You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 16, 2025

Thailand’s Cabinet Approves Principles of the Draft Entertainment Complex Act

On January 13, 2025, Thailand’s cabinet approved in principle the draft Entertainment Complex Act, as proposed by the Ministry of Finance. This landmark legislative proposal, which would allow casinos as part of larger “entertainment complexes,” will now proceed through further parliamentary review and approval.

Key provisions of the draft act are described below.

  • Corporate structure: Entertainment complexes must be operated by Thai-registered limited companies or public limited companies with a minimum paid-up capital of THB 10 billion. Directors of the licensed entity must be individuals and have the qualifications and none of the prohibited characteristics specified in the draft act. The draft act does not impose restrictions on foreign-majority ownership structures; however, it is worth monitoring whether any amendments addressing this matter are introduced during the legislative process.
  • Operating conditions: Each entertainment complex must be located in an area designated under a royal decree. It must also include at least four types of entertainment businesses listed in the annex to the draft act (e.g., shopping mall, hotel, sports stadium, amusement park), along with a casino. The allocation of casino space must comply with regulations to be specified at a later date.
  • Licensing conditions: Licenses will be valid for 30 years, renewable in increments of up to 10 years. The license issuance fee is THB 5 billion, the annual fee is THB 1 billion, and the renewal fee is THB 5 billion. The Entertainment Complex Policy Committee, chaired by the prime minister, will review and approve applications.
  • Online gambling restrictions: Licensees are prohibited from offering gambling through internet-connected systems or electronic devices that allow access from outside the casino premises.
  • Labor requirements: Thai and foreign employee ratios must adhere to prescribed regulations.
  • Land privileges: Lease agreements for land use are limited to 50 years. Renewal is permitted for up to 49 additional years, starting from the end of the initial term.
  • Entry fee for Thai nationals: Thai nationals must register and pay a fee of THB 5,000 per visit to access casino facilities.

Legislative Process and Timeline

As this matter continues to be widely reported on in the press, it is worth keeping in mind the stages that the draft Entertainment Complex Act has left to go through:

  • Council of State review: The cabinet will submit the amended draft to the Council of State within the next few weeks.
  • Second cabinet review and approval: After review by the Council of State, if no further comments are made, the bill will be resubmitted to the cabinet for final approval—expected to occur possibly around late February or early March 2025.
  • House of Representatives deliberation: Once approved, the bill will proceed to the House of Representatives for a deliberation period that may last for up to 180 days. The deliberation period comprises three readings.
  • Senate review: After passage by the House of Representatives, the bill will be submitted to the Senate for three additional readings, which may take up to 60 days.
  • Royal assent: Upon Senate approval, the bill will be forwarded to the king for royal assent and published in the Government Gazette.

The exact timing of these stages may vary widely, but passage of the draft act likely will not be possible until at least the second half of 2025.

For more details on the draft Entertainment Complex Act, or on any aspect of gaming regulations in Thailand, please contact Tilleke & Gibbins at [email protected].

RELATED INSIGHTS​ 

May 15, 2024
On May 1, 2024, Thailand’s National Cyber Security Committee (NCSC) published the draft NCSC Notification Re: Cloud Cybersecurity Standards for a public hearing period, which was open until May 14, 2024. These standards have been drafted to drive the country’s cloud-first policy with the aim of minimizing risks from cyber threats to cloud services utilized by government agencies, supervising or regulating organizations, and critical information infrastructure (CII) organizations. The key points of the draft Cloud Cybersecurity Standards are below. Scope The standards apply to government agencies, supervising or regulating organizations, and CII organizations under the Cybersecurity Act B.E. 2562 (2019), as well as cloud service providers (defined below). The standards prescribe cloud system cybersecurity measures for cloud service customers (defined below) and providers only to the extent that the service is provided to the in-scope organizations outlined above. Definitions Cloud service customers (CSCs): In-scope organizations that have a formal contractual agreement to use cloud services provided by a cloud service provider. Cloud service providers (CSPs): Persons who enable cloud services to be used by a cloud service customer, responsible for maintaining infrastructure, platforms, and software that enable provision of the cloud services and for managing these resources to ensure their accessibility, security, and scalability for their cloud service customers. Application In-scope organizations that will use or have been using cloud services must comply with the Cloud Cybersecurity Standards by taking into account their data or technology information systems’ level of impact, as specified in the previously issued Notification of the NCSC Re: Standards for Defining the Security Category for Data and Information Systems B.E. 2566 (2023). The impact level related to personal data is to be rated as being at least at the medium level, and the minimum standards for that level specified in the draft Cloud Cybersecurity Standards
May 13, 2024
On May 2, 2024, Vietnam’s Ministry of Justice published on its online platform the most recent version of the draft decree on administrative sanctions for violations in the field of cybersecurity (“Draft Sanction Decree”) to gather feedback and contributions from the community and stakeholders. After receiving the Ministry of Justice’s assessment, the Ministry of Public Security (“MPS”), in charge of drafting the Draft Sanction Decree, may make further revisions before submitting it to the government for review and final decision on enactment. The decree is expected to have an effective date of June 1, 2024. The stringent penalties for infringements involving personal data of the previous draft version remain in this Draft Sanction Decree—a sign of the proactive stance of the MPS in enforcing the Personal Data Protection Decree (“PDPD”). Effective Date and Transitional Provisions It is important to note that the Draft Sanction Decree does not impose any new obligations on organizations or individuals, and only sets out the administrative sanctions that could be imposed on violators as soon as June 1, 2024, which is indicated as the effective date in Article 49. This signals the MPS’s eagerness to begin taking enforcement actions against recalcitrant organizations and individuals that have not complied with the various obligations imposed on them under the Law on Network Information Security (enacted in 2015), the Law on Cybersecurity (enacted in 2018) and its guiding decree (Decree 53 – enacted in 2022), and the most recent PDPD (enacted in 2023). Article 50.1 of the Draft Sanction Decree outlines the transitional provisions regarding administrative violations in the cybersecurity field. It clarifies that the decree does not have retroactive effect, by stating that violations occurring before its effective date, but discovered or under review after such effective date will be subject to the regulations on administrative
May 9, 2024
As non-cash payments continue to surge in Vietnam, the requirement for strong security standards and a clear legislative framework for intermediary payment services (“IPS”) is becoming more and more critical. Recognizing this, the State Bank of Vietnam (“SBV”) has been working on a draft decree to supersede the outdated Decree No. 101/2012/ND-CP dated November 22, 2012, on non-cash payments (“Draft Non-Cash Payment Decree”), which will lay the groundwork for non-cash payments in general and the provision of IPS in particular. Building upon this, the SBV recently issued a draft circular to replace Circular No. 39/2014/TT-NHNN dated December 11, 2014, on IPS (“Circular 39”) (“Draft IPS Circular”), which will offer more detailed guidance on the provision of IPS in Vietnam on top of the Draft Non-Cash Payment Decree. The Draft IPS Circular will be applicable to (i) IPS providers; (ii) foreign organizations providing IPS in Vietnam; and (iii) organizations and individuals involved in the provision of IPS. Some key updates regarding the Draft IPS Circular are as follows: Scope of Application The Draft IPS Circular sets out further guidance for the provision of IPS as listed under the Draft Non-Cash Payment Decree, including: (i) electronic clearing services; (ii) electronic wallet (“e-wallet”) services; (iii) collection and payment support services; (iv) financial switching services; (v) international financial switching services; and (vi) electronic payment gateway services. Notably, the Draft IPS Circular has explicitly excluded from its scope of application the provision of accounts by goods/service providers to their customers solely for the purpose of payment within the systems of such providers (e.g., cards/coupons or service/transaction accounts of online game service providers, transportation service providers, or securities companies, etc.). Requirements on the Provision of IPS Electronic Clearing Services: The Draft IPS Circular introduces regulations to cover certain elements of electronic clearing services that have
May 9, 2024
On April 29, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) issued the master plan for personal data protection, which outlines the PDPC’s strategies for developing and enhancing the data protection framework in Thailand from 2024 to 2027. A draft of this four-year plan had previously been released for a public hearing on November 27, 2023. Overview The master plan sets out the long-term direction for the protection of personal data in Thailand, analyzing the current landscape, challenges, and obstacles encountered since the full enactment of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). It aims to align with Thailand’s National Security Policy and Plan for 2024–2027 and focuses on key sectors in its initial two years. These sectors are: Public security and key government services; Retail and e-commerce; Information and communication technology and telecommunications; Finance, investment, and insurance; Public health; Tourism; and Education. Objectives The master plan’s goals include increasing organizational compliance with the PDPA, reducing data breaches, updating the PDPA to reflect current circumstances, introducing various PDPC e-services, and enhancing Thailand’s global competitiveness in data privacy and personal data protection. It sets targets and indicators of the plan’s success, such as achieving a 100% PDPA compliance rate across all sectors in Thailand and raising Thailand’s digital competitiveness to at least 30th in the World Digital Competitiveness Rankings from the IMD World Competitiveness Center. Strategic Initiatives To achieve these objectives, the master plan introduces four strategic initiatives: Effective and balanced PDPA enforcement: Develop standards, principles, criteria, tools, indicators, and data privacy governance, including law enhancements. A recent example of this is the PDPC’s launch of the Personal Data Protection Surveillance Centre (PDPC Eagle Eye) to monitor data breaches. Knowledge and trust enhancement: Build human capacity and trust by enhancing knowledge through initiatives like the forthcoming