You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 22, 2012

Using the Computer Crimes Act to Combat Online Piracy

Informed Counsel

The increase in online shopping has proven lucrative for legitimate retailers. But traders selling counterfeit and pirated products have also taken advantage by selling a wide range of counterfeit products online. In searching for new solutions to battle intellectual property infringement on the internet, recent meetings between government officials and members of the private sector have resulted in an innovative approach that relies on existing legislation. This article will provide an overview of the current regulatory environment and the recommended procedures that will facilitate the shutting down of illegal retail websites, and help to halt the rise in purchases of counterfeit goods on the internet.

Online Piracy Challenges

According to a report by the Department of Intellectual Property (DIP), 40 percent of pirated films, music DVDs, and CDs are offered for sale online. For counterfeiters, there are three key benefits in shifting from traditional brick-and-mortar marketplaces to online retailing:

  1. There is no stall rental fee.
  2. Many of the corrupt activities surrounding the sale of counterfeit goods can be avoided.
  3. Storage of goods is not required, which reduces the chances of being caught in possession of the illegal goods and subsequently arrested.

Since existing IP laws in Thailand do not explicitly sanction the sale of counterfeit goods online, IP owners have, up until now, been unable to take aggressive action against these online sellers. In practice, IP owners have tried to tackle this type of infringement in Thailand by conducting investigations to uncover the source of the fake goods, followed by raid actions at storage facilities, stockrooms, and warehouses.

This investigation-and-raid approach however, is increasingly becoming hampered by the fact that online traders do not typically store their goods on their premises. Instead, traders purchase the counterfeit products from other sellers in the market, after having received purchase orders from their customers.

Existing Legal Framework

In the absence of specific legislation to address these activities, the Thai government has tried to solve this problem by relying on related legislation. When advising IP owners of their enforcement options, one suggestion raised by the DIP is to apply Sections 14 and 20 of the Computer Crimes Act B.E. 2550 (2007).              

Section 14: Whoever commits the following offenses shall be liable to imprisonment for a term not exceeding five years, or a fine of not exceeding THB 100,000, or both:

(1) Entering wholly or partially spurious computer data or false computer data into a computer system, in a manner that is likely to cause injury to other persons or the public. …

Section 20: In the case where the commission of an offense under this Act involves the distribution of computer data that may affect the security of the Kingdom, as prescribed in Book II, Title I or Title I/I of the Penal Code, which may be inconsistent with public order or good morals, the competent official may apply for a motion to the court to order that the distribution of such computer data be blocked.

In 2011, these sections were applied to a case related to food and medical products before Thailand’s Criminal Court. In Red Case Sor. 33/2554, the defendant committed an offense of advertising the sale of food, medicine, and medical equipment by using untrue information that was deceptive to consumers. The court deemed that this act constituted an offense under Section 14(1) of the Computer Crimes Act. The court therefore issued an order to block the distribution activities undertaken by the website, pursuant to Section 20 of the Act.

As this judgment shows, Sections 14 and 20 grant to the court the authority to block the distribution of forged computer data or false computer data, upon the request of an officer, if the court finds that such contents may be inconsistent with public order or good morals. Unfortunately, the content of the Computer Crimes Act is not clear in defining whether offering counterfeit goods for sale on a website can be considered “forged computer data.” Although some government officials claim that this law sets out the right to take action against websites that offer fake goods for sale online, others opine that fake goods offered on a website cannot be deemed “forged computer data” under Section 14.

Proposed New Approach

In seeking a solution to this problem, representatives from the Ministry of Information and Communication Technology (MICT), the DIP, and the private sector met on March 12 and March 20, 2012. During the meeting, the Director-General of the DIP stated that she encouraged IP representatives or IP owners to submit a formal letter to the MICT requesting to shut down these websites under Section 14. When an IP owner proceeds with such a formal letter, this would provide a type of test case to determine whether Section 14 of the Computer Crimes Act can feasibly be used to shut down websites that offer fake goods for sale.

In light of these developments, a new procedure was proposed during the meeting (see graphic below). If all parties implement this procedure, it could enable IP owners to shut down websites selling counterfeit or pirated goods in as little as two weeks. Clearly, this would be a major development for long-suffering IP owners who have battled online piracy for years.

Implementing the Procedure

Although the debate is ongoing, it is evident that the Thai government intends to implement more stringent measures in the near future to inhibit the stream of illicit gains enjoyed by illegal online retailing operations. When an IP owner decides to test the approach proposed by the DIP and a court order is requested, practitioners will eagerly await the outcome for any developments in this area of the law. If the Computer Crimes Act is deemed practicable, it would provide an efficient route for IP owners to shut these websites down, without incurring additional investigation costs.

However, if the court decides that the activities of illegal online retailers—specifically, offering counterfeit goods for sale on a website—do not constitute “forged computer data” under Section 14, it will then be necessary for all stakeholders to push ahead with further amendments to existing IP law.

RELATED INSIGHTS​ 

June 5, 2026
Vietnam’s AI regulatory framework has reached an important milestone. While the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law) established the foundation for AI governance, many practical compliance requirements were left to implementing regulations. On April 30, 2026, the government issued Decree No. 142/2026/ND-CP (Decree 142), which took effect on May 1, 2026, and provides the first detailed guidance on the implementation of the AI Law. Although an official list of high-risk AI systems is still pending from the prime minister, Decree 142 provides valuable insight into how Vietnam’s risk-based AI regulatory framework will operate in practice. Risk Classification Framework The AI Law adopts a risk-based approach under which AI systems are classified as high-risk, medium-risk, or low-risk. Decree 142 builds on this framework by providing detailed guidance on how these classifications are determined. High-risk AI systems are determined based on factors such as (i) their potential impact on life, health, property, human rights, public interests, or national security; (ii) the sector in which they are deployed; and (iii) the scale of affected users or integration with critical infrastructure. The latest draft list of high-risk AI systems appears to follow these same principles. Medium-risk AI systems generally include systems that may mislead, influence, or manipulate users, particularly where users may not realize they are interacting with AI or AI-generated content. The focus is therefore on transparency and authenticity risks rather than broader societal or safety concerns. Low-risk AI systems are those that do not meet the criteria for either high-risk or medium-risk classification. Importantly, Decree 142 seeks to avoid over-classification. Certain systems may fall outside the high-risk or medium-risk regimes, including internal-use systems, office-support tools, technical editing applications, certain back-end processing systems, and AI systems used in artistic, gaming, cinematic, or other creative contexts. Providers must also review and
June 5, 2026
On May 11, 2026, Thailand’s Ministry of Social Development and Human Security released a draft Child Protection Act (“CPA”) for public review. The draft CPA would completely repeal and replace the current Child Protection Act B.E. 2546 (2003). This represents the most comprehensive overhaul of Thailand’s child protection framework in over two decades, reflecting the government’s stated objective of modernizing the law to address evolving social challenges—including those arising from digital technology—and to promote greater coordination among government agencies, local authorities, and civil society. The public review period closes on June 9, 2026. Key changes introduced by the draft CPA that could have significant implications for businesses, particularly online platform providers, media companies, and entities operating child-related services in Thailand, are set out below. Expanded Definition of “Child” Under the current CPA, a “child” is defined as a person under the age of 18, excluding those who have attained legal majority through marriage. The draft CPA removes the marriage exception entirely, broadening the scope of the law’s protections to include all individuals under 18 without exception. Replacement of “Abuse” with Broader Concept of “Violence” The current CPA uses the term “abuse/cruelty,” which covers acts causing harm to a child’s liberty, body, or mind; sexual offenses against children; and using children in harmful or immoral activities. The draft CPA replaces this with the broader concept of “violence,” which encompasses any act or omission causing harm to a child’s body, mind, or development; abandonment or neglect; improper exploitation; and sexual abuse. Notably, the new definition adds developmental harm as a recognized category of injury and captures all forms of misconduct regardless of the child’s consent. New Standalone Definition of Sexual Abuse, Including Online Conduct One of the most significant additions in the draft CPA is the introduction of a standalone definition
May 25, 2026
After several years of policy discussion and continued efforts led by the Ministry of Commerce (MOC) to relax the list of reserved businesses under the Foreign Business Act B.E. 2542 (1999) (FBA), the reform process has now reached a significant milestone. On May 12, 2026, the Thai cabinet approved in principle two draft subordinate legislative instruments aimed at delisting certain reserved business activities under the FBA and reducing licensing requirements for foreign business operators. These developments signal a renewed and concrete effort by the government to modernize Thailand’s business regulatory framework in order to attract foreign investment and boost Thailand’s competitiveness in the global market. Nine Businesses Set for FBA Delisting Below is a list of the nine businesses that are being targeted for delisting from the FBA’s restrictions. A draft ministerial regulation would delist the first eight reserved businesses, while a royal decree has been drafted to delist the ninth business: Telecommunications services (Type 1 license only, covering operators without their own telecommunications infrastructure), under the supervision of the Office of the National Broadcasting and Telecommunications Commission. Treasury center services subject to the Foreign Exchange Control Act B.E. 2485 and under the supervision of the Bank of Thailand. Securities-collateralized lending, pursuant to the laws governing securities and exchange and derivatives regulated by the Securities and Exchange Commission. Agency, dealer, advisory, or fund management services relating to derivatives where the underlying assets fall outside the scope of the Derivatives Act B.E. 2546 (2003) Intra-group shared services, including administrative, human resources, and IT functions Intra-group domestic debt guarantee services Leasing of partial space for installation of financial service machines and automatic vending machines for employee use Petroleum drilling services Trading of agricultural product derivatives through a futures exchange, with physical delivery or receipt of agricultural products at a futures exchange–designated
May 25, 2026
Thailand published new rules on May 1, 2026, establishing clear procedures for how the Anti-Money Laundering Office (AMLO) handles digital assets seized during criminal and money laundering investigations. Taking effect the following day, the Regulation of the Anti-Money Laundering Board on the Custody and Management of Seized or Frozen Assets (No. 3) B.E. 2569 applies to digital asset businesses, cryptocurrency holders, and anyone subject to asset seizure under Thailand’s anti-money laundering laws. For the first time, authorities now have a detailed roadmap for transferring seized digital property from private or foreign control into secure state custody. Digital asset businesses holding customer assets under investigation must be prepared to comply with these rules compelling repatriation of such assets in enforcement actions. Expanded Definition of Digital Assets The regulation defines digital assets to include not only those covered by Thailand’s existing digital asset business law but also any other property that can be stored using the same methods as digital assets. This broad formulation means the custody rules will apply to emerging blockchain-based assets and tokenized property that may not yet fall within the statutory definition of a digital asset business, giving authorities flexibility as the technology evolves. Mandatory Transfer to Domestic Custody When digital assets are held with service providers outside Thailand, AMLO will first attempt to transfer them to an account the office maintains with a licensed domestic digital asset business operator. If the domestic operator does not support that particular asset, the office will instead move the assets to its own cold wallet (offline, internet-isolated storage system). If neither option is feasible, the seizing official will report the situation to the Anti-Money Laundering Committee for alternative instructions. A similar hierarchy governs assets held in an accused party’s private wallet or by any third party that is not a