You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 29, 2017

Thailand’s Payment Systems Act 2017: Electronic Payments and Bankruptcy

Informed Counsel

In October 2017, the Thai government published the Payment Systems Act in the Government Gazette, setting out the framework for a new licensing and registration regime to regulate electronic payment business operators and putting in place several provisions for a stable and reliable e-payment ecosystem. The Act is expected to facilitate the offering of many new and innovative payment services in Thailand. Operation of the new regime will depend on forthcoming regulations, which are yet to be issued, and it is necessary to await those regulations before offering any actionable commentary on that aspect of the Act. However, some other aspects of the Act, which have drawn less attention, have a significant effect and are very worthy of attention.

Electronic payments have been governed under multiple laws and layers of regulations which, until now, have lacked statutory provisions for finality of payment. This raises a concern that if a payment system participant enters into receivership or reorganization, transactions involving that participant could be canceled or reversed, which can affect other participants in the payment system; for example, where a recorded transfer is not funded or settlement fails. If the payments are for a large amount of money, this problem could spread even more broadly to other payment systems and other participants in them. In extreme scenarios, cancellations or reversals of high-value payments could present serious risks to the entire financial system affecting both banks and non-banks.

Protecting “Important” Payment Systems

The Act sets out provisions for dealing with this issue, which are applicable to participants in “important” payment systems, the security or stability of which can have an impact on the financial institution system or the financial system of Thailand. To be regarded as an important payment system, a system must:

  1. be part of the main infrastructure of the country, trouble with or disruption of which would have a broad effect on the continuity of its participants’ business; and
  2. be a system that supports high-value transfers or that is used for clearing or settlement among its members.

Any payment systems established or operated by the Bank of Thailand (e.g., BAHTNET and the imaged check clearing system) are deemed to be important payment systems. Beyond those, the Minister of Finance has the authority, on the recommendation of the Bank of Thailand, to specify important payment systems in secondary legislation. Therefore, private-sector payment systems could also be designated as important, if specified in ministerial regulations, meaning that these provisions would also be applicable to their participants.

The Act provides that, where a court accepts a reorganization petition in respect of a participant in an important payment system, or orders the participant into receivership, any of the participant’s transfers, clearing, and settlement that were pending before the court order must continue until completion under the payment system rules, but not beyond the end of the date of the court order. The law makes it clear that such transactions cannot be reversed, modified, stopped, or suspended, and that statutory provisions for revocation of a fraudulent act or other act under the Civil and Commercial Code or the Bankruptcy Act cannot affect the validity of such a payment system’s operations. Further, any cash, securities, or instruments that such a participant maintains in the payment system, must be protected, and must not be distributed to the participant’s creditors without the Bank of Thailand’s approval. Each of these measures is important to ensure that instructed transfers are made, and that settlement successfully occurs, despite a participant’s bankruptcy. In that sense, it can help to contain what could otherwise be a contagion.

Protecting Customers of “Payment Service Providers”

For a similar purpose, the Act also sets out provisions for payment service providers that hold customer funds. “Payment service providers” under the Act will include providers of: (1) credit, debit, and ATM cards; (2) e-money; (3) electronic payment services to a seller, service provider, or creditor; (4) electronic money transfer services; and (5) other payment services that may affect the financial system or public interest, and others that may be specified by royal decree.

While current regulations already require certain categories of electronic payment business operators to establish separate bank accounts for holding customer funds, the Act  expands on them.

Specifically, the Act protects customer funds held by a payment service provider from disposal or transfer under a court order, in the following circumstances:

  1. where the service provider suspends its operations under the Payment Services Act or another law;
  2. if a petition for reorganization is filed in respect of the payment service provider;
  3. if a petition is filed in bankruptcy court in respect of the payment service provider; or
  4. if the court orders the payment service provider into receivership.

Further, if a payment service provider is a judgment debtor in a civil case or is ordered into receivership, any customer funds that it holds will not be subject to attachment or execution, and will not be distributed to the payment service provider’s creditors.

In the case of receivership, the Act provides that the Bank of Thailand will return customer funds to the customers, transfer the accounts to another payment service provider, and/or take other actions necessary to conclude business with the customer funds. Customers unrelated to the payment service provider will have priority over those that are related. Any remaining compensation due would be subject to regular bankruptcy proceedings.

The new Payment Services Act offers the possibility of many innovative services for customers in Thailand to enjoy. From a legal standpoint, however, perhaps the greatest achievement of the Act is the security and stability of payment finality and the protection of customer funds.

RELATED INSIGHTS​ 

April 3, 2026
On March 16, 2026, Vietnam’s Ministry of Public Security released a draft version of a new Decree on the Prevention and Combating of Cybercrime and High-Tech Crime to replace the currently effective Decree 25/2014/ND-CP. In the draft, the ministry has proposed a comprehensive regulatory framework aimed at addressing violations occurring within the cybersecurity domain, including measures related to intellectual property. Acts of Online IP Infringement Article 9 of the draft decree notably introduces specific provisions addressing online intellectual property infringement, with detailed lists of acts considered to constitute infringement in the online environment. Copyright and related rights infringement includes: Uploading or sharing works, performances, sound recordings, video recordings, broadcasts, computer programs, software, research, documents, theses, or other intellectual creations on digital platforms without the consent of the rights holder. Unauthorized livestreaming of copyrighted television programs, sporting events, or artistic performances. Uploading, sharing, storing, transmitting, or providing links to infringing works or digital content via websites, social networks, applications, or digital platforms. Providing or using software, tools, devices, or access codes to circumvent technological protection measures or evade lawful control mechanisms implemented by rights holders. Using artificial intelligence (AI) tools to replicate the ideas or structure of another person’s work without significant new creativity or without proper attribution, thereby causing damage to the original author. Industrial property infringement includes: Manufacturing, trading, advertising, or distributing counterfeit goods bearing counterfeit trademarks, geographical indications, or industrial designs, as well as goods infringing industrial property rights through online platforms. Unauthorized registration, appropriation, or use of domain names, account names, or digital identifiers that create confusion regarding the rights holder or the origin of goods or services. Producing, using, or offering for sale products containing all or part of a patented invention via online platforms. Advertising or introducing products with technical features or characteristics identical
April 3, 2026
Thailand’s Securities and Exchange Commission (SEC) has established a comprehensive governance framework for the use of artificial intelligence and machine learning (AI/ML) in the capital markets. The framework provides guidance to capital market business operators on understanding the risks associated with AI/ML implementation and adopting appropriate practices to build public confidence in Thailand’s capital markets. While the guidelines are principle-based rather than prescriptive, they reflect the SEC’s expectations for responsible AI/ML governance and are likely to inform supervisory activities and industry standards going forward. Scope The framework applies to capital market business operators supervised by the SEC. This includes, for example, securities and derivatives firms, asset management companies, mutual fund and private fund managers, investment advisors and investment consultants (including robo-advisory service providers), derivatives intermediaries, and other licensed intermediaries and market operators in the Thai capital markets that deploy AI/ML in their operations. Core Principles of the Guidelines The framework is presented as a best-practice manual rather than prescriptive regulation, providing guidance that regulated entities may apply to their AI/ML governance and risk management as appropriate. While currently nonbinding, the guidelines signal the SEC’s expectations for the sector, particularly in relation to other binding SEC regulations such as those covering IT risk management and market conduct. The guidelines name four core principles for AI/ML deployment: Fairness: Design and develop AI/ML with consideration for fairness, equality, and social diversity to prevent discrimination against individuals or groups. Legal and ethical compliance: Ensure AI/ML use aligns with applicable laws, ethical standards, and organizational values and policies. Accountability: Establish clear responsibility—both internally and externally—for AI/ML activities and outcomes. Transparency: Provide adequate disclosure to users about AI/ML use, including explainability of decisions and traceability of activities. AI/ML Best Practices The guidelines prescribe best practices across four stages of the AI/ML lifecycle, as described below.
April 2, 2026
Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance. What Has Changed: OIC and PDPC Alignment The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers. Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible. Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors. Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels. DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on
March 30, 2026
On March 24, 2026, the Trade Competition Commission of Thailand (TCCT) published its long-anticipated Guidelines on Multi-Sided Platforms and E-Commerce Businesses in the Government Gazette, following the conclusion of a public hearing conducted last year. The guidelines entered into force on March 25, 2026, and significantly expand the application of Thai competition law to digital platform ecosystems. These rules introduce targeted restrictions on platform conduct, such as price-ranking algorithms and tying and bunding, that leverages network effects, and will have far-reaching implications across Thailand’s digital economy—affecting not only platform operators but also platform participants, including sellers, logistics providers, advertisers, and payment service providers operating on or alongside such platforms. The guidelines clarify how existing prohibitions under the Trade Competition Act B.E. 2560 (2017) (TCA)—including abuse of market dominance, cartel conduct, and unfair trade practices—apply in the context of platform-based business models. While many provisions reflect earlier draft guidelines, the final version delivers more precise definitions and clearer enforcement parameters, increasing regulatory certainty while also raising compliance expectations. Applicability The guidelines introduce core definitions that determine their coverage: Multi-sided platform: A platform that acts as an intermediary connecting two or more groups of users, enabling them to have direct interaction in order to exchange or rely on services from one another. Examples include digital platforms for trading goods or services (e-commerce), as defined below. Digital platform for trading goods or services (e-commerce): A platform that acts as an intermediary connecting the distribution, purchase, sale, or exchange of goods or services. This includes operations carried out to facilitate transactions or interactions between business operators through an electronic transaction system, regardless of whether a service fee is charged. Operator of a digital platform business for trading goods or services: A provider of digital platform services for trading goods or services, as described