You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 6, 2025

Thailand Releases Draft Guidelines on Government Cloud Adoption and Data Classification

Thailand’s Digital Government Development Agency (DGA) has released drafts of two pivotal documents to guide Thai government agencies in adopting cloud technology and classifying data for cloud usage. These draft guidelines, open for public hearing through August 12, 2025, are part of the national “Go Cloud First” policy, which aims to accelerate digital transformation, improve efficiency, and ensure robust data security across the public sector. The new standards will have significant implications for both government agencies and cloud service providers operating in Thailand.

Highlights of the draft guidelines are presented below.

Government Cloud Usage Guidelines

  • Cloud-first transformation: All government agencies are directed to prioritize cloud solutions for new IT projects, in line with the cabinet’s “Go Cloud First” policy.
  • Cloud model selection: Agencies must assess their needs and select the most appropriate cloud deployment model—public, private, hybrid, or community cloud—based on the sensitivity of the data and operational requirements.
  • Service types: The guidelines provide criteria for choosing between Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS), emphasizing the importance of using standard, non-customized services where possible.
  • Cost management: Agencies are required to plan and separate cloud-related expenses, ensuring transparency and efficient budget allocation.
  • Cloud migration: The guidelines outline the steps for migrating to the cloud and highlight the role of cloud service providers in facilitating the process, including supporting innovation and enabling smooth exit strategies.
  • Procurement compliance: All cloud procurement must comply with public sector procurement laws and regulations. Only providers meeting government-mandated standards can be selected.
  • Security and shared responsibility: The guidelines clarify the division of security responsibilities between cloud providers and government agencies. While providers manage infrastructure security, agencies remain responsible for data, application, and access controls.
  • Legal framework: Agencies must comply with the Digital Government Administration Act, Cybersecurity Act, Personal Data Protection Act (PDPA), and other relevant laws.

Cloud Data Classification Guidelines

  • Three-tier data classification: Government data is classified into three categories:
    1. Official data: Low-sensitivity data, suitable for public cloud storage.
    2. Protected data: Data that could cause harm if disclosed (e.g., tax, medical, or financial records), recommended to be stored in domestic public clouds with enhanced security.
    3. Highly protected data: Critical or top-secret data (e.g., national security information), must be stored in sovereign or state-controlled clouds within Thailand, with the highest security measures.
  • Data sovereignty and localization: The guidelines stress that all government data is recommended to be stored within Thailand to ensure compliance with local laws and maintain data sovereignty. Exceptions require DGA approval, except for highly protected data. The guidelines also distinguish between data at rest and data in transit or processing. While the focus of localization is on data at rest, data in transit (e.g., during transmission) or temporary processing outside Thailand could be permitted under certain technical and legal safeguards, provided no unauthorized access occurs. A localization exemption could be granted with special approval from the DGA.
  • Cross-border data transfers: Storing data outside Thailand is generally prohibited for sensitive information, with limited exceptions subject to DGA approval. The guidelines define “data that should be in Thailand” as data at rest (i.e., data stored on servers), and this does not include data in transit (data being transferred) or data being processed.
  • Risk assessment: Agencies must conduct risk assessments based on confidentiality, integrity, and availability to determine the appropriate level of security and cloud deployment.
  • Security controls: The guidelines mandate strict access controls, encryption, and compliance with international standards (e.g., ISO 27001) for sensitive data.
  • Legal compliance: The framework aligns with the Official Information Act, PDPA, Cybersecurity Act, and other national security regulations.

Implications and Action Steps for Government Agencies and Cloud Providers

Under the new guidelines, cloud adoption will be highly encouraged for government agencies. Any deviation from the cloud-first approach will need to be justified, with the decision-making process documented.

Government agencies who have implemented or are seeking to implement cloud technology will need to review and update their internal policies to align with the new guidelines, implement robust data classification and risk assessment processes for all digital services before migrating data to the cloud, and plan cloud migrations accordingly.

To be eligible for government contracts, cloud service providers will need to meet stringent security, localization, and compliance standards, and prepare for increased scrutiny regarding data residency, security certifications, and service transparency.

Outlook

These new guidelines represent a significant step forward in Thailand’s digital government strategy. All stakeholders should familiarize themselves with the requirements to ensure compliance, minimize risk, and support the secure and efficient adoption of cloud technology in the public sector.

RELATED INSIGHTS​ 

November 12, 2025
Thailand’s Customs Department has announced the cancellation of the longstanding de minimis exemption, which waives import duties on goods valued at THB 1,500 or less, as of January 1, 2026. This policy shift will directly impact e-commerce, logistics, and retail sectors, and will have wide-ranging implications for any company involved in cross-border trade with Thailand. Background Under current regulations, imported goods with a customs value (cost, insurance, and freight, or “CIF”) of THB 1,500 or less are exempt from import duties. This has been a cornerstone of the cross-border e-commerce model, allowing for the duty-free import of millions of small parcels. Under the new policy effective January 1, 2026, all imported goods, regardless of value, will be subject to assessment for import duties upon entry into Thailand. The stated rationale for this change is to create fair competition for Thai small and medium-sized enterprises (SMEs), which must pay VAT and other costs on their goods, putting them at a price disadvantage against foreign sellers who utilize the de minimis loophole. Business Implications This policy change will create new costs, compliance burdens, and operational challenges. For foreign e-commerce sellers and platforms: The most direct impact will be the addition of import duties to low-value items. Assuming the costs are passed on to the consumer, the higher prices and potentially more complex or slower customs clearance processes could lead to increased cart abandonment and reduced consumer demand. Businesses should review their pricing models and develop a clear strategy for calculating, declaring, and paying these new duties. For logistics providers and customs brokers: The administrative burden will be considerable. Carriers that previously handled millions of nondutiable parcels will now be required to process them for duty assessment and collection. This may necessitate new IT systems and streamlined processes to avoid delays at
November 7, 2025
Thailand and the United States signed a memorandum of understanding (MOU) titled “Cooperation to Diversify Global Critical Minerals Supply Chains and Promote Investments” on October 26, 2025, signaling a new strategic alignment aimed at developing Thailand’s mineral sector, particularly in rare earth elements (REEs). The MOU has implications for investments in technology, manufacturing, and other related sectors. This update outlines the key provisions of the MOU and the potential opportunities and legal navigating points for businesses. Objectives The primary driver of this agreement is the US initiative to diversify global supply chains for critical minerals and reduce reliance on current market leaders, particularly China. For Thailand, it represents a major opportunity to attract high-tech investment and develop its downstream processing industries. The cooperation is set to focus on five main areas: Technical knowledge: Exchange of technical expertise and international best practices to strengthen Thailand’s mining and processing sector. Joint cooperation: Establishing workshops, seminars, and scientific collaboration to boost innovation. Regulatory practice: Promoting good governance and streamlining regulatory and licensing procedures. Information sharing: Sharing data on potential projects and global market prices. Full-value chain: The MOU covers the entire mineral lifecycle, from exploration and extraction to processing, refining, and recycling. “First Opportunity to Invest” Clause The most debated provision within the MOU states that “participants expect to have the first opportunity to invest . . . in critical minerals assets that may be sold in Thailand.” Business implications: This clause is widely interpreted as granting US companies a first look or preferential access to investment opportunities in Thailand’s critical minerals sector. This could be a significant advantage for US-based or affiliated companies in mining, technology, and energy seeking to secure a foothold in a developing REE supply chain. Thai government position: Thai officials, including the prime minister, have publicly clarified
October 31, 2025
On September 29, 2025, Thailand’s Office of the Personal Data Protection Committee (PDPC Office) published its Regulations on the Review and Certification of Binding Corporate Rules B.E. 2568 (2025) (the Regulations). The Regulations provide clarity on the PDPC Office’s approach to reviewing and certifying binding corporate rules (BCRs) under Section 29 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA), and aim to facilitate international data transfers within a group of undertakings or enterprises (a “corporate group”). In conjunction with this development, the PDPC Office also approved BCRs for two companies operating in Thailand on September 30, 2025. This milestone represents the first concrete progress since the PDPC’s Notification on Criteria for the Protection of Personal Data Sent or Transferred to a Foreign Country pursuant to Section 29 of the PDPA B.E. 2566 (2023) came into effect in March 2024. Some key features of the Regulations are set out below. Categorization of BCRs BCRs are classified into two types: (1) BCRs for Controllers (BCR-C) and (2) BCRs for Processors (BCR-P). The category must be clearly specified when submitting the BCRs to the PDPC Office. Documentation Requirement The applicant must prepare and submit the application (a standard template may be provided by the PDPC Office in the future) along with supporting documents for review and certification in the Thai language. If the supporting documents are in a foreign language, a certified Thai translation should be provided. The translation must be notarized by a notary public or qualified person. Supporting documents may include, among others, a binding instrument such as an intra-group agreement, or a list of entities subject to the BCRs. Expedited Process Requirement Organizations with existing BCR approvals under the EU or UK GDPR, or from countries announced by the PDPC under Section 28, may apply through an
October 26, 2025
AI-generated songs are now making waves in Vietnam on platforms like TikTok, with tracks such as “Say mot doi vi em” quickly gaining popularity and sparking widespread attention. This phenomenon raises a host of legal and ethical questions: Who is the author of these songs? Can they be protected by copyright? Who is responsible if there is an infringement? These questions are becoming increasingly urgent as AI music becomes more mainstream in Vietnam. Copyright Protection for AI-Generated Music in Vietnam Under current Vietnamese law, copyright protection is reserved for works that bear the mark of human creativity. The 2022 amendments to Vietnam’s Intellectual Property Law reaffirm that only works created by humans are eligible for copyright. In practice, if a human meaningfully contributes to the creative process—by providing prompts, making selections, editing, or arranging—their contribution may be protected. However, if a song is generated entirely by AI without significant human input, it is unlikely to qualify for copyright protection. When an AI-generated song does not qualify for copyright protection, the question arises as to whether the person who writes the prompts, edits, or compiles the work can still be considered the owner of an asset under the Vietnamese Civil Code. According to Article 105 of the Civil Code 2015, assets include objects, money, valuable papers, and property rights. While AI-generated music that is not protected by copyright is not considered money or valuable papers, it may be regarded as an object (in the form of a digital file or recording) or as a property right if it can be possessed, used, transferred, or exploited for value. Use of AI-Generated Works Without Copyright Protection If a song is not protected by copyright, does that mean anyone can use it freely? Not necessarily. The absence of copyright does not mean the