You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 29, 2024

Thailand Updates Requirements for Digital Asset Business Governance and Exchange Rules

Thailand’s Securities and Exchange Commission (SEC) has revised its regulations on digital asset operators and exchanges to impose stricter governance standards on digital asset business operators and to align digital asset exchange rules with international standards. The new regulations are laid out in SEC Notification No. GorThor. 23/2567 on the Criteria, Conditions, and Procedures for Operating a Digital Asset Business (No. 24) and SEC Notification No. GorLorThor. 24/2567 on Determination of Prohibited Qualifications for Directors and Executives of Digital Asset Business Operators (No. 5). These were published in the Government Gazette on August 16, 2024, with most of the provisions taking effect on the same date.

Governance for Digital Asset Businesses

The heightened standards for digital asset business operators aim to ensure efficient business supervision and appropriate response to operational risks. The new requirements mainly address:

  • Board of directors composition. Large-sized digital asset business operators (i.e., those with at least 10,000 customers and holding customer assets of at least THB 500 million) who do not provide digital asset custodian services must have at least five directors, at least two of whom must be independent directors. In addition, the business operators must establish an audit committee, with at least two members being independent directors, to create an appropriate “check and balance” mechanism within the organizational structure. Current digital asset business operators must comply with the requirements within 180 days of the notification’s effective date.
  • Qualifications of authorized directors and managers. Authorized directors and managers are now required to (1) either have at least one year of working experience in the digital asset field or have participated in a digital asset course from an SEC-approved list, and (2) participate in a good corporate governance course recognized by the SEC. Current authorized directors and managers who have not previously completed a good corporate governance training course must complete such a course within one year of the notification’s effective date.
  • Management and operational structures. Check-and-balance mechanisms are required for every major operational system. Business operators must establish a customer asset management policy, and all customer assets in the business operator’s custody must be managed according to the security risk and by separate personnel from other operational personnel that may have a conflict of interest. Business operators must also provide a customer service system that is suitable to the risk and complexity levels of the relevant types of digital assets.

Exchange Rules

The SEC has also introduced new minimum requirements for digital asset exchange rules, which must be approved by the SEC. The key updates include:

  • Listing and delisting rules. As indicated by a new utility token supervisory scheme that was issued days earlier, group 1 utility tokens are not allowed to be listed on the exchange. (Group 1 utility tokens are those issued for consumption purposes or as a digital representation of a certificate, such as loyalty points, concert tickets, NFTs, and carbon credits.) In addition, listing rules now require adoption of the “silent period” concept, whereby tokens offered for sale below the market price cannot be listed in the six months after the offering. In terms of issuer disclosure, digital asset exchanges must now require digital token issuers to disclose information as stipulated by the SEC.
  • Trading, clearing, and settlement rules. Digital asset exchanges are now required to have a real-time trade monitoring system to detect abnormal trades, and daily monitoring reports must be submitted to the SEC. If the digital asset exchange finds suspicious action, it must promptly report this to the SEC. The digital asset exchange must also have signposting to inform investors about potential risks from investing in certain tokens.
  • Market makers. Digital asset exchanges with market makers must have rules on qualifications, scope of work, ongoing performance supervision, and noncompliance measures relating to market makers.

For more information on these new notifications, or on any aspect of digital assets and cryptocurrency in Thailand, please contact Kobkit Thienpreecha at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

January 6, 2026
Among the eight implementing decrees issued on December 18, 2025, to provide the legal framework for Vietnam’s new International Financial Centers (IFC), Decree No. 323/2025/ND‑CP serves the core function of officially establishing the IFC as a unified entity in two locations—Ho Chi Minh City and Da Nang—and setting out a plan for its development and governance. The key contents of the decree are summarized below. Location and Focus of IFCs The Vietnam International Financial Center in Ho Chi Minh City (VIFC‑HCMC) and the Vietnam International Financial Center in Da Nang (VIFC‑DN) are designed to attract capital, fintech, and international market participants under a dedicated regulatory framework. The IFCs will host functional zones for financial trading, banking, securities and commodities exchanges, offices, dispute resolution (via specialized court and international arbitration center), and related activities as set by the executive authority of each IFC. VIFC-HCMC, with a total area of 898 hectares in central Ho Chi Minh City, is oriented to develop a comprehensive and diverse financial ecosystem, providing traditional and specialized financial services, and leveraging synergies between financial services such as capital mobilization, investment, payment services, issuance and trading of financial products, asset management, fintech, and green financial services. VIFC-DN, with a total area of 300 hectares, is oriented to develop as a modern IFC, closely integrated with the innovation ecosystem, digital technology, and sustainable finance. VIFC-DN will establish a controlled testing platform for new financial models, taking the lead in the deployment and scaling of digital-asset products, digital payments, and specialized trading platforms and exchanges, while promoting supply chain finance, third-party services, and non-bank financial intermediaries to complement and support the traditional financial market, developing specialized, flexible, and innovative financial products. Near‑Term Priorities and Review Timeline In 2026, the government will prioritize completing the essential infrastructure and ensuring adequate
January 5, 2026
On December 31, 2025, the government of Vietnam promulgated Decree No. 356/2025/ND-CP detailing and guiding the implementation of the new Personal Data Protection Law (PDPL) that was issued in June 2025. The new decree, like the PDPL, entered into force on January 1, 2026, with the previous Decree No. 13/2023/ND-CP on personal data protection ceasing effect on the same day. Some key points of the new decree include the following: Comprehensive lists of basic and sensitive personal data are provided, which will require companies to review again their existing documents and data type classification to ensure compliance. New timelines are established for responding to specific data subject requests. These timelines are more reasonable and longer than the previous 72-hour requirements. Additional consent guidelines are provided, prohibiting default consent or ambiguous instructions that confuse data subjects about giving or withholding consent. Mandatory content for data transfer agreements/clauses in particular cases is provided. This covers, among other things, (i) the legal basis for the transfer of personal data; (ii) responsibilities for personal data protection during the transfer and processing of personal data; (iii) responsibilities for ensuring the exercise of the rights of personal data subjects; and (iv) responsibilities for coordination and compliance of the parties in cases where violations of personal data protection regulations are detected. The qualifications and responsibilities of data protection officers (DPOs) and data protection departments include, among others, having been trained and fostered in legal knowledge and professional skills regarding personal data protection. There are no specific provisions governing the qualifications or requirements for organizations that provide data protection training or education. New mandatory templates and requirements are provided in relation to data processing impact assessment and data transfer impact assessment, and for cases in which companies need to re-submit assessments to the regulator. Stricter requirements are
January 5, 2026
Resolution No. 222/2025/QH15 dated June 27, 2025, of the National Assembly of Vietnam (the “IFC Resolution” – see our previous article) set out the foundational legal framework for the establishment and development of Vietnam’s first-ever International Financial Centers (IFC). In furtherance of this framework, on December 18, 2025, the government of Vietnam issued eight implementing decrees to provide detailed regulatory guidance and to operationalize the IFC Resolution in practice. The Eight Implementing Decrees: An Integrated Regulatory Ecosystem The new decrees governing the IFC include the following: Decree No. 323/2025/ND-CP on the establishment of the IFC. Decree No. 324/2025/ND-CP on financial policies applicable within the IFC. Decree No. 325/2025/ND-CP on labor, employment, and social security within the IFC. Decree No. 326/2025/ND-CP on land and environmental matters within the IFC. Decree No. 327/2025/ND-CP on entry, exit, and residence of foreign nationals in the IFC. Decree No. 328/2025/ND-CP on the International Arbitration Center of the IFC. Decree No. 329/2025/ND-CP on banking licensing, foreign exchange management, and anti-money laundering and combating the financing of terrorism (AML/CFT) within the IFC. Decree No. 330/2025/ND-CP on the establishment and operation of commodity exchanges within the IFC. Taken as a whole, these eight decrees translate the IFC Resolution into a coherent and fully operational legal regime governing the establishment, organization, and functioning of Vietnam’s IFC. Collectively, they demonstrate that Vietnam’s IFC framework is best understood not as a collection of isolated incentives, but as a deliberately designed and integrated regulatory system. The Legal Architecture of the IFC: Four Interlocking Pillars Read together, the decrees seem to be designed to address four core regulatory questions from the outset: (i) what the IFC is, from a legal and institutional perspective; (ii) who may participate in the IFC and what activities are permitted; (iii) how people, capital, and projects operate
December 30, 2025
On December 17, 2025, Laos’ Ministry of Industry and Commerce (MOIC) issued a notice introducing a new digital system that allows e-commerce businesses to obtain required certificates and licenses through an online, application-based platform. Notice No. 3988, which will take effect on February 1, 2026, introduces the E-Trust platform, a downloadable application that allows e-commerce businesses to remotely obtain acknowledgement certificates and business operating licenses. New Digital Registration Options Under the previous framework established by the Decree on E-commerce (2021), businesses were required to complete registration exclusively through paper-based submissions. The new system now offers businesses two registration options: Traditional paper-based process at the Division of E-commerce Management within the MOIC; or Electronic registration and renewal through the E-Trust platform. This change is expected to streamline procedures, reduce administrative burdens, and enhance accessibility for businesses operating outside Vientiane. The E-Trust platform facilitates compliance for both individuals and legal entities required to submit applications and renewals for required certificates and licenses. The development is particularly beneficial for businesses located in remote provinces, as it eliminates the need for physical travel and significantly accelerates processing times. Compliance Requirements and Penalties Businesses must obtain or renew the required certificates and licenses to avoid sanctions under the Decision on Fines and Other Measures for Violation of the Decree and Regulations on E-commerce (No. 2828/MOIC, dated November 11, 2025). Penalties for noncompliance may include monetary fines and other enforcement measures.