You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 19, 2022

Thailand’s SEC Opens Public Hearing Period on ICO Portal Regulations

On June 23, 2022, Thailand’s Securities and Exchange Commission (SEC) opened a public hearing period on regulatory controls for initial coin offering (ICO) portals that serve as financial advisors to digital token issuers. The proposed measures aim to prevent conflicts of interest; allow ICO portals to outsource certain functions; and establish additional notification obligations for ICO portals.

The public hearing is open for general comments until July 23, 2022, and the new legislation is expected to be issued soon after that. During the public hearing period, any interested parties can comment on the SEC’s proposed principles. The key proposed points are outlined below.

Conflicts of Interest

Similar to SEC-approved financial advisors for securities offerings, ICO portals must be clear of conflicts of interest when representing issuers in a coin offering. According to the draft regulation, the following conflicts of interest are prohibited:

  • The ICO portal (and certain individuals as specified by the SEC) directly or indirectly holds a prohibited amount of shares in the issuer, its affiliates, or its subsidiaries. If the issuer is not a listed company, any shareholding or portion thereof is prohibited. If the issuer is a listed company on the Stock Exchange of Thailand (SET), the shares held by the ICO platform may not total more than five percent of the total voting rights.
  • The issuer (and certain individuals as specified by the SEC) directly or indirectly holds shares in the ICO portal in any amount if the ICO portal is not a listed company, or totaling more than five percent of the voting rights if the ICO portal is listed on the SET.
  • Any of the ICO portal’s directors or executives, or the head of the department responsible for screening the ICO project, is also a director in the issuer.
  • The ICO portal has a relationship with, or any interest in, the issuer in a way that could impede the independence of the ICO portal with respect to conducting its duties.

Outsourcing ICO Portal Functions

To increase efficiency, ICO portals will be allowed to outsource certain tasks, subject to the following conditions:

  • The ICO portal must adopt an outsourcing policy, measures, and procedures (approved by the board of directors), to be reviewed annually or upon any event that might have a material impact on business operations.
  • The scope of outsourced tasks must be appropriate, reasonable, and not so substantial that the ICO portal will become an entity with no business operations (an “empty box”). ICO portals may only outsource tasks relating to digital token offerings, such as contacting and providing services to investors, and supporting digital token offerings and subscription management. Core tasks, such as screening ICO projects, may not be outsourced.
  • The ICO portal must notify the SEC within 15 days when it outsources a task to a third party, when there is a significant change to the outsourcing, or when the third party subcontracts any task to another party.

Additional Notification Obligations

To facilitate additional supervisory control, ICO portals will have to notify the SEC within 15 days if there are any changes to their qualifications, personnel, and functions, or if the ICO portal is unable to maintain the necessary qualifications or comply with the requirements detailed in the relevant section of SEC Notification No. GorJor. 16/2561 Re: Criteria, Provisions, and Procedure for Approval of an ICO Portal Service Provider. In the notification, the ICO portal must identify the cause and report on any remedial measures planned or already taken.

If an ICO portal wishes to suspend operations, it must also notify the SEC and provide a list of unfinished tasks along with a plan to mitigate any potential impact on customers. When the ICO portal wishes to resume operations, it must again notify the SEC and explain how it has resolved the issues that caused the suspension of operations, along with any significant changes to the portal’s characteristics.

Tilleke & Gibbins will continue to monitor these ICO portal regulations and provide updates as needed. For more information on any aspect of digital asset business, cryptocurrency, digital tokens, or digital asset regulations in Thailand, please contact Kobkit Thienpreecha at [email protected], Onunya Chanpen at [email protected], or Sorawit Partomtanasarn at [email protected].

RELATED INSIGHTS​ 

July 2, 2025
On June 27, 2025, Vietnam’s National Assembly adopted a Resolution on International Financial Centers in Vietnam (“IFC Resolution”), which is set to take effect September 1, 2025, putting forward major policy breakthroughs on multiple fronts. The IFC Resolution has the goal of turning Ho Chi Minh City and Da Nang into leading international financial centers with autonomy and tools to compete, thereby raising Vietnam’s position in the global financial network, in association with economic growth drivers. Below are some of the key points of the IFC Resolution, which has notable changes from previous drafts (see our articles on Vietnam’s Draft Resolution on Financial Centers: Implications for Fintech and Banking and Vietnam’s Emerging Regulatory Landscape for Blockchain and Cryptocurrency), including: The removal of the Central Supervisory Agency. The addition of a definition of international financial centers, which are specific geographic areas in Ho Chi Minh City and Da Nang with members entitled to special policies. The addition of a list of entities eligible for membership, and entitlement to the special policies. Major Policy Breakthroughs The IFC Resolution introduces specific policies in the following areas: Liberalization of foreign exchange control for members, including policies such as open foreign exchange use between members and exemption from foreign exchange control procedures for 100% foreign-owned members. Specialized licensing for members to establish and operate single-member limited liability banks and foreign bank branches with the ability to apply accounting standards, debt classification, risk provisions, and prudential ratios according to the owner’s policies. Creation of a capital market for innovative startups, including a crowdfunding mechanism or private placement mechanism through a licensed platform, and development of a green finance market with green certification. Creation of a regulatory sandbox for fintech technologies, products, services, and business models not yet prescribed by law, offering exemption from compliance with
July 1, 2025
Now halfway through 2025, Thailand continues to advance in the realm of data privacy, with the ambitious goal of achieving zero data breaches. The Personal Data Protection Committee (PDPC), an independent government body established by the Personal Data Protection Act (PDPA), is taking a more proactive approach, having published several rulings and orders to enhance data protection measures and clarify compliance expectations for businesses. Here is a look back at Thailand’s data privacy developments in the first half of the year. Strengthening Law Enforcement and New Guidance for Compliance Enforcement of existing data protection laws and regulations has taken a step forward this year. Some of the specific initiatives include: Increased enforcement by the PDPC. A key trend to watch from the first half of 2025 is the PDPC’s active enforcement of the PDPA as it intensifies oversight through compliance orders and public warnings against noncompliant organizations while ramping up efforts to prevent and halt the illegal trading of personal data by actively monitoring emerging societal issues. Call center scams and cyber fraud control. Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Orders from the Expert Committee. Several orders issued by the Expert Committee under the PDPA were announced in the first half of this year. These include directives for data controllers to take corrective actions to comply with the PDPA, as well as initiatives to raise awareness of data privacy within organizations, reflecting the regulator’s focus on promoting organizational awareness and compliance. A guideline report summarizing the Expert Committee’s decisions and orders was also published to serve as a reference for compliance. Public issue monitoring. The PDPC has been taking a more proactive approach
June 27, 2025
Three American giants are actively protecting their intellectual property rights against generative AI, as two legal battles commence on both sides of the Atlantic. In the UK, Seattle-based media company Getty Images accuses UK-based Stability AI of multiple IP infringements. In the US, The Walt Disney Company and Universal Studios are teaming up against Midjourney, an AI startup, with their main ground being copyright infringement. Both cases are centered around questions legal minds have been posing since the introduction of generative AI: Is the output of generative AI an infringement? And who is ultimately responsible for the output, the platform or the user? Getty Images v. Stability AI Getty initially filed a claim in the High Court in 2023, which resulted in Stability applying for reverse summary judgment on the grounds that Getty had no real prospect of success, arguing that their operations took place outside the UK. However, the High Court judge hearing the case decided that the claims brought by Getty did have a real prospect of succeeding in court. Despite this, Stability saw a small victory when the court ruled that the representative action brought by Getty would not succeed due to the difficulties in identifying who qualified for the class. The proposed class was comprised of 50,000 rightsholders who alleged their rights were also infringed. Stability was successful in arguing that identifying these individuals would be challenging due to the unclear definition of the class. This current trial is centered around four main grounds: Copyright infringement. Getty accuses Stability of using content that Getty owns or has an exclusive license for when training their model, Stable Diffusion, resulting in the generated output containing substantial parts of that content. Getty is also alleging secondary copyright infringement, arguing that Stability is importing an article into the UK
June 26, 2025
Vietnam’s new Personal Data Protection Law (PDPL) was passed by the National Assembly on June 26, 2025, and will enter into force on January 1, 2026. The PDPL introduces several new concepts, exemptions, and obligations in comparison with the current Decree No. 13/2023/ND-CP on personal data protection (PDPD), while other contents remain essentially the same. The relationship between the PDPD and the PDPL has not been clearly addressed; however, it is expected that the government will issue a new decree providing necessary guidance on certain requirements under the PDPL, and the PDPD will remain in effect until it is replaced by this new decree. Some key points of the new PDPL include the following: Personal data will be further defined by lists of basic personal data and sensitive personal data to be issued by the government. The consent-centric approach of the PDPD remains in place, along with additional exemptions for certain data processing activities. The requirements for the data processing impact assessment (DPIA) and transfer impact assessment (TIA) remain unchanged. However, there are new exemptions for the TIA, including for the processing and storing in the cloud of employee data, and when the data subject is the person sending its own data outside of Vietnam. Consent obtained under the PDPD remains valid under the PDPL. DPIAs and TIAs submitted under the PDPD are valid under the PDPL but may need to be updated to be in line with the requirements of the PDPL. Administrative fines depend on the type of violation. The fine for sale and purchase of personal data will be 10 times the revenue from the sale or VND 3 billion (about USD 115,000), whichever is higher. The fine for cross-border transfer violations is 5% of the violator’s revenue of the preceding year or VND 3 billion,