You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 10, 2026

Thailand Launches Public Consultation on Draft Data-Sharing Law

On July 31, 2026, Thailand’s Big Data Institute (BDI) launched a public consultation on the principles of a proposed new data-sharing law, with comments accepted until August 31, 2026. If enacted, the law would establish Thailand’s first comprehensive framework for government and private-sector data sharing, creating a systematic, secure, and transparent regime to support analytics, policymaking, research, and innovation.

Central Data-Sharing Platform

The draft law establishes a central system for data sharing, managed by the BDI. Government agencies would be required to connect to the BDI’s Data Integration and Intelligence Platform (also referred to as D2), in accordance with the BDI’s rules and procedures.

Five Dimensions of Data Sharing

The draft law covers five key types of data sharing between government (G), businesses (B), and consumers (C):

  • G2B: Private organizations may request government data specifically for research and development purposes. The BDI will assess the applicant’s data governance, security, and privacy capabilities whether such measures meet prescribed standards before forwarding the request to the relevant government agency within 90 days. Any dispute may be escalated to a newly established Data-Sharing Promotion Committee for final determination.
  • G2G: Government agencies may request data from other agencies through the central system. The data-holding agency must respond within 90 days, taking legality, necessity, proportionality, public interest, and personal data protection into account. Disputes may be referred to the Data-Sharing Promotion Committee for adjudication.
  • B2G: In emergency situations involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society may require private entities to provide data through the central data-sharing system. Government agencies must specify the data requested, demonstrate its necessity and expected benefits, and request only data reasonably available to the data holder. Requests for personal data must be limited to the minimum amount necessary.
  • B2C: Royal decrees may require businesses in designated sectors to share customer data or business data with consumers or authorized third parties to promote consumer rights and competition. The relevant royal decree must specify at least the covered sectors, categories of data to be shared, eligible recipients, technical standards, exemptions, conditions for disclosure, and oversight mechanisms.
  • B2B: Data sharing between businesses is governed by freedom of contract and is subject to applicable laws, including data protection and competition laws. To promote trust, the government will issue a nonbinding framework on trusted data-sharing and a voluntary certification system for providers of data-sharing services, under which certified providers may display a recognized trust mark indicating compliance with prescribed standards.

Key Provisions of the Draft Law

The draft law addresses several additional areas of note:

  • Personal data protections. Where government data requested for sharing contains personal data, the data-holding agency must either deidentify the data, obtain data-subject consent, or confirm that a lawful basis for disclosure under the Personal Data Protection Act applies. In B2G emergencies, pseudonymized personal data may only be requested if nonpersonal data is demonstrably insufficient, and the Office of the Personal Data Protection Committee must be promptly notified.
  • Documentation and transparency. Government agencies and private organizations that receive and use government data in accordance with the law must submit details of the relevant data sharing agreement to the BDI within 15 days executing it. The BDI will make details of such agreements publicly available.
  • Data-Sharing Promotion Committee composition. The new Data-Sharing Promotion Committee mentioned above will be chaired by the Minister of Digital Economy and Society and comprises 10 ex-officio members and six expert members. The committee will issue regulations and policy recommendations, resolve disputes, oversee the voluntary certification of data-sharing service providers, and monitor implementation of the data-sharing regime.
  • Enforcement. Noncompliance is classified as a pinai (civil fine) offense. Civil fines apply to private entities that refuse to share data following a ministerial emergency order, and to designated business operators that fail to share consumer or business data as required by royal decree. No criminal penalties are imposed under the draft law.
  • Voluntary certification for data-sharing service providers. The draft law introduces a voluntary certification regime for data-sharing service providers, including data intermediaries, deidentification service providers, and secure access data service providers. Providers that meet prescribed standards may register with the Data-Sharing Promotion Committee and obtain a trust mark.

Impact on Private Sector

Companies operating in Thailand should be aware of several key implications:

  • Emergency data-sharing obligations. Private entities may be required by ministerial order to connect their systems and share data during declared national emergencies, with civil fines for noncompliance.
  • Sector-specific consumer data-sharing mandates. Businesses in sectors designated by royal decree—such as banking, insurance, e-commerce, or telecommunications—may be required to share customer data and business data at the request of consumers, comparable to “smart data” schemes in the UK and other jurisdictions. Such royal decrees may impose additional compliance requirements and designate a regulator for oversight and enforcement.
  • New opportunities for data-driven innovation. The new framework may enable qualifying businesses to access government data for research and development, creating opportunities to develop new products, services, and analytical capabilities.

Companies and other stakeholders should review the draft principles of the proposed data-sharing law and consider submitting comments during the public consultation period, which is open through August 31, 2026.

RELATED INSIGHTS​ 

October 3, 2025
On September 26, 2025, the Contract Committee under Thailand’s Consumer Protection Board issued a regulation that aims to standardize contracts and enhance consumer protection within the beauty and wellness industry. The Notification on Prescribing the Beauty Service Business as a Contract-Controlled Business B.E. 2568 (2025), which takes effect on January 24, 2026, requires business operators to use a prescribed standard contract in Thai and adhere to strict mandatory provisions and prohibitions. These regulations apply to operators across all in-person and online service channels, including via digital platforms. “Beauty services business” is defined as the provision of services under an agreement allowing consumers to receive a series of treatments, either over a set number of sessions or within a set period. This includes massage, spa, other methods for cleanliness, beauty, or care of facial or body skin, and weight control and body shaping—including services offered electronically. The law excludes surgery, liposuction, and medical treatments performed by licensed practitioners. The notification establishes the following key requirements: Mandatory contract and formatting. All contracts with consumers must use the standard contract form, in Thai, with clear, readable text (minimum font size of 2 millimeters, no more than 11 characters per inch), and include all essential terms from the annexed form. Contract execution. Contracts must be made in duplicate, with one copy given to the consumer at signing. For agreements concluded through electronic channels, the process must comply with the Electronic Transactions Act and use the same required terms. Digital platforms. Business operators who provide services facilitated through a digital platform as an intermediary are ultimately responsible for ensuring the consumer receives a compliant contract. Prohibited clauses. The law prohibits clauses that limit or exclude liability for damages to life, body, health, mind, or property resulting from breach of contract or a wrongful act;
September 26, 2025
As Vietnam accelerates its digital transformation, data centers have emerged as critical infrastructure supporting the shift toward a digital government, digital economy, and digital society. For businesses targeting Vietnam’s rapidly growing data center market, a clear understanding of the evolving regulatory landscape, compliance obligations, and government incentives is key to successful market entry and operation. This article provides a strategic overview of investment opportunities and key compliance requirements in Vietnam’s dynamic data center sector. Investment Incentives to Boost Data Center Growth Since July 1, 2024, organizations and individuals across all economic sectors have been encouraged to invest in and contribute to the development of data centers. By law, there are no restrictions on shareholding ratios, capital contributions, or foreign investor participation in data center and cloud computing services under business cooperation contracts. Currently, investment in AI data centers is classified as a specially incentivized industry, qualifying for preferential treatments and incentives in terms of investment, taxation, land use, and other related areas. Large-scale data centers, together with AI and cloud computing, are currently considered as strategic technologies and products for which Vietnam offers significant fiscal, tax, and land incentives to promote investment. Additionally, these large-scale projects may receive direct financial support from local development budgets for facility construction, technical infrastructure, and equipment procurement, subject to state budget provisions and applicable laws. AI data center construction projects also enjoy preferential treatment under customs regulations. Regulatory Approvals for Providing Data Center Services The 2023 Telecom Law and its guiding documents marked a significant milestone by classifying data center services as value-added telecom services. Under the law, a data center service is defined as a telecom service that enables users to process, store, and retrieve information via a telecom network through the leasing of part or all of a data center. A
September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 22, 2025
On September 15, 2025, Vietnam’s Ministry of Science and Technology announced that the country will issue an updated version of its National AI Strategy (first issued in 2021) and its first-ever AI Law by the end of this year. The ministry emphasized that the AI strategy is not just a legal framework, but a commitment to embracing AI to drive Vietnam into a new era. The AI adoption plan is set as a priority of the country, and marks a significant step in shaping Vietnam’s AI governance and innovation landscape. Highlights of the plan include the following: Strategic vision. Vietnam’s ambition is to leverage AI for economic growth, social development, and global competitiveness, under the guiding principle “AI for humans – safe, autonomous, cooperative, inclusive, and sustainable.” AI as national infrastructure. The updated strategy positions AI as core national infrastructure, comparable to electricity or the internet, aiming to provide every citizen with a “personal digital assistant.” Core principles for AI legislation. The AI Law will be built around the following six core principles: Risk-based regulation Transparency and accountability Human-centric development Domestic AI autonomy AI as a driver of sustainable growth Digital sovereignty, with data, infrastructure, and AI technology being three strategic pillars Ethics and openness. A National AI Ethics Code will accompany the upcoming law, aligned with international standards but tailored to the Vietnamese context. The government emphasizes open standards and open-source development. Market development and incentives. The government plans to expand domestic AI adoption, particularly in public services and key industries. The National Technology Innovation Fund (NATIF) will allocate at least 40% of its budget to AI projects, prioritizing SMEs through vouchers for locally developed AI solutions. Background on AI Law Development Regulations on AI are found in various Vietnamese laws and regulations, notably the recently adopted Law