You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 27, 2024

Thailand Lays Out New Cybersecurity Standards

Thailand’s National Cyber Security Committee (NCSC) released three notifications under the Cybersecurity Act on January 18, 2024, setting cybersecurity-related requirements for key organizations and assets. While one of these notifications already took effect, the two most notable will take effect on January 18, 2025 (i.e., one year from their publication in the Government Gazette).

These two are the NCSC Notification Re: Standards for Defining the Security Category for Data or Information Systems B.E. 2566 (2023) (“Notification on Security Category”) and the NCSC Notification Re: Minimum Standards for Data and Information Systems B.E. 2566 (2023) (“Notification on Minimum Standards”).

These notifications apply to:

  • State agencies;
  • Supervising or regulating organizations (i.e., state organizations, private organizations, or persons designated by law to regulate or supervise the affairs of state organizations or critical information infrastructure organizations); and
  • Critical information infrastructure organizations (i.e., organizations related to or providing national security, significant public services, banking and finance, information technologies and telecommunications, transportation and logistics, energy and public utilities, and public health).

Collectively these are defined as “Organizations” under the notifications.

Notification on Security Category

The Notification on Security Category sets forth risk-based security classifications—or “security categories”—for Organizations’ data or information systems.

For security category assessment purposes, Organizations are required to perform a self-assessment of their data or information systems based on three key security objectives: confidentiality, integrity, and availability. Each of these objectives is further categorized into three risk levels (low, medium, and high), taking into account the assessment of potential impact in the following areas:

  • Organizations’ financial value or reputation;
  • Organizations’ number of service users;
  • Organizations’ ability to perform their duties;
  • State stability or public order.

The risk levels for the three objectives are determined by considering whether there are “minimal,” “severe,” or “serious severe” effects, as described below:

  • Confidentiality (not including data classified as “secret,” which follows different criteria): The effects of unauthorized disclosure of data on Organizations’ reputation and financial value;
  • Integrity: The effects of unauthorized alteration or destruction of data on Organizations’ performance; and
  • Availability: The effects of inability to access or use the data or information system on Organizations’ performance.

If their systems handle different types of data, Organizations must assess each type and set the security category based on the highest risk level identified.

The security category should be reviewed at least once every three years, with the results properly recorded.

Notification on Minimum Standards

Once the security category is determined, Organizations are responsible for applying the minimum cybersecurity measures stipulated in the Notification on Minimum Standards. These measures are outlined in the table below, which indicates the items that are required for minimum cybersecurity measures under each security category.

For more information on compliance with these notifications under the Cybersecurity Act, or on any aspect of cybersecurity in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Napassorn Lertussavavivat at [email protected], or Rada Lamsam at [email protected].

RELATED INSIGHTS​ 

September 6, 2022
The Thai National Cybersecurity Committee (NCSC), as required by the Cybersecurity Act, reported to the cabinet in mid-August on trends and developments regarding cyber incidents in Thailand. According to the NCSC, the top five most common cyber incidents involve website phishing, website defacement, data leakage, data security vulnerabilities, and ransomware. Reported incidents of cyberattacks have increased in recent years. The report stated that affected organizations primarily responded to cyber incidents and attacks by notifying the NCSC about the incident and the remedial actions planned or taken, and conducting internal training to increase awareness of cyber threats. Only two organizations chose to conduct IT risk assessments and vulnerability tests as preventive measures against future cyber threats. The NCSC report also showed that aside from telecom infrastructure, energy and utilities, and education operators falling victim to cyberattacks, healthcare, webhosting, and data center operators have also become “more common victims” of cyber incidents. The NCSC recommended that all organizations prepare for inevitable future cyber incidents. This includes ensuring that businesses and organizations comply with international standards, which includes measures that are recognized and incorporated in Thailand’s Personal Data Protection Act (PDPA) and Cybersecurity Act. Conducting internal training for employees as well as directors and officers is also recommended by the NCSC, as this can help prevent cyber incidents and ensure that businesses comply with the minimum required security standards issued by the Personal Data Protection Committee (PDPC) in their Notification Re: Security Measures of the Data Controller B.E. 2565 (2022), which came into effect on June 21, 2022. Industry-specific minimum required security standards (e.g., those regulated by the Bank of Thailand, Office of Insurance Commission, etc.) should also be considered in conjunction with those in this PDPC notification—particularly when sectoral requirements are more stringent than the PDPC’s recommended measures. PDPA statutory penalties
August 19, 2022
Vietnam’s Cybersecurity Law was promulgated on June 12, 2018, and came into effect on January 1, 2019, with a majority of its provisions enforceable from the effective date. However, certain provisions of the law, including the very concerning data localization requirements, still awaited further guidance from implementing regulations. After more than three years of being drafted and submitted back and forth to the government for consideration and approval, Decree No. 53/2022/ND-CP to implement certain articles of the Cybersecurity Law (Decree 53) was finally promulgated on August 15, 2022, with an effective date of October 1, 2022. Key provisions of Decree 53 include the following. 1. Data localization requirements (Articles 26 & 27) Decree 53 retains most of the data localization requirements of the last accessible version of the draft decree dated August 21, 2019 (Draft Decree), clearly extends the scope of requirements to cover both domestic and foreign enterprises, adds regulations on force majeure events, and amends the timeline to implement data localization requirements for business facilitation. (i) Data subject to data localization: Data (information in the form of symbols, writing, numbers, images, sounds, or similar forms) which must be stored in Vietnam (“regulated data”) includes: Data on personal information of service users in Vietnam: Data used to identify an individual. Data generated by service users in Vietnam: Data reflecting the process of participating in, operating and/or using cyberspace by service users and information about network equipment and services used in order to connect with cyberspace in the territory of Vietnam. This includes the account name for use of services, duration of use of services, credit card information, email address, IP addresses for the latest login and logout, and registered telephone number attached to the account or data. Data on the relationships of service users in Vietnam: Data reflecting
August 11, 2022
In July 2022, the Thai cabinet approved in principle a royal decree exempting some businesses and other entities from parts of the Personal Data Protection Act B.E. 2562 (PDPA). The draft royal decree proposes to exempt certain business operators and activities from the requirements of the following portions of the PDPA: Chapter II: Personal Data Protection – Consent, notification, cross-border transfer of the personal data requirements, etc. Chapter III: Rights of the Data Subject – Requirements and criteria on data subject rights. Chapter V: Complaints – Requirements on the submission of complaints to the Office of the Personal Data Protection Commission. Chapter VI: Civil Liability – Conditions in relation to the civil liability of a data controller or data processor. Chapter VII: Penalties – Administrative and criminal penalties. The proposed exemptions would apply to three main categories of business operators and activities: 1. Data controllers acting on government requests in adherence with specific laws for the following purposes: State security and public safety. Exempted operations include activities intended to safeguard state security, intelligence, and information relating to national security, as well as efforts to maintain fiscal and economic security and public security. Also exempt are prevention and suppression of certain criminal activities, such as money laundering, drug trafficking, transnational threats and terrorism, transnational crime, and human trafficking; activities to bolster anticorruption or cybersecurity efforts; and actions relating to public health, sanitation to prevent epidemics, and protection of public life, health, and property. Taxation. Exempted activities include those related to tax collection under laws that are the responsibility of the Revenue Department, Customs Department, or Excise Department. This also extends to any action relating to the enforcement of taxation fees or duties, and actions related to social security, the performance of obligations, or international cooperation. Risk mitigation, monitoring, and surveillance.
July 31, 2022
Thailand’s Securities and Exchange Commission (SEC) has announced three new regulatory requirements, which primarily require digital asset business operators to provide investors with training or a knowledge test on cryptocurrencies and to disclose information about the quality of their service and IT usage capacity. The amended SEC notification detailing these new obligations was promulgated on July 1, 2022; however, the measures come into effect separately, as detailed below. Training or Testing on Cryptocurrency From August 30, 2022, cryptocurrency exchanges, brokers, and dealers must provide guidance and education to their clients on basic asset allocation suitable to their capacity. These types of digital asset business operators must also provide for training or a knowledge test on cryptocurrency. The content should at least cover cryptocurrency, blockchain technology, digital wallets, and an overview of the market and investments. The following types of clients are exempted from these requirements: Existing clients of the digital asset business operators before July 1, 2022; New clients of the operator who already have experience investing in cryptocurrency before using the service of the business operator; and Institutional investors, ultra-high-net-worth investors, and high-net-worth investors. If the clients are legal entities other than those mentioned above, their representatives or appointed persons are required to undergo training or testing. The training or knowledge test is a prerequisite to using a digital asset business operator’s services. Operators are not allowed to provide their services to clients who do not undergo training or testing. Disclosure of Service Quality and IT Usage Capacity From January 1, 2023, cryptocurrency/digital token exchanges, brokers, and dealers are required to disclose to the SEC information about the quality of their services (including any technological errors and complaints from clients), and their IT usage capacity. For more information about the latest SEC rules and regulations for digital assets,