You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

Athistha (Nop) Chitranukroh

Partner and Director, Corporate and Commercial

Biography

Nop Chitranukroh is a partner and director of Tilleke & Gibbins’ corporate and commercial group. She is one of the leaders of the firm’s technology and insurance teams and regularly advises clients across industries on a wide range of regulatory compliance matters relating to cybersecurity and data privacy, fintech, insurance, insurtech, and payments. She also represents multinational and local financial services, payments, and technology industry clients on a range of strategic matters, including market entry, M&As, and ongoing compliance across Southeast Asia.

Prior to joining Tilleke & Gibbins, Nop served as Thailand general counsel of an American multinational corporation, listed on the New York Stock Exchange, where she oversaw all operations within the legal department in Thailand. Nop was previously Asia-Pacific regional counsel for the same multinational finance and insurance corporation, based in Singapore. She has also served as a legal counsel at an industry-leading Irish-American financial services and software-as-a-service (SaaS) provider of payment processing software and related application programming interfaces (APIs) for e-commerce websites and mobile applications.

Widely recognized as a top practitioner in insurance and TMT legal practice in Southeast Asia, Nop is ranked as a leading lawyer in technology by Chambers Asia-Pacific, a Next Generation Partner in TMT by The Legal 500, a leader for data in Who’s Who Legal Southeast Asia 2022-2024. Most recently, Nop has been named to the Asia Super 50 TMT Lawyers 2023 and 2024 list by Asian Legal Business from Thomson Reuters. Nop has been appointed as the Knowledge Network Chair from IAPP for Thailand for 2024-2026. In 2023, Nop was named one of Asia Super 50 TMT Lawyers by Thomson Reuters’ Asian Legal Business.

Nop is a Certified Information Privacy Professional/Asia (CIPP/A) with the International Association of Privacy Professionals (IAPP) and serves as an advisory board member of Insurtech Asia. She has acted as a legal advisor for the Thailand Insurance Association for more than a decade.

Experience

  • Advising a multinational American corporation listed on the S&P 500 on a number of M&A transactions, including its corporate restructuring in Thailand, conversion into a public company, transfer of an entire business to one of its Thai entity and a joint venture arrangement.
  • Advising one of the world’s largest international insurance broker groups on its M&A and corporate restructuring in Thailand, including a joint venture arrangement with Thai investors and investment structuring in the Indochina region.
  • Advising one of the world’s largest search engine companies on setting up operations in Thailand, including drafting, negotiating, and reviewing an extensive range of business and technology transactional arrangements. This includes setting up the client’s insurtech and fintech business partnership with a local business operator.
  • Assisted a British insurance broker in an insurtech matter, involving setting up its online insurance products marketplace in Thailand and advising on business arrangement structures with all of the top ten leading motor insurers in the Thai market.
  • Advising a global technology company, based in Asia, on regulatory matters related to beacon devices, over-the-top (OTT) businesses, and data privacy regulatory requirements.
  • Advising a global social media/technology company, based in Korea and Japan, on one of its largest joint venture arrangements with one of the largest local mobile carriers and transportation operators for its e-payment system and fintech-related business in Thailand.
  • Advised one of the largest property and casualty insurers on a facultative reinsurance placement for a USD 870 million hydroelectric energy project involving parties from Thailand and Laos.
  • Providing advice to a leading American broadband and telecommunications company on the launch of its fintech business in Thailand, and on data privacy regulatory matters.
ABOUT Athistha (Nop)

Practices

Corporate/M&A

Locations

Languages

    Thai

    English

Education

    LLM, University of Wisconsin

    LLM, Georgetown University

    LLB, Chulalongkorn University

Insights

August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must
July 28, 2026
Data protection officers (DPOs) have become a fixture of Thailand’s privacy compliance landscape since the Personal Data Protection Act B.E. 2562 (2019) (PDPA) took full effect and the Office of the Personal Data Protection Committee (PDPC) began requiring certain organizations to appoint them. On July 7, 2026, the Office of the PDPC presented draft guidance on DPOs as part of a public consultation on a series of draft personal data protection manuals and recommendations. The draft offers the clearest indication yet of how the regulator expects the DPO role to work in practice, addressing recurring implementation issues under the PDPA—including when an organization must appoint a DPO, how the DPO should operate independently, how to manage conflicts of interest, and how data subjects and regulators should be able to contact the DPO. Because it remains in draft, organizations have an opportunity to weigh the practical implications now before the guidance is finalized. When a DPO Must Be Appointed The draft guidance clarifies the triggers for mandatory DPO appointment, including: Regular and systematic monitoring of personal data or systems on a large scale, such as tracking, analyzing, or predicting behavior, attitudes, or individual characteristics. Core activities involving large-scale processing of sensitive personal data, such as health data, biometric data, or criminal records. Certain foreign-organization representative arrangements. Public-sector coverage under relevant notifications identifying government entities that must appoint a DPO. Processing involving 100,000 or more data subjects may be considered large-scale. The guidance also contemplates voluntary DPO appointment for organizations that wish to raise their privacy governance standards, and such organizations should still comply with the standards applicable to DPOs under the law. Independence and Reporting Lines The draft guidance identifies lack of DPO independence as a core risk because an ineffective or constrained DPO may be unable to raise deficiencies
July 21, 2026
Thailand’s Ministry of Digital Economy and Society (MDES) published a notification establishing an expedited court-ordered takedown mechanism for online content in cases of “urgent necessity.” The notification, which was issued on July 17, 2026, under the Computer Crime Act B.E. 2550 (2007), as amended, took effect the following day. It significantly expands the categories of content subject to rapid government-initiated removal. Content Categories Subject to Takedown The notification defines “urgent necessity” (section 20, paragraph 5, of the Computer Crime Act) as circumstances where any delay in suppressing computer data may impact national security, religion, the monarchy, good morals, social culture, or public order. In this regard, it establishes four broad categories of content: Computer Crime Act offenses. National security offenses. IP and other criminal offenses, where it is contrary to public order or good morals and a competent officer has requested its suppression. Content contrary to public order or good morals, a broad residual category encompassing 14 subcategories approved by the Computer Data Screening Committee. The fourth category is the most expansive. Its 14 subcategories include: Content defaming, mocking, satirizing, or devaluing the monarchy. Online gambling advertising or facilitation. Offering illegal firearms for sale. Offering baraku (hookah) products or e-cigarettes for sale. Offering cannabis inflorescences or processed cannabis products for sale. Advertising or soliciting prostitution. Content inciting violence, hatred, or social division. Unauthorized overseas employment advertising. Offering boiled kratom juice for sale. Online sale or advertising of alcoholic beverages. Content satirizing or degrading Buddhism. Money lending at interest rates exceeding legally prescribed limits. Advertising or disseminating information about surrogacy services. Forgery of documents, cards, or official documents. Enforcement Procedure In cases of urgent necessity, a competent official assigned by the MDES permanent secretary must file a petition with supporting evidence to the court with jurisdiction, requesting an order to
July 20, 2026
On July 16, 2026, Thailand’s Personal Data Protection Committee (PDPC) published a notification in the Government Gazette establishing detailed rules governing data subjects’ right of access under section 30 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notification will take effect 60 days after publication—mid-September 2026—giving data controllers a limited window to bring their processes into compliance. Scope The notification covers requests to access or obtain copies of personal data and requests for disclosure of the source of data collected without consent. Data subjects may exercise their rights directly or through authorized representatives. Key Requirements Important requirements set by the notification include the following: Required request channels. Controllers must provide at least two request channels: direct submission at the business location and registered mail. Electronic channels are optional but, if offered, may also be used for fulfilling requests. Request contents. Requests must be in writing or in electronic form and include the data subject’s name, the preferred access method, details of the data requested, and the requester’s signature. Controllers may request additional identifying information as needed. Identity and authority verification. Controllers may require official identity documents for verification. Authorized representatives must provide authorization documents and identity documents for both the data subject and the representative. Alternative verification methods (e.g., digital authentication) are permitted if they do not unreasonably obstruct data subjects’ rights. Review and response timelines. Controllers must review requests within 15 days. If the request is incomplete, the controller must notify the requester and allow at least 15 days to correct deficiencies. If not corrected, the request may be treated as abandoned. Once verified, controllers must fulfill requests within 30 days, extendable by another 30 days for large-volume or complex requests with notice to the requester. Methods for providing access or copies. Controllers may fulfill

Awards & Rankings

July 22, 2026
Tilleke & Gibbins has been named Best Insurance Law Firm in Thailand in the InsuranceAsia News Country Awards for Excellence 2026. This is the firm’s first recognition from InsuranceAsia News, and Tilleke & Gibbins was the sole law firm honored in the Thailand awards. The award recognizes the strength of Tilleke & Gibbins’ insurance practice and the team’s work advising clients in the sector. InsuranceAsia News selected the winners based on submission reviews, independent research, market knowledge, and analysis by the publication’s judging panel. InsuranceAsia News provides news, analysis, and market intelligence for insurers and related organizations across Asia. For more information and to view the full list of winners, please visit the InsuranceAsia News website.
May 11, 2026
Tilleke & Gibbins has been recognized in five practice areas at the Asia Business Law Journal (ABLJ) Vietnam Law Firm Awards 2026, reflecting the firm’s continued strength across a range of legal disciplines in Vietnam. The firm received honors in the following categories: Artificial Intelligence Data Compliance and Cyber Security IP Litigation Labor & Employment Technology, Media & Telecommunications The ABLJ Vietnam Law Firm Awards highlight leading law firms across key practice areas, with multiple firms typically recognized in each category. The 2026 edition marks the fourth year of the awards program. These recognitions underscore the work of Tilleke & Gibbins’ Vietnam-based teams, particularly in technology-driven and regulatory-focused areas of practice. For more details and the full list of winners, please visit the ABLJ website.
April 3, 2026
Tilleke & Gibbins is pleased to announce that the firm has been shortlisted in two categories at the Financial Times (FT) Innovative Lawyers APAC 2026 awards: Innovative Lawyers in Cyber and Data Privacy – “Digital Identity & Cryptocurrency Compliance” Innovative Practitioner – Athistha (Nop) Chitranukroh The FT Innovative Lawyers APAC Awards recognize law firms and practitioners who are driving innovation in legal services and delivering innovative client solutions across the Asia-Pacific region. This recognition marks our third acknowledgment in the Innovative Lawyers category and, notably, our first-ever nomination in the Innovative Practitioner category at the FT Innovative Lawyers APAC awards. It reflects our team’s continued ability to support clients on groundbreaking, forward-looking projects across the region. The awards ceremony will take place on May 14, 2026, in Hong Kong. To learn more about the FT Innovative Lawyers APAC 2026 awards and to view the full list of shortlisted organizations, please visit the FT website.

Other Professionals