You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 9, 2026

Thailand’s Tech Industry Outlook for 2026

Thailand continues to advance its legal and regulatory framework for the technology sector, with several key laws undergoing review and proposed amendments. These developments reflect Thailand’s broader efforts to ensure that its regulatory landscape keeps pace with rapid technological change and aligns more closely with international standards and best practices.

The following are key legal developments and proposed legislative reforms in 2026 that are expected to impact businesses operating in the technology sector and the broader Thai business landscape.

Data Privacy and Cybersecurity

Personal Data Protection Act B.E. 2562 (2019)

Following the full enforcement of Thailand’s Personal Data Protection Act (PDPA) in June 2022, businesses and practitioners have identified practical implementation challenges and interpretative issues. These challenges were reflected in an effectiveness assessment conducted by the Personal Data Protection Committee (PDPC) in late 2024. The PDPC published a set of principles for public consultation to identify issues and directions for potential amendments to the PDPA.

  • Key issues: Emerging issues include clarifying the definitions of “data controller,” “data processor,” and “criminal record”; revisiting the scope of sensitive personal data to better reflect Thailand’s context; proposing amendments to the hierarchy of legal bases to avoid misconceptions of consent as the default legal basis; and clarifying the required level of expressiveness for explicit consent, as well as rules for collecting personal data from other sources.
  • Current status: The first round of public consultation has concluded.
  • Next steps: The proposed amendments are proceeding to a revised draft following the consultation outcomes.

Cybersecurity Act B.E. 2562 (2019)

Thailand is moving forward with proposed amendments to enhance the effectiveness of its national cybersecurity framework, as evolving digital technologies bring new risks such as misinformation, system intrusions, and attacks on critical infrastructure, making cybersecurity a national priority.

  • Key issues: The amendments aim to clarify and strengthen the roles and duties of private entities, particularly critical information infrastructure (CII) operators, in preventing, mitigating, and responding to cyber threats. Key highlights include broadening the meaning of “cyber threat” from a narrow technical focus to a holistic assessment of potential national and public impacts; introducing defined terms such as “cyber threat incident,” “computer data,” and “computer system”; strengthening risk management and incident response by CII operators; and expanding the scope of CII organizations to include public and private entities related to industrial work.
  • Current status: The third round of public consultation has concluded.
  • Next steps: The draft amendments are being revised following the consultation outcomes.

Child Online Safety

Penal Code Amendments

Recent Penal Code amendments, effective December 30, 2025, introduced provisions on sexual harassment and revised provisions on sexual assault. Offenses under these provisions that take place through online channels may result in a court order requiring the removal of the relevant content within a prescribed period, with penalties imposed for failure to comply with such a court order. Thailand is proposing further amendments to address technology-related crimes and online platform-facilitated crimes against minors, including child grooming and sexting.

  • Key issues: The proposals introduce new offenses covering online grooming, transmission of sexually explicit content to minors, and sexual extortion, alongside stricter penalties and extended extraterritorial jurisdiction, reflecting a strengthened focus on child protection in the digital environment.
  • Current status: The first round of public consultation has concluded.
  • Next steps: The Office of the Council of State will consider the draft at the third reading in January 2026.

Artificial Intelligence

AI Regulatory Framework

The Electronic Transactions Development Agency (ETDA) has continued its efforts to develop an AI regulatory framework by opening a public hearing on draft principles for future AI legislation.

  • Key issues: The proposed principles focus on a risk-based approach to AI development and deployment while supporting innovation through measures such as data reuse and sandbox mechanisms. (See more details here.)
  • Next steps: The initiative currently remains at the drafting stage, and a further public hearing on a provision-by-provision draft is expected in 2026.

Fintech

Payment Systems Act B.E. 2560 (2017)

Thailand’s payments landscape continues to be shaped by the Payment Systems Act and an active supervisory agenda from the Bank of Thailand (BOT) focused on fraud risk, interoperability, and digital-first service models.

  • Key issues: The BOT’s Guidelines for Digital Fraud Management took effect on December 17, 2025, and impose end-to-end fraud controls across prevention, monitoring, detection, and remediation for financial institutions and operators of inter-institutional fund transfer systems, e-money, and e-fund transfer services under the Payment Systems Act.

Emergency Decree on Digital Asset Businesses B.E. 2561 (2018)

Thailand’s Securities and Exchange Commission (SEC) has released relaxed digital asset regulations that pave the way for tokenization of carbon credit and renewable energy assets, expanding financing and trading options in the environmental sector.

  • Key issues: The amended regulations permit the offering, trading, and provision of other services related to tokenized carbon credits, tokenized renewable energy certificates (RECs), and tokenized carbon allowances through licensed digital asset exchanges, brokers, and dealers. This regulatory development is aimed at facilitating the green economy and the country’s net-zero goal, while increasing the diversity of products in the regulated digital assets market.

Digital Platforms

Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022)

Thailand’s platform governance entered a more prescriptive phase in 2025-2026 as regulators moved from system registration to targeted oversight of higher-risk platform categories. In parallel, Thailand is developing a primary law, the draft Platform Economy Act (PEA), which, if enacted, is expected to supersede the royal decree and consolidate user-protection and competition tools for the platform economy.

  • Key issues: During 2025, the regulator designated online marketplaces with particular risk characteristics under section 18(2) of the royal decree and imposed additional duties focused on merchant traceability and accountability and compliance with goods standards and takedown mechanisms. With respect to the draft PEA, the principles remain under development at the Council of State, with further drafting and a subsequent hearing expected. Latest policy signals continue to envisage adoption of an EU Digital Services Act–inspired regime, with the royal decree expected to be repealed upon commencement and transitional oversight mechanisms to apply.
  • Next steps: Operators should maintain compliance with the royal decree while monitoring developments in new or amended applicable regulations, as well as the PEA’s trajectory.

Telecommunications

Foreign Satellite Operators Draft Notification

Proposed by the National Space Policy Committee (NSPC) for public consultation on August 20, 2025, with the comment period concluding on September 3, 2025, this draft aims to replace the existing notification issued in 2021 to better align with current national policies on foreign satellite usage.

  • Key issues: The draft notification permits both Thai and foreign satellite operators to use foreign satellites to operate a business providing satellite communication services within Thailand. The consideration for granting permission takes into account technical justifications, economic benefits, social benefits, and national security considerations.
  • Next steps: The draft amendments are being revised following the public consultation outcomes.

Gaming

Draft Gaming Industry Promotion Act

The draft was initially proposed by the Digital Economy Promotion Agency (DEPA) under the Minister of Digital Economy and Society (MDES) by opening a public hearing on draft principles for a future Gaming Act.

  • Key issues: The draft law aims to support the growth of Thailand’s online gaming sector while safeguarding youth and society. The draft law introduces registration requirements for developers and platforms (potentially including offshore entities), which may include a rating system. It is also expected to apply to all types of games, with particular focus on games that incorporate gambling-like features, such as lucky draw mechanisms or point-accumulation and reward-redemption systems. This reflects the Thai government’s position of combating online gambling and online scam activities.
  • Next steps: The initiative currently remains at the drafting stage, and DEPA has recently announced that it will proceed with proposing the Draft Act to the MDES for consideration and subsequent submission to the Cabinet. Further public hearing is expected within 2026.

Looking Ahead

Thailand’s technology regulatory landscape continues to develop through a combination of new legislation, subordinate regulations, regulatory guidance, and evolving enforcement priorities. Technology sector businesses should actively monitor these developments and begin preparing for possible compliance adjustments. In particular, companies should review their data governance frameworks, cybersecurity readiness, platform governance structures, and AI risk management practices to ensure they are well positioned as Thailand’s technology regulatory landscape continues to evolve.

We will continue to monitor these developments closely and provide quarterly updates to keep you informed of any significant changes or new regulatory measures impacting Thailand’s technology sector.

RELATED INSIGHTS​ 

June 18, 2024
On June 1, 2024, Thailand’s Securities and Exchange Commission (SEC) issued four notifications amending existing regulations to recognize sustainability-related tokens and institute specific measures for regulating them. These tokens are intended to offer diverse sustainability-related products to ESG funds in Thailand and drive the growth of a sustainable digital economy in the country. The key points in the notifications are summarized below. Definitions Under the notifications, sustainability-related tokens are classified into four types: Green tokens: Digital tokens specifically intended to incentivize or fund projects that promote environmental sustainability. Social tokens: Digital tokens specifically intended to support and fund initiatives that contribute to social welfare. Sustainability tokens: Digital tokens intended to support projects that enhance both environmental and social welfare through funding and incentives. Sustainability-linked tokens: Digital tokens intended to fund activities that promote sustainability. This includes tokens that have adjustable returns based on the performance of the issuing entity or its affiliates in meeting specified sustainability-related goals or outcomes. The offering of sustainability-related tokens is subject to Thailand’s general requirements for token offerings: (1) approval from the SEC and (2) filing the registration statements and the draft prospectus with the SEC before marketing and offering the sustainability-related tokens to public investors in Thailand, unless exempted. The sustainability-related tokens must be offered through an SEC-approved ICO portal, which will assume a role similar to that of a financial adviser and an underwriter in a public offering of securities. Sustainability-Related Token Offerings In addition to complying with the general requirements for token offerings, sustainability-related token offerings must comply with the following measures: Issuer disclosure: The issuer must disclose certain sustainability information, both before and after the offering, according to standards comparable to those of nationally or internationally recognized green, social, and sustainable bonds (GSSBs) and sustainability-linked bonds (SLBs)—such as the principles
June 13, 2024
The Bank of Thailand (BOT) has announced its new Enhanced Regulatory Sandbox, which provides an opportunity to experiment with currently restricted financial innovations under a controlled environment. The BOT is employing a thematic approach to determine the scope of technology or innovations that may participate in the Enhanced Regulatory Sandbox and will only accept applications in each theme for a limited period. The first announced theme is “programmable payments,” which refers to payment and payment-related transactions with automatic execution upon the fulfillment of a predefined condition utilizing distributed ledger technology (DLT) and a smart contract or comparable technology in which electronic data units are issued on an electronic system or network. The application period for programmable payment testing in the Enhanced Regulatory Sandbox runs from June 13 to September 13, 2024. A summary of the programmable payment testing framework under the Enhanced Regulatory Sandbox is provided below. Scope The Enhanced Regulatory Sandbox accepts applications for the following programmable payment activities: Automated payment and settlement upon fulfillment of predefined conditions. Escrow services with predefined delivery or transactional conditions. Asset tokenization through issuance of digital tokens representing rights in an asset, with payment for tokens or payment of benefits or returns to holders of digital tokens occurring automatically when conditions are met. Other testing related to the items mentioned above. Requirements and Conditions Programmable payment testing activities in the Enhanced Regulatory Sandbox must comply with the following requirements and conditions: Electronic data units issued for programmable payment testing must be pegged to the Thai baht (THB) on a one-for-one basis (i.e., 1 unit = THB 1), with the float account storing THB equal to the value of the electronic data units issued. Participants must define the redemption rights of the unitholders and proceed with the THB redemption according to the participants’
June 3, 2024
On May 24, 2024, the Central Bank of Myanmar (“CBM”) issued a public notice warning individuals against participating in the sale, purchase, exchange, or transfer of unregulated digital currencies, as well as unauthorized money transfers. The CBM has indicated its readiness to enforce regulations by closing bank accounts and pursuing legal action, which may result in imprisonment, fines, or both, in accordance with the Central Bank of Myanmar Law, the Anti-Money Laundering Law and the Financial Institutions Law. The CBM is the sole legal entity authorized to issue currency in Myanmar, as stipulated in the Central Bank of Myanmar Law. The CBM does not recognize digital currencies as official currency, nor has it granted permission to financial institutions within Myanmar to trade them. The existing legal framework, comprising the Foreign Exchange Management Law and the Financial Institutions Law, further cements the illegality of cryptocurrency transactions within the nation’s borders. Four years ago, in May 2020, the CBM issued Notification No. 9/2020, prohibiting all persons residing in Myanmar from engaging in the sale, purchase, or exchange of unregulated digital currencies. The list of prohibited currencies includes widely recognized cryptocurrencies such as Bitcoin (BTC), Litecoin (LTD), Ethereum (ETH), and Perfect Money (PM), with a particular emphasis on transactions conducted through personal Facebook accounts and web pages. Before the issuance of the 2020 notification, the CBM had announced that anyone engaging in digital currency transactions did so at their own risk, but no enforcement measures were being taken at the time. However, after the 2020 notification was issued, the CBM has pursued legal action against persons involved in illegal currency conversion and unauthorized hundi money transfers using Tether (USDT). These enforcement measures have included shutting down bank accounts and initiating legal proceedings under the Anti-Money Laundering Law and the Financial Institutions Law.
May 15, 2024
On May 1, 2024, Thailand’s National Cyber Security Committee (NCSC) published the draft NCSC Notification Re: Cloud Cybersecurity Standards for a public hearing period, which was open until May 14, 2024. These standards have been drafted to drive the country’s cloud-first policy with the aim of minimizing risks from cyber threats to cloud services utilized by government agencies, supervising or regulating organizations, and critical information infrastructure (CII) organizations. The key points of the draft Cloud Cybersecurity Standards are below. Scope The standards apply to government agencies, supervising or regulating organizations, and CII organizations under the Cybersecurity Act B.E. 2562 (2019), as well as cloud service providers (defined below). The standards prescribe cloud system cybersecurity measures for cloud service customers (defined below) and providers only to the extent that the service is provided to the in-scope organizations outlined above. Definitions Cloud service customers (CSCs): In-scope organizations that have a formal contractual agreement to use cloud services provided by a cloud service provider. Cloud service providers (CSPs): Persons who enable cloud services to be used by a cloud service customer, responsible for maintaining infrastructure, platforms, and software that enable provision of the cloud services and for managing these resources to ensure their accessibility, security, and scalability for their cloud service customers. Application In-scope organizations that will use or have been using cloud services must comply with the Cloud Cybersecurity Standards by taking into account their data or technology information systems’ level of impact, as specified in the previously issued Notification of the NCSC Re: Standards for Defining the Security Category for Data and Information Systems B.E. 2566 (2023). The impact level related to personal data is to be rated as being at least at the medium level, and the minimum standards for that level specified in the draft Cloud Cybersecurity Standards