You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 19, 2011

Yesteryear – Bangkok in 1956: What Was It Like When AMCHAM Thailand Was Founded?

AMCHAM 50th Anniversary

In this text of a presentation for the 50th anniversary of the American Chamber of Commerce in Thailand, David Lyman reflects on the changes he has observed in Thailand in the 50 years since AMCHAM’s founding.

RELATED INSIGHTS​ 

January 14, 2025
Thailand’s Department of Industrial Works (DIW) has issued a new regulation (Ministerial Regulation Re: Designation of Type, Kind, and Size of Factories (No. 3) B.E. 2567 (2024)), which removes the factory license requirement for electricity generation from solar energy installations on rooftops, roof decks, or any part of a building used for residential or other purposes, regardless of capacity. The new rules took effect on December 28, 2024. Under the previous regulations, solar rooftop installations had to seek approval from the DIW if their capacity exceeded 1,000 kW (1 MW), which added time and administrative costs when adopting renewable energy solutions. Benefits and Further Compliance The updated regulation benefits industrial operators by facilitating faster installation times and lower costs, as solar rooftops can now be installed without the need for prior approval of a factory license from the DIW. Operators can now more easily contribute to environmental sustainability and carbon reduction efforts. Despite the lifting of the factory licensing requirement, other compliance obligations, such as an energy business license (or exemption from an energy business license), a controlled energy production license, and a construction permit, may still apply. Reason for the Change Removing the classification of rooftop or building-installed solar power plants as factories aligns with Thailand’s renewable energy goals and reduces regulatory burdens for industrial operators. Additionally, it supports the achievement of energy policies aligned with the UN’s Sustainable Development Goals and Thailand’s international commitments to reduce greenhouse gas emissions through the participation of all sectors. For further details on how this change affects business operations or to explore strategies for renewable energy implementation, please contact Supasit Boonsanong at [email protected], Charuwan Charoonchitsathian at [email protected], or Phareeya Yongpanich at [email protected].
January 13, 2025
The State Bank of Vietnam’s Circular No. 50/2024/TT-NHNN regulating safety and security for the provision of online services in the banking sector (“Circular 50”), issued on October 31, 2024, took effect on January 1, 2025, with delayed effectiveness for certain provisions on (i) network, communication, and security systems, online banking application software, and mobile banking application software (July 1, 2025); (ii) transaction confirmation for payment transactions conducted via the straight-through processing method (January 1, 2026); and (iii) authentication forms and reporting obligations (July 1, 2026). The cybersecurity situation in Vietnam is complicated, and the banking and finance sector has been one of the top targets of high-tech criminals. Circular 50 seeks to enhance user protection by expanding the technical requirements to more services in the banking sector as well as standardizing how transactions are authenticated. Expanded Scope of Services Covered Previous regulations on safety and security of online services in the banking sector only covered banking services and intermediary payment services. Circular 50 expands the scope to include other services of credit institutions and foreign bank branches such as credit information services, foreign exchange services, securities depository services, and services related to factoring and letters of credit, which now need to comply with technical requirements and standards for online services such as firewalls and DMZ network barriers. Risk-Based Approach to Authentication Circular 50 sets out standards for payment transactions and card transactions by: Classifying various online transactions based on the type of client, the purpose of the transfer, the value of the specific transaction, and the total value of certain transactions during the day; and Applying various types of authentication for the corresponding types of online transactions, e.g., using passwords or PINs for small-value online transactions, and using OTPs (through SMS, voice, or email), biometric matching, or e-signatures for
January 10, 2025
On January 8, 2025, Thailand’s Office of the Personal Data Protection Committee published two notifications in the Government Gazette—one for data controllers and the other for data processors—concerning exemptions for data controllers and data processors from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019). The notification for data processors took effect on January 9, 2025, the day after its publication. The notification for data controllers will take effect on April 8, 2025. The content of these notifications is identical to that in the draft versions of the notifications previously released for public consultation in October 2024. For more information on the ROPA exemptions for data controllers and data processors, or on any aspect of personal data protection in Thailand, please contact Nopparat Lalitkomon at [email protected] or Wilin Somya at [email protected].
January 9, 2025
On January 1, 2025, Myanmar’s State Administration Council enacted Cybersecurity Law No. 1/2025, which aims to regulate various aspects of digital security and online activities. The law has not yet been implemented and will come into force on a date specified by the Myanmar president, who will also provide an official adoption and compliance timeline for individuals and organizations impacted by the new regulations. Below are some of the key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The