You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 29, 2024

Thailand Updates Requirements for Digital Asset Business Governance and Exchange Rules

Thailand’s Securities and Exchange Commission (SEC) has revised its regulations on digital asset operators and exchanges to impose stricter governance standards on digital asset business operators and to align digital asset exchange rules with international standards. The new regulations are laid out in SEC Notification No. GorThor. 23/2567 on the Criteria, Conditions, and Procedures for Operating a Digital Asset Business (No. 24) and SEC Notification No. GorLorThor. 24/2567 on Determination of Prohibited Qualifications for Directors and Executives of Digital Asset Business Operators (No. 5). These were published in the Government Gazette on August 16, 2024, with most of the provisions taking effect on the same date.

Governance for Digital Asset Businesses

The heightened standards for digital asset business operators aim to ensure efficient business supervision and appropriate response to operational risks. The new requirements mainly address:

  • Board of directors composition. Large-sized digital asset business operators (i.e., those with at least 10,000 customers and holding customer assets of at least THB 500 million) who do not provide digital asset custodian services must have at least five directors, at least two of whom must be independent directors. In addition, the business operators must establish an audit committee, with at least two members being independent directors, to create an appropriate “check and balance” mechanism within the organizational structure. Current digital asset business operators must comply with the requirements within 180 days of the notification’s effective date.
  • Qualifications of authorized directors and managers. Authorized directors and managers are now required to (1) either have at least one year of working experience in the digital asset field or have participated in a digital asset course from an SEC-approved list, and (2) participate in a good corporate governance course recognized by the SEC. Current authorized directors and managers who have not previously completed a good corporate governance training course must complete such a course within one year of the notification’s effective date.
  • Management and operational structures. Check-and-balance mechanisms are required for every major operational system. Business operators must establish a customer asset management policy, and all customer assets in the business operator’s custody must be managed according to the security risk and by separate personnel from other operational personnel that may have a conflict of interest. Business operators must also provide a customer service system that is suitable to the risk and complexity levels of the relevant types of digital assets.

Exchange Rules

The SEC has also introduced new minimum requirements for digital asset exchange rules, which must be approved by the SEC. The key updates include:

  • Listing and delisting rules. As indicated by a new utility token supervisory scheme that was issued days earlier, group 1 utility tokens are not allowed to be listed on the exchange. (Group 1 utility tokens are those issued for consumption purposes or as a digital representation of a certificate, such as loyalty points, concert tickets, NFTs, and carbon credits.) In addition, listing rules now require adoption of the “silent period” concept, whereby tokens offered for sale below the market price cannot be listed in the six months after the offering. In terms of issuer disclosure, digital asset exchanges must now require digital token issuers to disclose information as stipulated by the SEC.
  • Trading, clearing, and settlement rules. Digital asset exchanges are now required to have a real-time trade monitoring system to detect abnormal trades, and daily monitoring reports must be submitted to the SEC. If the digital asset exchange finds suspicious action, it must promptly report this to the SEC. The digital asset exchange must also have signposting to inform investors about potential risks from investing in certain tokens.
  • Market makers. Digital asset exchanges with market makers must have rules on qualifications, scope of work, ongoing performance supervision, and noncompliance measures relating to market makers.

For more information on these new notifications, or on any aspect of digital assets and cryptocurrency in Thailand, please contact Kobkit Thienpreecha at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

March 27, 2024
The Bank of Thailand (BOT) has opened a public comment period on their consultation paper titled “Criteria for Supervising Virtual Banks” from March 19, 2024, to April 17, 2024. The consultation paper reveals that the BOT intends to apply traditional commercial bank supervisory standards to virtual banks. However, the BOT also explains that the wholly digital nature of the services offered by virtual banks necessitates additional regulatory supervision. Additional Supervisory Criteria for Virtual Banks Financial business group: If a virtual bank is within the same financial business group as other financial institutions, its parent company must structure the virtual bank to be under its own sole consolidated financial business group. After the virtual bank has undergone the “restricted phase” in its initial years of operation (see below), other financial institutions within the group are prohibited from extending credit to or engaging in transactions similar to lending activities with the virtual bank. Shareholding structure: If the increase in the financial institution system capital is higher than the actual capital injection resulting from the bank’s shareholding structure, the BOT aims to issue an additional regulation to supervise the capital of the virtual bank and financial institution system to prevent double counting. Operational risk: Virtual banks must not use a trademark or logo that bears resemblance to or implies association with other financial institutions or financial institution groups. Governance: Virtual banks must have at least one director and chief technology officer (CTO) with at least three years of experience in IT or digital service. Additionally, the CTO must work full-time for the virtual bank and may not be an employee of another legal entity. Restriction on related lending and related-party transactions: Virtual banks must obtain prior unanimous approval from their boards of directors before engaging in transactions with major shareholders or businesses
March 27, 2024
Last year, the government of Vietnam issued the Personal Data Protection Decree (PDPD), which took effect on July 1, 2023. The Department of Cybersecurity and High-Tech Crime Prevention and Control (referred to as “A05”) under the Ministry of Public Security (MPS) is tasked with implementing and enforcing the requirements under the PDPD. While a decree on sanctioning provisions for noncompliance with the PDPD is still pending issuance, further movements from the MPS/A05 indicate that it aims to start conducting its first inspections into PDPD compliance. This is the first time that companies and government agencies have been officially questioned by the MPS about their compliance with the PDPD. The purposes of this inspection program are (1) to evaluate the compliance status of a group of selected companies and government agencies and to understand challenges in complying with the PDPD requirements; (2) to propose sanctions for noncompliance; and (3) to collect information and comments for the development of the upcoming Personal Data Protection Law—not to spot noncompliance with the PDPD specifically. This round of inspection includes a number of companies in 14 sectors (including e-commerce, aviation, telecom, banking and finance, intermediary payment, insurance, gaming, education, healthcare, real estate, data processing services, ride hailing, etc.). The companies targeted by this inspection program must: (1) submit a report on compliance to the MPS/A05 by May 30, 2024 (this report is different from the data protection impact assessment (DPIA)/transfer impact assessment (TIA) submission requirements); and (2) coordinate with the MPS/A05 on any further investigation actions from June to August 2024. The inspection results will be available by September 2024. Key information to be reported includes, among others: (1) a description of the activities and measures carried out to implement the PDPD (such as protecting data subjects’ rights, performing administrative procedures, preventing violations, etc.)
March 18, 2024
Vietnam’s new Telecom Law 2023 was promulgated on November 24, 2023, and will take effect on July 1, 2024, for most telecom services. For three newly introduced telecom services—OTT telecom services, internet data center services, and cloud computing services—implementation and compliance will be delayed until January 1, 2025. These new services will be explored briefly below. The Ministry of Information Communication (MIC) is currently in the process of developing a number of decrees and circulars that will detail the implementation of the Telecom Law 2023, including one main decree that guides the new law in general. This decree is scheduled for prompt promulgation to coincide with the law’s effective date of July 1, 2024. The draft version of this decree, dated February 22, 2024 (“Draft Decree”), was shared for consultation with international organizations, associations, and enterprises by the Vietnam Telecom Agency (VNTA) in early March 2024 to gather feedback. The Draft Decree is expected to undergo further revisions before being sent to relevant state agencies for input and submission to the Ministry of Justice for assessment by the end of March 2024. The MIC anticipates submitting the subsequent version to the government by April 15, 2024.   New Telecom Services: OTT Telecom Services, IDC Services, and Cloud Computing Services In comparison to the Telecom Law 2009, the Telecom Law 2023 has three new telecom services: Basic telecommunications services on the internet (OTT telecom services) are defined as services whose primary functions including the sending, transmission, and receipt of information between two persons or a group of people using telecommunications services on the internet (Article 3.8 of the Telecom Law 2023). By incorporating the term “primary functions” into the definition, the Telecom Law 2023 aims to exclude services such as ride-hailing platforms where the primary function is transportation, not telecom
March 15, 2024
Vietnam’s fintech industry is booming, and the rapid emergence of tech startups and non-bank institutions offering innovative financial services has been outpacing existing regulations. This regulatory gap not only creates uncertainty for both innovators and consumers, but also poses a number of imminent risks in areas such as consumer protection, data privacy, cybersecurity, and anti-money laundering, among others. The State Bank of Vietnam (SBV) is stepping up to tackle these challenges by accelerating the promulgation of a long-awaited Fintech Sandbox Decree with the issuance of an updated draft (“Draft Fintech Sandbox Decree”) on March 4, 2024. The Draft Fintech Sandbox Decree establishes a controlled environment where fintech companies and financial institutions can test solutions that do not fall squarely within the parameters of existing regulations. The pilot activities will be limited in scope, scale, and duration, with a number of precautionary measures in place. The SBV will supervise this “sandbox” closely, effectively mitigating risks and gathering valuable data to inform future regulations. Who Can Participate in the Sandbox? Traditional financial institutions (credit institutions): Banks and other institutions licensed to provide financial services can participate in the sandbox to test new offerings or refine existing ones. Independent fintech companies: Startups and established companies specializing in fintech solutions can leverage the sandbox to pilot innovative ideas before seeking wider market adoption. Other relevant organizations involved in the pilot: Depending on the specific solution being tested, other entities may also be involved in the sandbox. Geographical scope: Limited to Vietnamese territory; cross-border testing is not allowed. Focusing on Three Solution Categories Earlier versions of the Draft Fintech Sandbox Decree included categories like blockchain technology and other innovative business models, but these were removed in the latest version. To allow the SBV to assess the associated risks and work on the solutions more