You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 15, 2025

Thailand Prepares Startup Promotion Act to Unlock Fundraising and Support

Thailand is taking steps to energize its startup scene by drafting the Startup Promotion Law. This draft law aims to remove obstacles, open new funding opportunities, and provide coordinated government support. The goal is to make it easier for Thailand-based startups to grow and compete on a global stage.

Why Is This Law Needed?

For many years, Thai startups have operated under traditional company law frameworks that were not designed with high-growth businesses or with fundraising opportunities in mind. Restrictions on issuing bonds, offering shares to outside investors, and repurchasing shares for employee incentive programs made it challenging for emerging companies to access capital and accelerate their growth. The draft Startup Promotion Act seeks to remove these obstacles and foster a more competitive, entrepreneur-friendly environment in Thailand.

Who’s in Charge?

Two main organizations will oversee the startup ecosystem:

  • Startup Promotion Committee: This group, to be appointed by the National Science, Research, and Innovation Policy Council, will set national strategies, policies, and budget; design promotional campaign and incentives; and propose further legislative amendments to promote startups.
  • National Innovation Agency (NIA): Under the draft act, the NIA will be the main contact for startups and will serve as the secretariat office of the Startup Promotion Committee, coordinating data, advising startups, maintaining the public registry, and providing funding and investment (grants, repayable grants, loans, and equity) under committee criteria and, where applicable, cabinet approval.

What Startups Are Eligible for Benefits?

To be officially recognized and access benefits, a company must:

  • Be a private limited company less than 10 years old at the time of application. Existing companies that already exceed the 10-year threshold may still apply for startup statues within one year of the law’s enactment, as long as they otherwise still qualify for the new regime.
  • Have average annual revenue not exceeding THB 300 million over the past three years (with possible adjustments for different sectors).
  • Never have declared dividends before.
  • Not be controlled by another company, unless the parent is also a certified startup or a university spinoff focused on commercializing research.

Application Process

Applications must be submitted online to the NIA, and applicants must certify the accuracy of all information provided. Once approved, the company’s name will be published by the NIA on a list categorized by business sector.

Labor Requirement

Within two years of certification, startups must employ a minimum number of qualified Thai workers, as specified by the Startup Promotion Committee.

What Are the Main Benefits for Eligible Startups?

Certified startups will receive special privileges for five years. For categories designated as deep‑tech, the committee may extend the term for a total of up to ten years.

Flexible Corporate Financing

  • Startups can publicly offer shares and issue corporate bonds, which are currently restricted under Thai law.
  • They can allocate new shares to outside investors in addition to existing shareholders.
  • Debt can be converted into equity, making it easier to use modern investment tools like convertible notes.
  • Preferred shares can be converted into ordinary shares.
  • Startups can buy back up to 20% of their own shares as treasury stock. Buybacks are allowed for financial management, fulfilling investment agreements, or acquiring shares from dissenting shareholders. Treasury shares can be used for employee stock option programs (ESOPs) or future investment allocations.

Government Support Measures

  • Tax incentives: Access to tax benefits designed to support startup growth.
  • Immigration benefits: Facilitation under existing immigration and foreign-worker laws; the committee may propose categories of qualified foreign experts and high-skill personnel for certified startups.
  • Government procurement: Where suitable, agencies will treat certified startups’ goods and services as items the state intends to promote under the Public Procurement and Supplies Administration Act.
  • Intellectual property support: Assistance with IP registration and protection.
  • Investment incentives: Eligibility for incentives under the Board of Investment (BOI), Eastern Economic Corridor (EEC), and other competitiveness enhancement initiatives.

The draft law requires the relevant government agencies to assist certified startups in accessing these applicable benefits. The NIA will coordinate information, request documents, and serve as a hub connecting startups to tax, immigration, procurement, IP, BOI/EEC, and other authorities.

How Is Compliance Enforced?

The law sets out clear sanctions and other mechanisms to make sure only eligible startups benefit and that privileges are not abused:

  • Administrative fines: Fines range from THB 20,000 to THB 100,000 for violations such as unlawful public offerings of shares or bonds, holding too many treasury shares, failing to maintain a share register, or not canceling unallocated shares after a project ends. Ongoing violations can result in additional daily fines.
  • Personal liability: Directors, managers, and responsible officers can be held personally liable if a violation occurs due to their actions or inaction.
  • Annual reconfirmation: Startups must reconfirm their eligibility every year. Failure to do so, or providing false information, can result in removal from the official list and loss of benefits.
  • Oversight and monitoring: The NIA monitors compliance and may conduct checks or request more information from certified startups.

Outlook

Thailand’s Startup Promotion Law is a significant step toward modernizing business regulations and supporting local innovation. By making fundraising easier and improving access to government support, the law aims to help startups grow and compete internationally. The draft act has completed public consultation and is now progressing to Parliament, and both startups and investors should keep track of its developments.

RELATED INSIGHTS​ 

May 15, 2024
On May 1, 2024, Thailand’s National Cyber Security Committee (NCSC) published the draft NCSC Notification Re: Cloud Cybersecurity Standards for a public hearing period, which was open until May 14, 2024. These standards have been drafted to drive the country’s cloud-first policy with the aim of minimizing risks from cyber threats to cloud services utilized by government agencies, supervising or regulating organizations, and critical information infrastructure (CII) organizations. The key points of the draft Cloud Cybersecurity Standards are below. Scope The standards apply to government agencies, supervising or regulating organizations, and CII organizations under the Cybersecurity Act B.E. 2562 (2019), as well as cloud service providers (defined below). The standards prescribe cloud system cybersecurity measures for cloud service customers (defined below) and providers only to the extent that the service is provided to the in-scope organizations outlined above. Definitions Cloud service customers (CSCs): In-scope organizations that have a formal contractual agreement to use cloud services provided by a cloud service provider. Cloud service providers (CSPs): Persons who enable cloud services to be used by a cloud service customer, responsible for maintaining infrastructure, platforms, and software that enable provision of the cloud services and for managing these resources to ensure their accessibility, security, and scalability for their cloud service customers. Application In-scope organizations that will use or have been using cloud services must comply with the Cloud Cybersecurity Standards by taking into account their data or technology information systems’ level of impact, as specified in the previously issued Notification of the NCSC Re: Standards for Defining the Security Category for Data and Information Systems B.E. 2566 (2023). The impact level related to personal data is to be rated as being at least at the medium level, and the minimum standards for that level specified in the draft Cloud Cybersecurity Standards
May 13, 2024
On May 2, 2024, Vietnam’s Ministry of Justice published on its online platform the most recent version of the draft decree on administrative sanctions for violations in the field of cybersecurity (“Draft Sanction Decree”) to gather feedback and contributions from the community and stakeholders. After receiving the Ministry of Justice’s assessment, the Ministry of Public Security (“MPS”), in charge of drafting the Draft Sanction Decree, may make further revisions before submitting it to the government for review and final decision on enactment. The decree is expected to have an effective date of June 1, 2024. The stringent penalties for infringements involving personal data of the previous draft version remain in this Draft Sanction Decree—a sign of the proactive stance of the MPS in enforcing the Personal Data Protection Decree (“PDPD”). Effective Date and Transitional Provisions It is important to note that the Draft Sanction Decree does not impose any new obligations on organizations or individuals, and only sets out the administrative sanctions that could be imposed on violators as soon as June 1, 2024, which is indicated as the effective date in Article 49. This signals the MPS’s eagerness to begin taking enforcement actions against recalcitrant organizations and individuals that have not complied with the various obligations imposed on them under the Law on Network Information Security (enacted in 2015), the Law on Cybersecurity (enacted in 2018) and its guiding decree (Decree 53 – enacted in 2022), and the most recent PDPD (enacted in 2023). Article 50.1 of the Draft Sanction Decree outlines the transitional provisions regarding administrative violations in the cybersecurity field. It clarifies that the decree does not have retroactive effect, by stating that violations occurring before its effective date, but discovered or under review after such effective date will be subject to the regulations on administrative
May 9, 2024
As non-cash payments continue to surge in Vietnam, the requirement for strong security standards and a clear legislative framework for intermediary payment services (“IPS”) is becoming more and more critical. Recognizing this, the State Bank of Vietnam (“SBV”) has been working on a draft decree to supersede the outdated Decree No. 101/2012/ND-CP dated November 22, 2012, on non-cash payments (“Draft Non-Cash Payment Decree”), which will lay the groundwork for non-cash payments in general and the provision of IPS in particular. Building upon this, the SBV recently issued a draft circular to replace Circular No. 39/2014/TT-NHNN dated December 11, 2014, on IPS (“Circular 39”) (“Draft IPS Circular”), which will offer more detailed guidance on the provision of IPS in Vietnam on top of the Draft Non-Cash Payment Decree. The Draft IPS Circular will be applicable to (i) IPS providers; (ii) foreign organizations providing IPS in Vietnam; and (iii) organizations and individuals involved in the provision of IPS. Some key updates regarding the Draft IPS Circular are as follows: Scope of Application The Draft IPS Circular sets out further guidance for the provision of IPS as listed under the Draft Non-Cash Payment Decree, including: (i) electronic clearing services; (ii) electronic wallet (“e-wallet”) services; (iii) collection and payment support services; (iv) financial switching services; (v) international financial switching services; and (vi) electronic payment gateway services. Notably, the Draft IPS Circular has explicitly excluded from its scope of application the provision of accounts by goods/service providers to their customers solely for the purpose of payment within the systems of such providers (e.g., cards/coupons or service/transaction accounts of online game service providers, transportation service providers, or securities companies, etc.). Requirements on the Provision of IPS Electronic Clearing Services: The Draft IPS Circular introduces regulations to cover certain elements of electronic clearing services that have
May 9, 2024
On April 29, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) issued the master plan for personal data protection, which outlines the PDPC’s strategies for developing and enhancing the data protection framework in Thailand from 2024 to 2027. A draft of this four-year plan had previously been released for a public hearing on November 27, 2023. Overview The master plan sets out the long-term direction for the protection of personal data in Thailand, analyzing the current landscape, challenges, and obstacles encountered since the full enactment of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). It aims to align with Thailand’s National Security Policy and Plan for 2024–2027 and focuses on key sectors in its initial two years. These sectors are: Public security and key government services; Retail and e-commerce; Information and communication technology and telecommunications; Finance, investment, and insurance; Public health; Tourism; and Education. Objectives The master plan’s goals include increasing organizational compliance with the PDPA, reducing data breaches, updating the PDPA to reflect current circumstances, introducing various PDPC e-services, and enhancing Thailand’s global competitiveness in data privacy and personal data protection. It sets targets and indicators of the plan’s success, such as achieving a 100% PDPA compliance rate across all sectors in Thailand and raising Thailand’s digital competitiveness to at least 30th in the World Digital Competitiveness Rankings from the IMD World Competitiveness Center. Strategic Initiatives To achieve these objectives, the master plan introduces four strategic initiatives: Effective and balanced PDPA enforcement: Develop standards, principles, criteria, tools, indicators, and data privacy governance, including law enhancements. A recent example of this is the PDPC’s launch of the Personal Data Protection Surveillance Centre (PDPC Eagle Eye) to monitor data breaches. Knowledge and trust enhancement: Build human capacity and trust by enhancing knowledge through initiatives like the forthcoming