You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 15, 2025

Thailand Prepares Startup Promotion Act to Unlock Fundraising and Support

Thailand is taking steps to energize its startup scene by drafting the Startup Promotion Law. This draft law aims to remove obstacles, open new funding opportunities, and provide coordinated government support. The goal is to make it easier for Thailand-based startups to grow and compete on a global stage.

Why Is This Law Needed?

For many years, Thai startups have operated under traditional company law frameworks that were not designed with high-growth businesses or with fundraising opportunities in mind. Restrictions on issuing bonds, offering shares to outside investors, and repurchasing shares for employee incentive programs made it challenging for emerging companies to access capital and accelerate their growth. The draft Startup Promotion Act seeks to remove these obstacles and foster a more competitive, entrepreneur-friendly environment in Thailand.

Who’s in Charge?

Two main organizations will oversee the startup ecosystem:

  • Startup Promotion Committee: This group, to be appointed by the National Science, Research, and Innovation Policy Council, will set national strategies, policies, and budget; design promotional campaign and incentives; and propose further legislative amendments to promote startups.
  • National Innovation Agency (NIA): Under the draft act, the NIA will be the main contact for startups and will serve as the secretariat office of the Startup Promotion Committee, coordinating data, advising startups, maintaining the public registry, and providing funding and investment (grants, repayable grants, loans, and equity) under committee criteria and, where applicable, cabinet approval.

What Startups Are Eligible for Benefits?

To be officially recognized and access benefits, a company must:

  • Be a private limited company less than 10 years old at the time of application. Existing companies that already exceed the 10-year threshold may still apply for startup statues within one year of the law’s enactment, as long as they otherwise still qualify for the new regime.
  • Have average annual revenue not exceeding THB 300 million over the past three years (with possible adjustments for different sectors).
  • Never have declared dividends before.
  • Not be controlled by another company, unless the parent is also a certified startup or a university spinoff focused on commercializing research.

Application Process

Applications must be submitted online to the NIA, and applicants must certify the accuracy of all information provided. Once approved, the company’s name will be published by the NIA on a list categorized by business sector.

Labor Requirement

Within two years of certification, startups must employ a minimum number of qualified Thai workers, as specified by the Startup Promotion Committee.

What Are the Main Benefits for Eligible Startups?

Certified startups will receive special privileges for five years. For categories designated as deep‑tech, the committee may extend the term for a total of up to ten years.

Flexible Corporate Financing

  • Startups can publicly offer shares and issue corporate bonds, which are currently restricted under Thai law.
  • They can allocate new shares to outside investors in addition to existing shareholders.
  • Debt can be converted into equity, making it easier to use modern investment tools like convertible notes.
  • Preferred shares can be converted into ordinary shares.
  • Startups can buy back up to 20% of their own shares as treasury stock. Buybacks are allowed for financial management, fulfilling investment agreements, or acquiring shares from dissenting shareholders. Treasury shares can be used for employee stock option programs (ESOPs) or future investment allocations.

Government Support Measures

  • Tax incentives: Access to tax benefits designed to support startup growth.
  • Immigration benefits: Facilitation under existing immigration and foreign-worker laws; the committee may propose categories of qualified foreign experts and high-skill personnel for certified startups.
  • Government procurement: Where suitable, agencies will treat certified startups’ goods and services as items the state intends to promote under the Public Procurement and Supplies Administration Act.
  • Intellectual property support: Assistance with IP registration and protection.
  • Investment incentives: Eligibility for incentives under the Board of Investment (BOI), Eastern Economic Corridor (EEC), and other competitiveness enhancement initiatives.

The draft law requires the relevant government agencies to assist certified startups in accessing these applicable benefits. The NIA will coordinate information, request documents, and serve as a hub connecting startups to tax, immigration, procurement, IP, BOI/EEC, and other authorities.

How Is Compliance Enforced?

The law sets out clear sanctions and other mechanisms to make sure only eligible startups benefit and that privileges are not abused:

  • Administrative fines: Fines range from THB 20,000 to THB 100,000 for violations such as unlawful public offerings of shares or bonds, holding too many treasury shares, failing to maintain a share register, or not canceling unallocated shares after a project ends. Ongoing violations can result in additional daily fines.
  • Personal liability: Directors, managers, and responsible officers can be held personally liable if a violation occurs due to their actions or inaction.
  • Annual reconfirmation: Startups must reconfirm their eligibility every year. Failure to do so, or providing false information, can result in removal from the official list and loss of benefits.
  • Oversight and monitoring: The NIA monitors compliance and may conduct checks or request more information from certified startups.

Outlook

Thailand’s Startup Promotion Law is a significant step toward modernizing business regulations and supporting local innovation. By making fundraising easier and improving access to government support, the law aims to help startups grow and compete internationally. The draft act has completed public consultation and is now progressing to Parliament, and both startups and investors should keep track of its developments.

RELATED INSIGHTS​ 

March 29, 2024
Thailand’s Cybersecurity Regulating Committee (CRC) released a notification under the Cybersecurity Act on February 22, 2024, setting key operational obligations for critical information infrastructure (CII) organizations. The notification takes effect on June 20, 2024. CII organizations are state or private entities that carry out services related to national security, public services, banking and finance, information technology and telecommunications, transportation and logistics, energy and public utilities, or public health. CII organizations will be identified by the National Cyber Security Committee (NCSC) and notified of their status. The key obligations of CII organizations are laid out below. Reporting to the National Cyber Security Agency (NCSA) CII organizations must provide the following to the NCSA: A list of executive and operational staff, along with emergency contacts who can be reached within 60 minutes in the event of a cyber threat. The NCSA must be notified of any updates to this list within 15 days following any changes. A list of internal departments or individuals who are the responsible persons, owners, and holders of the computer systems, along with emergency contacts who can be reached within 60 minutes in the event of a cyber threat. The NCSA must be notified of any updates to this list at least 7 days prior to any changes (or within 15 days after the change if there is a necessary reason). Policies, Guidelines, and Procedures As specified in the National Cyber Security Committee (NCSC) guidelines, CII organizations must prepare the following internal documents by June 20, 2025: Cybersecurity practice guidelines, consisting of an inspection plan, risk assessment, and incident response plan. Cybersecurity standards framework, consisting of measures for risk identification, risk prevention, threat detection and monitoring, incident responses, and resilience and recovery. CII organizations must also prepare the following: Mechanisms, procedures, and steps for monitoring and detecting
March 29, 2024
Vietnam’s Ministry of Public Security (MPS) is drafting two reports to present to the government in May 2024 to advocate for the development and adoption of a Law on Personal Data Protection. These reports include an assessment of the policy impact of the proposal to develop a personal data protection law, and an assessment of the current state of social relations related to personal data protection. Decree No. 13/2023/ND-CP on Personal Data Protection (PDPD), adopted in April 2023, became the first comprehensive legal instrument on data protection in Vietnam. When the National Assembly was debating its text and adoption in 2022 and 2023, questions were raised as to the status of this new regulation and the legality to adopt a decree before a law. In accordance with the public announcements made throughout the development of the PDPD assuring that a law would be developed at a later stage, the MPS is now advocating for the development of a Personal Data Protection Law and has drafted the two reports pursuant to the Law on the Promulgation of Legal Documents. The main arguments advanced by the MPS in the two reports are as follows: As the right to privacy is enshrined in the Constitution, any restrictions thereof must be made through a law and not a decree. The MPS is notably referring to the lawful basis for processing and limited exceptions to consent under the PDPD. This may be a sign that the MPS intends to widen the exceptions to consent under the new law. The definitions of “personal data” and “personal data protection” need to be harmonized to consolidate the regulatory framework. The MPS indicates that there are 69 legal documents directly related to “personal data protection” in Vietnam with more than 10 different definitions, while “personal information” appears in
March 28, 2024
Recently, Vietnam has witnessed a dramatic increase in cyber fraud, causing significant financial losses and posing a grave threat to both Vietnamese and foreign entities. With the increasing reliance on digital technology and the widespread adoption of online platforms, the country has become fertile ground for cybercriminals to exploit vulnerabilities and conduct various fraudulent activities. This article aims to present an overview of addressing cyber fraud in Vietnam and offers practical advice for businesses to safeguard themselves from becoming victims of such illicit activities.
March 27, 2024
Two notifications on the cross-border transfer of personal data, issued by Thailand’s Personal Data Protection Committee (PDPC), came into effect on March 24, 2024. These notifications, which we detailed in a previous update, set out the criteria governing the cross-border transfer of personal data offshore, specifically focusing on situations where appropriate personal data protection standards are in place. Of particular importance is the role of binding corporate rules (BCRs) in enabling the cross-border transfer of personal data among affiliated businesses or within the same group of undertakings. The implementation of BCRs requires a comprehensive review and approval process by the Office of the PDPC, strictly in accordance with the criteria set out in one of the two notifications. With the notifications now fully enforceable, the Office of the PDPC has begun accepting BCRs for review. Data controllers and data processors intending to adopt BCRs as a means for transferring data to offshore affiliates or group companies must initiate the BCR submission process promptly. Failure to comply with PDPA requirements concerning the cross-border transfer of personal data could result in substantial penalties. Organizations involved in cross-border personal data transfers should be proactive in complying with the prescribed criteria to avoid these regulatory penalties and maintain the data protection standards mandated by the PDPA. For more information on these cross-border personal data transfer regulations, or on any aspect of complying with Thailand’s data protection laws, please contact Nopparat Lalitkomon at [email protected], Gvavalin Mahakunkitchareon at [email protected], or Wilin Somya at [email protected].