You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 24, 2023

Thailand Tightens Rules for Consumer Loan Agreements

The Contract Committee of Thailand’s Consumer Protection Board has issued new requirements and prohibitions for consumer loan agreements. The Notification of the Contract Committee Re: Stipulation of Loan Business for Consumers as a Contract-Controlled Business B.E. 2565 (2022) was published in the Government Gazette on December 13, 2022, and will take effect after 90 days (i.e., on March 13, 2023).

The notification repeals and replaces the Contract Committee’s previous notifications regarding the same subject matter, which were issued in 2001 (Nos. 1–2), 2002 (No. 3), and 2015 (No. 4). The notification enhances protection for consumers by extending the scope of application and stringently regulating the content of agreements for loans to individual consumers.

Key Definitions

The scope of the notification is largely indicated by its definitions of a few key terms:

  • “Loan business for consumers” refers to a business in which the operator enters into an agreement to grant a loan to a consumer (i.e., not a juristic person) or to allow the consumer to borrow money from the business operator, whereby the consumer will spend money for a purpose other than their occupation or business to earn income. This includes granting loans to consumers through an electronic channel. The notification can also apply to personal loan businesses, digital loan businesses, and peer-to-peer lending businesses regulated by the Bank of Thailand.
  • “Business operators” include financial institutions under the law relating to financial institutions; banks established under specific laws; individuals who carry out a loan business in their ordinary course of business; and juristic persons that engage in loan business, securitization business, or asset management of rights to monetary claim. Certain types of businesses and organizations—such as cooperatives—are excluded from the scope of this notification.
  • “Interest” means legal interest in accordance with the Civil and Commercial Code, and it includes compensation, profits, and other benefits with the same characteristics as legal interest, regardless of name.

Required Loan Agreement Content

The notification requires that the loan agreement be clearly legible in Thai language, and it must be executed in two copies for both the lender and the borrower. The font size must not be smaller than two millimeters, with no more than 11 characters within one inch. The details that must be stipulated in the agreement include:

  • Interest rate and other expenses together with calculation formula;
  • Details about collection fees and expenses;
  • Conditions on default—in bold, italic or underlined text, or otherwise made more clearly visible than other terms and conditions;
  • Conditions for assignment of rights to claim repayment;
  • Conditions for payment in installments;
  • Notification duties and address to receive notifications by post or email;
  • Data protection rules, especially in case of disclosure of personal data to a third party; and
  • Conditions on guarantee by person.

If the loan agreement gives the lender the right to adjust the interest rate, the lender must notify all borrowers concerned in writing by registered post or email regarding any interest rate adjustment, depending on circumstances as stipulated in the Contract Committee’s notification.

Prohibited Loan Agreement Content

The Contract Committee’s notification prohibits the loan agreement from including certain clauses that provide excessive benefits to the lender, including:

  • Restriction or exemption of liabilities of the lender in case of its default.
  • Allowing the lender to claim for outstanding debt or call for repayment before the due date of the repayment period when the borrower is not in default.
  • Allowing the lender to terminate the agreement without written notification.
  • Allowing the lender to adjust the interest rate, fees, or expenses unless otherwise permitted under this notification.
  • Requiring the borrower to apply for insurance, except for a housing loan or loan with collateral.
  • Granting the lender the right to charge a penalty or fees before the due date for receiving payment has passed in accordance with the period specified in the agreement, except in certain circumstances prescribed in this notification.

Online, electronic, and digital loan businesses must also comply with this notification and ensure that the content of loan agreements complies with the specified requirements and prohibitions. Operators of platforms that act as an intermediary, such as peer-to-peer lending, must facilitate the distribution of loan agreements to the concerned parties (particularly the borrower).

Grandfather Clause

The provisions under this notification do not apply to loan agreements executed before the new notification’s effective date (i.e., March 13, 2023), which would have to be in accordance with the Contract Committee’s previous notification on consumer loans.

As the new notification has an extensive scope of application and notable requirements and prohibitions, business operators—particularly nonfinancial institutions—should prepare for these more rigid provisions and review their draft loan agreements to ensure full compliance.

For more information or advice on the notification’s requirements, review of draft loan agreements, or any other aspect of consumer lending in Thailand, please contact Nutavit Sirikan at [email protected].

RELATED INSIGHTS​ 

August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must
July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 17, 2026
On July 11, 2026, media reports conveyed key messages from Bank of Thailand (BOT) Governor Vitai Ratanakorn’s announcement of a sweeping regulatory crackdown on grey capital activities. The measures target high-value cash transactions, gold trading, and stablecoin flows, with new requirements set to take effect in the fourth quarter of 2026. The initiative aims to prevent financial institutions from facilitating shadow economy activity, money laundering—particularly through stablecoins—and capital flight, through enhanced compliance obligations on commercial banks across multiple transaction channels. Expanded Cash Controls Close the Deposit–Withdrawal Circuit New fourth-quarter guidelines will require individuals depositing THB 5 million or more in cash to formally verify the source of their funds. This builds on restrictions introduced in April 2026, which required anyone withdrawing 5 million baht or more in cash to provide their bank with verified commercial justification for why electronic transfers or checks could not be used. That initial measure caused high-value physical cash withdrawals to drop by 35 percent nationwide. The upcoming deposit-side requirement closes the circuit on large cash movements. The BOT is also assessing tracking mechanisms for high-value banknote swaps, specifically targeting individuals seeking to exchange large volumes of THB 1,000 notes into smaller THB 100 or THB 500 denominations without clear business justification. Governor Vitai emphasized that these measures require continuous deployment of multiple parallel strategies rather than short-term fixes. Tightened Bullion Reporting Frameworks Restrict Money Laundering Channels The BOT has also tightened reporting frameworks for gold trading to close money laundering loopholes and shield the Thai baht from speculative bullion volatility. Regulators identified a recurring pattern in which buyers purchased large quantities of gold through digital applications in the morning and then made same-day physical withdrawals from retail gold shops in the afternoon. Gold shops are reminded of their duties to flag and report cash
June 23, 2026
On May 14, 2026, Thailand published a ministerial regulation in the Government Gazette to prescribe measures for prevention and suppression of technology crimes. The regulation creates a comprehensive procedural framework for returning money and digital assets to victims of technology crimes. It will take effect 90 days after publication (in mid-August 2026), giving affected entities a limited window to prepare. Mandatory Reporting Obligations for Financial Institutions When a deposit account, e-money account, or digital asset wallet is frozen in connection with a technology crime, the relevant financial institution or business operator must report transaction data to the Anti-Money Laundering Office (AMLO) via AMLO’s designated electronic system. Required data elements include account numbers (sender and receiver), names, identification or passport numbers, legal entity registration numbers, phone numbers, remaining balance, damage amount, transaction reference numbers, and the bank case ID. Institutions that already share data through the information-sharing system under the emergency decree are deemed to have satisfied this reporting obligation, creating an incentive for platform participation. When the Royal Thai Police or the Department of Special Investigation seize or freeze assets related to technology crimes, they must provide AMLO with investigation reports, complaint evidence, money-trail data, and account statements. Notification and Claims Process Once the AMLO secretary-general approves verified reports of a technology crime, the account information of persons connected to the crime will be published in the Government Gazette, triggering a 90-day window for victims to file claims and for related persons to file objections. Officers will also publish details on AMLO’s electronic media and send registered mail to identified victims, which will be deemed received after 7 days domestically or 15 days internationally. Victims have 90 days from the date the crime is published in the Government Gazette to file claims through AMLO’s electronic system. Claims must include