You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 20, 2026

Thailand Ties Data Center Tax Breaks to Workforce and Supply Chain Development

Thailand’s Board of Investment (BOI) now requires data center projects to demonstrate measurable benefits for local workforce development, R&D, SME capability, and domestic supply chains to qualify for corporate income tax (CIT) exemptions. BOI Notification No. Por. 3/2569, issued on February 6, 2026, updates the requirements for projects seeking promotion under BOI category 8.2.1 (data centers).

All data center projects must now submit and implement plans covering development of Thai human resources and domestic supply chain support before benefiting from any CIT exemption.

Human Resources Development Plan

The BOI seeks to promote local talent development beyond basic training. Plans must include the following elements:

  • Training for data center design, construction, and operations targeting vocational students, engineering and ICT undergraduates and postgraduates, and energy and building personnel in Thailand.
  • Joint curricula with Thai universities and technical institutes.
  • Collaborative R&D with Thai nationals or institutions in areas including AI, resource allocation, high-performance computing, and data center hardware and systems.
  • Thai SME upskilling in electrical and energy systems and IT services.

Domestic Supply Chain Support Plan

Plans must demonstrate knowledge transfer in design, construction, cooling, security, and power and water management. Projects must also include usage or installation of domestically manufactured equipment or engage specialist domestic entities.

Criteria for BOI Evaluation

The BOI will assess data center operators’ eligibility for CIT incentives based on two criteria:

  • Scale requirement: Training and joint-curriculum initiatives must reach a total participants equal to at least 10 times the project headcount and run for the duration of the CIT incentive. If this threshold is not met, the applicant must also implement continuous R&D or SME skills-development plans throughout the incentive period.
  • Substantiality test: Supply-chain plans must be substantive, meet industry standards, and show measurable development of the domestic digital and data center supply base.

To ensure compliance, the BOI will conduct two-stage verification. Before using CIT exemptions, applicants must provide evidence of binding commitments, such as agreements with educational institutions or agencies. At full project startup, the BOI will cross-check plans against the BOI application, including any amendments, financial statements, accounting records, and partner confirmation letters.

Outlook

The BOI now ties incentives to measurable local impact. Projects must commit to sustained investment in Thai talent, R&D, and domestic suppliers. Investors should integrate these requirements into project planning from the start to secure and fully benefit from BOI tax incentives.

RELATED INSIGHTS​ 

October 7, 2022
Thailand’s Office of the Personal Data Protection Committee (PDPC) has opened a public hearing period on its draft notification regarding cross-border transfer of personal data. The public hearing is open through October 24. The notification, once issued, will supplement the principle of cross-border transfer of personal data outside of Thailand set out in the Personal Data Protection Act (PDPA). The notification sets out the following key matters: Definitions “Transfer of personal data” means any sending or transferring of personal data by a transferor of personal data, either by way of a physical transfer or a remote transfer through a computer system or an internet network to the recipient of the personal data. It does not include sending personal data through an intermediary by transiting between computer systems or internet networks, or any storing or retaining of personal data, either permanently or temporarily, by a cloud computing service provider, whereby the personal data transferor and the personal data recipient (1) are not making the order, (2) are not involved with any data selection or the content of the personal data sent and received through the computer systems or internet networks, or (3) have the purpose of entering into an agreement or any juristic act. “Binding corporate rules” means the agreed terms or policy on personal data protection made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data within a group of corporations or companies. “Standard contractual clauses” means the contractual terms made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data. “Code of conduct” means a code that sets out the obligations of a personal data transferor and a personal data recipient outside of Thailand. “Certification” means an undertaking in relation to
September 21, 2022
Thailand’s Personal Data Protection Committee (PDPC) has released separate guidelines for data controllers to follow in obtaining data subjects’ consent and notifying data subjects of required information (i.e., regarding collection, use, or disclosure of their personal data). By following the guidelines, data controllers can mitigate the risk of violating the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The Guidelines on Obtaining Consent from the Data Subject according to the PDPA and the Guidelines on Notification of Purposes and Details upon the Collection of Personal Data from the Data Subject according to the PDPA were issued on September 7, 2022. Consent Guidelines The PDPC’s guidelines on obtaining consent list the requirements for consent to be considered valid. These requirements include stipulations on timing of requests, elements that need to be included in requests, and the nature of requests. For instance, consent must be obtained before or at the time of obtaining personal data, and data subjects must be informed of both the purposes and details of the personal data handling, among other specific requirements. In turn, there must be a clear affirmative act of the data subject in giving consent. Obtaining consent from minors is subject to more stringent requirements, and data controllers should implement appropriate identification and age-verification measures when collecting personal data about minors. The guidelines give two sets of requirements, depending on the age of the minor—between 10 and 20, and under 10. In general, with the older age group, parental consent is not required in all circumstances, while for the younger age group, parental consent is compulsory for giving consent on behalf of the minor. For a person deemed to be “incompetent” or “quasi-incompetent,” consent must always be given by the legal guardian. Notification Guidelines The guidelines on notifying data subjects when collecting personal data
September 16, 2022
Thailand’s Personal Data Protection Committee (PDPC) has issued a regulation establishing procedures for filing and processing data subjects’ complaints under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The Regulation Re: Complaint Filing, Rejection, Termination, Consideration, and the Period for the Consideration of the Complaint B.E. 2565 (2022) was issued in July 2022 and took effect on July 12, 2022. The PDPA entitles data subjects to file complaints against data controllers, data processors, and employees or service providers of either whose operations fail to comply with the PDPA. This article lays out the various requirements and procedures for the filing and processing of such a complaint. Complaint Submission The body designated by the PDPA to be responsible for handling complaints and imposing administrative penalties is called the “Expert Committee.” Data subjects who would like to make a complaint can submit it to the Expert Committee directly at the Office of PDPC, send it to the office by post, or submit the complaint electronically. The written or electronic complaint must use clear, plain, polite, and appropriate language, and must not give an impression of being directly or indirectly extorting or intimidating. The complaint must include at least the following information: Name, address, and telephone number or email address of the complainant (or an authorized representative), together with identification card, passport, or other official identification document (plus a power of attorney if submitted by a representative); Details and facts of the noncompliance with or violation of the PDPA; Details of resulting damages or impact; Supporting evidence (e.g., documentary evidence, physical evidence, witness statements); and Action desired of the offender. The complaint must include a statement certifying its veracity, and must be signed by the complainant or the authorized representative. Complaint Consideration When a complaint is submitted, the receiving official will
September 8, 2022
While much attention has been paid to the data localization requirements for foreign enterprises under Vietnam’s 2018 Cybersecurity Law (“CSL”) and the recently issued Decree 53 guiding its implementation, the corresponding requirements for domestic enterprises are often overlooked, despite being potentially more troublesome. Under Decree 53, “domestic enterprises” are defined to mean enterprises established or registered for establishment under Vietnamese law and having their head offices in Vietnam (Article 2.11), so this designation includes not only Vietnamese companies, but foreign-invested enterprises as well. Background Before analyzing the stipulations in Articles 26 and 27 of Decree 53 further guiding the data localization/storage requirements, it is worth restating the very problematic Article 26.3 of the CSL, which reads: “Domestic and foreign enterprises providing services on telecommunication networks or the internet or value-added services in cyberspace in Vietnam with activities of collecting, exploiting, analyzing, and/or* processing personal information data, data on the relationships of service users, or data generated by service users in Vietnam must store such data in Vietnam for the period prescribed by the government. Foreign enterprises mentioned in this clause must open branches or representative offices in Vietnam.” [* Note: The Vietnamese text simply uses a comma here, without specifying whether this should be “and” or “or,” leading to additional problems in interpretation.] Because of this very broad and ambiguous wording, Article 26.3 of the CSL required further guidance from the government and remained unenforced for more than three years after the CSL took effect on January 1, 2019. Decree 53 guiding the implementation of the CSL was finally issued on August 15, 2022, and provides additional clarity on this matter. But does Decree 53 provide sufficient guidelines for implementation with regard to domestic enterprises? Scope of Application With regard to foreign enterprises, although there remains some ambiguity, Decree