You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 9, 2026

Thailand’s Tech Industry Outlook for 2026

Thailand continues to advance its legal and regulatory framework for the technology sector, with several key laws undergoing review and proposed amendments. These developments reflect Thailand’s broader efforts to ensure that its regulatory landscape keeps pace with rapid technological change and aligns more closely with international standards and best practices.

The following are key legal developments and proposed legislative reforms in 2026 that are expected to impact businesses operating in the technology sector and the broader Thai business landscape.

Data Privacy and Cybersecurity

Personal Data Protection Act B.E. 2562 (2019)

Following the full enforcement of Thailand’s Personal Data Protection Act (PDPA) in June 2022, businesses and practitioners have identified practical implementation challenges and interpretative issues. These challenges were reflected in an effectiveness assessment conducted by the Personal Data Protection Committee (PDPC) in late 2024. The PDPC published a set of principles for public consultation to identify issues and directions for potential amendments to the PDPA.

  • Key issues: Emerging issues include clarifying the definitions of “data controller,” “data processor,” and “criminal record”; revisiting the scope of sensitive personal data to better reflect Thailand’s context; proposing amendments to the hierarchy of legal bases to avoid misconceptions of consent as the default legal basis; and clarifying the required level of expressiveness for explicit consent, as well as rules for collecting personal data from other sources.
  • Current status: The first round of public consultation has concluded.
  • Next steps: The proposed amendments are proceeding to a revised draft following the consultation outcomes.

Cybersecurity Act B.E. 2562 (2019)

Thailand is moving forward with proposed amendments to enhance the effectiveness of its national cybersecurity framework, as evolving digital technologies bring new risks such as misinformation, system intrusions, and attacks on critical infrastructure, making cybersecurity a national priority.

  • Key issues: The amendments aim to clarify and strengthen the roles and duties of private entities, particularly critical information infrastructure (CII) operators, in preventing, mitigating, and responding to cyber threats. Key highlights include broadening the meaning of “cyber threat” from a narrow technical focus to a holistic assessment of potential national and public impacts; introducing defined terms such as “cyber threat incident,” “computer data,” and “computer system”; strengthening risk management and incident response by CII operators; and expanding the scope of CII organizations to include public and private entities related to industrial work.
  • Current status: The third round of public consultation has concluded.
  • Next steps: The draft amendments are being revised following the consultation outcomes.

Child Online Safety

Penal Code Amendments

Recent Penal Code amendments, effective December 30, 2025, introduced provisions on sexual harassment and revised provisions on sexual assault. Offenses under these provisions that take place through online channels may result in a court order requiring the removal of the relevant content within a prescribed period, with penalties imposed for failure to comply with such a court order. Thailand is proposing further amendments to address technology-related crimes and online platform-facilitated crimes against minors, including child grooming and sexting.

  • Key issues: The proposals introduce new offenses covering online grooming, transmission of sexually explicit content to minors, and sexual extortion, alongside stricter penalties and extended extraterritorial jurisdiction, reflecting a strengthened focus on child protection in the digital environment.
  • Current status: The first round of public consultation has concluded.
  • Next steps: The Office of the Council of State will consider the draft at the third reading in January 2026.

Artificial Intelligence

AI Regulatory Framework

The Electronic Transactions Development Agency (ETDA) has continued its efforts to develop an AI regulatory framework by opening a public hearing on draft principles for future AI legislation.

  • Key issues: The proposed principles focus on a risk-based approach to AI development and deployment while supporting innovation through measures such as data reuse and sandbox mechanisms. (See more details here.)
  • Next steps: The initiative currently remains at the drafting stage, and a further public hearing on a provision-by-provision draft is expected in 2026.

Fintech

Payment Systems Act B.E. 2560 (2017)

Thailand’s payments landscape continues to be shaped by the Payment Systems Act and an active supervisory agenda from the Bank of Thailand (BOT) focused on fraud risk, interoperability, and digital-first service models.

  • Key issues: The BOT’s Guidelines for Digital Fraud Management took effect on December 17, 2025, and impose end-to-end fraud controls across prevention, monitoring, detection, and remediation for financial institutions and operators of inter-institutional fund transfer systems, e-money, and e-fund transfer services under the Payment Systems Act.

Emergency Decree on Digital Asset Businesses B.E. 2561 (2018)

Thailand’s Securities and Exchange Commission (SEC) has released relaxed digital asset regulations that pave the way for tokenization of carbon credit and renewable energy assets, expanding financing and trading options in the environmental sector.

  • Key issues: The amended regulations permit the offering, trading, and provision of other services related to tokenized carbon credits, tokenized renewable energy certificates (RECs), and tokenized carbon allowances through licensed digital asset exchanges, brokers, and dealers. This regulatory development is aimed at facilitating the green economy and the country’s net-zero goal, while increasing the diversity of products in the regulated digital assets market.

Digital Platforms

Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022)

Thailand’s platform governance entered a more prescriptive phase in 2025-2026 as regulators moved from system registration to targeted oversight of higher-risk platform categories. In parallel, Thailand is developing a primary law, the draft Platform Economy Act (PEA), which, if enacted, is expected to supersede the royal decree and consolidate user-protection and competition tools for the platform economy.

  • Key issues: During 2025, the regulator designated online marketplaces with particular risk characteristics under section 18(2) of the royal decree and imposed additional duties focused on merchant traceability and accountability and compliance with goods standards and takedown mechanisms. With respect to the draft PEA, the principles remain under development at the Council of State, with further drafting and a subsequent hearing expected. Latest policy signals continue to envisage adoption of an EU Digital Services Act–inspired regime, with the royal decree expected to be repealed upon commencement and transitional oversight mechanisms to apply.
  • Next steps: Operators should maintain compliance with the royal decree while monitoring developments in new or amended applicable regulations, as well as the PEA’s trajectory.

Telecommunications

Foreign Satellite Operators Draft Notification

Proposed by the National Space Policy Committee (NSPC) for public consultation on August 20, 2025, with the comment period concluding on September 3, 2025, this draft aims to replace the existing notification issued in 2021 to better align with current national policies on foreign satellite usage.

  • Key issues: The draft notification permits both Thai and foreign satellite operators to use foreign satellites to operate a business providing satellite communication services within Thailand. The consideration for granting permission takes into account technical justifications, economic benefits, social benefits, and national security considerations.
  • Next steps: The draft amendments are being revised following the public consultation outcomes.

Gaming

Draft Gaming Industry Promotion Act

The draft was initially proposed by the Digital Economy Promotion Agency (DEPA) under the Minister of Digital Economy and Society (MDES) by opening a public hearing on draft principles for a future Gaming Act.

  • Key issues: The draft law aims to support the growth of Thailand’s online gaming sector while safeguarding youth and society. The draft law introduces registration requirements for developers and platforms (potentially including offshore entities), which may include a rating system. It is also expected to apply to all types of games, with particular focus on games that incorporate gambling-like features, such as lucky draw mechanisms or point-accumulation and reward-redemption systems. This reflects the Thai government’s position of combating online gambling and online scam activities.
  • Next steps: The initiative currently remains at the drafting stage, and DEPA has recently announced that it will proceed with proposing the Draft Act to the MDES for consideration and subsequent submission to the Cabinet. Further public hearing is expected within 2026.

Looking Ahead

Thailand’s technology regulatory landscape continues to develop through a combination of new legislation, subordinate regulations, regulatory guidance, and evolving enforcement priorities. Technology sector businesses should actively monitor these developments and begin preparing for possible compliance adjustments. In particular, companies should review their data governance frameworks, cybersecurity readiness, platform governance structures, and AI risk management practices to ensure they are well positioned as Thailand’s technology regulatory landscape continues to evolve.

We will continue to monitor these developments closely and provide quarterly updates to keep you informed of any significant changes or new regulatory measures impacting Thailand’s technology sector.

RELATED INSIGHTS​ 

May 13, 2024
On May 2, 2024, Vietnam’s Ministry of Justice published on its online platform the most recent version of the draft decree on administrative sanctions for violations in the field of cybersecurity (“Draft Sanction Decree”) to gather feedback and contributions from the community and stakeholders. After receiving the Ministry of Justice’s assessment, the Ministry of Public Security (“MPS”), in charge of drafting the Draft Sanction Decree, may make further revisions before submitting it to the government for review and final decision on enactment. The decree is expected to have an effective date of June 1, 2024. The stringent penalties for infringements involving personal data of the previous draft version remain in this Draft Sanction Decree—a sign of the proactive stance of the MPS in enforcing the Personal Data Protection Decree (“PDPD”). Effective Date and Transitional Provisions It is important to note that the Draft Sanction Decree does not impose any new obligations on organizations or individuals, and only sets out the administrative sanctions that could be imposed on violators as soon as June 1, 2024, which is indicated as the effective date in Article 49. This signals the MPS’s eagerness to begin taking enforcement actions against recalcitrant organizations and individuals that have not complied with the various obligations imposed on them under the Law on Network Information Security (enacted in 2015), the Law on Cybersecurity (enacted in 2018) and its guiding decree (Decree 53 – enacted in 2022), and the most recent PDPD (enacted in 2023). Article 50.1 of the Draft Sanction Decree outlines the transitional provisions regarding administrative violations in the cybersecurity field. It clarifies that the decree does not have retroactive effect, by stating that violations occurring before its effective date, but discovered or under review after such effective date will be subject to the regulations on administrative
May 9, 2024
As non-cash payments continue to surge in Vietnam, the requirement for strong security standards and a clear legislative framework for intermediary payment services (“IPS”) is becoming more and more critical. Recognizing this, the State Bank of Vietnam (“SBV”) has been working on a draft decree to supersede the outdated Decree No. 101/2012/ND-CP dated November 22, 2012, on non-cash payments (“Draft Non-Cash Payment Decree”), which will lay the groundwork for non-cash payments in general and the provision of IPS in particular. Building upon this, the SBV recently issued a draft circular to replace Circular No. 39/2014/TT-NHNN dated December 11, 2014, on IPS (“Circular 39”) (“Draft IPS Circular”), which will offer more detailed guidance on the provision of IPS in Vietnam on top of the Draft Non-Cash Payment Decree. The Draft IPS Circular will be applicable to (i) IPS providers; (ii) foreign organizations providing IPS in Vietnam; and (iii) organizations and individuals involved in the provision of IPS. Some key updates regarding the Draft IPS Circular are as follows: Scope of Application The Draft IPS Circular sets out further guidance for the provision of IPS as listed under the Draft Non-Cash Payment Decree, including: (i) electronic clearing services; (ii) electronic wallet (“e-wallet”) services; (iii) collection and payment support services; (iv) financial switching services; (v) international financial switching services; and (vi) electronic payment gateway services. Notably, the Draft IPS Circular has explicitly excluded from its scope of application the provision of accounts by goods/service providers to their customers solely for the purpose of payment within the systems of such providers (e.g., cards/coupons or service/transaction accounts of online game service providers, transportation service providers, or securities companies, etc.). Requirements on the Provision of IPS Electronic Clearing Services: The Draft IPS Circular introduces regulations to cover certain elements of electronic clearing services that have
May 9, 2024
On April 29, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) issued the master plan for personal data protection, which outlines the PDPC’s strategies for developing and enhancing the data protection framework in Thailand from 2024 to 2027. A draft of this four-year plan had previously been released for a public hearing on November 27, 2023. Overview The master plan sets out the long-term direction for the protection of personal data in Thailand, analyzing the current landscape, challenges, and obstacles encountered since the full enactment of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). It aims to align with Thailand’s National Security Policy and Plan for 2024–2027 and focuses on key sectors in its initial two years. These sectors are: Public security and key government services; Retail and e-commerce; Information and communication technology and telecommunications; Finance, investment, and insurance; Public health; Tourism; and Education. Objectives The master plan’s goals include increasing organizational compliance with the PDPA, reducing data breaches, updating the PDPA to reflect current circumstances, introducing various PDPC e-services, and enhancing Thailand’s global competitiveness in data privacy and personal data protection. It sets targets and indicators of the plan’s success, such as achieving a 100% PDPA compliance rate across all sectors in Thailand and raising Thailand’s digital competitiveness to at least 30th in the World Digital Competitiveness Rankings from the IMD World Competitiveness Center. Strategic Initiatives To achieve these objectives, the master plan introduces four strategic initiatives: Effective and balanced PDPA enforcement: Develop standards, principles, criteria, tools, indicators, and data privacy governance, including law enhancements. A recent example of this is the PDPC’s launch of the Personal Data Protection Surveillance Centre (PDPC Eagle Eye) to monitor data breaches. Knowledge and trust enhancement: Build human capacity and trust by enhancing knowledge through initiatives like the forthcoming
May 3, 2024
Vietnam’s Ministry of Public Security (MPS) recently published on its website a dossier of the Draft Law on Data (the “Draft Law”) for public feedback, initiating a consultation period from February 26 to March 26, 2024. The dossier comprises a Policy Impact Assessment Report and a Summary Report on the implementation of existing legal documents governing data. An outline of the Draft Law was later circulated to relevant organizations for their input and commentary. The MPS drafted this legislation with several objectives, including bolstering national data infrastructure, advancing digital government while streamlining administrative procedures, fostering growth in the digital economy and building a digital society, and establishing a National Data Center. Comprising 65 articles across 6 chapters, the Draft Law is slated for implementation on January 1, 2026. The Draft Law currently is very preliminary, resembling a framework document. It features numerous provisions akin to policy mandates, yet only presents introductory concepts without further elaboration. Scope of Application The Draft Law applies to agencies, organizations, and individuals involved in data activities in Vietnam. This scope of application appears excessively broad and ambiguous, without a clear definition of “data activities”, leaving uncertainty regarding the breadth of this term’s coverage. Key Policy Groups The Draft Law focuses on four key policy groups: 1. Regulations on development, processing, and management of data This policy group focuses on matters relating to the collection, digitalization, and creation of data; assurance of data quality; data classification; data storage; data combination, adjustment, and updating; data strategy; data management; data sharing; provision of data to state agencies; data analysis and synthesis; data verification and authentication; data disclosure; access and retrieval of data; data encryption and decryption; data copying, transmission, and transfer; data revocation, deletion, and destruction; application of science and technology in data processing; identification and management