You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

//
INSIGHTS

Insights

We provide you with all of the latest legal developments in Southeast Asia, ensuring that you have the up-to-date knowledge you need to navigate the ever-changing legal landscape affecting your business. You can browse our entire library of publications below, and email [email protected] to sign up for updates that are relevant to your interests, delivered straight to your mailbox, as they emerge.

Search Insights

  • Order by
  • Reset

Search Results

0 results found

August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with over 100,000 users are required to
August 1, 2025
Tilleke & Gibbins has contributed the Vietnam chapter to Corporate Governance 2025, part of the International Comparative Legal Guides (ICLG) series published by Global Legal Group. This respected guide offers comprehensive, jurisdiction-specific overviews of corporate governance laws and practices around the world. Each jurisdictional chapter follows a clear Q&A format, providing practical insights into critical issues such as: Sources of corporate governance regulation Shareholders’ rights, powers, and responsibilities Structure and duties of management bodies Stakeholder involvement in governance Transparency and reporting requirements ESG and sustainability-related obligations Cybersecurity and technology-related disclosures The Vietnam chapter was authored by Tram Ngoc Bich Nguyen, Truc Thi Thanh Tran, Dung Thi Phuong Le, and Quang Minh Vu, members of Tilleke & Gibbins’ corporate and commercial team in Ho Chi Minh City. The authors provide detailed analysis of Vietnam’s corporate governance framework, including recent developments such as the 2025 amendments to the Law on Enterprises requiring disclosure of ultimate beneficial ownership and the increasing emphasis on sustainable business practices and responsible corporate conduct. The chapter also discusses practical considerations for foreign investors in Vietnam, such as overlapping signing authorities between key company officers, enforcement of shareholders’ agreements, and disclosure obligations related to ownership and management roles. The complete Vietnam chapter is available as a PDF below. The Vietnam chapter—and the full Corporate Governance 2025 guide—are also freely available on the ICLG website.
August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention and response to cyber threats and incidents, with
July 31, 2025
The Madrid System for international trademark registration provides the opportunity for a simplified and cost-effective way to register trademarks in multiple countries through a single application. Indonesia joined the Madrid System in 2018, and in 2024 alone, it received over 8,600 applications through this system. Despite the system’s effectiveness, it is important for trademark owners to be aware of the potential risks of refusal that can arise during the process of registration. Trademark applicants must pay close attention to these critical points when designating Indonesia. Appointing a Local Representative to Respond An applicant or representative of an international registration (IR) application that has been provisionally refused must appoint a local Indonesian representative in order to submit a response to the provisional refusal. This appointment is solely for the purpose of responding to the refusal in Indonesia; it is not necessary if the IR has not received any rejection. Furthermore, the local representative should not be registered with WIPO, as doing so would affect representation across all designated countries. Timing When it comes to calculating the deadline for responding to a provisional refusal, there is a discrepancy between the methods used by the DGIP and WIPO. Under the Indonesian Trademark Law, trademark owners can file a response within 30 working days, excluding weekends and national holidays. However, the WIPO cover letter accompanying the DGIP’s provisional refusal notice specifies both the start date and the deadline for responding to the notification, which is calculated as 30 calendar days, including weekends and national holidays. Therefore, a response to the provisional refusal of IR should be submitted in accordance with the WIPO cover letter to prevent any formality issue. Grounds for Refusal After an IR application is published in Indonesia’s Trademark Gazette, it undergoes substantive examination by the Directorate General of Intellectual Property (DGIP) examiners. The trademark is primarily assessed against absolute
July 30, 2025
Artificial intelligence (AI) model training and data scraping are essential processes in the development of modern AI systems. AI model training involves using large datasets to teach machine learning algorithms to recognize patterns, make predictions, or generate new content. Data scraping refers to the automated extraction of information from websites or digital sources, often to assemble the vast datasets required for effective AI training. As these practices become more widespread, questions about the legality of using third-party content—especially copyrighted works—have become increasingly important. In Thailand, the legal landscape for AI developers is shaped primarily by the Copyright Act, which presents unique challenges due to the absence of a fair-use exception. This article examines the copyright-related risks and legal uncertainties facing AI developers under Thailand’s current copyright law and practices, offering strategic guidance for navigating this complex environment. Copyright Risks in AI Scraping and Training Thailand’s Copyright Act does not provide a broad fair use or fair dealing exception, unlike some other jurisdictions, such as the United States. This absence has significant consequences for AI developers: No general defense for AI training: Any use of copyrighted material for AI model training is presumed to be infringing unless a specific, narrow statutory exception applies or explicit permission is obtained from the rights holder. There is no general legal basis for using copyrighted works in AI training without authorization. Increased rights clearance burden: Developers must identify and secure licenses for every copyrighted work included in their training datasets. Given the scale and diversity of data required for effective AI models, this process can be both impractical and costly. Legal ambiguity and litigation risk: The lack of clear statutory guidance or case law leaves developers in a legal gray area. There is no established precedent clarifying whether certain uses of copyrighted material for AI training might be tolerated or
July 25, 2025
現代のビジネス戦略が持続可能性が重視されるようになり、ESG原則の影響は商品デザイン、パッケージ、そしてブランド保護に新たな形を与えている。タイにおけるラベルレスボトルから立体商標の法的重要性まで、これらの動向は環境責任と知的財産の結びつきの深まりを浮き彫りにしている。 ESGの台頭 ESG原則は、世界中でビジネス戦略を策定する上で不可欠な要素となっている。企業はESGデータを開示することをますます要求され、これは投資家の意思決定、融資、そして消費者行動に影響を与えている。調査によると、消費者は持続可能なパッケージに対してより多くのお金を払う意思があり、ESGへの取り組みに力を入れている企業は高い成長率を達成する傾向がある。 プロダクト・ミニマイゼーションのトレンド 大きな変革を経験している分野の一つが消費財業界で、世界中のブランドがESG原則に沿ったパッケージを採用している。注目すべき取り組みの一つはパッケージの小型化で、pepsiが2022年に中国で初めてラベルレスPETボトルを導入したことがその好例である。同様にタイでは、SPRINCLEの飲料水「Redesign to Reduce」および同様のイニシアチブをはじめ、複数のボトル・ウォーターのブランドがラベルレス・デザインを採用している。 こうした変化はブランドイメージの向上だけでなく、消費者やビジネスパートナーからも温かく歓迎されている。例えば、キャセイパシフィック航空は、機内リサイクル活動の強化に向けた継続的な取り組みの一環として、一部のフライトと客室でラベルフリーのボトル・ウォーターを導入した。 立体商標でデザインから識別性へ パッケージはブランド・アイデンティティの重要な要素へと進化し、機能性と識別性を融合させることで消費者の認知度とロイヤルティを高める。この変化は知的財産に大きな影響を及ぼしている。これらのデザインは、その高い商業的価値を考えると、もはやオプション的なものではなく、不可欠な要素である。意匠権や立体商標などを介して法的保護を確保することは、戦略的に不可欠な要素となっている。持続可能性とイノベーションが重視される時代において、識別可能なパッケージを保護することは、単なる予防措置ではなく、競争優位性を維持し、ブランドの永続的な成功を確保するための基本的なステップである。 タイでは、商標法により、幅、高さ、奥行きを含む物体の立体的な形状を表す立体商標を登録することができる。立体商標が登録されるためには、識別性、つまりある事業者の商品またはサービスを他の事業者の商品またはサービスと区別できる特徴を示すことが必要がある。ただし、その形状は、単に商品の本質的な形状を反映したもの、または技術的機能を実現するために不可欠なデザインであってはならない。 その構成に固有の識別力が欠けているとしても、継続的かつ広範囲な使用を通じて消費者の幅広い認知を得ている場合は、登録が認められる可能性がある。このような場合、企業は、そのデザインが商品の出所を強く識別する役割を果たしていることを証明する必要がある。このプロセスでは通常、マーケティング資料、広告記録、流通データなど、消費者の認知を効果的に裏付ける包括的な証拠を収集する必要がある。注目すべき例として、イタリアの高級ブランドであるBulgariは、独自の円形状物が勘合する香水瓶のデザインをタイで立体商標として登録することに成功した。 重要なポイント 企業がパッケージ戦略やブランディング戦略に持続可能性を組み込む傾向は、ますます強まっている。環境に配慮した取り組みの一環として、ミニマルでラベルレスなデザインが世界中で人気を集めている。個性的なパッケージデザインは、ブランド・アイデンティティを定義する上で重要な役割を果たし、商標法の下、法的に保護され得る。タイでは、立体商標として保護されるためには、デザインが識別性または消費者の認知度の高さを示す必要があり、多くの場合、マーケティング記録や流通データなどのたくさんの証拠によって裏付けらる。これらの法的要件を早期に理解することで、企業はブランド・アイデンティティを守るための積極的な対策を講じることができる。商品の出所を自然に伝えるデザインについては、ESG(環境(Environment)、社会(Social)、企業統治(Governance))が重視される今日の環境において、法的保護を求めることが最優先事項である。   備考:本和文は英文記事を翻訳したものです。原文については、以下のリンクをご参照ください。 The Rise of ESG and Its Implications for 3D Mark Protection in Thailand            
July 25, 2025
On June 17, 2025, the National Assembly of Vietnam adopted Law No. 76/2025/QH15 (Amended LOE) amending and supplementing the 2020 Law on Enterprises, which aims to reshape the legal framework to enhance transparency and alignment with international standards. The Amended LOE took effect from July 1, 2025. Below are key notes on the Amended LOE. Recognition of Beneficial Owners The beneficial owner (BO) concept was previously addressed under Vietnam’s anti-money laundering framework. However, the formal recognition of a BO in the Amended LOE marks a pivotal advancement in embedding ownership transparency into corporate governance, in line with the G7 Financial Action Task Force’s standards on anti-money laundering and counter-terrorism financing. Under the Amended LOE and Decree No. 168/2025/ND-CP of the government dated June 30, 2025, on enterprise registration (Decree 168), a BO is identified through either equity ownership or control rights. Equity ownership: Individuals holding 25% or more of a company’s charter capital or voting shares, either directly or indirectly, qualify as BOs. Indirect ownership is further defined as ownership of at least 25% of charter capital or voting shares through an intermediary organization. Control rights: Individuals with the authority to make or influence major decisions are considered BOs. The actual control over a company includes the power (i) to appoint or remove most or all members of the board of directors or the members’ council or the general director of a company; (ii) to amend the charter; or (iii) to decide other key matters specified in the company’s charter. Notably, individuals representing state ownership in state-owned enterprises are excluded from the scope of the BO concept. Companies are responsible for collecting, updating, and retaining information about BOs and cooperating with authorities when requested to identify BOs, among other obligations. Additionally, any companies registered before July 1, 2025, must submit a list of their BOs when
July 25, 2025
Over the first half of 2025, the government of Vietnam has implemented a comprehensive suite of legislative reforms that significantly impact the country’s intellectual property (IP) framework. These amendments, most of which took effect on 1 July 2025, span the criminal, civil, administrative, and judicial sectors, and are part of a broader initiative to modernize Vietnam’s legal infrastructure, strengthen enforcement mechanisms, and harmonize domestic regulations with international standards. A summary of the key legislative changes and their potential implications for IP protection and enforcement across Vietnam is provided below. Criminal Code: Stricter penalties Under the 2025 amendments to Vietnam’s Criminal Code, penalties for offenses involving the manufacturing and trading of counterfeit goods have been significantly escalated. Individuals convicted of such violations now face fines ranging from VND 200 million to VND 2 billion (approximately USD 7,700 to USD 77,000; up from VND 100 million to VND 1 billion). For corporate entities, the penalties are even more severe, with fines ranging from VND 2 billion to VND 40 billion (roughly USD 77,000 to USD 1.54 million; up from VND 1 billion to VND 20 billion). These heightened penalties reflect the government’s intensified efforts to deter counterfeit-related crimes and protect consumer rights. Law on Handling Administrative Violations: Extended statute of limitations and application of electronic procedure The statute of limitations for addressing administrative violations in the IP sector is still two years. However, in cases where such violations are referred by procedural authorities, this period is extended by one year. The time taken by these authorities to process the case is now included within the overall limitation period. In addition, the Law on Handling Administrative Violations facilitates the use of electronic procedures, provided that the necessary infrastructure, technical systems, and information conditions are in place. Specifically, enforcement authorities are now permitted to deliver decisions, records, and related