You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 25, 2024

Thailand Seeks Comments on Principles of Draft Platform Economy Act

Thailand has released the set of principles that will form the official draft Platform Economy Act (PEA) for a public hearing period that runs until December 15, 2024. The PEA is likely to be positioned as a general or overarching law for digital intermediary services and digital platform service businesses.

In January 2024, an early, unofficial version of the proposed law had been circulated among a limited group of operators in certain industries to get comments for the working group charged with the PEA’s development. Now, however, the proposed principles that will underpin the official draft PEA have been released publicly to gather comments, feedback, and suggestions from any interested stakeholders.

The principles of the draft PEA cover two main areas: user protection and fair competition. The key details in these two areas are outlined below.

User Protection

The main regulator supervising the law’s user protection elements will be the Electronic Transactions Development Agency (ETDA).

The draft PEA is expected to impose user protection obligations on service providers based on their nature, size, and risk level. The principles set out a three-tiered classification system for service providers that will be covered under the draft PEA, as detailed below, ordered from fewest obligations to most:

  • Intermediary Service Provider: This describes a service provider acting as an intermediary between a sender and recipient of information on a computer network, the internet, or a telecommunications network.

    Service providers likely to fall under this category include cloud service providers and web hosting providers.

    Intermediary service providers may be further categorized into the following subtypes:

    • Mere conduit service providers;
    • Caching service providers;
    • Hosting service providers; and
    • Other service providers as prescribed in ministerial regulations.
  • Online Platform: This refers to an intermediary service provider offering data storage services that connect various types of users to enable transactions or interactions between them, whether or not fees are charged. These providers may also offer additional services to facilitate the transactions or interactions.

    Service providers likely to fall under this category include social media platforms, online marketplace platforms, ride-hailing platforms, and search engines.

  • Very Large Online Platform: Online platforms that have a significant impact on the country’s economy and society are categorized as “very large online platforms.” To qualify as a very large online platform, a platform must:

    • Have annual revenue from digital platform services in Thailand exceeding THB 1 billion;
    • Have an average monthly domestic user count exceeding six million; and
    • Pose significant risks to the economy, social security, or public well-being, as determined by the Digital Platform Economy Committee based on ETDA recommendations.

    The ETDA must officially announce the list of the platforms meeting all three criteria before imposing additional obligations.

All types of service providers identified above must appoint a point of contact (POC) responsible for coordination with the ETDA, and notify the ETDA of the POC’s contact information. This requirement applies to both onshore and offshore service providers—a difference from the similar requirement under the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification B.E. 2565 (2022) (the “DPS Royal Decree”), which limits this obligation to offshore providers only.

The draft PEA principles also introduce a safe harbor mechanism, which exempts intermediary service providers from liability for offenses related to transmitted or stored data if they can prove “no involvement” in the offense. There are three specific safe harbor rules that apply to each type of intermediary service provider. Online platforms, as defined above, qualify as “hosting service providers” and must meet the burden of proof for hosting service providers under the safe harbor rule.

Additional Obligations for Platforms

Online platforms must also fulfill the following obligations:

  • Publication of terms and conditions (T&Cs). Under the Draft PEA, all online platforms are generally required to disclose their T&Cs, unlike under the DPS Royal Decree, which limits this obligation to certain marketplace platforms and search engines.
  • Collaboration with trusted flaggers. Online platforms must work with trusted flaggers—certified individuals who report illegal activities—by providing a dedicated channel for them to open accounts and submit reports.
  • Notice and action mechanism. Online platforms must provide a channel for complaints and reports of illegal activities on the platform.

In addition to these obligations, very large online platforms also have the following obligations:

  • Reporting of required information to the ETDA. The draft PEA requires only very large online platforms to report certain information to the ETDA. This differs from the DPS Royal Decree, under which the obligation to notify the ETDA applies to all in-scope digital platform services.
  • Preparation of an annual transparency report. Under the draft PEA, very large online platforms must prepare an annual transparency report on their digital platform services and keep it publicly accessible at all times.
  • Appointment of an independent external auditor. Very large online platforms must appoint an independent external auditor to conduct audits covering (1) IT systems and (2) compliance with legal requirements.

Extraterritoriality

The principles of the draft PEA address the proposed extraterritorial scope of the law, with the draft PEA applying to platforms meeting criteria similar to those in the DPS Royal Decree—such as offering payments in Thai baht or displaying all or part of their content in Thai. Very large online platforms located outside Thailand that meet any of the criteria will be deemed to serve users in Thailand and will have to report the prescribed information to the ETDA.

Fair Competition

In the area of fair competition, the draft PEA aims to regulate “gatekeepers” (typically market actors that have significant control or influence over access to goods, services, or markets) by outlining both the criteria for being designated as a gatekeeper and the obligations that apply to parties that have been so designated. The main regulator supervising the fair competition elements of the law is the Trade Competition Commission of Thailand (TCCT).

Designation of Gatekeepers

In deciding whether to designate a platform as a gatekeeper, the Platform Economy Committee will:

  1. Determine if the platform qualifies as a core platform service (CPS). Ten types of services are classified as CPSs, including online search engines, online social networking services, and virtual assistants.
  2. Consider whether the CPS meets all relevant gatekeeper criteria. Currently, this includes three proposed qualitative criteria—(1) having a significant impact on Thailand’s economy or society, (2) being an important gateway for business users to reach end users, and (3) having an entrenched and durable position—as well as additional quantitative criteria.

CPS providers must conduct a self-assessment if they meet the qualitative and quantitative gatekeeper criteria and must report the prescribed information to the Digital Platform Economy Committee, which will review the submitted information and announce the list of designated gatekeepers.

Gatekeeper Obligations

After being included in the list announced by the Digital Platform Economy Committee, designated gatekeepers will be subject to additional obligations under the draft PEA. The details of these obligations are still uncertain but pertain largely to two main issues:

  • Required and prohibited actions. Two sets of rules under this ex-ante approach (imposing rules that focus on preventing potential issues or risks before they occur) concern:
    • Most favored nation (MFN) clauses. Designated gatekeepers must not set prices or conditions or take actions that discriminate against or restrict users offering similar products or services to those the designated gatekeepers provide on their platforms.
    • Anti-steering provisions. Designated gatekeepers must allow users to freely communicate with or promote their products or services to consumers without additional charges, whether through the platform or through other channels provided by the service provider.
  • Modification of T&Cs. Designated gatekeepers must allow at least 15 days for user feedback before modifying T&Cs. A summary of the feedback and any amendments must be submitted to the TCCT. This obligation applies only to designated gatekeepers, which is different from the similar obligation under the DPS Royal Decree.

Status

Comments on the principles of the draft PEA will be accepted until December 15, 2024. All input gathered from stakeholders will be presented to the Council of State, which will then evaluate the principles’ appropriateness, assess potential impacts, and contribute to the development of the final draft PEA.

For more information on compliance with Thailand’s requirements for digital platform services, please contact Tilleke & Gibbins’ digital platform specialists Athistha (Nop) Chitranukroh at [email protected], Pornpan Wichawut at [email protected], Rada Lamsam at [email protected], or Karnravee Jitvilai at [email protected].

RELATED INSIGHTS​ 

January 6, 2026
On December 30, 2025, Thailand’s Electronic Transactions Development Agency (ETDA) notified digital marketplace operators of a consolidated list of “high‑risk products” that are subject to strict monitoring on digital platforms. The list was jointly prepared by the Thai Industrial Standards Institute (TISI) and the Food and Drug Administration (FDA) to guide platform compliance in the initial phase of implementation of the Electronic Transaction Committee’s Notification on Other Measures for Marketplace for Goods with Specific Characteristics under Section 18(2) of the 2022 Royal Decree on Digital Platform Businesses Requiring Notification B.E.2568 (2025). The notice is addressed to operators of digital platform services that function as product marketplaces with specific characteristics laid out in the notification. The ETDA states that the TISI and the FDA are closely monitoring the high‑risk product categories on digital platforms, and the published list serves as the baseline reference for platform screening during the initial phase of the notification’s implementation. High‑Risk Product List The list aggregates categories of products that are illegal to sell online or are otherwise tightly regulated under Thai law, with an emphasis on health-related products, controlled substances, medical devices, and a wide range of industrial products that require certification or compliance with specified Thai Industrial Standards, as detailed below. Prohibited and tightly controlled health products. This includes all categories of modern medicines subject to control other than general household remedies; all categories of controlled herbal products except for over-the-counter herbal products; narcotics; psychotropic substances; and medical devices requiring use in medical facilities or a physician’s prescription. Selected industrial products requiring heightened controls. The list highlights dozens of TISI-regulated items commonly sold online. Examples include pacifiers, rice cookers, electrical wire, food wrap film, crayons, washing machines and dryers, air conditioners, electric cookers and air fryers, water heaters, microwave ovens, LED luminaires, hair dryers
January 5, 2026
On December 31, 2025, the government of Vietnam promulgated Decree No. 356/2025/ND-CP detailing and guiding the implementation of the new Personal Data Protection Law (PDPL) that was issued in June 2025. The new decree, like the PDPL, entered into force on January 1, 2026, with the previous Decree No. 13/2023/ND-CP on personal data protection ceasing effect on the same day. Some key points of the new decree include the following: Comprehensive lists of basic and sensitive personal data are provided, which will require companies to review again their existing documents and data type classification to ensure compliance. New timelines are established for responding to specific data subject requests. These timelines are more reasonable and longer than the previous 72-hour requirements. Additional consent guidelines are provided, prohibiting default consent or ambiguous instructions that confuse data subjects about giving or withholding consent. Mandatory content for data transfer agreements/clauses in particular cases is provided. This covers, among other things, (i) the legal basis for the transfer of personal data; (ii) responsibilities for personal data protection during the transfer and processing of personal data; (iii) responsibilities for ensuring the exercise of the rights of personal data subjects; and (iv) responsibilities for coordination and compliance of the parties in cases where violations of personal data protection regulations are detected. The qualifications and responsibilities of data protection officers (DPOs) and data protection departments include, among others, having been trained and fostered in legal knowledge and professional skills regarding personal data protection. There are no specific provisions governing the qualifications or requirements for organizations that provide data protection training or education. New mandatory templates and requirements are provided in relation to data processing impact assessment and data transfer impact assessment, and for cases in which companies need to re-submit assessments to the regulator. Stricter requirements are
December 30, 2025
On December 17, 2025, Laos’ Ministry of Industry and Commerce (MOIC) issued a notice introducing a new digital system that allows e-commerce businesses to obtain required certificates and licenses through an online, application-based platform. Notice No. 3988, which will take effect on February 1, 2026, introduces the E-Trust platform, a downloadable application that allows e-commerce businesses to remotely obtain acknowledgement certificates and business operating licenses. New Digital Registration Options Under the previous framework established by the Decree on E-commerce (2021), businesses were required to complete registration exclusively through paper-based submissions. The new system now offers businesses two registration options: Traditional paper-based process at the Division of E-commerce Management within the MOIC; or Electronic registration and renewal through the E-Trust platform. This change is expected to streamline procedures, reduce administrative burdens, and enhance accessibility for businesses operating outside Vientiane. The E-Trust platform facilitates compliance for both individuals and legal entities required to submit applications and renewals for required certificates and licenses. The development is particularly beneficial for businesses located in remote provinces, as it eliminates the need for physical travel and significantly accelerates processing times. Compliance Requirements and Penalties Businesses must obtain or renew the required certificates and licenses to avoid sanctions under the Decision on Fines and Other Measures for Violation of the Decree and Regulations on E-commerce (No. 2828/MOIC, dated November 11, 2025). Penalties for noncompliance may include monetary fines and other enforcement measures.
December 26, 2025
Thailand has granted ride-sharing platforms additional time to comply with new regulatory requirements, extending the compliance deadline to March 31, 2026 (replacing the previous deadline of October 2, 2025). The postponement was made official on December 18, 2025, when Thailand’s Electronic Transactions Development Agency (ETDA) published the second Notification Regarding Supervision of Ride-Hailing Platforms Classified as High-Impact Digital Platform Services under the Royal Decree on Digital Platform Service Businesses. The notification provides additional time for ride-sharing platforms and drivers to transition to full regulatory compliance. The extension replaces the effective date provision of the earlier notification and applies specifically to ride-hailing activities. Background The postponement responds to feedback from operators and driver groups regarding challenges converting private vehicles into legally registered public vehicles, including complex registration procedures, high compliance costs, and operational delays. The Department of Land Transport (DLT) is concurrently reforming its vehicle registration and driver verification processes to streamline operations. Given these issues, the Electronic Transactions Committee has deferred enforcement to provide an adjustment period for operators and drivers to meet compliance requirements. Ongoing Obligations While the effective date has been deferred, the substantive obligations imposed on ride-sharing platforms remain fully intact. Operators must continue preparing to comply with the additional duties applicable to high-impact digital platform services, beyond the general requirements under the digital platform services framework. Operators are expected to use the extended transition period to finalize operational and compliance readiness ahead of enforcement on March 31, 2026. Key focus areas include: Integration with DLT vehicle-registration systems Deployment of robust driver and passenger identity verification mechanisms Updates to platform terms of service, driver-onboarding standards, and internal operational policies Preparation for ETDA reporting obligations and future audit and review processes Next Steps While the postponement replaces the previous effective date with the new March 31, 2026,