You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

//
INSIGHTS

Insights

We provide you with all of the latest legal developments in Southeast Asia, ensuring that you have the up-to-date knowledge you need to navigate the ever-changing legal landscape affecting your business. You can browse our entire library of publications below, and email [email protected] to sign up for updates that are relevant to your interests, delivered straight to your mailbox, as they emerge.

Search Insights

  • Order by
  • Reset

Search Results

0 results found

March 12, 2024
タイの国家サイバーセキュリティ委員会(NCSC : National Cyber Security Committee)は、2024年1月18日にサイバーセキュリティ法に基づく3つの通知を発表し、主要な組織と資産に対するサイバーセキュリティ関連の要件を設定した。これらの通知のうち1つは既に施行されているが、最も注目すべき2つは2025年1月18日(すなわち、官報に掲載された日から1年間した日)に施行する。 これら2つの通知は、NCSC Notification Re: Standards for Defining the Security Category for Data or Information Systems B.E.2566(2023)(「データ・情報システムのセキュリティカテゴリに関する通知」)とNCSC Notification Re: Minimum Standards for Data and Information Systems B.E.2566(2023)(「データ・情報の最低基準に関する通知」)である。 これらの通知は次の場合に適用される。 国家機関 監督又は規制機関(すなわち、国家機関、民間機関、あるいは、国家機関又は重要な情報基盤組織の業務を規制又は監督するために法律によって指定された個人) 重要情報基盤組織(すなわち、国家安全保障、重要な公共サービス、銀行及び金融、情報技術及び電気通信、輸送及び物流、エネルギー及び公益事業、並びに公衆衛生に関連する又はこれらを提供する組織) 上記は、通知の下でまとめて「組織」として定義される。 セキュリティカテゴリに関する通知 セキュリティカテゴリに関する通知は、「組織」のデータ又は情報システムのリスクベースのセキュリティ分類、つまり「セキュリティカテゴリ」を示している。 セキュリティカテゴリの評価のために、組織は、3つの主要なセキュリティ目標(つまり、機密性(confidentiality)、完全性(integrity)、可用性(availability))に基づいて、データ・情報システムの自己評価を実行することが要求される。これらの各目標は、以下の分野における潜在的影響の評価を考慮して、さらに3つのリスクレベル(低、中、高)に分類される。 組織の財務的価値又は評判 組織のサービス利用者数 組織の職務遂行能力 国家の安定又は公の秩序 3つの目的のリスクレベルは、以下に説明するように、「最小限(minimal)」、「重度(severe)」、又は「深刻(serious severe)」に影響があるかどうかを考慮して決定される。 機密保持(異なる基準に従って「機密」として分類されるデータは含まれない):データの不正開示が組織の評判や財務的価値に及ぼす影響 完全性:データの不正な変更又は破壊が組織のパフォーマンスに及ぼす影響 可用性:データ・情報システムにアクセスできない、又は使用できないことが組織のパフォーマンスに与える影響 組織のシステムが異なるカテゴリのデータを扱う場合、組織は、各タイプを評価し、特定された最も高いリスク・レベルに基づいてセキュリティカテゴリを設定しなければならない。 セキュリティカテゴリは、少なくとも3年に1回見直しを行い、その結果を適切に記録すべきである。 最低基準に関する通知 セキュリティカテゴリが決定された後、組織は、最低基準に関する通知に規定された最低限のサイバーセキュリティ対策を適用する責任を負う。これらの対策の概要を次の表に示し、各セキュリティカテゴリの最低限のサイバーセキュリティ対策に必要な項目を示す。 サイバーセキュリティ法にの詳細については、Athistha (Nop) Chitranukroh ([email protected]), Nopparat Lalitkomon ([email protected]), Napassorn Lertussavavivat ([email protected]), 又はRada Lamsam ([email protected])までお問い合わせください。   備考:本和文は英文記事を翻訳したものです。原文については、以下のリンクをご参照ください。 Thailand Lays Out New Cybersecurity Standards
March 12, 2024
Thailand’s Ministry of Finance has issued the Notification re: Criteria, Methods and Conditions for Applying for and Issuing Licenses to Operate Virtual Bank Business, which was published in the Government Gazette on March 4, 2024. This notification opens an opportunity for qualified experts in technology, digital services, and diverse data usage fields to apply for virtual bank licenses to provide financial services through new digital channels. The main goal is to serve the financial needs of target groups that may not have received sufficient or tailored financial services from the traditional banking system. Licensing Timeline Application submission period: 6 months (March 20–September 19, 2024). Announcement of successful applicants: Mid-2025 (approx. 9 months–1 year from the end of the submission period) After the announcement, successful licensees must demonstrate their readiness to commence virtual bank operations within 1 year (extendable for up to 1 additional year) via the following: Having paid-up registered capital of THB 5 billion and plans to increase the paid-up registered capital to at least THB 10 billion after the initial business period; Establishment or adjustment of a financial business group; Procurement of human resources, IT systems, and relevant risk management tools. Number of Licenses to be Issued No written or specified limit, subject to the discretion of the Bank of Thailand (BOT). Key Qualifications Applicants must have the following: Experience and resources to support virtual banking operations according to the business model and plan. Expertise and experience in conducting business that utilizes technology and provides services through digital channels. Experience demonstrating the ability to obtain, access, manage, and utilize data, including development of systems or data connections to facilitate user activities, allowing them to use their data to conduct transactions with other providers. Criteria In assessing applicants’ qualifications for a virtual bank license, the BOT will consider the following criteria: Whether the applicant possesses the key qualifications; Whether the applicant can conduct business operations following
March 11, 2024
The Thai government has released an updated draft Liability for Defective Goods Act after the Office of the Consumer Protection Board completed its second round of public hearings on the law in December 2023. The draft law sets out a new liability regime for different types of goods, and is being drafted in response to concerns over inadequate protection for buyers and the current lack of clear liability regulations for defective goods. Key Points in the Draft Act The latest draft introduces new and broader definitions for “seller” and “buyer,” which replace “business operator” and “consumer” as defined in the previous draft. The act will apply to and govern hire-purchase contracts and sales contracts and will have retroactive effect on agreements that were made before the act’s effective date. The draft’s new liability regime has the following characteristics: Liability provisions are specified for different categories of goods while excluding used products and living animals. Sellers are presumed to be at fault for defects that exist at the time of delivery, with specific timelines and conditions for (1) automobiles and motorcycles; (2) electrical appliances, electronic devices, and mechanical devices; and (3) other products. Agreements made before the discovery of a defect are deemed void if they conflict with the act or unfairly burden buyers. The latest draft also sets new prescription periods: For the “other products” category, the prescription period is one year from the discovery of a defect or from the seller’s agreement to repair, replace, or reduce the sale price. For the “automobiles and motorcycles” and “electrical appliances, electronic devices, and mechanical devices” categories, the prescription period is two years under similar conditions. Now that the draft Liability for Defective Goods Act has passed the public hearing stage, its potential impact on the public is being assessed further before the draft continues moving through the legislative process. For more details
March 11, 2024
Tilleke & Gibbins is pleased to announce the release of Company Directors in Thailand: Guidelines and Q&A on Duties and Liability. This publication is a go-to resource for prospective and existing company directors who need to understand the duties and liabilities that come with assuming this important corporate role. Authored by Kobkit Thienpreecha, partner and director of the firm’s corporate and commercial department, Company Directors in Thailand provides key information topics essential for companies and their directors to know as they engage in the Thailand market. In the guide, Kobkit, who regularly leads training sessions on directors’ liability for directors at many of the top companies in Thailand, gives an overview of directors’ role and responsibilities as well as the civil and criminal liabilities they could potentially face. This is followed by a Q&A section that directors frequently ask regarding their liability and the legal actions that could be brought against them. The full guide can be downloaded as a PDF through the button below.
February 28, 2024
Experts on real estate law from Tilleke & Gibbins provided the chapter on Vietnam for Practical Law’s Commercial Real Estate Global Guide 2024, a comparative jurisdictional guide in Q&A format giving a a high-level overview of real estate investment structures, restrictions on foreign ownership, and other important issues of real estate law. The main topics include the following: Real estate investment Title to real estate Sale of real estate Real estate tax Real estate finance Real estate leases Planning and development controls To read the Vietnam chapter, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
February 28, 2024
On February 1, 2024, Laos’ Decree on Condominiums No. 352/GOV took effect. This decree expands on the Law on Land (2019), which introduced the concept of condominiums into the Lao regulatory framework and opened the possibility for foreigners to own apartment units (redefined as “condominium units”—see below). The Law on Land revolutionized concepts of property ownership and investment in a country where foreign ownership is still uncommon. The recent Decree on Condominiums elaborates on the law by clarifying definitions, outlining procedures for acquiring a unit, setting requirements for operating a condominium business in Laos, and addressing issues related to ownership of condominiums. Definitions Condominium: The Decree on Condominiums defines a condominium as a multistory building containing several units and various facilities. The construction must be on a parcel of land registered as “condominium land.” The units composing the condominium can be sold or assigned to domestic and foreign individuals, legal entities, or organizations. Unit: This refers to any of the units that compose the condominium and whose ownership can be by Lao or foreign individuals, legal entities, or organizations. The decree classifies units into three categories: Residential units for living in; Office units for working spaces for enterprises; and Commercial and service units that serve as a trade or service center, such as for department stores, restaurants, fitness centers, and so on. Unit owners must register the unit in accordance with its specific purpose, which must be in line with any applicable urban planning restrictions on certain types of units. Apartment building: This is a building composed of several floors and rooms that cannot be sold to Lao or foreign nationals. According to the Decree on Condominiums, rooms composing the apartment building can only be offered for rent by the owner. This is the main difference between “condominium” and “apartment.” Condominium Registration Only buildings constructed on condominium land can acquire
February 28, 2024
The Myanmar Investment Commission (MIC) has announced the opening of the trial period for MIC-permitted or MIC-endorsed companies to reenter investment data for using the Myanmar Investment Online (MyInO) system. The trial period is open until June 30, 2024. The MyInO system allows for the submission and recordal of applications for investment under the Myanmar Investment Law. With the implementation of phase 2 from September 1, 2023, applications for the appointment or resignation of foreign experts and employees within MIC-permitted or MIC-endorsed companies can now be submitted manually or through the Investment Monitoring System available on MyInO. To initiate the application process in MyInO, applicants are required to create an account on the platform. Subsequently, companies holding an MIC permit or endorsement must reenter all investment-related data since the obtaining of the relevant permits/endorsements, in compliance with the announcement. Following this data update, applications can be filed through MyInO. After this trial period, the submission of applications for appointments will be available online. The benefit of using MyInO to submit a foreign expert or employee appointment or resignation application is that the application can be submitted within 30 days of the foreign expert’s arrival in Myanmar. In contrast, hard copy applications must be submitted within seven working days of arrival. According to the Myanmar Investment Law, a foreign expert is one who qualifies as a senior manager, technical or operational expert, or advisor in permitted or endorsed companies within Myanmar. For assistance with completing the investment data reentry process or filing applications for appointment or resignation of foreign experts or employees, or for further details on any aspect of the Investment Monitoring System under MyInO, please contact Tilleke & Gibbins at [email protected].
February 27, 2024
Thailand’s National Cyber Security Committee (NCSC) released three notifications under the Cybersecurity Act on January 18, 2024, setting cybersecurity-related requirements for key organizations and assets. While one of these notifications already took effect, the two most notable will take effect on January 18, 2025 (i.e., one year from their publication in the Government Gazette). These two are the NCSC Notification Re: Standards for Defining the Security Category for Data or Information Systems B.E. 2566 (2023) (“Notification on Security Category”) and the NCSC Notification Re: Minimum Standards for Data and Information Systems B.E. 2566 (2023) (“Notification on Minimum Standards”). These notifications apply to: State agencies; Supervising or regulating organizations (i.e., state organizations, private organizations, or persons designated by law to regulate or supervise the affairs of state organizations or critical information infrastructure organizations); and Critical information infrastructure organizations (i.e., organizations related to or providing national security, significant public services, banking and finance, information technologies and telecommunications, transportation and logistics, energy and public utilities, and public health). Collectively these are defined as “Organizations” under the notifications. Notification on Security Category The Notification on Security Category sets forth risk-based security classifications—or “security categories”—for Organizations’ data or information systems. For security category assessment purposes, Organizations are required to perform a self-assessment of their data or information systems based on three key security objectives: confidentiality, integrity, and availability. Each of these objectives is further categorized into three risk levels (low, medium, and high), taking into account the assessment of potential impact in the following areas: Organizations’ financial value or reputation; Organizations’ number of service users; Organizations’ ability to perform their duties; State stability or public order. The risk levels for the three objectives are determined by considering whether there are “minimal,” “severe,” or “serious severe” effects, as described below: Confidentiality (not including data classified as “secret,” which follows different criteria): The effects of unauthorized disclosure of data on Organizations’