You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 3, 2025

Thailand’s Beauty Industry Gets a Makeover with New Contract Standards

On September 26, 2025, the Contract Committee under Thailand’s Consumer Protection Board issued a regulation that aims to standardize contracts and enhance consumer protection within the beauty and wellness industry. The Notification on Prescribing the Beauty Service Business as a Contract-Controlled Business B.E. 2568 (2025), which takes effect on January 24, 2026, requires business operators to use a prescribed standard contract in Thai and adhere to strict mandatory provisions and prohibitions.

These regulations apply to operators across all in-person and online service channels, including via digital platforms. “Beauty services business” is defined as the provision of services under an agreement allowing consumers to receive a series of treatments, either over a set number of sessions or within a set period. This includes massage, spa, other methods for cleanliness, beauty, or care of facial or body skin, and weight control and body shaping—including services offered electronically. The law excludes surgery, liposuction, and medical treatments performed by licensed practitioners.

The notification establishes the following key requirements:

  • Mandatory contract and formatting. All contracts with consumers must use the standard contract form, in Thai, with clear, readable text (minimum font size of 2 millimeters, no more than 11 characters per inch), and include all essential terms from the annexed form.
  • Contract execution. Contracts must be made in duplicate, with one copy given to the consumer at signing. For agreements concluded through electronic channels, the process must comply with the Electronic Transactions Act and use the same required terms.
  • Digital platforms. Business operators who provide services facilitated through a digital platform as an intermediary are ultimately responsible for ensuring the consumer receives a compliant contract.
  • Prohibited clauses. The law prohibits clauses that limit or exclude liability for damages to life, body, health, mind, or property resulting from breach of contract or a wrongful act; bind consumers to business operators’ rules without consent; allow unilateral changes to services or fees; permit termination without notice or cause; forfeit prepayments; prohibit termination or refunds; impose no-refund; policies; automatically renew contracts; or misuse personal data in violation of the Personal Data Protection Act.
  • Key required contractual terms. The standardized contract template imposes a mandatory structure requiring the inclusion of clear and specific terms designed to safeguard consumer rights. Business operators are obliged to adopt and implement the required information in their service agreements. The Contract Committee’s recent notification contains an extensive list of terms and details that must be included in contracts.

To stay compliant and protect consumer trust, business operators must update their contracts to the new standardized form, eliminate any prohibited clauses, and ensure that electronic and platform-based agreements fully adhere to the new regulations. Embracing these changes is essential for maintaining credibility and thriving in Thailand’s evolving beauty and wellness industry.

RELATED INSIGHTS​ 

October 7, 2022
Thailand’s Office of the Personal Data Protection Committee (PDPC) has opened a public hearing period on its draft notification regarding cross-border transfer of personal data. The public hearing is open through October 24. The notification, once issued, will supplement the principle of cross-border transfer of personal data outside of Thailand set out in the Personal Data Protection Act (PDPA). The notification sets out the following key matters: Definitions “Transfer of personal data” means any sending or transferring of personal data by a transferor of personal data, either by way of a physical transfer or a remote transfer through a computer system or an internet network to the recipient of the personal data. It does not include sending personal data through an intermediary by transiting between computer systems or internet networks, or any storing or retaining of personal data, either permanently or temporarily, by a cloud computing service provider, whereby the personal data transferor and the personal data recipient (1) are not making the order, (2) are not involved with any data selection or the content of the personal data sent and received through the computer systems or internet networks, or (3) have the purpose of entering into an agreement or any juristic act. “Binding corporate rules” means the agreed terms or policy on personal data protection made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data within a group of corporations or companies. “Standard contractual clauses” means the contractual terms made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data. “Code of conduct” means a code that sets out the obligations of a personal data transferor and a personal data recipient outside of Thailand. “Certification” means an undertaking in relation to
October 3, 2022
Impacts from the COVID-19 pandemic have led some manufacturers to reduce costs by changing production methods, designs, or machinery, or reducing the number of employees on payroll. While these strategies may reduce costs and help their business survive, they may also result to lower quality goods. In the worst case, however, these poor quality goods may cancel out or even outweigh a manufacturer’s cost savings if the products are deemed to be unsafe for consumers under Thailand’s Product Liability Act (officially the Liability for Damages Arising from Unsafe Products Act). The Product Liability Act has been in force for 14 years. However, there have been few landmark Supreme Court decisions related to it as most cases are settled before the final judgment. Consequently, most business owners have limited knowledge of the precedent cases and are unsure about what actions they can take to manage and mitigate the risk of being found liable for claims of damages due to an unsafe product. The Product Liability Act identifies several types of entrepreneurs and business operators (individuals and entities) as “potentially liable parties” (PLPs) who may be penalized under the law: Manufacturers or hirers Importers Sellers of goods for which the manufacturer, hirer, or importer cannot be identified; Any other party who uses the name, trade name, trademark, or statements of the alleged unsafe products, or acts in a manner that causes them to be seen as a manufacturer, hirer, or importer The Product Liability Act defines a “product” as any kind of movable property that has been manufactured or imported for sale—including agricultural products and electricity, but excluding those ruled out by ministerial regulations. Therefore, real estate and services are excluded from the Product Liability Act. However, real estate buyers are protected by the Civil and Commercial Code, and by the
September 30, 2022
In keeping with the government’s strong focus on consumer protection in recent years, Cambodia’s consumer protection authority issued a notice on consumer product labeling on September 23, 2022. The notice from the General Department of Consumer Protection, Competition, and Fraud Repression (CCF) provides clarifications on labeling rules for general consumer products, goods, and services. The most significant clarification is that both locally produced and imported products, goods, and services must have a Khmer-language label or attach a product description in Khmer language. Imports may use a sticker with Khmer language as long as the minimum labeling requirements are met. The notice announces a transition period for companies to amend their labeling, allowing them to make changes to the labeling until December 31, 2022. According to the notice, the CCF will investigate and take enforcement measures starting January 1, 2023. This likely signals a major increase in enforcement efforts throughout 2023. Labeling Rules The CCF notice gives instructions on product labeling rules. In Cambodia, “product” refers to general products, goods, and services on the Cambodian market. Product-specific labeling regulations (e.g., for food products) overrule the requirements for these general products. The CCF notice provides the following instructions: All products on the market must have a label, or attach a product description, using Khmer language. Imported products that do not have a Khmer-language label printed on the packaging should provide a product description in Khmer. Companies can attach the necessary information or apply a sticker to the product. Trademarks on the products may use a foreign language but must be in line with the relevant local trademark registration. Foreign-language or different labeling is only permitted if authorized by the regulator, or by regulations that apply to a specific type of product. The label or product description must use an appropriate font
September 21, 2022
Thailand’s Personal Data Protection Committee (PDPC) has released separate guidelines for data controllers to follow in obtaining data subjects’ consent and notifying data subjects of required information (i.e., regarding collection, use, or disclosure of their personal data). By following the guidelines, data controllers can mitigate the risk of violating the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The Guidelines on Obtaining Consent from the Data Subject according to the PDPA and the Guidelines on Notification of Purposes and Details upon the Collection of Personal Data from the Data Subject according to the PDPA were issued on September 7, 2022. Consent Guidelines The PDPC’s guidelines on obtaining consent list the requirements for consent to be considered valid. These requirements include stipulations on timing of requests, elements that need to be included in requests, and the nature of requests. For instance, consent must be obtained before or at the time of obtaining personal data, and data subjects must be informed of both the purposes and details of the personal data handling, among other specific requirements. In turn, there must be a clear affirmative act of the data subject in giving consent. Obtaining consent from minors is subject to more stringent requirements, and data controllers should implement appropriate identification and age-verification measures when collecting personal data about minors. The guidelines give two sets of requirements, depending on the age of the minor—between 10 and 20, and under 10. In general, with the older age group, parental consent is not required in all circumstances, while for the younger age group, parental consent is compulsory for giving consent on behalf of the minor. For a person deemed to be “incompetent” or “quasi-incompetent,” consent must always be given by the legal guardian. Notification Guidelines The guidelines on notifying data subjects when collecting personal data