You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 10, 2026

Thailand Launches Public Consultation on Draft Data-Sharing Law

On July 31, 2026, Thailand’s Big Data Institute (BDI) launched a public consultation on the principles of a proposed new data-sharing law, with comments accepted until August 31, 2026. If enacted, the law would establish Thailand’s first comprehensive framework for government and private-sector data sharing, creating a systematic, secure, and transparent regime to support analytics, policymaking, research, and innovation.

Central Data-Sharing Platform

The draft law establishes a central system for data sharing, managed by the BDI. Government agencies would be required to connect to the BDI’s Data Integration and Intelligence Platform (also referred to as D2), in accordance with the BDI’s rules and procedures.

Five Dimensions of Data Sharing

The draft law covers five key types of data sharing between government (G), businesses (B), and consumers (C):

  • G2B: Private organizations may request government data specifically for research and development purposes. The BDI will assess the applicant’s data governance, security, and privacy capabilities whether such measures meet prescribed standards before forwarding the request to the relevant government agency within 90 days. Any dispute may be escalated to a newly established Data-Sharing Promotion Committee for final determination.
  • G2G: Government agencies may request data from other agencies through the central system. The data-holding agency must respond within 90 days, taking legality, necessity, proportionality, public interest, and personal data protection into account. Disputes may be referred to the Data-Sharing Promotion Committee for adjudication.
  • B2G: In emergency situations involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society may require private entities to provide data through the central data-sharing system. Government agencies must specify the data requested, demonstrate its necessity and expected benefits, and request only data reasonably available to the data holder. Requests for personal data must be limited to the minimum amount necessary.
  • B2C: Royal decrees may require businesses in designated sectors to share customer data or business data with consumers or authorized third parties to promote consumer rights and competition. The relevant royal decree must specify at least the covered sectors, categories of data to be shared, eligible recipients, technical standards, exemptions, conditions for disclosure, and oversight mechanisms.
  • B2B: Data sharing between businesses is governed by freedom of contract and is subject to applicable laws, including data protection and competition laws. To promote trust, the government will issue a nonbinding framework on trusted data-sharing and a voluntary certification system for providers of data-sharing services, under which certified providers may display a recognized trust mark indicating compliance with prescribed standards.

Key Provisions of the Draft Law

The draft law addresses several additional areas of note:

  • Personal data protections. Where government data requested for sharing contains personal data, the data-holding agency must either deidentify the data, obtain data-subject consent, or confirm that a lawful basis for disclosure under the Personal Data Protection Act applies. In B2G emergencies, pseudonymized personal data may only be requested if nonpersonal data is demonstrably insufficient, and the Office of the Personal Data Protection Committee must be promptly notified.
  • Documentation and transparency. Government agencies and private organizations that receive and use government data in accordance with the law must submit details of the relevant data sharing agreement to the BDI within 15 days executing it. The BDI will make details of such agreements publicly available.
  • Data-Sharing Promotion Committee composition. The new Data-Sharing Promotion Committee mentioned above will be chaired by the Minister of Digital Economy and Society and comprises 10 ex-officio members and six expert members. The committee will issue regulations and policy recommendations, resolve disputes, oversee the voluntary certification of data-sharing service providers, and monitor implementation of the data-sharing regime.
  • Enforcement. Noncompliance is classified as a pinai (civil fine) offense. Civil fines apply to private entities that refuse to share data following a ministerial emergency order, and to designated business operators that fail to share consumer or business data as required by royal decree. No criminal penalties are imposed under the draft law.
  • Voluntary certification for data-sharing service providers. The draft law introduces a voluntary certification regime for data-sharing service providers, including data intermediaries, deidentification service providers, and secure access data service providers. Providers that meet prescribed standards may register with the Data-Sharing Promotion Committee and obtain a trust mark.

Impact on Private Sector

Companies operating in Thailand should be aware of several key implications:

  • Emergency data-sharing obligations. Private entities may be required by ministerial order to connect their systems and share data during declared national emergencies, with civil fines for noncompliance.
  • Sector-specific consumer data-sharing mandates. Businesses in sectors designated by royal decree—such as banking, insurance, e-commerce, or telecommunications—may be required to share customer data and business data at the request of consumers, comparable to “smart data” schemes in the UK and other jurisdictions. Such royal decrees may impose additional compliance requirements and designate a regulator for oversight and enforcement.
  • New opportunities for data-driven innovation. The new framework may enable qualifying businesses to access government data for research and development, creating opportunities to develop new products, services, and analytical capabilities.

Companies and other stakeholders should review the draft principles of the proposed data-sharing law and consider submitting comments during the public consultation period, which is open through August 31, 2026.

RELATED INSIGHTS​ 

July 8, 2026
On July 7, 2026, the Trade Competition Commission of Thailand (TCCT) issued a press release announcing the establishment of two new subcommittees designed to intensify oversight of digital platforms and modern trade businesses. The formation of the digital platform subcommittee marks a significant escalation in competition enforcement following the TCCT’s Guidelines on Multi-Sided Platforms and E-Commerce Businesses, which took effect on March 25, 2026. Platform operators, sellers, and related service providers should expect heightened regulatory scrutiny and potential investigations into practices already flagged under the March guidelines. Two Dedicated Enforcement Bodies The first new body is the digital platform subcommittee—formally the Subcommittee on Supervision, Monitoring, and Prevention of Trade Conduct in Digital Platform Business. It is tasked with driving intensive oversight of digital platform businesses. It will coordinate with government agencies, the private sector, business operators, and other relevant stakeholders to supervise and prevent trade conduct that may affect competition, and to promote free and fair competition in the digital platform sector. The subcommittee will be composed of TCCT members and representatives from the Department of Internal Trade. The second body—the Subcommittee on Determining Guidelines and Action Plans Concerning Competition Conditions in Modern Wholesale and Retail Business—will study, analyze, and monitor market structure in modern wholesale and retail businesses, compile databases to analyze retail business concentration, assess impacts on small-scale operators, and propose supervisory measures for the retail sector. TCCT members will serve on the subcommittee alongside experts from government and private organizations, including the Office of Industrial Economics, the Office of Small and Medium Enterprises Promotion, the Thai SME Federation, and the Thai SME Council. Operational Impact for Industry Participants These subcommittees provide the TCCT with a focused mechanism to investigate various trade practices deemed unfair, and the TCCT has authority under the Trade Competition Act to issue cease-and-desist
July 6, 2026
Vietnam has introduced an official list of high-risk AI systems, triggering more stringent compliance obligations for developers, suppliers, and deployers operating in the country. On June 30, 2026, the prime minister issued Decision No. 33/2026/QD-TTg (Decision 33), which establishes the List of High-Risk AI Systems under the Law on Artificial Intelligence (AI Law) and Decree No. 142/2026/ND-CP (Decree 142). Decision 33 takes effect on August 15, 2026. Decision 33 is significant because only AI systems included on the list will be subject to the heightened compliance obligations applicable to high-risk AI systems under the AI Law and Decree 142. These include, among others, local presence requirements for foreign providers, mandatory conformity assessment before deployment, comprehensive risk management and data quality documentation, and strict liability for damages even when the provider is fully compliant. Decision 33 also specifies the applicable conformity assessment pathway for each listed system, indicating whether the system must undergo mandatory third-party conformity certification before being placed into use, or whether the provider may self-assess conformity or voluntarily engage a registered or recognized conformity assessment body. Which AI Systems Are Covered? Decision 33 identifies high-risk AI systems across six sectors—the key attributes of which are summarized below. Education: AI systems used for automated assessment, learner ranking, behavioral monitoring, or generating educational content from uncontrolled data sources. Ethnic affairs and religion: AI systems used to automatically score, classify, or rank applications for government ethnic policies; approve or reject regulatory applications; suspend benefits on suspicion of fraud; allocate budgets; or infer and classify individuals by ethnicity or religion for administrative purposes. Healthcare: AI-assisted surgical systems and autonomous AI-powered surgical robots. Banking: AI systems that autonomously conduct electronic banking transactions or make credit approval decisions. Judicial proceedings: Certain large-scale biometric identification systems used in public-interest civil proceedings. Transport: Thirty-one categories
July 6, 2026
Indonesia’s regulation on reporting online intellectual property (IP) infringement provides comprehensive procedural guidance for IP rights holders and their licensees in reporting online infringement complaints. Issued in December 2025 by the Ministry of Law as Regulation No. 47 of 2025 regarding Handling of Intellectual Property Infringement Reports in Electronic Systems, this regulation covers all types of IP rights. It also specifies documentation when reporting infringement, and lays out the procedures for examination, verification, and enforcement actions. Submission of Complaints Complainants may submit reports through the online system of the Directorate General of Intellectual Property (DGIP) or in person at the DGIP office. Complaints may also be filed through an authorized proxy. Under the regulation, complainants are required to provide the following information and documents: Personal details of the complainant; Brief description of the protected work or subject matter (i.e., type of IP and name or address of the infringing website, portal, account, or application, or a link to the location of the infringing content); Complete description of the alleged infringement; Certificate of registration or recordal of the relevant IP; Recordal of IP license agreement, if any; and Other supporting evidence. Verification and Examination Process Upon receiving a complaint, the responsible formality officer may request clarification or additional supporting documents. In the latter case, the complainant must then submit the necessary administrative documents within 14 days of the notification date. Once the documentation is deemed complete and sufficient, the case will be formally registered. Subsequently, the DGIP will establish a verification team to handle online IP violations, which will include the Civil Servant Investigator (PPNS), the Ministry of Communication and Digital Affairs, experts with relevant expertise in IP, and representatives from related associations such as AVISI (Indonesian Video Streaming Association). After examining the report, the team will prepare the Minutes
July 6, 2026
Tilleke & Gibbins has contributed the Vietnam chapter to Data Protection & Privacy 2027, a global guide published by Lexology Panoramic that provides comparative insights into data protection and privacy regimes across multiple jurisdictions. The Vietnam chapter offers a comprehensive overview of the country’s data protection framework, addressing both regulatory structure and practical compliance considerations for businesses operating in or engaging with Vietnam. Topics covered include: Law and the regulatory authority: Legislative framework; data protection authority; cooperation with other data protection authorities; breaches of data protection law; judicial review of data protection authority orders Scope: Exempt sectors and institutions; interception of communications and surveillance laws; other laws; personal information formats; extraterritoriality; covered uses of personal information Legitimate processing of personal information: Lawful bases for processing; grounds for legitimate processing; types of personal information Data handling responsibilities of owners of personal information: Transparency; exemptions from transparency obligations; data accuracy; data minimization; data retention; purpose limitation; automated decision-making Security: Security obligations; notification of data breaches; internal controls Accountability: Data protection officer requirements; record-keeping; risk assessment; design of personal information processing systems Registration and notification: Registration requirements; other transparency duties Sharing and cross-border transfers of personal information: Sharing with processors and service providers; restrictions on third-party disclosures; cross-border transfers; further transfers; localization requirements Rights of individuals: Right of access; other statutory rights; compensation Enforcement: Enforcement mechanisms; exemptions, derogations, and restrictions; further exemptions and restrictions Specific data processing: Cookies and similar technologies; electronic communications marketing; targeted advertising; sensitive personal information; profiling; cloud services The chapter concludes with an update on key legal and regulatory developments over the past year and emerging trends in Vietnam’s data protection landscape. The full Vietnam chapter is available as a PDF through the button below. Readers can also gain 30 days of complementary access to the full Data