You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 11, 2026

Thailand Set to Overhaul Its E-Transactions Framework

Thailand’s Electronic Transactions Development Agency (ETDA) has released a revised draft Electronic Transactions Act (ETA) for public hearing from May 12, 2026, to June 15, 2026. This is not merely an amendment to certain provisions of the current ETA, but a comprehensive redrafting of the entire act.

The revised draft ETA introduces several significant changes from the current framework, with practical implications for businesses operating in Thailand.

Unified Coverage of Public and Private Sectors

The current law segregates government transactions into a separate chapter with distinct rules. The draft ETA eliminates this division, defining “transaction” to encompass civil and commercial juristic acts as well as administrative procedures, administrative contracts, and other acts of government agencies.

Enhanced E-Signature Definition

The definition of “electronic signature” is broadened to expressly include biometric data and refocused on identifying the signatory and demonstrating intent regarding the content of the electronic data.

Shift in Burden of Proof

When a party challenges the reliability of electronic data created using a “trusted electronic method” or a method prescribed by the ETDA, the burden of proof and the cost of proving unreliability shifts to the challenger.

Introduction of New Digital Method Concepts

The draft ETA introduces several new digital method concepts that are not currently recognized under the existing ETA framework. These include:

  • Electronic timestamping (e-timestamp)
  • Electronic registered delivery
  • Electronic company seals
  • Electronic stamp duty compliance
  • Electronic identity authentication and verification
  • Electronic transferable records (electronic bills of lading, promissory notes, and similar negotiable instruments)

Recognition of Automated Systems and Electronic Contracting

The draft ETA expressly recognizes the legal validity and enforceability of contracts formed through automated systems, including contracts concluded entirely between automated systems or between an automated system and a person. A party may not deny the binding effect of such contracts solely because no human review or intervention was involved in the transaction process.

The draft, however, also introduces safeguards for unexpected automated actions. Where an automated system acts in a manner that could not reasonably have been anticipated by the party using the system, the action may not be legally binding if the counterparty knew or should reasonably have known that such action was unintended or unforeseeable.

In addition, the draft ETA provides protection for input errors made by individuals interacting with another party’s automated system. If the system does not provide a means to correct the error, the individual may withdraw the erroneous electronic communication, provided that notice of the error is given promptly after discovery; and the individual has not received or benefited from the relevant goods or services.

These new requirements would impact the use of AI, especially agentic AI, in business operations.

New Obligations for E-Transaction Service Providers

The draft ETA proposes to replace the current mandatory licensing regime applicable to certain electronic transaction businesses with a voluntary certification framework.

The draft ETA identifies seven categories of electronic transaction services: (1) identity verification, (2) electronic signature services, (3) timestamping, (4) electronic data transmission and storage, (5) website or domain name registration/certification, (6) electronic transferable record systems, and (7) other services prescribed by ministerial regulation. Service providers in these categories must comply with detailed operational duties, including maintaining reliable systems, processes, and personnel; implementing risk management frameworks; publishing electronic channels for complaints; and enforcing cybersecurity measures together with protocols for notifying, remedying, and mitigating damage from incidents.

Providers that clearly disclose the purpose and limitations of their services are shielded from liability where users act outside or beyond those disclosed boundaries.

Shifting Criminal Penalties to Civil Liability

The draft ETA removes the existing criminal penalties imposed on service providers operating without the required license, registration, or notification. These violations currently carry penalties of imprisonment for up to three years and/or fines of up to THB 300,000. This change aligns with the draft ETA’s shift from a mandatory licensing regime to a voluntary certification framework. Under the proposed framework, enforcement would instead focus on civil liability. In particular, service providers that fail to comply with their duties prescribed in the Draft ETA may be held liable for damages suffered by users or other relevant parties.

Implications for Businesses

The draft ETA carries several key implications for businesses operating in Thailand:

  • Digital-first policy. Organizations should evaluate whether internal workflows—especially government filings, notices, and contract execution—can migrate to fully electronic processes.
  • E-signatures and biometrics. Organizations using biometric authentication (fingerprints, facial recognition) for contract execution will have clearer statutory backing but must ensure compliance with Thailand’s Personal Data Protection Act.
  • Burden of proof. Businesses should proactively align their systems with ETDA-prescribed standards.
  • New digital methods. Businesses may rely on e-signatures, e-stamping, e-delivery, and digital identity verification with greater legal certainty, reducing operational friction and supporting digital transformation.
  • Automated systems. Businesses should review their internal procedures and legal limitations for automated systems, AI tools, and digital contracting.
  • Licensing regime. The draft ETA shifts from regulatory approval to a standards-based framework. While licensing burdens may decrease, greater emphasis will be placed on ETDA-prescribed standards, operational reliability, and civil liability.
  • Civil liability shift. Despite reduced criminal exposure, service providers must maintain compliance and operational standards, as failures may result in civil liability for damages.

Next Steps

After the public hearing, the draft ETA will be revisited and further proposed to the parliament for consideration and approval before enactment. This process may take up to a year.

RELATED INSIGHTS​ 

June 8, 2023
At a conference organized by Vietnam’s Ministry of Public Security (MPS) on June 7, 2023, government officials provided more guidance on the recently issued Personal Data Protection Decree (PDPD), which is set to take effect on July 1, 2023. Key takeaways included the following: A national portal on personal data protection for online submission of notifications and registrations will be launched before July 1, 2023. The MPS also plans to issue templates for data processing impact assessments (DPIAs) and transfer impact assessments (TIAs) in the near future. The PDPD requires data controllers, data processors, and data controller-processors to prepare a DPIA at the start of personal data processing. The MPS clarified that the DPIA is expected to be prepared and submitted once. Only changes to its content would require submission of an updated DPIA. Both DPIAs and TIAs (which are for cross-border data transfers) must be prepared in Vietnamese. Since the sale and purchase of personal data is strictly prohibited unless explicitly permitted by law, the MPS has handled approximately 14 cases involving unlawful trading of personal data, including sensitive data. Under the PDPD, sensitive data has a broader definition than under the GDPR (the European Union’s General Data Protection Regulation), and also includes location data, creditworthiness, and personal financial data. Consent is not a legal basis for the trading of personal data, including sensitive data. The 72-hour timeline for responding to a data subject’s request does not mean 72 working or business hours. Rather, it means 72 actual consecutive hours. Any organization transferring the personal data of Vietnamese citizens outside of Vietnam must comply with the PDPD, regardless of the organization’s location. For organizations incorporated overseas that must comply with the PDPD, there is no requirement to appoint a local representative (unlike the GDPR)—but appointment of a data
June 2, 2023
In Southeast Asia, artificial intelligence (AI) products and services are being leveraged across industries such as finance, healthcare, retail, agriculture, and manufacturing. Governments across the region are recognizing the benefits of harnessing AI and the positive impact of AI technology on economic development. As the rise in AI deployment creates opportunities for economic growth in Southeast Asia, regulatory and digital governance efforts should focus on ethical, inclusivity, and cybersecurity concerns to help ensure that the widespread use of AI technology in the region is sustainable. Two jurisdictions in the region that have already made significant strides in developing initiatives surrounding AI are Singapore and Thailand. Singapore Due to its more advanced technological infrastructure, Singapore was one of the first countries in the region to address AI-related issues. Singapore has been aligning its data protection policies and regulations with the changing digital landscape since 2012—the year Singapore passed its Personal Data Protection Act. In 2019, Singapore unveiled its National AI Strategy to increase the use of AI technologies and deploy “scalable, impactful AI solutions in key verticals by 2030.” The goal is to align talent, regulation, and business growth to ensure AI applications serve society. Singapore’s approach is to facilitate innovation while safeguarding consumer interests, as it strives to become one of the regional leaders in the field of AI. In terms of Singapore’s regulatory landscape, Singapore’s Personal Data Protection Commission (PDPC) oversees data and AI, including AI developers and AI-using companies, which consist of backroom operations, front-end usage companies, and distributors of equipment with AI features. The Singapore Academy of Law (SAL) oversees all laws applicable to AI systems and decides on issues that impact the AI industry. Singapore has joined various bilateral and regional trade arrangements to facilitate research, development, and collaboration in support of its growing digital
May 24, 2023
The draft Royal Decree on Artificial Intelligence System Service Business, which was introduced by the Office of the National Digital Economy and Society Commission earlier for public comment in October last year, focuses on potential risks from artificial intelligence (AI) systems to public health, safety, and freedoms. The framework emphasizes the importance of risk assessment, reporting requirements, and the establishment of specific measures and criteria deemed necessary to minimize AI risks. AI Systems Defined by the Decree Under the draft royal decree, an AI system is defined as a machine-based system that can make predictions, recommendations, or decisions that affect real or virtual environments pursuant to the objectives set by humans. The definition clarifies that artificial intelligence systems are designed to operate at different levels of autonomy, including: machine learning AI; logic-based and knowledge-based AI; statistical AI; Bayesian estimation AI; and search and optimization AI. Risk-based Approach The draft AI royal decree takes a risk-based approach to regulation and specifically identifies prohibited or high-risk AI services that could cause harm or engage in unethical practices to ensure that AI systems do not pose major risks to public health, safety, or freedoms. The extent of regulatory scrutiny applied to an AI system corresponds to the level of risk presented by the AI system. For example, AI systems that pose unacceptable risks are generally prohibited, AI systems considered to be high-risk are subject to a conformity assessment, and AI systems considered to be limited-risk are subject to transparency requirements. Compliance with specified criteria and procedures to minimize potential risks of each AI service would be further outlined in subregulations. Prohibited AI Systems The draft AI royal decree prohibits AI systems that: employ subliminal techniques to covertly influence human behavior (below the threshold of conscious awareness); utilize social scoring; access sensitive personal
May 17, 2023
In Myanmar, a Union Tax Law is enacted each year to announce the rates of tax set out in the Income Tax Law 1974, the Commercial Tax Law 1990, and the Special Goods Tax Law 2016. The Union Tax Law 2023 (UTL 2023) came into force on April 1, 2023. It sets the rates of special goods tax (SGT), income tax (IT), and commercial tax (CT) for the period of April 1, 2023, to March 31, 2024, and exempts certain goods and services from these taxes. The key changes implemented by the UTL 2023 are summarized below. Special Goods Tax The UTL 2023 exempts battery electric vehicles (BEVs) from SGT. At the same time, it increases the rate of SGT on imported liquor. Previously, the rate of SGT ranged from 190 MMK per liter to 60 percent of the per-liter price of imported liquor in the previous fiscal year. The UTL 2023 raises the minimum rate to 209 MMK per liter while leaving the upper rate unchanged. Commercial Tax and Customs Tariffs BEVs imported into Myanmar were made exempt from CT under the Law Amending the Union Tax Law 2022. The UTL 2023 extends the exemption until the end of the 2023–24 fiscal year, along with two- and three-wheeler BEVs, BEV batteries, and related parts for specific use in BEVs. The CT exemption for battery charging services for BEVs, also introduced in 2022, has similarly been extended. Following enactment of the UTL 2023, the Ministry of Planning and Finance (MOPF) issued Notification No. 31/2023, reducing to zero the customs tariffs on imported BEVs, including those imported completely built up (CBU), completely knocked down (CKD), or semi-knocked down (SKD). The tariffs on spare parts and materials for BEVs have also been reduced to zero. In addition to exempting BEVs from