You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 27, 2024

Thailand Lays Out New Cybersecurity Standards

Thailand’s National Cyber Security Committee (NCSC) released three notifications under the Cybersecurity Act on January 18, 2024, setting cybersecurity-related requirements for key organizations and assets. While one of these notifications already took effect, the two most notable will take effect on January 18, 2025 (i.e., one year from their publication in the Government Gazette).

These two are the NCSC Notification Re: Standards for Defining the Security Category for Data or Information Systems B.E. 2566 (2023) (“Notification on Security Category”) and the NCSC Notification Re: Minimum Standards for Data and Information Systems B.E. 2566 (2023) (“Notification on Minimum Standards”).

These notifications apply to:

  • State agencies;
  • Supervising or regulating organizations (i.e., state organizations, private organizations, or persons designated by law to regulate or supervise the affairs of state organizations or critical information infrastructure organizations); and
  • Critical information infrastructure organizations (i.e., organizations related to or providing national security, significant public services, banking and finance, information technologies and telecommunications, transportation and logistics, energy and public utilities, and public health).

Collectively these are defined as “Organizations” under the notifications.

Notification on Security Category

The Notification on Security Category sets forth risk-based security classifications—or “security categories”—for Organizations’ data or information systems.

For security category assessment purposes, Organizations are required to perform a self-assessment of their data or information systems based on three key security objectives: confidentiality, integrity, and availability. Each of these objectives is further categorized into three risk levels (low, medium, and high), taking into account the assessment of potential impact in the following areas:

  • Organizations’ financial value or reputation;
  • Organizations’ number of service users;
  • Organizations’ ability to perform their duties;
  • State stability or public order.

The risk levels for the three objectives are determined by considering whether there are “minimal,” “severe,” or “serious severe” effects, as described below:

  • Confidentiality (not including data classified as “secret,” which follows different criteria): The effects of unauthorized disclosure of data on Organizations’ reputation and financial value;
  • Integrity: The effects of unauthorized alteration or destruction of data on Organizations’ performance; and
  • Availability: The effects of inability to access or use the data or information system on Organizations’ performance.

If their systems handle different types of data, Organizations must assess each type and set the security category based on the highest risk level identified.

The security category should be reviewed at least once every three years, with the results properly recorded.

Notification on Minimum Standards

Once the security category is determined, Organizations are responsible for applying the minimum cybersecurity measures stipulated in the Notification on Minimum Standards. These measures are outlined in the table below, which indicates the items that are required for minimum cybersecurity measures under each security category.

For more information on compliance with these notifications under the Cybersecurity Act, or on any aspect of cybersecurity in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Napassorn Lertussavavivat at [email protected], or Rada Lamsam at [email protected].

RELATED INSIGHTS​ 

October 7, 2022
Thailand’s Office of the Personal Data Protection Committee (PDPC) has opened a public hearing period on its draft notification regarding cross-border transfer of personal data. The public hearing is open through October 24. The notification, once issued, will supplement the principle of cross-border transfer of personal data outside of Thailand set out in the Personal Data Protection Act (PDPA). The notification sets out the following key matters: Definitions “Transfer of personal data” means any sending or transferring of personal data by a transferor of personal data, either by way of a physical transfer or a remote transfer through a computer system or an internet network to the recipient of the personal data. It does not include sending personal data through an intermediary by transiting between computer systems or internet networks, or any storing or retaining of personal data, either permanently or temporarily, by a cloud computing service provider, whereby the personal data transferor and the personal data recipient (1) are not making the order, (2) are not involved with any data selection or the content of the personal data sent and received through the computer systems or internet networks, or (3) have the purpose of entering into an agreement or any juristic act. “Binding corporate rules” means the agreed terms or policy on personal data protection made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data within a group of corporations or companies. “Standard contractual clauses” means the contractual terms made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data. “Code of conduct” means a code that sets out the obligations of a personal data transferor and a personal data recipient outside of Thailand. “Certification” means an undertaking in relation to
September 21, 2022
Thailand’s Personal Data Protection Committee (PDPC) has released separate guidelines for data controllers to follow in obtaining data subjects’ consent and notifying data subjects of required information (i.e., regarding collection, use, or disclosure of their personal data). By following the guidelines, data controllers can mitigate the risk of violating the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The Guidelines on Obtaining Consent from the Data Subject according to the PDPA and the Guidelines on Notification of Purposes and Details upon the Collection of Personal Data from the Data Subject according to the PDPA were issued on September 7, 2022. Consent Guidelines The PDPC’s guidelines on obtaining consent list the requirements for consent to be considered valid. These requirements include stipulations on timing of requests, elements that need to be included in requests, and the nature of requests. For instance, consent must be obtained before or at the time of obtaining personal data, and data subjects must be informed of both the purposes and details of the personal data handling, among other specific requirements. In turn, there must be a clear affirmative act of the data subject in giving consent. Obtaining consent from minors is subject to more stringent requirements, and data controllers should implement appropriate identification and age-verification measures when collecting personal data about minors. The guidelines give two sets of requirements, depending on the age of the minor—between 10 and 20, and under 10. In general, with the older age group, parental consent is not required in all circumstances, while for the younger age group, parental consent is compulsory for giving consent on behalf of the minor. For a person deemed to be “incompetent” or “quasi-incompetent,” consent must always be given by the legal guardian. Notification Guidelines The guidelines on notifying data subjects when collecting personal data
September 16, 2022
Thailand’s Personal Data Protection Committee (PDPC) has issued a regulation establishing procedures for filing and processing data subjects’ complaints under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The Regulation Re: Complaint Filing, Rejection, Termination, Consideration, and the Period for the Consideration of the Complaint B.E. 2565 (2022) was issued in July 2022 and took effect on July 12, 2022. The PDPA entitles data subjects to file complaints against data controllers, data processors, and employees or service providers of either whose operations fail to comply with the PDPA. This article lays out the various requirements and procedures for the filing and processing of such a complaint. Complaint Submission The body designated by the PDPA to be responsible for handling complaints and imposing administrative penalties is called the “Expert Committee.” Data subjects who would like to make a complaint can submit it to the Expert Committee directly at the Office of PDPC, send it to the office by post, or submit the complaint electronically. The written or electronic complaint must use clear, plain, polite, and appropriate language, and must not give an impression of being directly or indirectly extorting or intimidating. The complaint must include at least the following information: Name, address, and telephone number or email address of the complainant (or an authorized representative), together with identification card, passport, or other official identification document (plus a power of attorney if submitted by a representative); Details and facts of the noncompliance with or violation of the PDPA; Details of resulting damages or impact; Supporting evidence (e.g., documentary evidence, physical evidence, witness statements); and Action desired of the offender. The complaint must include a statement certifying its veracity, and must be signed by the complainant or the authorized representative. Complaint Consideration When a complaint is submitted, the receiving official will
September 8, 2022
While much attention has been paid to the data localization requirements for foreign enterprises under Vietnam’s 2018 Cybersecurity Law (“CSL”) and the recently issued Decree 53 guiding its implementation, the corresponding requirements for domestic enterprises are often overlooked, despite being potentially more troublesome. Under Decree 53, “domestic enterprises” are defined to mean enterprises established or registered for establishment under Vietnamese law and having their head offices in Vietnam (Article 2.11), so this designation includes not only Vietnamese companies, but foreign-invested enterprises as well. Background Before analyzing the stipulations in Articles 26 and 27 of Decree 53 further guiding the data localization/storage requirements, it is worth restating the very problematic Article 26.3 of the CSL, which reads: “Domestic and foreign enterprises providing services on telecommunication networks or the internet or value-added services in cyberspace in Vietnam with activities of collecting, exploiting, analyzing, and/or* processing personal information data, data on the relationships of service users, or data generated by service users in Vietnam must store such data in Vietnam for the period prescribed by the government. Foreign enterprises mentioned in this clause must open branches or representative offices in Vietnam.” [* Note: The Vietnamese text simply uses a comma here, without specifying whether this should be “and” or “or,” leading to additional problems in interpretation.] Because of this very broad and ambiguous wording, Article 26.3 of the CSL required further guidance from the government and remained unenforced for more than three years after the CSL took effect on January 1, 2019. Decree 53 guiding the implementation of the CSL was finally issued on August 15, 2022, and provides additional clarity on this matter. But does Decree 53 provide sufficient guidelines for implementation with regard to domestic enterprises? Scope of Application With regard to foreign enterprises, although there remains some ambiguity, Decree