You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 29, 2017

Thailand’s Payment Systems Act 2017: Electronic Payments and Bankruptcy

Informed Counsel

In October 2017, the Thai government published the Payment Systems Act in the Government Gazette, setting out the framework for a new licensing and registration regime to regulate electronic payment business operators and putting in place several provisions for a stable and reliable e-payment ecosystem. The Act is expected to facilitate the offering of many new and innovative payment services in Thailand. Operation of the new regime will depend on forthcoming regulations, which are yet to be issued, and it is necessary to await those regulations before offering any actionable commentary on that aspect of the Act. However, some other aspects of the Act, which have drawn less attention, have a significant effect and are very worthy of attention.

Electronic payments have been governed under multiple laws and layers of regulations which, until now, have lacked statutory provisions for finality of payment. This raises a concern that if a payment system participant enters into receivership or reorganization, transactions involving that participant could be canceled or reversed, which can affect other participants in the payment system; for example, where a recorded transfer is not funded or settlement fails. If the payments are for a large amount of money, this problem could spread even more broadly to other payment systems and other participants in them. In extreme scenarios, cancellations or reversals of high-value payments could present serious risks to the entire financial system affecting both banks and non-banks.

Protecting “Important” Payment Systems

The Act sets out provisions for dealing with this issue, which are applicable to participants in “important” payment systems, the security or stability of which can have an impact on the financial institution system or the financial system of Thailand. To be regarded as an important payment system, a system must:

  1. be part of the main infrastructure of the country, trouble with or disruption of which would have a broad effect on the continuity of its participants’ business; and
  2. be a system that supports high-value transfers or that is used for clearing or settlement among its members.

Any payment systems established or operated by the Bank of Thailand (e.g., BAHTNET and the imaged check clearing system) are deemed to be important payment systems. Beyond those, the Minister of Finance has the authority, on the recommendation of the Bank of Thailand, to specify important payment systems in secondary legislation. Therefore, private-sector payment systems could also be designated as important, if specified in ministerial regulations, meaning that these provisions would also be applicable to their participants.

The Act provides that, where a court accepts a reorganization petition in respect of a participant in an important payment system, or orders the participant into receivership, any of the participant’s transfers, clearing, and settlement that were pending before the court order must continue until completion under the payment system rules, but not beyond the end of the date of the court order. The law makes it clear that such transactions cannot be reversed, modified, stopped, or suspended, and that statutory provisions for revocation of a fraudulent act or other act under the Civil and Commercial Code or the Bankruptcy Act cannot affect the validity of such a payment system’s operations. Further, any cash, securities, or instruments that such a participant maintains in the payment system, must be protected, and must not be distributed to the participant’s creditors without the Bank of Thailand’s approval. Each of these measures is important to ensure that instructed transfers are made, and that settlement successfully occurs, despite a participant’s bankruptcy. In that sense, it can help to contain what could otherwise be a contagion.

Protecting Customers of “Payment Service Providers”

For a similar purpose, the Act also sets out provisions for payment service providers that hold customer funds. “Payment service providers” under the Act will include providers of: (1) credit, debit, and ATM cards; (2) e-money; (3) electronic payment services to a seller, service provider, or creditor; (4) electronic money transfer services; and (5) other payment services that may affect the financial system or public interest, and others that may be specified by royal decree.

While current regulations already require certain categories of electronic payment business operators to establish separate bank accounts for holding customer funds, the Act  expands on them.

Specifically, the Act protects customer funds held by a payment service provider from disposal or transfer under a court order, in the following circumstances:

  1. where the service provider suspends its operations under the Payment Services Act or another law;
  2. if a petition for reorganization is filed in respect of the payment service provider;
  3. if a petition is filed in bankruptcy court in respect of the payment service provider; or
  4. if the court orders the payment service provider into receivership.

Further, if a payment service provider is a judgment debtor in a civil case or is ordered into receivership, any customer funds that it holds will not be subject to attachment or execution, and will not be distributed to the payment service provider’s creditors.

In the case of receivership, the Act provides that the Bank of Thailand will return customer funds to the customers, transfer the accounts to another payment service provider, and/or take other actions necessary to conclude business with the customer funds. Customers unrelated to the payment service provider will have priority over those that are related. Any remaining compensation due would be subject to regular bankruptcy proceedings.

The new Payment Services Act offers the possibility of many innovative services for customers in Thailand to enjoy. From a legal standpoint, however, perhaps the greatest achievement of the Act is the security and stability of payment finality and the protection of customer funds.

RELATED INSIGHTS​ 

August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with
August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention
July 30, 2025
Artificial intelligence (AI) model training and data scraping are essential processes in the development of modern AI systems. AI model training involves using large datasets to teach machine learning algorithms to recognize patterns, make predictions, or generate new content. Data scraping refers to the automated extraction of information from websites or digital sources, often to assemble the vast datasets required for effective AI training. As these practices become more widespread, questions about the legality of using third-party content—especially copyrighted works—have become increasingly important. In Thailand, the legal landscape for AI developers is shaped primarily by the Copyright Act, which presents unique challenges due to the absence of a fair-use exception. This article examines the copyright-related risks and legal uncertainties facing AI developers under Thailand’s current copyright law and practices, offering strategic guidance for navigating this complex environment. Copyright Risks in AI Scraping and Training Thailand’s Copyright Act does not provide a broad fair use or fair dealing exception, unlike some other jurisdictions, such as the United States. This absence has significant consequences for AI developers: No general defense for AI training: Any use of copyrighted material for AI model training is presumed to be infringing unless a specific, narrow statutory exception applies or explicit permission is obtained from the rights holder. There is no general legal basis for using copyrighted works in AI training without authorization. Increased rights clearance burden: Developers must identify and secure licenses for every copyrighted work included in their training datasets. Given the scale and diversity of data required for effective AI models, this process can be both impractical and costly. Legal ambiguity and litigation risk: The lack of clear statutory guidance or case law leaves developers in a legal gray area. There is no established precedent clarifying whether certain uses of copyrighted material for
July 24, 2025
Thai authorities have escalated efforts to block unlawful cross-border digital asset business operators. On June 19, 2025, the Ministry of Digital Economy and Society (MDES) issued a notification empowering it to ban internet access to operations or services offered by digital asset business operators who lack licenses from the Thailand Securities and Exchange Commission (SEC) under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This ban, issued under the 2023 Royal Decree on Measures for the Prevention and Suppression of Technology Crime, particularly aims to block Thai users’ access to services offered by unlicensed offshore digital asset providers via their own apps or websites or through public social media platforms. Compliance Requirements The notification requires internet service providers and social media platforms selected by MDES to immediately impose internet access restrictions on identified apps, websites, and IP addresses of illegal operators upon receiving MDES orders. Takedown Orders There are two tracks for competent officials at MDES to issue orders to operators: If the competent official is notified by the SEC of licensing noncompliance by a particular digital asset business operator, the competent official can issue a takedown order to the operator upon approval from the permanent secretary of MDES. If the competent official independently discovers, or receives a complaint from any third party other than the SEC, that a digital asset business operator may have violated licensing requirements, the competent official can ask the SEC to verify and confirm the relevant facts and noncompliance before seeking approval from the permanent secretary of MDES to issue the takedown order. Streamlined Enforcement Prior to this notification, the SEC could obtain takedown orders only from Thai courts under the 2007 Computer Crime Act to take down or block access to unlicensed digital asset platforms and apps. This was a relatively