You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 15, 2025

Thailand Prepares Startup Promotion Act to Unlock Fundraising and Support

Thailand is taking steps to energize its startup scene by drafting the Startup Promotion Law. This draft law aims to remove obstacles, open new funding opportunities, and provide coordinated government support. The goal is to make it easier for Thailand-based startups to grow and compete on a global stage.

Why Is This Law Needed?

For many years, Thai startups have operated under traditional company law frameworks that were not designed with high-growth businesses or with fundraising opportunities in mind. Restrictions on issuing bonds, offering shares to outside investors, and repurchasing shares for employee incentive programs made it challenging for emerging companies to access capital and accelerate their growth. The draft Startup Promotion Act seeks to remove these obstacles and foster a more competitive, entrepreneur-friendly environment in Thailand.

Who’s in Charge?

Two main organizations will oversee the startup ecosystem:

  • Startup Promotion Committee: This group, to be appointed by the National Science, Research, and Innovation Policy Council, will set national strategies, policies, and budget; design promotional campaign and incentives; and propose further legislative amendments to promote startups.
  • National Innovation Agency (NIA): Under the draft act, the NIA will be the main contact for startups and will serve as the secretariat office of the Startup Promotion Committee, coordinating data, advising startups, maintaining the public registry, and providing funding and investment (grants, repayable grants, loans, and equity) under committee criteria and, where applicable, cabinet approval.

What Startups Are Eligible for Benefits?

To be officially recognized and access benefits, a company must:

  • Be a private limited company less than 10 years old at the time of application. Existing companies that already exceed the 10-year threshold may still apply for startup statues within one year of the law’s enactment, as long as they otherwise still qualify for the new regime.
  • Have average annual revenue not exceeding THB 300 million over the past three years (with possible adjustments for different sectors).
  • Never have declared dividends before.
  • Not be controlled by another company, unless the parent is also a certified startup or a university spinoff focused on commercializing research.

Application Process

Applications must be submitted online to the NIA, and applicants must certify the accuracy of all information provided. Once approved, the company’s name will be published by the NIA on a list categorized by business sector.

Labor Requirement

Within two years of certification, startups must employ a minimum number of qualified Thai workers, as specified by the Startup Promotion Committee.

What Are the Main Benefits for Eligible Startups?

Certified startups will receive special privileges for five years. For categories designated as deep‑tech, the committee may extend the term for a total of up to ten years.

Flexible Corporate Financing

  • Startups can publicly offer shares and issue corporate bonds, which are currently restricted under Thai law.
  • They can allocate new shares to outside investors in addition to existing shareholders.
  • Debt can be converted into equity, making it easier to use modern investment tools like convertible notes.
  • Preferred shares can be converted into ordinary shares.
  • Startups can buy back up to 20% of their own shares as treasury stock. Buybacks are allowed for financial management, fulfilling investment agreements, or acquiring shares from dissenting shareholders. Treasury shares can be used for employee stock option programs (ESOPs) or future investment allocations.

Government Support Measures

  • Tax incentives: Access to tax benefits designed to support startup growth.
  • Immigration benefits: Facilitation under existing immigration and foreign-worker laws; the committee may propose categories of qualified foreign experts and high-skill personnel for certified startups.
  • Government procurement: Where suitable, agencies will treat certified startups’ goods and services as items the state intends to promote under the Public Procurement and Supplies Administration Act.
  • Intellectual property support: Assistance with IP registration and protection.
  • Investment incentives: Eligibility for incentives under the Board of Investment (BOI), Eastern Economic Corridor (EEC), and other competitiveness enhancement initiatives.

The draft law requires the relevant government agencies to assist certified startups in accessing these applicable benefits. The NIA will coordinate information, request documents, and serve as a hub connecting startups to tax, immigration, procurement, IP, BOI/EEC, and other authorities.

How Is Compliance Enforced?

The law sets out clear sanctions and other mechanisms to make sure only eligible startups benefit and that privileges are not abused:

  • Administrative fines: Fines range from THB 20,000 to THB 100,000 for violations such as unlawful public offerings of shares or bonds, holding too many treasury shares, failing to maintain a share register, or not canceling unallocated shares after a project ends. Ongoing violations can result in additional daily fines.
  • Personal liability: Directors, managers, and responsible officers can be held personally liable if a violation occurs due to their actions or inaction.
  • Annual reconfirmation: Startups must reconfirm their eligibility every year. Failure to do so, or providing false information, can result in removal from the official list and loss of benefits.
  • Oversight and monitoring: The NIA monitors compliance and may conduct checks or request more information from certified startups.

Outlook

Thailand’s Startup Promotion Law is a significant step toward modernizing business regulations and supporting local innovation. By making fundraising easier and improving access to government support, the law aims to help startups grow and compete internationally. The draft act has completed public consultation and is now progressing to Parliament, and both startups and investors should keep track of its developments.

RELATED INSIGHTS​ 

August 1, 2025
Thailand’s Personal Data Protection Committee (PDPC) announced to the press on August 1, 2025, that it had issued eight new administrative fines under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) in five cases of noncompliance by public and private entities. The enforcement actions reflect a growing commitment by the PDPC to penalize noncompliance across all sectors, regardless of organizational type or size. The total amount imposed to date was approximately THB 21.5 million (approx. USD 654,690), underscoring the financial risks tied to PDPA violations. The five cases—one involving a state agency and the remainder in the private sector—are summarized below. Case 1: State Agency Providing Online Services to the Public The order in this case stemmed from a cyberattack on a state agency’s web app, resulting in personal data of 200,000 data subjects being leaked to and sold on the dark web. The software developer was also found to have implemented no privacy by design, lacked an access control system, had no data breach prevention measures, and failed to conduct risk assessments or review existing security measures. Key noncompliance identified: Lack of appropriate security measures Weak password protection No risk assessment or ongoing review of security measures No data processing agreement with software developer that acted as data processor The state agency and the developer were each fined THB 153,120 (approx. USD 4,670). Case 2: Private Hospital This case involved a hospital that engaged an individual contractor to destroy patient medical record documents. However, the contractor stored the documents at their own premises, failed to follow the required destruction protocols, and ultimately used the medical records to wrap sweets, resulting in the leak of over 1,000 records during the destruction process. The contractor also failed to notify the hospital of the data breach. Although there was a
August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with
August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention
July 30, 2025
Artificial intelligence (AI) model training and data scraping are essential processes in the development of modern AI systems. AI model training involves using large datasets to teach machine learning algorithms to recognize patterns, make predictions, or generate new content. Data scraping refers to the automated extraction of information from websites or digital sources, often to assemble the vast datasets required for effective AI training. As these practices become more widespread, questions about the legality of using third-party content—especially copyrighted works—have become increasingly important. In Thailand, the legal landscape for AI developers is shaped primarily by the Copyright Act, which presents unique challenges due to the absence of a fair-use exception. This article examines the copyright-related risks and legal uncertainties facing AI developers under Thailand’s current copyright law and practices, offering strategic guidance for navigating this complex environment. Copyright Risks in AI Scraping and Training Thailand’s Copyright Act does not provide a broad fair use or fair dealing exception, unlike some other jurisdictions, such as the United States. This absence has significant consequences for AI developers: No general defense for AI training: Any use of copyrighted material for AI model training is presumed to be infringing unless a specific, narrow statutory exception applies or explicit permission is obtained from the rights holder. There is no general legal basis for using copyrighted works in AI training without authorization. Increased rights clearance burden: Developers must identify and secure licenses for every copyrighted work included in their training datasets. Given the scale and diversity of data required for effective AI models, this process can be both impractical and costly. Legal ambiguity and litigation risk: The lack of clear statutory guidance or case law leaves developers in a legal gray area. There is no established precedent clarifying whether certain uses of copyrighted material for