You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 26, 2022

Thailand’s SEC Updates Regulatory Framework for Digital Asset Business Operators

During the first quarter of 2022, Thailand’s Securities and Exchange Commission (SEC) announced a series of notifications aiming to strengthen the regulatory regime for digital assets while safeguarding investors’ interests. The updated rules and conditions apply to digital asset business operators licensed by the SEC.

The key features of the new notifications, which took effect in March and April 2022, are summarized below.

Custody of customers’ assets (effective March 1, 2022)

As custodians of their customers’ assets, digital asset business operators must:

  • Segregate customers’ assets in their custody so that the operators can clearly identify which assets belong to which investors. If customers’ digital assets are to be deposited with a third party, the operators must inform the customers accordingly.
  • Refrain from seeking benefits from customers’ assets in any manner other than the purpose for which the assets are held. This includes refraining from using customers’ assets to provide benefits to others or to the customers themselves, and from depositing customers’ digital assets with a custodian that intends to lend out the digital assets (but does not include giving the customer’s assets to a licensed digital asset fund manager for investment in digital assets).
  • Reconcile customers’ assets and keep evidentiary documentation for a period of at least five years.

Privacy coin services (effective April 1, 2022)

Digital asset business operators are prohibited from providing privacy coin services that can conceal (or allow the concealing of) specific transactional information, such as data about the transferor, the transferee, and the transfer amount.

Digital asset business operators that provided privacy coin services to customers before the effective date of these new regulations may continue to provide such services, but they must arrange for their customers to disclose at least the required transactional information or agree not to engage in information concealment.

Digital assets as a means of payment (effective April 1, 2022)

Digital asset business operators are prohibited from using digital assets as a means of payment and must not provide any services or undertake any activities that encourage or promote the use of digital assets to pay for goods or services. This includes:

  • Representing to any customer (through an advertisement, etc.) that the business operator will accept payment for goods or services using digital assets;
  • Establishing a system or tool facilitating the use of digital assets to pay for goods or services;
  • Providing e-wallets for the purpose of using digital assets as a means of payment;
  • Providing a service for transferring THB-denominated funds from a customer’s account to third-party accounts;
  • Providing a service for transferring digital assets from a customer’s account to third party accounts in order to pay for goods or services; and
  • Providing any other services that support the use of digital assets to pay for goods or services.

Business operators must take action (e.g., warnings, account suspension or termination, etc.) against customers who fail to comply with service terms and conditions.

Providing customers with activity reports (effective March 30, 2022)

The SEC now requires digital asset operators to provide their customers with a report, within one business day of a transaction, containing specific information about the customers’ digital asset trading, exchanging, and investment activity. Operators must retain the disclosed information for at least 18 months.

Although the requirement came into effect on March 30, there is an initial implementation stage until April 30, 2022, during which operators only need to provide reports to their customers within a reasonable period of time upon request. The reporting requirement will be fully implemented from May 1, 2022, onward.

For more information on the latest SEC rules and regulations for digital assets, or on any aspect of digital asset business or cryptocurrency in Thailand, please contact Kobkit Thienpreecha at [email protected], Onunya Chanpen at [email protected], Sorawit Partomtanasarn at [email protected], or Napassorn Lertussavavivat at [email protected].

RELATED INSIGHTS​ 

June 26, 2024
Tilleke & Gibbins’ Fintech Law in Southeast Asia provides fintech operators and service providers with an overview of relevant regulations across all of our full-service jurisdictions—Cambodia, Laos, Myanmar, Thailand, and Vietnam.
June 21, 2024
On June 4, Thailand’s Ministry of Commerce (MOC) issued a new notification on e-commerce business registration pursuant to the Commercial Registration Act B.E. 2499 (1956) (CRA), replacing a similar notification from 2010. The new notification (officially titled “Notification Re: Business Regulations that Commercial Operators Must Register and Businesses that Are Not Subject to the Commercial Registration Act, B.E. 2549 B.E. 2567”) took effect on June 5, 2024. While the previous notification required all individuals and legal entities engaged in regulated activities, such as selling goods or services online, to register their businesses with the local district office, the new notification effectively lifts this requirement for certain legal entities. The new notification clearly states that the CRA does not apply to regulated activities conducted by: Private limited companies, registered ordinary partnerships, and limited partnerships (i.e., legal entities under the Civil and Commercial Code); and Public limited companies (i.e., legal entities under the Public Limited Companies Act). Now that the new notification is in effect, limited companies and other specified legal entities are no longer required to register their e-commerce activities and obtain an e-commerce certificate from the MOC. E-commerce certificates previously issued to these legal entities are also voided by the new notification. Nevertheless, the requirement to register for direct marketing and obtain a direct marketing certificate under the Direct Sales and Direct Marketing Act B.E. 2545 (2002) remains in effect for any online sales or e-marketplace platforms administered by legal entities. Given the recent proactive enforcement of penalties for noncompliance with direct marketing registration requirements, we strongly advise business operators to assess whether their operations fall within the scope of direct marketing regulations and require a direct marketing certificate. For more information on e-commerce and direct marketing registration in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Nopparat Lalitkomon
June 19, 2024
Vietnam’s financial landscape is set to further transform on July 1, 2024, when the government’s long-awaited Decree No. 52/2024/ND-CP dated May 15, 2024 (“Decree 52”), will officially replace Decree No. 101/2012/ND-CP dated November 22, 2012, on non-cash payments (“Decree 101”). Decree 52 marks an important milestone by introducing the country’s first-ever legal definition of e-money. In addition, the decree brings forth new updates to regulations governing payment and intermediary payment services, laying the groundwork for more comprehensive guidance that will be provided in draft circulars now being developed by the State Bank of Vietnam (SBV). Non-Cash Payment Instruments The new definition of non-cash payment instruments under Decree 52 expands upon the previous definition in Decree 101. Notably, it clearly specifies the issuing entities as payment service providers, financial companies licensed to issue credit cards, and e-wallet service providers. Additionally, the new definition further clarifies that bank cards include debit, credit, and prepaid cards, and adds e-wallets to the list of non-cash payment instruments. Unlawful non-cash payment instruments are still defined as those that are not otherwise specified. E-Money Prior to Decree 52, the concept of e-money lacked a precise legal definition, despite its growing prevalence in forms like prepaid cards and e-wallets. The absence of a clear framework for e-money led to confusion with terms like “cryptpcurrency” and “virtual currency” and left significant ambiguity on whether e-money includes certain instruments, such as online game cards and mobile money. Decree 52 addresses this issue by clearly defining e-money as value in Vietnamese dong (VND) stored electronically and prepaid by customers to banks, foreign bank branches, and e-wallet service providers. It also specifically designates e-wallets and prepaid cards as types of storage mechanisms for e-money. Non-Cash Payment Services Decree 52 categorizes non-cash payment services into services with and without client payment
June 19, 2024
On June 14, 2024, the Personal Data Protection Committee (PDPC) released a draft notification under the Personal Data Protection Act 2019 (PDPA), setting out criteria for how data controllers must delete, destroy, and de-identify personal data. According to the PDPA, a data subject can request that a data controller delete, destroy, or de-identify their personal data in any of the following circumstances: The personal data is no longer necessary for the purposes for which it was collected, used, or disclosed. The data subject has withdrawn their consent for the processing of the personal data, and no other lawful basis for processing remains. The data subject has objected to the processing of their personal data on grounds of legitimate interests or official tasks, the data controller has no other compelling grounds to refuse the request, and the data is not needed for legal claims. The data subject objects to the processing of their personal data for direct marketing purposes. The processing of personal data is unlawful. The draft stipulates that data controllers respond to a data subject’s request to delete, destroy, or de-identify personal data immediately, and within 60 days of receiving the request. If the data controller cannot fulfill the request immediately, they must take interim measures to ensure that the personal data is made difficult to collect, use, or disclose. This includes implementing measures such as preventing access to the data and applying appropriate security measures to protect the data from unauthorized use or disclosure. De-identification or Anonymization of Personal Data In certain circumstances, a data controller may opt to de-identify or anonymize personal data, rather than delete or destroy it. If doing so, the data controller must satisfy the following criteria: There must be a structured process to remove or eliminate all direct identifiers linked to the