You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 30, 2021

Thailand’s BOI Revamps Promoted Digital Activities

On September 16, 2021, Thailand’s Board of Investment (BOI) announced the consolidation of its list of promoted digital activities into a single new category for development of software, platforms for digital services, or digital content (5.10). When Announcement No. Sor. 4/2564 came into effect the following day, the new category subsumed and replaced the previous categories of “software” (5.7), “e-commerce” (5.8), and “digital services” (5.9).

The new category is entitled to A2-level incentives, which include a capped eight-year corporate income tax (CIT) exemption along with other tax and non-tax incentives. For this category, the BOI has specified two extraordinary allowances rarely seen in other promotional categories. The first is that the cap calculation for the annual CIT exemption is based on the actual amount of prescribed expenses (e.g., 100% of remuneration to Thai IT personnel and 200% of their training costs). The second is that the BOI will allow investment projects under this category to include used machinery.

To be eligible for BOI promotion under the new digital activity category, projects must:

  • hire new Thai IT personnel whose annual salary expenses combined equal at least THB 1.5 million (approximately USD 44,275); and
  • have a development process for the software, platform for digital services, or content to be carried out in Thailand under BOI approval.

Investment projects under this new category are not eligible for additional merit-based incentives or for investment promotion measures for small and medium enterprises (SMEs).

Projects that qualify for CIT exemption must derive their revenue from sales or services directly related to the software, platforms for digital services, or digital content developed under BOI promotion. In addition, the BOI specifies that retail or wholesale business (e.g., the sale of goods through the platform) is not covered by the new category and therefore is not considered a BOI-promoted activity.

Companies seeking BOI promotion that also wish to apply for the Eastern Economic Corridor (EEC) scheme for human resources development must notify the BOI when submitting the promotion application. Once a promoted project has been approved, that request cannot be amended.

RELATED INSIGHTS​ 

August 26, 2024
On August 13, 2024, Thailand’s Personal Data Protection Committee (PDPC) published a notification on the Criteria for Personal Data Deletion, Destruction, and De-identification in the Government Gazette, taking effect on November 11, 2024. Most of the content remains unchanged from the June 2024 draft of the legislation that was released for public comment. Only minor amendments have been made, as outlined below: Data controllers must respond to data subjects’ requests to delete, destroy, or de-identify personal data, including any copies or backups, without delay and within 90 days of receiving the request. This timeframe has been extended from the previous draft, which allowed only 60 days. In deleting, destroying, or de-identifying personal data, the data controller must ensure that no one is able to recover or reverse personal data to enable the direct or indirect identification of the data subject by any means that could reasonably be expected. If the data controller cannot fulfill the request within the 90-day period, it must take measures to ensure that the personal data is made difficult to collect, use, or disclose until the personal data can be deleted, destroyed, or de-identified according to the notification. In such cases, appropriate organizational, technical, and physical measures must be implemented to protect the data, meeting the criteria set forth by the notification. One newly added provision allows data controllers to delete, destroy, or de-identify a data subject’s personal data using a different method than the one requested by the data subject, provided they inform the data subject of the alternative method. However, this is not allowed when the data subject exercises this right on the grounds that the personal data has been unlawfully collected, used or processed, and there are no grounds to reject the request. In relation to the de-identification or anonymization of personal
August 23, 2024
Thailand’s Securities and Exchange Commission (SEC) amended its utility token supervisory framework by issuing seven notifications that came into effect on August 13, 2024. Ready-to-use utility tokens (tokens that can be used immediately to acquire specific goods or services), which were previously unregulated, are now subject to the supervisory scheme set forth by the seven new notifications in both primary and secondary markets. This is intended to provide an investor protection mechanism that responds to the characteristics, risks, and usage of the different types of ready-to-use utility tokens. Under the new notifications, ready-to-use utility tokens are categorized into two groups. These are detailed below. Group 1 Utility Tokens Group 1 utility tokens include ready-to-use utility tokens issued for consumption purposes or as a digital representation of a certificate. Examples include loyalty points, digital movie or concert tickets, NFTs, and carbon credits, among others. Principally, there is no change in the regulation of group 1 utility tokens under the new notifications. In the primary market, issuance of this type of token is not subject to the initial coin offering (ICO) requirements. In the secondary market, providing services related to group 1 utility tokens is not considered to be the same as operating a digital asset business with licensing requirements under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). Licensed digital asset operators (including exchanges, brokers, and dealers) are not permitted to list or trade group 1 utility tokens. To provide services in relation to group 1 utility tokens, these licensed digital asset operators must establish a separate entity to provide those services and must not use names or messages that could cause the public to misunderstand that the separate entity is engaged in a digital asset business under SEC supervision. Group 2 Utility Tokens Group 2 utility tokens
August 22, 2024
The Personal Data Protection Committee (PDPC) of Thailand’s Ministry of Digital Economy and Society (MDES) has announced the first administrative fine under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). A major private company was fined THB 7 million for noncompliance with specific PDPA requirements, resulting in the unauthorized disclosure of personal data to a call center gang (phone scam fraudsters). Key Findings of Noncompliance The PDPC determined that there were three key violations of specific requirements of the PDPA: Failure to appoint a data protection officer (DPO): Despite processing personal data for over 100,000 individuals as part of its core operations, the company did not appoint a DPO. Inadequate security measures: The company lacked the required security measures, leading to a data breach involving a call center gang, causing widespread damage. Delayed data breach notification: The company did not notify authorities of the data breach within the required timeframe and failed to address the breach promptly, making it impossible to remedy the situation. In addition to the monetary fine, the PDPC, along with the PDPA’s Expert Committee, issued a corrective order requiring the company to undertake the following actions and notify the Office of the PDPC of the relevant correction measures within seven days of receiving the order: Implement up-to-date security measures: The company must improve its current security measures to prevent future breaches and ensure that the security measures are up-to-date with changing technologies. Raise awareness of personnel: The company must provide training to relevant personnel to ensure awareness of data compliance and protection practices. This significant administrative action establishes a precedent for addressing data breaches in both governmental and commercial sectors in Thailand. It also confirms the importance of PDPA compliance, particularly the need for robust security measures, timely breach notifications, and the appointment of
August 15, 2024
On August 9, 2024, Thailand’s Electronic Transactions Development Agency (ETDA) opened a period for public feedback regarding the 2022 Royal Decree on Digital Platforms and its subregulations. To collect this feedback, the ETDA has prepared a 44-question survey on specific attributes of the royal decree and its requirements, covering issues such as the definition of digital platform services (DPSs), types of services that are subject to notification requirements, information that must be submitted annually, and the royal decree’s extraterritorial scope. Business operators that fall within the scope of the royal decree and wish to provide feedback on its effectiveness should prepare and submit the survey online to the ETDA by the end of August 2024. Royal Decree on Digital Platforms Thailand’s Royal Decree on Digital Platforms was published in the Government Gazette on December 22, 2022. It defines a DPS as any service that facilitates or mediates transactions between users through a digital platform, such as e-commerce, food delivery, ride-hailing, online travel agency, online payment provider, or social media platform. The decree requires DPS operators to notify the ETDA before commencing operations, with some limited exemptions. The decree also empowers the ETDA to issue notifications (i.e., subregulations) and guidelines for implementing the decree and to monitor and enforce compliance by DPS operators. The ETDA may impose administrative sanctions, such as warnings, fines, service suspension, or revocation of notification, for any violation of the royal decree or the ETDA’s subregulations. In-scope DPS operators should take this opportunity to provide comments to the ETDA in order to voice their opinions on the practicality of the requirements and support the regulator in shaping the requirements of the royal decree and its subregulations. For more information on this initiative from the ETDA, or on any aspect related to the Royal Decree on Digital