You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 25, 2024

Thailand Seeks Comments on Principles of Draft Platform Economy Act

Thailand has released the set of principles that will form the official draft Platform Economy Act (PEA) for a public hearing period that runs until December 15, 2024. The PEA is likely to be positioned as a general or overarching law for digital intermediary services and digital platform service businesses.

In January 2024, an early, unofficial version of the proposed law had been circulated among a limited group of operators in certain industries to get comments for the working group charged with the PEA’s development. Now, however, the proposed principles that will underpin the official draft PEA have been released publicly to gather comments, feedback, and suggestions from any interested stakeholders.

The principles of the draft PEA cover two main areas: user protection and fair competition. The key details in these two areas are outlined below.

User Protection

The main regulator supervising the law’s user protection elements will be the Electronic Transactions Development Agency (ETDA).

The draft PEA is expected to impose user protection obligations on service providers based on their nature, size, and risk level. The principles set out a three-tiered classification system for service providers that will be covered under the draft PEA, as detailed below, ordered from fewest obligations to most:

  • Intermediary Service Provider: This describes a service provider acting as an intermediary between a sender and recipient of information on a computer network, the internet, or a telecommunications network.

    Service providers likely to fall under this category include cloud service providers and web hosting providers.

    Intermediary service providers may be further categorized into the following subtypes:

    • Mere conduit service providers;
    • Caching service providers;
    • Hosting service providers; and
    • Other service providers as prescribed in ministerial regulations.
  • Online Platform: This refers to an intermediary service provider offering data storage services that connect various types of users to enable transactions or interactions between them, whether or not fees are charged. These providers may also offer additional services to facilitate the transactions or interactions.

    Service providers likely to fall under this category include social media platforms, online marketplace platforms, ride-hailing platforms, and search engines.

  • Very Large Online Platform: Online platforms that have a significant impact on the country’s economy and society are categorized as “very large online platforms.” To qualify as a very large online platform, a platform must:

    • Have annual revenue from digital platform services in Thailand exceeding THB 1 billion;
    • Have an average monthly domestic user count exceeding six million; and
    • Pose significant risks to the economy, social security, or public well-being, as determined by the Digital Platform Economy Committee based on ETDA recommendations.

    The ETDA must officially announce the list of the platforms meeting all three criteria before imposing additional obligations.

All types of service providers identified above must appoint a point of contact (POC) responsible for coordination with the ETDA, and notify the ETDA of the POC’s contact information. This requirement applies to both onshore and offshore service providers—a difference from the similar requirement under the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification B.E. 2565 (2022) (the “DPS Royal Decree”), which limits this obligation to offshore providers only.

The draft PEA principles also introduce a safe harbor mechanism, which exempts intermediary service providers from liability for offenses related to transmitted or stored data if they can prove “no involvement” in the offense. There are three specific safe harbor rules that apply to each type of intermediary service provider. Online platforms, as defined above, qualify as “hosting service providers” and must meet the burden of proof for hosting service providers under the safe harbor rule.

Additional Obligations for Platforms

Online platforms must also fulfill the following obligations:

  • Publication of terms and conditions (T&Cs). Under the Draft PEA, all online platforms are generally required to disclose their T&Cs, unlike under the DPS Royal Decree, which limits this obligation to certain marketplace platforms and search engines.
  • Collaboration with trusted flaggers. Online platforms must work with trusted flaggers—certified individuals who report illegal activities—by providing a dedicated channel for them to open accounts and submit reports.
  • Notice and action mechanism. Online platforms must provide a channel for complaints and reports of illegal activities on the platform.

In addition to these obligations, very large online platforms also have the following obligations:

  • Reporting of required information to the ETDA. The draft PEA requires only very large online platforms to report certain information to the ETDA. This differs from the DPS Royal Decree, under which the obligation to notify the ETDA applies to all in-scope digital platform services.
  • Preparation of an annual transparency report. Under the draft PEA, very large online platforms must prepare an annual transparency report on their digital platform services and keep it publicly accessible at all times.
  • Appointment of an independent external auditor. Very large online platforms must appoint an independent external auditor to conduct audits covering (1) IT systems and (2) compliance with legal requirements.

Extraterritoriality

The principles of the draft PEA address the proposed extraterritorial scope of the law, with the draft PEA applying to platforms meeting criteria similar to those in the DPS Royal Decree—such as offering payments in Thai baht or displaying all or part of their content in Thai. Very large online platforms located outside Thailand that meet any of the criteria will be deemed to serve users in Thailand and will have to report the prescribed information to the ETDA.

Fair Competition

In the area of fair competition, the draft PEA aims to regulate “gatekeepers” (typically market actors that have significant control or influence over access to goods, services, or markets) by outlining both the criteria for being designated as a gatekeeper and the obligations that apply to parties that have been so designated. The main regulator supervising the fair competition elements of the law is the Trade Competition Commission of Thailand (TCCT).

Designation of Gatekeepers

In deciding whether to designate a platform as a gatekeeper, the Platform Economy Committee will:

  1. Determine if the platform qualifies as a core platform service (CPS). Ten types of services are classified as CPSs, including online search engines, online social networking services, and virtual assistants.
  2. Consider whether the CPS meets all relevant gatekeeper criteria. Currently, this includes three proposed qualitative criteria—(1) having a significant impact on Thailand’s economy or society, (2) being an important gateway for business users to reach end users, and (3) having an entrenched and durable position—as well as additional quantitative criteria.

CPS providers must conduct a self-assessment if they meet the qualitative and quantitative gatekeeper criteria and must report the prescribed information to the Digital Platform Economy Committee, which will review the submitted information and announce the list of designated gatekeepers.

Gatekeeper Obligations

After being included in the list announced by the Digital Platform Economy Committee, designated gatekeepers will be subject to additional obligations under the draft PEA. The details of these obligations are still uncertain but pertain largely to two main issues:

  • Required and prohibited actions. Two sets of rules under this ex-ante approach (imposing rules that focus on preventing potential issues or risks before they occur) concern:
    • Most favored nation (MFN) clauses. Designated gatekeepers must not set prices or conditions or take actions that discriminate against or restrict users offering similar products or services to those the designated gatekeepers provide on their platforms.
    • Anti-steering provisions. Designated gatekeepers must allow users to freely communicate with or promote their products or services to consumers without additional charges, whether through the platform or through other channels provided by the service provider.
  • Modification of T&Cs. Designated gatekeepers must allow at least 15 days for user feedback before modifying T&Cs. A summary of the feedback and any amendments must be submitted to the TCCT. This obligation applies only to designated gatekeepers, which is different from the similar obligation under the DPS Royal Decree.

Status

Comments on the principles of the draft PEA will be accepted until December 15, 2024. All input gathered from stakeholders will be presented to the Council of State, which will then evaluate the principles’ appropriateness, assess potential impacts, and contribute to the development of the final draft PEA.

For more information on compliance with Thailand’s requirements for digital platform services, please contact Tilleke & Gibbins’ digital platform specialists Athistha (Nop) Chitranukroh at [email protected], Pornpan Wichawut at [email protected], Rada Lamsam at [email protected], or Karnravee Jitvilai at [email protected].

RELATED INSIGHTS​ 

July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 21, 2026
Thailand’s Ministry of Digital Economy and Society (MDES) published a notification establishing an expedited court-ordered takedown mechanism for online content in cases of “urgent necessity.” The notification, which was issued on July 17, 2026, under the Computer Crime Act B.E. 2550 (2007), as amended, took effect the following day. It significantly expands the categories of content subject to rapid government-initiated removal. Content Categories Subject to Takedown The notification defines “urgent necessity” (section 20, paragraph 5, of the Computer Crime Act) as circumstances where any delay in suppressing computer data may impact national security, religion, the monarchy, good morals, social culture, or public order. In this regard, it establishes four broad categories of content: Computer Crime Act offenses. National security offenses. IP and other criminal offenses, where it is contrary to public order or good morals and a competent officer has requested its suppression. Content contrary to public order or good morals, a broad residual category encompassing 14 subcategories approved by the Computer Data Screening Committee. The fourth category is the most expansive. Its 14 subcategories include: Content defaming, mocking, satirizing, or devaluing the monarchy. Online gambling advertising or facilitation. Offering illegal firearms for sale. Offering baraku (hookah) products or e-cigarettes for sale. Offering cannabis inflorescences or processed cannabis products for sale. Advertising or soliciting prostitution. Content inciting violence, hatred, or social division. Unauthorized overseas employment advertising. Offering boiled kratom juice for sale. Online sale or advertising of alcoholic beverages. Content satirizing or degrading Buddhism. Money lending at interest rates exceeding legally prescribed limits. Advertising or disseminating information about surrogacy services. Forgery of documents, cards, or official documents. Enforcement Procedure In cases of urgent necessity, a competent official assigned by the MDES permanent secretary must file a petition with supporting evidence to the court with jurisdiction, requesting an order to
July 20, 2026
On July 16, 2026, Thailand’s Personal Data Protection Committee (PDPC) published a notification in the Government Gazette establishing detailed rules governing data subjects’ right of access under section 30 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notification will take effect 60 days after publication—mid-September 2026—giving data controllers a limited window to bring their processes into compliance. Scope The notification covers requests to access or obtain copies of personal data and requests for disclosure of the source of data collected without consent. Data subjects may exercise their rights directly or through authorized representatives. Key Requirements Important requirements set by the notification include the following: Required request channels. Controllers must provide at least two request channels: direct submission at the business location and registered mail. Electronic channels are optional but, if offered, may also be used for fulfilling requests. Request contents. Requests must be in writing or in electronic form and include the data subject’s name, the preferred access method, details of the data requested, and the requester’s signature. Controllers may request additional identifying information as needed. Identity and authority verification. Controllers may require official identity documents for verification. Authorized representatives must provide authorization documents and identity documents for both the data subject and the representative. Alternative verification methods (e.g., digital authentication) are permitted if they do not unreasonably obstruct data subjects’ rights. Review and response timelines. Controllers must review requests within 15 days. If the request is incomplete, the controller must notify the requester and allow at least 15 days to correct deficiencies. If not corrected, the request may be treated as abandoned. Once verified, controllers must fulfill requests within 30 days, extendable by another 30 days for large-volume or complex requests with notice to the requester. Methods for providing access or copies. Controllers may fulfill
July 16, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) published a series of draft guidance documents for public consultation on July 7, 2026. Issued under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), the drafts address a range of compliance issues and offer insight into the regulator’s current enforcement priorities. This article examines two of those drafts: one on lawful bases for processing personal data, and another on marketing and direct marketing. Together, they reflect the Office of the PDPC’s evolving expectations on lawful-basis selection, accountability, and the use of personal data in marketing. Organizations operating in Thailand should assess the practical implications now, before the guidance is finalized. Lawful Bases: A Structured Selection Process The draft guidance on lawful bases introduces a systematic five-step process for selecting an appropriate lawful basis for each processing activity. Organizations are expected to: Identify the processing activity involved. Assess the appropriate lawful basis. Evaluate whether the data is necessary for the processing. Conduct a legitimate interest assessment (LIA) where applicable. Ensure transparency through privacy notices. The guidance provides practical explanations and examples for each lawful basis under section 24 of the PDPA—including archiving, research, statistics, vital interests, contractual necessity, legal obligation, public task, legitimate interests, and consent—as well as the bases applicable to sensitive personal data under section 26. The aim is to promote more consistent and accurate lawful-basis selection across public- and private-sector organizations. A recurring theme throughout the guidance is that organizations should select the lawful basis that most accurately reflects the actual purpose and circumstances of the processing activity. The guidance cautions against treating consent as a default or catch-all basis where another lawful basis is more appropriate. For processing based on legitimate interests, organizations should conduct and document an LIA. Processing involving sensitive personal data may require