You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 24, 2023

Thailand Tightens Rules for Consumer Loan Agreements

The Contract Committee of Thailand’s Consumer Protection Board has issued new requirements and prohibitions for consumer loan agreements. The Notification of the Contract Committee Re: Stipulation of Loan Business for Consumers as a Contract-Controlled Business B.E. 2565 (2022) was published in the Government Gazette on December 13, 2022, and will take effect after 90 days (i.e., on March 13, 2023).

The notification repeals and replaces the Contract Committee’s previous notifications regarding the same subject matter, which were issued in 2001 (Nos. 1–2), 2002 (No. 3), and 2015 (No. 4). The notification enhances protection for consumers by extending the scope of application and stringently regulating the content of agreements for loans to individual consumers.

Key Definitions

The scope of the notification is largely indicated by its definitions of a few key terms:

  • “Loan business for consumers” refers to a business in which the operator enters into an agreement to grant a loan to a consumer (i.e., not a juristic person) or to allow the consumer to borrow money from the business operator, whereby the consumer will spend money for a purpose other than their occupation or business to earn income. This includes granting loans to consumers through an electronic channel. The notification can also apply to personal loan businesses, digital loan businesses, and peer-to-peer lending businesses regulated by the Bank of Thailand.
  • “Business operators” include financial institutions under the law relating to financial institutions; banks established under specific laws; individuals who carry out a loan business in their ordinary course of business; and juristic persons that engage in loan business, securitization business, or asset management of rights to monetary claim. Certain types of businesses and organizations—such as cooperatives—are excluded from the scope of this notification.
  • “Interest” means legal interest in accordance with the Civil and Commercial Code, and it includes compensation, profits, and other benefits with the same characteristics as legal interest, regardless of name.

Required Loan Agreement Content

The notification requires that the loan agreement be clearly legible in Thai language, and it must be executed in two copies for both the lender and the borrower. The font size must not be smaller than two millimeters, with no more than 11 characters within one inch. The details that must be stipulated in the agreement include:

  • Interest rate and other expenses together with calculation formula;
  • Details about collection fees and expenses;
  • Conditions on default—in bold, italic or underlined text, or otherwise made more clearly visible than other terms and conditions;
  • Conditions for assignment of rights to claim repayment;
  • Conditions for payment in installments;
  • Notification duties and address to receive notifications by post or email;
  • Data protection rules, especially in case of disclosure of personal data to a third party; and
  • Conditions on guarantee by person.

If the loan agreement gives the lender the right to adjust the interest rate, the lender must notify all borrowers concerned in writing by registered post or email regarding any interest rate adjustment, depending on circumstances as stipulated in the Contract Committee’s notification.

Prohibited Loan Agreement Content

The Contract Committee’s notification prohibits the loan agreement from including certain clauses that provide excessive benefits to the lender, including:

  • Restriction or exemption of liabilities of the lender in case of its default.
  • Allowing the lender to claim for outstanding debt or call for repayment before the due date of the repayment period when the borrower is not in default.
  • Allowing the lender to terminate the agreement without written notification.
  • Allowing the lender to adjust the interest rate, fees, or expenses unless otherwise permitted under this notification.
  • Requiring the borrower to apply for insurance, except for a housing loan or loan with collateral.
  • Granting the lender the right to charge a penalty or fees before the due date for receiving payment has passed in accordance with the period specified in the agreement, except in certain circumstances prescribed in this notification.

Online, electronic, and digital loan businesses must also comply with this notification and ensure that the content of loan agreements complies with the specified requirements and prohibitions. Operators of platforms that act as an intermediary, such as peer-to-peer lending, must facilitate the distribution of loan agreements to the concerned parties (particularly the borrower).

Grandfather Clause

The provisions under this notification do not apply to loan agreements executed before the new notification’s effective date (i.e., March 13, 2023), which would have to be in accordance with the Contract Committee’s previous notification on consumer loans.

As the new notification has an extensive scope of application and notable requirements and prohibitions, business operators—particularly nonfinancial institutions—should prepare for these more rigid provisions and review their draft loan agreements to ensure full compliance.

For more information or advice on the notification’s requirements, review of draft loan agreements, or any other aspect of consumer lending in Thailand, please contact Nutavit Sirikan at [email protected].

RELATED INSIGHTS​ 

November 24, 2025
A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC). The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities. The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives. Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.
September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.
August 25, 2025
To implement the recently issued Resolution on International Financial Centers in Vietnam (“IFC Resolution”), which is set to take effect on September 1, 2025 (see our previous article), the government of Vietnam is making every effort to formulate and issue guiding decrees—up to eight in total—before the effective date of the resolution. These decrees will establish key principles, define the rights and obligations of stakeholders, and outline permissible business activities within the IFCs, and serve as a foundation for the legal framework of the IFCs. Below are highlights of two draft decrees that have been released for public consultation. Draft Decree on IFC Establishment Ho Chi Minh City: The IFC in Ho Chi Minh City will focus on capital markets integrated with asset management services, fund management, insurance, financial products and financial derivatives; banking systems and money market products; fintech and financial innovation through sandbox mechanisms; specialized exchanges and new trading platforms; commodity markets, commodity and commodity derivatives exchanges linked to domestic and international physical commodity markets; and regional supply chain services, logistics hubs, maritime transport, and seaport infrastructure. Da Nang: The IFC in Da Nang will mainly develop green finance and commercial finance for SMEs and innovative enterprises, non-resident organizations and individuals (i.e., offshore financial services); cross-border trade activities linked to free trade zones, high-tech zones, new economic zones, and industrial zones; pilot control mechanisms for emerging models, such as digital assets, cryptocurrencies, and digital payments and transfers; new exchanges and trading platforms; investment funds, remittance funds, and small and medium fund management companies; startups in financial solutions for consumer services, tourism, e-commerce, logistics, and services within free trade zones; and related support, advisory, development, and legal services. Incentives: The People’s Committees of Ho Chi Minh City and Da Nang will need to decide on their list of