You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 24, 2024

Thailand: Ruling Clarifies “Lawful Basis” for Processing Certain Personal Data

In March 2024, a Thai court of first instance handed down a decision in a personal data protection case against an insurance company in Thailand. The landmark ruling has important implications for the disclosure of special categories of personal data.

The case concerned an individual, acting as the plaintiff, who filed a claim against an insurance company, as a data controller, and its representatives, for collecting, using, and disclosing the results of the plaintiff’s blood alcohol level test, along with a photo of the plaintiff taking the test, without explicit consent, resulting in his insurance claim being rejected. The company also disclosed the data to the insured party, who is the plaintiff’s family member, causing the plaintiff to suffer reputational damage, discrimination, humiliation, and ill treatment.

Since results of a blood alcohol level test are considered a special category of personal data pursuant to section 26 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA), the plaintiff filed the claim with the criminal court, requesting that the criminal penalties under the PDPA and the Penal Code be imposed on the defendants, and that the defendants delete or destroy the plaintiff’s personal data. The insurance company argued that it had disclosed the test results and the photograph to the plaintiff’s family member—as the insured under the insurance agreement—for the purpose of informing the insured of the rejection of the insurance claim.

Considering these facts and reasons, the criminal court ruled that the processing of this special category of personal data was necessary for the defense of the insurance company’s legal claims pursuant to section 26(4) of the PDPA, and therefore, explicit consent was not required. As a result, the criminal court dismissed the case.

Key Takeaways

While this case was dismissed, it indicates that explicit consent is not the only legal basis for processing a special category of personal data, and data controllers are able to process personal data as long as there is a lawful purpose and an appropriate legal basis to achieve that purpose. This case also suggests that data subjects are now becoming more aware of their rights in regard to privacy and personal data, which could increase the likelihood of more cases being brought before the courts.

As this ruling was made by the court of first instance, it might be appealed.

For more information on the interpretation of the PDPA, or on any aspect of data compliance in Thailand, please contact Nop Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Gvavalin Mahakunkitchareon at [email protected], or Wilin Somya at [email protected].

RELATED INSIGHTS​ 

July 18, 2025
タイ銀行(BOT: Bank of Thailand)は、金融セクターにおける人工知能(AI)リスク管理の原則を定めるガイドライン草案を公表した。このガイドライン草案は、AI技術の責任ある導入のための構造化された枠組みを提供している。金融サービス提供者は、このガイドラインを参考に、国際的に認められたベスト・プラクティスに沿ってリスクを適切に管理することができる。 BOTは2025年6月30日までガイドライン草案に対するパブリックコメントを募集している。 範囲および適用 本ガイドライン草案は、金融機関業法(Financial Institution Business Act)に基づく金融機関及び特別金融機関、並びに資金決済法(Payment Systems Act)に基づく決済事業者を含む全ての金融サービス提供者に適用される。本ガイドライン草案は、ITリスク管理、サードパーティリスク管理、データ・ガバナンス、市場行動規範を含む既存のBOTリスク管理ガイドラインを補完するものである。 ガイドライン草案では、AIシステムを、機械学習、ディープラーニング、生成AI(大規模言語モデルなど)、エージェンティックAIなど、人間の知能を模倣するシステムと定義している。この定義では、ロボティック・プロセス・オートメーション(RPA)等のルール・ベースの自動化システムは明確に除外されている。 主要なリスク管理原則 ガイドライン草案では、AI リスクを管理するための 2 つの主要な原則が示されている。 ガバナンス:金融サービス提供者は、FEAT (公平性(fairness)、倫理性(ethics)、説明責任(accountability)、透明性(transparency)) の原則を遵守するために、金融サービス提供者の職員と AI システム監督構造の明確な役割と責任を次のように定義し、確立する必要がある。 ステークホルダーの役割と責任 金融サービス提供者は、AIリスクの監視に関する取締役と経営陣の役割と責任を定義する必要がある。責任には、AIシステム利用ポリシーの策定、AIリスク管理責任者の任命、組織内におけるAI関連リスクに関する意識向上などが含まれる。 AIシステム利用ポリシー AIシステム利用ポリシーは、組織の目標、規制要件、およびFEAT原則と整合させる必要がある。これらのポリシーは、技術の進歩とリスクプロファイルの変化に対応するために定期的に見直す必要がある。 AIライフサイクル全体にわたるリスク管理 リスク管理は、リスク許容度の確立から、継続的なリスク評価と特定の利用ケースに合わせた管理策の実施まで、AIライフサイクル全体を網羅する必要がある。AIシステムが戦略的な機能や顧客とのインタラクション(例:融資の承認、口座開設)に使用される場合、意思決定プロセスには人間による監視が組み込まれている必要がある。顧客とAIシステムのインタラクションにおいては、顧客に通知を行い、AI機能を無効化またはバイパスするオプションを提供する必要がある。 開発およびセキュリティ管理:金融サービス提供者は、次のように AI の開発と展開のライフサイクルをカバーするリスク管理を行う必要がある。 データリスク 金融サービス提供者は、AIモデルの学習に使用するデータの品質、正確性、最新性、量、多様性を評価し、確保するための対策を講じる必要がある。また、データ漏洩防止対策も実施する必要がある。 モデル開発リスク 金融サービス提供者は、(1)導入前後の継続的なテストとモニタリングを通じてモデルの精度と信頼性を評価するための明確な評価指標、および、(2)AIの結果の説明可能性を確保するための手段を備える必要がある。生成AIアプリケーションについては、AIハルネーションリスク(AI hallucination risks)を低減するための具体的な対策が必要である。 サイバーセキュリティリスク 金融サービス提供者は、OWASP機械学習セキュリティトップ10などの確立された標準に基づいて、AIシステムを標的とした新たなサイバー脅威を防止および検出するための対策を講じる必要がある。 タイのフィンテック、テクノロジー、サイバーセキュリティに関する詳細については、 Athistha Chitranukroh([email protected])、Nopparat Lalitkomon([email protected])、Pornpan Wichawut([email protected])、 Napassorn Lertussavavivat([email protected])、またはRujaporn Paritsantik([email protected])までお問い合わせください。   備考:本和文は英文記事を翻訳したものです。原文については、以下のリンクをご参照ください。 Thailand Drafts AI Risk Management Guidelines for Financial Service Providers
July 18, 2025
Vietnam’s electric vehicle (EV) industry is experiencing rapid growth, driven by a strong wave of new legislation, strategic plans, and government incentives. The government’s clear commitment to electrification is attracting foreign investment, supporting advanced production, and reducing reliance on internal combustion engine (ICE) imports. Recent national strategies, sector regulations, and technical standards demonstrate a rare level of regulatory momentum in Southeast Asia, positioning Vietnam as a competitive player in the global EV supply chain and an attractive market for foreign investors. An overview of legal developments for the EV sector in Vietnam is presented below. National Action Program for Green Transportation A key driver of Vietnam’s EV growth has been the National Action Program for Green Transportation through 2050 stipulated in Decision No. 876/QD-TTg of the prime minister dated July 22, 2022. The National Action Program sets a detailed roadmap for the green energy transition in road transport. For the period 2022–2030, the focus is on promoting the manufacturing, assembly, import, and conversion of road motor vehicles to electric power, expanding the use of 100% E5 gasoline for road vehicles, developing charging infrastructure to meet the needs of residents and businesses, and encouraging both new and existing bus stations and rest stops to meet green criteria. For the period 2031–2050, the roadmap aims to gradually restrict and ultimately cease by 2040 the manufacturing, assembly, and import of fossil fuel-powered cars, motorcycles, and mopeds for domestic use. By 2050, the goal is for 100% of road motor vehicles and construction vehicles participating in traffic to use electricity or green energy, for all bus stations and rest stops to meet green criteria, and for all machinery and equipment for loading and unloading to transition from fossil fuels to electricity or green energy. The program also calls for the completion of nationwide
July 17, 2025
On July 9, 2025, Thailand issued a notification that introduces comprehensive operational requirements for digital platform service providers operating as goods marketplaces, effective December 31, 2025 (i.e., 180 days after its publication in the Government Gazette). The regulation’s official name is Notification of the Electronic Transactions Committee Re: Other Actions for Digital Platform Service Operators in the Category of Marketplace for Goods with Specific Characteristics under Section 18(2) of the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification B.E. 2565 (2022), B.E. 2568 (2025). Scope of Application The notification applies exclusively to goods marketplace operators formally designated by the Electronic Transactions Development Agency (ETDA), which on the same day designated 19 platforms that had previously notified the ETDA of their operations. The goods requiring enhanced oversight by these operators are limited to those regulated by the Thai Food and Drug Administration (FDA) and the Thai Industrial Standards Institute (TISI). Development from Earlier Draft An earlier draft of the notification had included a requirement for offshore platforms to establish a local entity, but this requirement was removed from the final notification. Key Obligations Despite the removal of the local entity requirement, the notification imposes a range of additional obligations on designated goods marketplace operators: Transparency. Operators must implement robust transparency measures, including clear, accessible, and understandable disclosures to users in Thai. These disclosures must cover all relevant terms and conditions, comprehensive product information, and complaint management procedures. Operators must also submit an annual compliance report to the ETDA within 60 days after the end of their accounting period, including statistics on regulated goods. Business user registration and identity verification. Before permitting the sale or advertisement of regulated goods, operators must collect and verify business user information, including contact details, identification documents, registration
July 16, 2025
On June 27, 2025, the National Assembly of Vietnam officially passed the amended Law on Atomic Energy, which will take effect on January 1, 2026. This legislative milestone follows the release of the fourth draft in June 2025, which was circulated for public consultation and builds upon earlier drafts from February, April, and early June. (See our previous article on the draft version here), Many provisions have been retained or refined to ensure greater specificity and alignment with Vietnam’s current legal framework. Once in force, the amended law will replace the 2008 Law on Atomic Energy (No. 18/2008/QH12), marking a significant step forward in modernizing Vietnam’s legal infrastructure for nuclear energy. The new law aims to harmonize with international standards, promote the safe and sustainable development of nuclear power, and facilitate future nuclear projects in the country. Noteworthy Updates in the Final Legislation Definition of National Radiation and Nuclear Safety Authority (NRNSA): The law introduces a clear definition of the NRNSA, outlining its roles and responsibilities in line with IAEA standards. Currently, this function is performed by the Vietnam Agency for Radiation and Nuclear Safety (VARANS) under the Ministry of Science and Technology. Digital Transformation Requirements: New provisions mandate the development of an integrated digital platform for data management, administrative procedures, and safety oversight, enhancing transparency and security. Policy Support for Training and Privatization: The law sets out principles for workforce incentives and sector privatization, with detailed regulations to be issued by the government. Dedicated Safety and Security Mechanism: A new section outlines inspection, supervision, violation handling, and enforcement procedures in the field of atomic energy, particularly for nuclear power plants. The NRNSA is empowered to conduct unscheduled inspections, suspend operations, and recommend license revocation when safety risks are identified. Key Provisions Retained or Clarified from the Draft Licensing