You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 10, 2026

Thailand Launches Public Consultation on Draft Data-Sharing Law

On July 31, 2026, Thailand’s Big Data Institute (BDI) launched a public consultation on the principles of a proposed new data-sharing law, with comments accepted until August 31, 2026. If enacted, the law would establish Thailand’s first comprehensive framework for government and private-sector data sharing, creating a systematic, secure, and transparent regime to support analytics, policymaking, research, and innovation.

Central Data-Sharing Platform

The draft law establishes a central system for data sharing, managed by the BDI. Government agencies would be required to connect to the BDI’s Data Integration and Intelligence Platform (also referred to as D2), in accordance with the BDI’s rules and procedures.

Five Dimensions of Data Sharing

The draft law covers five key types of data sharing between government (G), businesses (B), and consumers (C):

  • G2B: Private organizations may request government data specifically for research and development purposes. The BDI will assess the applicant’s data governance, security, and privacy capabilities whether such measures meet prescribed standards before forwarding the request to the relevant government agency within 90 days. Any dispute may be escalated to a newly established Data-Sharing Promotion Committee for final determination.
  • G2G: Government agencies may request data from other agencies through the central system. The data-holding agency must respond within 90 days, taking legality, necessity, proportionality, public interest, and personal data protection into account. Disputes may be referred to the Data-Sharing Promotion Committee for adjudication.
  • B2G: In emergency situations involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society may require private entities to provide data through the central data-sharing system. Government agencies must specify the data requested, demonstrate its necessity and expected benefits, and request only data reasonably available to the data holder. Requests for personal data must be limited to the minimum amount necessary.
  • B2C: Royal decrees may require businesses in designated sectors to share customer data or business data with consumers or authorized third parties to promote consumer rights and competition. The relevant royal decree must specify at least the covered sectors, categories of data to be shared, eligible recipients, technical standards, exemptions, conditions for disclosure, and oversight mechanisms.
  • B2B: Data sharing between businesses is governed by freedom of contract and is subject to applicable laws, including data protection and competition laws. To promote trust, the government will issue a nonbinding framework on trusted data-sharing and a voluntary certification system for providers of data-sharing services, under which certified providers may display a recognized trust mark indicating compliance with prescribed standards.

Key Provisions of the Draft Law

The draft law addresses several additional areas of note:

  • Personal data protections. Where government data requested for sharing contains personal data, the data-holding agency must either deidentify the data, obtain data-subject consent, or confirm that a lawful basis for disclosure under the Personal Data Protection Act applies. In B2G emergencies, pseudonymized personal data may only be requested if nonpersonal data is demonstrably insufficient, and the Office of the Personal Data Protection Committee must be promptly notified.
  • Documentation and transparency. Government agencies and private organizations that receive and use government data in accordance with the law must submit details of the relevant data sharing agreement to the BDI within 15 days executing it. The BDI will make details of such agreements publicly available.
  • Data-Sharing Promotion Committee composition. The new Data-Sharing Promotion Committee mentioned above will be chaired by the Minister of Digital Economy and Society and comprises 10 ex-officio members and six expert members. The committee will issue regulations and policy recommendations, resolve disputes, oversee the voluntary certification of data-sharing service providers, and monitor implementation of the data-sharing regime.
  • Enforcement. Noncompliance is classified as a pinai (civil fine) offense. Civil fines apply to private entities that refuse to share data following a ministerial emergency order, and to designated business operators that fail to share consumer or business data as required by royal decree. No criminal penalties are imposed under the draft law.
  • Voluntary certification for data-sharing service providers. The draft law introduces a voluntary certification regime for data-sharing service providers, including data intermediaries, deidentification service providers, and secure access data service providers. Providers that meet prescribed standards may register with the Data-Sharing Promotion Committee and obtain a trust mark.

Impact on Private Sector

Companies operating in Thailand should be aware of several key implications:

  • Emergency data-sharing obligations. Private entities may be required by ministerial order to connect their systems and share data during declared national emergencies, with civil fines for noncompliance.
  • Sector-specific consumer data-sharing mandates. Businesses in sectors designated by royal decree—such as banking, insurance, e-commerce, or telecommunications—may be required to share customer data and business data at the request of consumers, comparable to “smart data” schemes in the UK and other jurisdictions. Such royal decrees may impose additional compliance requirements and designate a regulator for oversight and enforcement.
  • New opportunities for data-driven innovation. The new framework may enable qualifying businesses to access government data for research and development, creating opportunities to develop new products, services, and analytical capabilities.

Companies and other stakeholders should review the draft principles of the proposed data-sharing law and consider submitting comments during the public consultation period, which is open through August 31, 2026.

RELATED INSIGHTS​ 

July 2, 2026
Thailand’s Electronic Transactions Development Agency (ETDA) released a new version of the draft Act on Artificial Intelligence on July 2, 2026, for a public hearing period expected to be approximately 30 days. The draft act adopts a risk-based regulatory approach modeled in part on international frameworks—particularly the EU’s AI Act—while incorporating provisions tailored to Thailand’s regulatory landscape and digital economy objectives. If enacted in its current form, the law would introduce extraterritorial obligations, a tiered risk classification system, strict liability for AI-related damages, and new transparency requirements for AI-generated content. Scope and Extraterritorial Application The draft act applies to AI development, deployment, or any other action affecting people in Thailand, even if the action occurs outside the country. Of note: This extraterritorial reach creates compliance obligations for global AI companies whose systems impact Thai residents or consumers, even if the provider has no physical presence in Thailand. Foreign AI providers serving Thai deployers or users must appoint a local coordinator or authorized representative. Depending on the type of AI system, the representative may need full authority to act on behalf of the provider without any limitation of liability. Certain activities are exempt from the draft act’s oversight, including AI used by natural persons solely for personal or household activities, AI for educational research conducted by higher education institutions with ethics committee approval, research and development activities conducted prior to distribution or service provision, and other AI systems prescribed by royal decree. Risk-Based Classification Framework The draft act establishes a tiered risk classification system with three main categories: Prohibited AI. The act outright prohibits AI systems employing cognitive-behavioral manipulation using subliminal techniques, AI systems causing unfair broad-scale discrimination from processing irrelevant data, and other categories of serious risk as determined by announcement of a forthcoming committee that will be responsible
June 25, 2026
On June 18, 2026, Thailand’s Office of the Personal Data Protection Committee (PDPC) published two notifications in the Government Gazette establishing Thailand’s first formal certification framework for personal data protection standards under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notifications, which took immediate effect, introduce a voluntary certification framework aimed at promoting accountability, strengthening organizational data protection governance, and aligning Thailand more closely with international frameworks that recognize certification as a key compliance tool. Certification Criteria The first notification sets out the assessment criteria for organizations seeking certification. Applicants must undergo an evaluation against a framework comprising four assessment categories, 10 focus areas, and 128 assessment criteria covering key elements of a privacy management program. These include: Organizational oversight and internal policies and procedures. Human resource development, including staff training and awareness programs. Clearly defined operational processes and procedures covering data subject rights, transparency obligations, records of processing activities, and lawful basis management, as well as contractual safeguards such as data-processing and data-sharing agreements and risk assessments, including Data Protection Impact Assessments. Technical measures encompassing data security controls and breach response capabilities Based on the assessment results, organizations may be awarded either a PDPA Compliance Certificate or a higher-level PDPA Certificate accompanied by a certification mark. Application and Assessment Process The second notification establishes the application and assessment process for obtaining certification. Eligible applicants include government agencies and private-sector entities that demonstrate sufficient privacy governance maturity and meet the prescribed eligibility requirements. Applicants must submit their applications along with supporting documentation for review. Upon receiving an application, the Office of the PDPC will conduct a detailed evaluation, which may include both documentary review and on-site inspections. Incomplete applications may be rejected, though applicants are typically given a limited period to correct deficiencies before a final decision
June 23, 2026
On May 26, 2026, Thailand’s Department of Land Transport (DLT) published for public consultation a draft amendment to the Ministerial Regulation on Electronic Ride-Hailing Vehicles that would, for the first time, allow juristic persons (legal entities) to register vehicles as electronic ride-hailing cars—a right that currently belongs exclusively to natural persons, limited to one person per one vehicle. If finalized in its current form, the regulation would significantly expand the supply side of Thailand’s ride-hailing market by enabling corporate fleet operators to enter the space. The public comment period is open through June 24, 2026. Key Principles Under the Draft Regulation Under the proposed amendment, juristic persons that maintain a fleet of at least 50 vehicles will be permitted to register vehicles as electronic ride-hailing cars. This represents a fundamental shift from the current framework, which restricts registration to individual natural persons on a one-person-one-car basis. Vehicle Specifications Corporate-owned ride-hailing vehicles must meet the following requirements: Be brand new from the factory, or no more than two years old from first registration with no more than 20,000 km of use. Not be a vehicle that has been reconstructed or repaired after involvement in a serious accident affecting safety—a standard consistent with public transport vehicles (RorYor. 6). Be classified as small, medium, or large in accordance with ministerial or director-general specifications. The vehicles may be equipped with safety devices such as interior or exterior cameras (video/photo recording) and can retain the original factory color of the vehicle body (no mandatory color change is required). License Plates Corporate ride-hailing vehicles will use license plates of the same size, characteristics, and color as those for private passenger vehicles not exceeding seven seats (RorYor. 1), rather than public transport plates. Potential Impact The government has stated that the regulation is intended to: Promote
June 23, 2026
On May 14, 2026, Thailand published a ministerial regulation in the Government Gazette to prescribe measures for prevention and suppression of technology crimes. The regulation creates a comprehensive procedural framework for returning money and digital assets to victims of technology crimes. It will take effect 90 days after publication (in mid-August 2026), giving affected entities a limited window to prepare. Mandatory Reporting Obligations for Financial Institutions When a deposit account, e-money account, or digital asset wallet is frozen in connection with a technology crime, the relevant financial institution or business operator must report transaction data to the Anti-Money Laundering Office (AMLO) via AMLO’s designated electronic system. Required data elements include account numbers (sender and receiver), names, identification or passport numbers, legal entity registration numbers, phone numbers, remaining balance, damage amount, transaction reference numbers, and the bank case ID. Institutions that already share data through the information-sharing system under the emergency decree are deemed to have satisfied this reporting obligation, creating an incentive for platform participation. When the Royal Thai Police or the Department of Special Investigation seize or freeze assets related to technology crimes, they must provide AMLO with investigation reports, complaint evidence, money-trail data, and account statements. Notification and Claims Process Once the AMLO secretary-general approves verified reports of a technology crime, the account information of persons connected to the crime will be published in the Government Gazette, triggering a 90-day window for victims to file claims and for related persons to file objections. Officers will also publish details on AMLO’s electronic media and send registered mail to identified victims, which will be deemed received after 7 days domestically or 15 days internationally. Victims have 90 days from the date the crime is published in the Government Gazette to file claims through AMLO’s electronic system. Claims must include