You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 23, 2024

Thailand SEC Amends Supervisory Framework for Ready-to-Use Utility Tokens

Thailand’s Securities and Exchange Commission (SEC) amended its utility token supervisory framework by issuing seven notifications that came into effect on August 13, 2024. Ready-to-use utility tokens (tokens that can be used immediately to acquire specific goods or services), which were previously unregulated, are now subject to the supervisory scheme set forth by the seven new notifications in both primary and secondary markets. This is intended to provide an investor protection mechanism that responds to the characteristics, risks, and usage of the different types of ready-to-use utility tokens.

Under the new notifications, ready-to-use utility tokens are categorized into two groups. These are detailed below.

Group 1 Utility Tokens

Group 1 utility tokens include ready-to-use utility tokens issued for consumption purposes or as a digital representation of a certificate. Examples include loyalty points, digital movie or concert tickets, NFTs, and carbon credits, among others.

Principally, there is no change in the regulation of group 1 utility tokens under the new notifications. In the primary market, issuance of this type of token is not subject to the initial coin offering (ICO) requirements.

In the secondary market, providing services related to group 1 utility tokens is not considered to be the same as operating a digital asset business with licensing requirements under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). Licensed digital asset operators (including exchanges, brokers, and dealers) are not permitted to list or trade group 1 utility tokens.

To provide services in relation to group 1 utility tokens, these licensed digital asset operators must establish a separate entity to provide those services and must not use names or messages that could cause the public to misunderstand that the separate entity is engaged in a digital asset business under SEC supervision.

Group 2 Utility Tokens

Group 2 utility tokens include other ready-to-use utility tokens besides those specified as group 1 utility tokens. Examples include native coins, governance tokens, DeFi/Cefi projects, and exchange tokens, among others.

For group 2 utility tokens, the new notifications impose more stringent regulations, including an ICO requirement if the tokens will be listed on a licensed digital asset exchange.

In the secondary market, providing services related to group 2 utility tokens is considered to be operating a digital asset business that requires a license under the Emergency Decree on Digital Asset Businesses. Therefore, only the licensed digital asset operators mentioned above can list, trade, or provide services in relation to these tokens.

Additional Requirements

The new notifications also emphasize that issuers must not issue tokens to be used as a means of payment (MOP) and must not accept tokens for staking purposes except as a verification mechanism, a voting method, or for joining events for sharing benefits from ecosystem activities. The new notifications further prescribe the characteristics of utility tokens that do not constitute MOP. These include a variety of common utility tokens, such as those that are specially created for loyalty programs or marketing promotion purposes, to purchase in-game items, to pay gas fees for digital transactions, and so on.

Various oversight mechanisms on digital asset exchange supervision were also strengthened, especially in relation to price speculation. These changes include revising minimum requirements for listing rules and trading rules, requiring signposting to inform investors about potential risks from investing in a certain token, and imposing disclosure requirements on issuers when tokens are to be listed on an exchange.

The governance of not-ready-to-use utility tokens remains unchanged under the new notifications, with the issuance of not-ready-to-use utility tokens subject to the ICO requirements.

For more information on these new notifications, or on any aspect of digital assets and cryptocurrency in Thailand, please contact Kobkit Thienpreecha at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

July 2, 2025
On June 27, 2025, Vietnam’s National Assembly adopted a Resolution on International Financial Centers in Vietnam (“IFC Resolution”), which is set to take effect September 1, 2025, putting forward major policy breakthroughs on multiple fronts. The IFC Resolution has the goal of turning Ho Chi Minh City and Da Nang into leading international financial centers with autonomy and tools to compete, thereby raising Vietnam’s position in the global financial network, in association with economic growth drivers. Below are some of the key points of the IFC Resolution, which has notable changes from previous drafts (see our articles on Vietnam’s Draft Resolution on Financial Centers: Implications for Fintech and Banking and Vietnam’s Emerging Regulatory Landscape for Blockchain and Cryptocurrency), including: The removal of the Central Supervisory Agency. The addition of a definition of international financial centers, which are specific geographic areas in Ho Chi Minh City and Da Nang with members entitled to special policies. The addition of a list of entities eligible for membership, and entitlement to the special policies. Major Policy Breakthroughs The IFC Resolution introduces specific policies in the following areas: Liberalization of foreign exchange control for members, including policies such as open foreign exchange use between members and exemption from foreign exchange control procedures for 100% foreign-owned members. Specialized licensing for members to establish and operate single-member limited liability banks and foreign bank branches with the ability to apply accounting standards, debt classification, risk provisions, and prudential ratios according to the owner’s policies. Creation of a capital market for innovative startups, including a crowdfunding mechanism or private placement mechanism through a licensed platform, and development of a green finance market with green certification. Creation of a regulatory sandbox for fintech technologies, products, services, and business models not yet prescribed by law, offering exemption from compliance with
July 1, 2025
Now halfway through 2025, Thailand continues to advance in the realm of data privacy, with the ambitious goal of achieving zero data breaches. The Personal Data Protection Committee (PDPC), an independent government body established by the Personal Data Protection Act (PDPA), is taking a more proactive approach, having published several rulings and orders to enhance data protection measures and clarify compliance expectations for businesses. Here is a look back at Thailand’s data privacy developments in the first half of the year. Strengthening Law Enforcement and New Guidance for Compliance Enforcement of existing data protection laws and regulations has taken a step forward this year. Some of the specific initiatives include: Increased enforcement by the PDPC. A key trend to watch from the first half of 2025 is the PDPC’s active enforcement of the PDPA as it intensifies oversight through compliance orders and public warnings against noncompliant organizations while ramping up efforts to prevent and halt the illegal trading of personal data by actively monitoring emerging societal issues. Call center scams and cyber fraud control. Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Orders from the Expert Committee. Several orders issued by the Expert Committee under the PDPA were announced in the first half of this year. These include directives for data controllers to take corrective actions to comply with the PDPA, as well as initiatives to raise awareness of data privacy within organizations, reflecting the regulator’s focus on promoting organizational awareness and compliance. A guideline report summarizing the Expert Committee’s decisions and orders was also published to serve as a reference for compliance. Public issue monitoring. The PDPC has been taking a more proactive approach
June 27, 2025
Three American giants are actively protecting their intellectual property rights against generative AI, as two legal battles commence on both sides of the Atlantic. In the UK, Seattle-based media company Getty Images accuses UK-based Stability AI of multiple IP infringements. In the US, The Walt Disney Company and Universal Studios are teaming up against Midjourney, an AI startup, with their main ground being copyright infringement. Both cases are centered around questions legal minds have been posing since the introduction of generative AI: Is the output of generative AI an infringement? And who is ultimately responsible for the output, the platform or the user? Getty Images v. Stability AI Getty initially filed a claim in the High Court in 2023, which resulted in Stability applying for reverse summary judgment on the grounds that Getty had no real prospect of success, arguing that their operations took place outside the UK. However, the High Court judge hearing the case decided that the claims brought by Getty did have a real prospect of succeeding in court. Despite this, Stability saw a small victory when the court ruled that the representative action brought by Getty would not succeed due to the difficulties in identifying who qualified for the class. The proposed class was comprised of 50,000 rightsholders who alleged their rights were also infringed. Stability was successful in arguing that identifying these individuals would be challenging due to the unclear definition of the class. This current trial is centered around four main grounds: Copyright infringement. Getty accuses Stability of using content that Getty owns or has an exclusive license for when training their model, Stable Diffusion, resulting in the generated output containing substantial parts of that content. Getty is also alleging secondary copyright infringement, arguing that Stability is importing an article into the UK
June 26, 2025
Vietnam’s new Personal Data Protection Law (PDPL) was passed by the National Assembly on June 26, 2025, and will enter into force on January 1, 2026. The PDPL introduces several new concepts, exemptions, and obligations in comparison with the current Decree No. 13/2023/ND-CP on personal data protection (PDPD), while other contents remain essentially the same. The relationship between the PDPD and the PDPL has not been clearly addressed; however, it is expected that the government will issue a new decree providing necessary guidance on certain requirements under the PDPL, and the PDPD will remain in effect until it is replaced by this new decree. Some key points of the new PDPL include the following: Personal data will be further defined by lists of basic personal data and sensitive personal data to be issued by the government. The consent-centric approach of the PDPD remains in place, along with additional exemptions for certain data processing activities. The requirements for the data processing impact assessment (DPIA) and transfer impact assessment (TIA) remain unchanged. However, there are new exemptions for the TIA, including for the processing and storing in the cloud of employee data, and when the data subject is the person sending its own data outside of Vietnam. Consent obtained under the PDPD remains valid under the PDPL. DPIAs and TIAs submitted under the PDPD are valid under the PDPL but may need to be updated to be in line with the requirements of the PDPL. Administrative fines depend on the type of violation. The fine for sale and purchase of personal data will be 10 times the revenue from the sale or VND 3 billion (about USD 115,000), whichever is higher. The fine for cross-border transfer violations is 5% of the violator’s revenue of the preceding year or VND 3 billion,