, test, or fine-tune AI models and have direct control over the technical methods, training data, or model parameters; Providers, who place AI systems on the market or put them into use under their own names; Deployers, who use AI systems under their control in professional, commercial, or service-provision activities; Users, who interact with AI
January 9, 2026
Thailand continues to advance its legal and regulatory framework for the technology sector, with several key laws undergoing review and proposed amendments. These developments reflect Thailand’s broader efforts to ensure that its regulatory landscape keeps pace with rapid technological change and aligns more closely with international standards and best practices. The following are key legal developments and proposed legislative reforms in 2026 that are expected to impact businesses operating in the technology sector and the broader Thai business landscape. Data Privacy and Cybersecurity Personal Data Protection Act B.E. 2562 (2019) Following the full enforcement of Thailand’s Personal Data Protection Act (PDPA) in June 2022, businesses and practitioners have identified practical implementation challenges and interpretative issues. These challenges were reflected in an effectiveness assessment conducted by the Personal Data Protection Committee (PDPC) in late 2024. The PDPC published a set of principles for public consultation to identify issues and directions for potential amendments to the PDPA. Key issues: Emerging issues include clarifying the definitions of “data controller,” “data processor,” and “criminal record”; revisiting the scope of sensitive personal data to better reflect Thailand’s context; proposing amendments to the hierarchy of legal bases to avoid misconceptions of consent as the default legal basis; and clarifying the required level of expressiveness for explicit consent, as well as rules for collecting personal data from other sources. Current status: The first round of public consultation has concluded. Next steps: The proposed amendments are proceeding to a revised draft following the consultation outcomes. Cybersecurity Act B.E. 2562 (2019) Thailand is moving forward with proposed amendments to enhance the effectiveness of its national cybersecurity framework, as evolving digital technologies bring new risks such as misinformation, system intrusions, and attacks on critical infrastructure, making cybersecurity a national priority. Key issues: The amendments aim to clarify and strengthen
January 8, 2026
Thailand’s Digital Government Development Agency (DGA) has proposed new standards that would require government agencies to select cloud services exclusively from a preapproved shortlist of providers. The draft Digital Government Standards re: Cloud Service Provider Standards aims to strengthen procurement confidence and reduce risks associated with selecting cloud service providers that do not meet the required standards. A public hearing period on these standards concluded on December 27, 2025. The DGA will now review submitted comments and consider revising the standards accordingly. Shortlisted Cloud Service Provider Tiers The draft standards establish three tiers of cloud service providers based on their assessed service capability levels, core qualifications, and certifications. The DGA sets qualification requirements for each tier, and it is at the discretion of each agency to select the tier of cloud service provider that best suits its operational needs, as follows: Tier 1 cloud service providers are suitable for providing services involving disclosable official data. Tier 2 cloud service providers are suitable for handling official data and protected data, such as personal data, which requires a high-security public cloud (e.g., virtual private cloud). Tier 3 cloud service providers are suitable for providing services to agencies with specific regulatory and security requirements that handle highly protected data, such as the national security system. These providers must offer sovereign or hybrid cloud as stipulated by the Ministry of Digital Economy and Society. All tiers of cloud service providers must be legal entities incorporated under Thai law and can be authorized distributors of offshore cloud service providers. However, each tier will be subject to different requirements, including infrastructure obligations. Government agencies are encouraged to select a cloud service provider appropriate for their intended use. For example, if a government agency intends to procure cloud services for operating applications that process personal data,