You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 10, 2025

Thailand Updates Draft Notification on Additional Obligations for Online Marketplaces

After making revisions to the initial draft notification released in November 2024, Thailand’s Electronic Transactions Development Agency (ETDA) has released an updated draft Notification on Additional Obligations for Digital Platform Service Operators of Online Marketplaces for Goods with Specific Characteristics under Section 18(2) of the Royal Decree on the Operation of Digital Platform Service Businesses Subject to Prior Notification B.E. 2565 (2022) B.E. … . A focus group session was also held to gather feedback from business operators.

Below is a summary of key provisions in the new draft.

Unchanged Items

Some key concerns that remain unchanged from the previous version of the draft notification include the following:

  • Offshore business operators running online marketplaces that act as intermediaries for the sale or exchange of goods and provide facility services for the sale of goods (referred to as “specific marketplace operators” in the draft) are required to establish a local entity in Thailand. However, the criteria for determining which operators are specific marketplace operators are still under discussion due to feedback from business operators.
  • Specific marketplace operators must submit a compliance report to the ETDA along with their annual report each year.
  • Specific marketplace operators must verify that “business users” (e.g., merchants) provide complete details about goods in accordance with product standardization requirements.

Removed Obligations

The updated draft notification has removed specific marketplace operators’ obligations to:

  • Conduct Identity Assurance Level 2 (IAL2) verification of business users before onboarding them on their platforms.
  • Submit a registry of business users’ information to the ETDA.
  • Retain business users’ information for a specified retention period.
  • Implement measures to filter reviews of products subject to specific standards.

Revisions

Key revisions made to the draft notification include the following:

  • The effective date has been extended to 120 days after the notification’s publication in the Government Gazette, up from 60 days in the previous draft.
  • The term “products subject to specific standards” now includes three additional categories of regulated goods: medical devices, herbal products, and hazardous substances. This expansion aims to cover all products regulated by Thailand’s Food and Drug Administration (FDA), as the intention of this notification is to encompass products under the supervision of both the Thai Industrial Standards Institute and the FDA.
  • The information that must be reported to the ETDA now includes:
    • The number and proportion of goods on the platform that are subject to product standards.
    • The number and proportion of business users selling or advertising such goods.
    • Data on removed goods and business users, including the number of removals.
    • Complaint handling statistics, including the number and proportion of complaints related to products subject to specific standards.
  • Instead of conducting IAL2 verification of business users, specific marketplace operators must collect certain information from business users, such as name, address, phone number, email address, a copy of their identification document (or electronic version), and bank account details.
  • Specific marketplace operators must have business users conduct self-certification for compliance with laws regarding products subject to specific standards.
  • The maximum complaint response period for specific marketplace operators is changed from 24 hours to 3 days.

Timeline

The ETDA is gathering feedback from relevant operators and will present the draft notification to the agency’s Electronic Transactions Committee in April 2025. Once the draft is finalized and approved by the committee, it will be published and implemented shortly after.

RELATED INSIGHTS​ 

February 26, 2025
Tilleke & Gibbins has contributed the Thailand chapter to Data Protection 2025, a newly published comparative guide from Global Legal Post’s Law Over Borders series. This comprehensive Q&A-style resource provides insights into data protection regulations across multiple jurisdictions worldwide, offering valuable guidance for businesses navigating the complex landscape of global data privacy requirements. The Thailand chapter offers a detailed analysis of the country’s data protection framework, with particular focus on the Personal Data Protection Act (PDPA) that came into full effect in 2022. The chapter addresses key aspects of data protection in Thailand through the following topics: Regulatory framework: National laws governing personal data, scope of application, territorial reach, and regulated operations. Data categories and protection: Types of personal data covered, special categories subject to enhanced protection, and processing requirements. Compliance obligations: Requirements for lawful processing, organizational responsibilities, and data subject rights. Marketing and cross-border considerations: Rules for commercial communications and international data transfers. Enforcement mechanisms: Regulatory powers, investigation procedures, sanctions, and remedies for noncompliance. Tilleke & Gibbins also contributed the Vietnam chapter to Data Protection 2025. Readers can access the complete Data Protection 2025 guide through Global Legal Post’s Law Over Borders platform.
February 23, 2025
On January 6, 2025, the government of Vietnam issued Decree No. 05/2025/ND-CP amending and supplementing Decree No. 08/2022/ND-CP detailing the Law on Environmental Protection (“Decree 05”). Decree 05 came into effect immediately upon issuance and provides several changes to the regulations governing extended producer responsibility (“EPR”) for applicable manufacturers and importers, outlining their obligations concerning the recycling and treatment of discarded products and packages. (See our previous article on Vietnam’s EPR regulations here.) Outlined below are some critical amendments in Decree 05. Entities Subject to EPR Regulations Previously, Decree 08 limited the responsibility for recycling to manufacturers and importers of products and packaging specified in statutory lists. Decree 05 expands this scope by also including entities responsible for the quality and labeling of the regulated products and goods in Vietnam. Decree 05 inherits the regulations from Decree 08 that manufacturers and importers, if they produce and import products and packaging as stipulated by law, must fulfill their responsibility to recycle or support waste treatment activities. However, Decree 05 amends the lists of products/packaging that must be recycled or undergo waste treatment, and new products/packaging and recycling methods. Notably, rechargeable batteries (including those used in vehicles or for electrical and electronic devices) have been added to the list of regulated products and self-propelled vehicles and construction machinery have been removed from the list. Decree 05 also not only streamlines the recycling methods required for each type of product/packaging, but also removes the minimum requirement on the mass of products/packaging that must be recovered when recycling. Manufacturers and importers now have more flexibility in selecting recycling methods that are more suitable for actual recycling conditions in Vietnam. Decree 05 has revised the cases of exemption from recycling and waste treatment obligations, clarifying that both packaging manufacturers and importers with annual product
February 20, 2025
Vietnam’s Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (Decree 147) was issued on November 9, 2024, and came into effect on December 25, 2024. Decree 147 represents a more stringently regulated digital landscape in Vietnam, creating challenges not only for offshore service providers offering cross-border services but also for onshore providers. As these new regulations impose stricter requirements, particularly in areas like content control, user authentication, data storage, and service license/notification, companies will need to adapt quickly to maintain compliance and minimize legal risks. The following are some of the key topics covered by Decree 147. [Note: Shortly after the issuance of Decree 147, Vietnam began a government restructuring process, with the aim of streamlining the government by consolidating and eliminating various ministries and agencies. Thus, the decree’s references to authorities such as the Authority of Broadcasting and Electronic Information (ABEI) and the Ministry of Information and Communications (MIC) are subject to change.] 1. Cross-Border Information Provision Cross-border information provision is defined broadly as the provision by overseas organizations and individuals of information and online information content services for service users in Vietnam to access or use. This wide-ranging definition encompasses various types of cross-border services, including social network services, online game services, and app store services. However, cross-border provision of online game services remains prohibited under Decree 147 (see further details below). Offshore providers of services on a cross-border basis who lease data storage in Vietnam or meet a threshold of 100,000 or more total visits per month from Vietnam for six consecutive months (“regulated cross-border providers”) must adhere to stricter requirements. Specifically, they are required to, among other requirements: Notify the relevant authority of their contact information, including the location of the main server providing the service, within 60
February 17, 2025
Thailand’s draft Emergency Decree on Technology Crimes Suppression, which we covered in a client alert in January 2025 primarily addressed to telecom operators and financial institutions, is expected to have significant implications for a wide range of business operators.  The draft emergency decree has already been approved by the cabinet but may undergo further developments as it continues in the legislative process. In this article, we will highlight the material impacts of the draft emergency decree on overseas and local fintech operators. Expanded Definition of “Technology Crimes” The definition of “technology crimes” now includes the following acts of forgery or alteration: Forging or altering the identity of individuals and biometric characteristics by utilizing computer or communication systems or other electronic means to commit offenses. Forging or altering symbols, trademarks, or seals of groups (e.g., foundations, community enterprises) or juristic persons, including acts by juristic persons using individuals or juristic persons as nominal directors or shareholders, regardless of whether such individuals or legal juristic persons reside in Thailand. Forging or altering digital or online platforms, regardless of the platform’s location or legal status. Individuals who conspire, utilize, assist, or support the commission of these offenses will face the same penalties as the principal offender. Business Operator Definition The scope of “business operators” is now expanded to cover various fintech and digital asset operators beyond those under the Payment Systems Act (PSA). The draft emergency decree now includes the following operators, whether they are legally authorized or not: Business operators under the PSA and business operators who operate “as if” they are payment system operators Business operators under the Royal Decree on Digital Asset Businesses or business operators who operate “as if” they are digital asset business operators. Foreign exchange business operators. Disclosure and Exchange of Information Business operators must disclose