You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 11, 2026

Thailand Set to Overhaul Its E-Transactions Framework

Thailand’s Electronic Transactions Development Agency (ETDA) has released a revised draft Electronic Transactions Act (ETA) for public hearing from May 12, 2026, to June 15, 2026. This is not merely an amendment to certain provisions of the current ETA, but a comprehensive redrafting of the entire act.

The revised draft ETA introduces several significant changes from the current framework, with practical implications for businesses operating in Thailand.

Unified Coverage of Public and Private Sectors

The current law segregates government transactions into a separate chapter with distinct rules. The draft ETA eliminates this division, defining “transaction” to encompass civil and commercial juristic acts as well as administrative procedures, administrative contracts, and other acts of government agencies.

Enhanced E-Signature Definition

The definition of “electronic signature” is broadened to expressly include biometric data and refocused on identifying the signatory and demonstrating intent regarding the content of the electronic data.

Shift in Burden of Proof

When a party challenges the reliability of electronic data created using a “trusted electronic method” or a method prescribed by the ETDA, the burden of proof and the cost of proving unreliability shifts to the challenger.

Introduction of New Digital Method Concepts

The draft ETA introduces several new digital method concepts that are not currently recognized under the existing ETA framework. These include:

  • Electronic timestamping (e-timestamp)
  • Electronic registered delivery
  • Electronic company seals
  • Electronic stamp duty compliance
  • Electronic identity authentication and verification
  • Electronic transferable records (electronic bills of lading, promissory notes, and similar negotiable instruments)

Recognition of Automated Systems and Electronic Contracting

The draft ETA expressly recognizes the legal validity and enforceability of contracts formed through automated systems, including contracts concluded entirely between automated systems or between an automated system and a person. A party may not deny the binding effect of such contracts solely because no human review or intervention was involved in the transaction process.

The draft, however, also introduces safeguards for unexpected automated actions. Where an automated system acts in a manner that could not reasonably have been anticipated by the party using the system, the action may not be legally binding if the counterparty knew or should reasonably have known that such action was unintended or unforeseeable.

In addition, the draft ETA provides protection for input errors made by individuals interacting with another party’s automated system. If the system does not provide a means to correct the error, the individual may withdraw the erroneous electronic communication, provided that notice of the error is given promptly after discovery; and the individual has not received or benefited from the relevant goods or services.

These new requirements would impact the use of AI, especially agentic AI, in business operations.

New Obligations for E-Transaction Service Providers

The draft ETA proposes to replace the current mandatory licensing regime applicable to certain electronic transaction businesses with a voluntary certification framework.

The draft ETA identifies seven categories of electronic transaction services: (1) identity verification, (2) electronic signature services, (3) timestamping, (4) electronic data transmission and storage, (5) website or domain name registration/certification, (6) electronic transferable record systems, and (7) other services prescribed by ministerial regulation. Service providers in these categories must comply with detailed operational duties, including maintaining reliable systems, processes, and personnel; implementing risk management frameworks; publishing electronic channels for complaints; and enforcing cybersecurity measures together with protocols for notifying, remedying, and mitigating damage from incidents.

Providers that clearly disclose the purpose and limitations of their services are shielded from liability where users act outside or beyond those disclosed boundaries.

Shifting Criminal Penalties to Civil Liability

The draft ETA removes the existing criminal penalties imposed on service providers operating without the required license, registration, or notification. These violations currently carry penalties of imprisonment for up to three years and/or fines of up to THB 300,000. This change aligns with the draft ETA’s shift from a mandatory licensing regime to a voluntary certification framework. Under the proposed framework, enforcement would instead focus on civil liability. In particular, service providers that fail to comply with their duties prescribed in the Draft ETA may be held liable for damages suffered by users or other relevant parties.

Implications for Businesses

The draft ETA carries several key implications for businesses operating in Thailand:

  • Digital-first policy. Organizations should evaluate whether internal workflows—especially government filings, notices, and contract execution—can migrate to fully electronic processes.
  • E-signatures and biometrics. Organizations using biometric authentication (fingerprints, facial recognition) for contract execution will have clearer statutory backing but must ensure compliance with Thailand’s Personal Data Protection Act.
  • Burden of proof. Businesses should proactively align their systems with ETDA-prescribed standards.
  • New digital methods. Businesses may rely on e-signatures, e-stamping, e-delivery, and digital identity verification with greater legal certainty, reducing operational friction and supporting digital transformation.
  • Automated systems. Businesses should review their internal procedures and legal limitations for automated systems, AI tools, and digital contracting.
  • Licensing regime. The draft ETA shifts from regulatory approval to a standards-based framework. While licensing burdens may decrease, greater emphasis will be placed on ETDA-prescribed standards, operational reliability, and civil liability.
  • Civil liability shift. Despite reduced criminal exposure, service providers must maintain compliance and operational standards, as failures may result in civil liability for damages.

Next Steps

After the public hearing, the draft ETA will be revisited and further proposed to the parliament for consideration and approval before enactment. This process may take up to a year.

RELATED INSIGHTS​ 

January 24, 2024
On 17 April 2023, the Vietnamese government issued the Personal Data Protection Decree, which is set to take effect 1 July 2023 without any transitional period. The PDPD is considered to be the first comprehensive document on data protection in Vietnam. Accordingly, it provides detailed regulations on the rights of data subjects, consent requirements and requirements for data processing impact assessments and outbound transfer impact assessments. In 2024, the adoption of the Law on the Protection of Consumer Rights and the Law on Electronic Transactions will play a vital role regarding data protection. The LPCR will require traders to obtain consent to collect consumer data and establish a mechanism enabling consumers to select the information they consent to traders collecting. Consumers must also be allowed to express consent in a suitable form. For special processing purposes — such as sharing, disclosure, or transfer of personal data to third parties, and use of personal data to send advertisements and to introduce products — the LPCR requires a mechanism which enables data subjects to clearly opt in to give, or not give, their consent. This requirement is similar to procedures currently required for regulated stakeholders under the PDPD. In the same vein, the LET strictly forbids the acts of trading data to protect Vietnamese personal data. The government is anticipated to provide more details relating to data privacy guidelines after the issuance of the Draft Law on Telecommunications. Accordingly, the draft requires enterprises to provide the requisite information — such as service user’s name and address, number and location of transmitting or receiving servers, call times, IP address and other personal information supplied by the service user when entering a contract — to the relevant authority, as per a request which is made in accordance with the law. Amendments to Decree
January 24, 2024
Thailand’s Personal Data Protection Act came into full effect on 1 June 2022 and various subordinate regulations have since been issued by the Personal Data Protection Committee. These include regulations on security measures to be implemented by data controllers, data breach notification requirements, a mandatory obligation to appoint a data protection officer when the processing activity requires regular monitoring of personal data or a system due to the large scale of personal data, administrative measures and data processors’ record of processing activities. As some areas under the PDPA still require further clarifications, a series of public consultations for the remaining draft subordinate regulations is anticipated in 2024. Potential areas include data protection impact assessments and cross-border transfers of personal data, which are crucial for organizations and particularly for entities with establishments in other jurisdictions. PDPA enforcement by Thai regulators was silent until the last quarter of 2023, when the PDPC published details about complaints that have been lodged to the Expert Committee. The committee is designated by virtue of the PDPA and has the power to make determinations related to imposing administrative fines and other penalties. Enforcement in 2024 is expected to become more active and potentially more serious, which means organizations should pay closer attention to ensure compliance with the PDPA. Similar to the GDPR, the PDPA also has extraterritorial effect. Once the subordinate regulation on international cooperation has been issued by the PDPC, this should clarify how PDPA enforcement against organizations located outside of Thailand will be conducted by Thai regulators. With respect to sector-specific data protection legislation, in September 2023, Thailand’s National Broadcasting and Telecommunications Commission issued the Notification of the NBTC Re: Measures to Protect Telecommunications Service Users’ Rights in regard to Personal Data, Privacy Rights, and Freedom of Telecommunications, which replaces the previous notification.
January 19, 2024
On November 24, 2023, the National Assembly of the Socialist Republic of Vietnam adopted Law No. 24/2023/QH15 on Telecommunications (“Telecom Law 2023”) after a lengthy period of extensive discussions and revisions. The Telecom Law 2023 is set to take effect on July 1, 2024, except for the requirements relating to basic telecom services on the internet (otherwise known as over-the-top services, or “OTT”), data center services, and cloud computing services, which will take effect on January 1, 2025. Some important highlights of the Telecom Law 2023 are discussed below. Updates on Telecom License Requirements With a few exceptions and save for certain types of telecom services, enterprises in Vietnam are required to obtain Telecom Licenses in order to provide telecom services. There are two types of Telecom Licenses: licenses for the provision of telecom services, and licenses for telecom operations. Telecom Licenses can be granted in two forms. The first is separate licensing, which is for telecom services with network infrastructures that use radio frequencies or operate in areas with special requirements set by the government. The second is group licensing, which covers telecom services with network infrastructure (except in certain cases), telecom services without network infrastructure (except in certain cases), and telecom operations. New Regulations for OTT, Data Center, and Cloud Computing Services The Telecom Law 2023 provides the definitions for OTT services, data center services, and cloud computing services, recognizing them as different types of telecom services. It also outlines the rights and obligations of service providers in these fields. Regarding market-entry conditions, foreign direct investments in OTT services, data center services, and cloud computing services are subject to no restrictions on share ownership ratio or capital contribution. Foreign investors can establish 100% foreign-owned enterprises in Vietnam to offer these services. Enterprises offering these services are not
January 12, 2024
Thailand’s Revenue Department (RD) has issued a notification requiring electronic platforms to report their revenue from business operators on their platform. With this information, the RD intends to track business operators’ income from the sale of goods and services through electronic platforms in order to facilitate accurate and efficient tax collection. The notification, which was enacted on December 27, 2023, took effect on January 1, 2024. Under the notification, electronic platforms are required to compile a “special account” containing information on the revenue received from each business operator on their platform and submit it to the RD through the department’s electronic reporting system within 150 days of the end of the fiscal year. The notification defines “electronic platforms” as entities that intermediate between business operators (i.e., sellers of goods or providers of services via the electronic platform) and consumers for the purpose of enabling electronic transactions between the parties. This covers online marketplace operators, ride-hailing operators, food delivery operators, and so on. This reporting requirement applies to electronic platforms registered in Thailand that have (or previously had, starting from the notification’s effective date) annual revenue exceeding THB 1 billion (approx. USD 28.5 million), except for electronic platforms under the supervision of the Bank of Thailand or the Office of the Securities and Exchange Commission, such as payment service providers and cryptocurrency exchanges. Electronic platforms can appoint a third party to prepare and submit the required special account information to the RD on their behalf. Compliance Steps As the requirements established by this notification mean that the RD will now have direct access to information on the income earned by vendors and merchants on electronic platforms, these business operators—whether corporate or individual—should ensure that they faithfully disclose their earnings, submit tax payments correctly, and file income tax returns in a