United States Finalizes Section 301 Tariff Framework Based on Forced Labor Enforcement: Thailand Subject to a 12.5% Tariff

In our previous article (USTR Section 301 Forced-Labor Determinations: Implications for Thailand – The Legal Co., Ltd.), we discussed the U.S. Section 301 investigation involving approximately 60 trading partners, including Thailand, and Thailand’s response to the proposed tariff measures through trade negotiations and domestic regulatory reforms.

The Office of the United States Trade Representative (“USTR“) has now concluded that review, announcing the final tariff framework under Section 301 of the Trade Act of 1974 on 23 July 2026. The framework imposes additional tariffs ranging from 10% to 12.5% on imports from approximately 60 trading partners, effective from 24 July 2026.

Although Thailand actively participated in the consultation process and sought both a reduction in the proposed tariff rate and additional product-specific exemptions, it remains subject to the higher 12.5% tariff, which took effect immediately upon the expiry of the preceding tariff measures.

The final framework is significant not only for the additional tariffs it introduces, but also for what it signals: the United States’ continued use of trade policy as a lever to address forced labor concerns and to encourage stronger labor standards and supply chain governance among its trading partners.

Overview of the Final Tariff Framework

The final framework adopts a tiered approach, with tariff rates determined by the USTR’s assessment of each trading partner’s efforts to prevent goods produced using forced labor from entering the U.S. market.

  • 10% tariff — applies to countries that (i) already prohibit imports of goods produced using forced labor, (ii) have committed to implementing such measures through reciprocal trade arrangements, or (iii) have introduced measures offering some protection against such imports. Countries in this category include Argentina, Bangladesh, Cambodia, Canada, Ecuador, El Salvador, Guatemala, Honduras, India, Indonesia, Jordan, Malaysia, Mexico, Pakistan, Sri Lanka, Trinidad and Tobago, and the United Kingdom.
  • 12.5% tariff — applies to countries the United States considers not to have implemented sufficiently effective measures to prevent goods produced using forced labor from entering U.S. supply chains. Thailand falls within this category, alongside China, Hong Kong, Japan, the Philippines, Singapore, and Vietnam, among other trading partners.

According to the USTR, the final framework applies to trading partners representing approximately 99.4% of total U.S. imports. Certain products remain exempt, including oil, natural gas, and goods that cannot be sourced domestically in the United States.

Legal Significance

Beyond the tariff rates themselves, the legal basis for the framework carries equal significance.

According to publicly available reports, the United States introduced the final tariff framework after the U.S. Supreme Court ruled that tariffs previously imposed under emergency powers were unlawful. Rather than relying on those emergency powers, the U.S. government has instead invoked Section 301 of the Trade Act of 1974, which authorizes the USTR to act against foreign government policies or practices considered unfair or burdensome to U.S. commerce.

This development demonstrates that, notwithstanding new limits on the use of emergency powers, the United States continues to rely on existing trade legislation to pursue its broader trade policy objectives. It also reflects a growing trend in which labor standards, human rights, and supply chain governance are increasingly treated as matters of international trade compliance, rather than solely as corporate social responsibility or ESG considerations.

Business Implications

The practical implications of the final tariff framework extend beyond the tariffs themselves.

Businesses exporting to the United States — including manufacturers, suppliers, and other participants in global supply chains — should expect increased requests from customers and business partners to demonstrate that their products are free from forced labor and that appropriate due diligence has been conducted throughout the supply chain.

Businesses should therefore consider:

  • reviewing supplier due diligence procedures;
  • strengthening supply chain traceability;
  • maintaining documentation on product origin and manufacturing processes; and
  • monitoring developments in U.S. trade policy, as well as Thailand’s proposed Human Rights Due Diligence (HRDD) framework.

Taking these steps early may help businesses respond more effectively to evolving customer expectations, reduce compliance risk, and minimize disruption to cross-border trade.

Key Considerations for Businesses

The final tariff framework reinforces the growing convergence between international trade policy, labor standards, and supply chain governance. While the immediate consequence is the additional 12.5% tariff imposed on imports from Thailand, the broader implication is that businesses should expect increasing scrutiny of their supply chains and rising expectations around responsible sourcing and human rights due diligence.

Businesses with operations or supply chains connected to the United States should review their existing compliance programmers, strengthen supplier due diligence and traceability measures, and continue monitoring regulatory developments in both the United States and Thailand to remain prepared for evolving trade compliance requirements.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Tomorrowland Thailand 2026: Business Opportunities and Operational Readiness for Local Investors

WeAreOne.World (Thailand) Co., Ltd., a Thai-Belgian joint venture, has received investment promotion approval from the Board of Investment (BOI) to organize Tomorrowland Thailand, a world-class electronic dance music (EDM) festival. The event will take place at Wisdom Valley, Chonburi Province, from December 11 to 13, 2026, marking the festival’s first-ever edition in Asia and featuring a star-studded lineup of internationally renowned artists and DJs.

The project is a joint venture between TL International BV, a subsidiary of the Belgium-based Tomorrowland Group, and Thailand’s One Asia Ventures Co., Ltd. TL International BV brings more than two decades of experience organizing EDM festivals worldwide, while One Asia Ventures has produced major music events in Thailand.

All 50,000 daily tickets — 150,000 in total across the three-day event — have officially sold out. Over 85% of attendees, or approximately 127,500 people, are expected to be international visitors, led by primary markets including Malaysia (8.5%), Singapore (7.5%), and Australia (6.5%), alongside secondary markets in Europe (8%) and the United States (3.5%).

Benefits for Thai Business Operators and Local Investors

The festival is projected to generate 6.13 billion Baht (approximately EUR 159 million) in immediate economic value, with a potential contribution exceeding 21,386 million Baht over its planned five-year run (2026–2030). This positions Thailand as a global event hub, driving revenue across hotels, accommodation, restaurants, transportation, and regional service providers.

1. Tourism, Hotels, and Accommodation Ticket sales have already driven more than 22,000 ticket-and-accommodation package bookings, along with over 250 pre and post-festival travel itineraries designed to extend visitor stays by one to two weeks. These offerings are well positioned to capture high-spending, long-stay travelers, allowing Thailand’s tourism sector to fully benefit from the event.

2. Creative and Music Industry Government representatives anticipate long-term advantages for Thailand’s creative sectors. By bringing world-class staging, acoustics, lighting, and visual production technology to the country, the event will give local designers and crew hands-on experience with international-standard setups — supporting Thailand’s long-term capability to host major global events.

3. Local Suppliers and Service Providers (Direct Impact) Event organizers will procure and contract directly with Thai suppliers and service providers, with an allocated budget exceeding 1,092 million Baht (EUR 28 million). This spans production and infrastructure, food and beverage, workforce and staffing, logistics and transportation, hospitality, venue management, and other local services.

4. Retail, Restaurant, and Transport Sector (Indirect Impact) Local businesses stand to benefit from more than 5,309 million Baht (EUR 131 million) in indirect economic circulation, generated by visitor spending on retail, local travel, and extended stays in neighboring provinces.

5. Job Creation The festival is expected to generate up to 21,386 jobs across tourism, events, logistics, and hospitality, beginning with 1,900 positions in its first year, with priority given to Thai personnel. Knowledge-transfer initiatives — including a DJ Academy and Festival Academy — will further build local expertise in festival management.

Preparation for Thai Business Operators and Investors

To capitalize effectively on the capital circulation generated by Tomorrowland Thailand, local businesses should prepare across five key areas:

1. Service Standards and Multilingual Support With international visitors making up the majority of attendees, hotel, restaurant, and transport operators should train staff in English and key ASEAN languages, and ensure full integration of international payment gateways (credit cards, digital wallets, and e-payment systems).

2. Long-Stay Travel Packages As the event falls in December, many attendees are likely to extend their stay by one to two weeks. Tourism operators in Chonburi, Rayong, and surrounding provinces — including Bangkok and Chiang Mai — should develop experiential travel packages, airport transfer services, and premium programs tailored to high-spending travelers.

3. Supplier and Production Readiness Businesses in events, production, lighting, audio, logistics, F&B, and security should upgrade operational, hygiene, and safety standards to international levels to compete for direct-procurement subcontracts. Commercial agreements should be drafted clearly and enforceably to protect business interests.

4. Cross-Border Business and Contractual Readiness Businesses pursuing joint ventures, co-branding, or merchandise sales at the event should establish robust JV agreement structures and carefully review trademark licensing requirements to avoid intellectual property infringement.

5. Regulatory Compliance Operators should review all applicable laws for large-scale festival operations and establish clear compliance frameworks, including:

  • Food, Beverage, and Alcohol Control Laws: Temporary liquor sales permits must be obtained from the Excise Department for on-site sales points, with strict age-verification (20 years and older, as required by law).
  • Personal Data Protection Act (PDPA): Operators collecting customer data, using ticket or room scanning systems, or capturing photos/video for promotional use must provide proper privacy notices and implement valid consent mechanisms.

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

OCPB: National Action Plan on Online Products Signals More Coordinated Regulatory Oversight

Thailand is moving toward a more coordinated approach to regulating products sold through online channels. The Office of the Consumer Protection Board (OCPB) is leading the development of a National Action Plan (NAP) on online products following a nationwide public consultation process. The initiative aims to strengthen cooperation among government agencies responsible for consumer protection, product safety, intellectual property, customs, taxation, digital platforms, and law enforcement.

Although the National Action Plan is still under development, it signals the government’s intention to enhance oversight of online commerce through coordinated enforcement rather than relying on individual regulators acting independently. Businesses participating in Thailand’s digital marketplace should closely monitor these developments and consider reviewing their compliance frameworks in anticipation of increased regulatory cooperation.

A Coordinated Regulatory Framework:

The proposed National Action Plan is intended to establish an integrated framework for addressing issues associated with products sold online. Rather than creating an entirely new regulatory regime, the initiative seeks to improve cooperation, information sharing, and joint enforcement among relevant authorities.

Its objectives include:

  • strengthening consumer protection in online commerce;
  • reducing the circulation of counterfeit, unsafe, and non-compliant products;
  • improving coordination among regulatory and enforcement agencies;
  • enhancing traceability within online supply chains; and
  • promoting confidence in Thailand’s digital economy.

If implemented as proposed, the framework would enable authorities to respond more efficiently to unlawful online activities by combining investigative resources and sharing information across agencies.

A Broad Regulatory Focus:

The proposed framework extends beyond intellectual property enforcement. Authorities have indicated that the initiative is intended to address a broad range of consumer protection and regulatory concerns relating to products sold online.

Areas expected to receive greater attention include:

  • products that fail to meet mandatory safety standards;
  • cosmetics, food, medical devices, and health products marketed without required approvals;
  • prohibited or restricted goods;
  • misleading or deceptive product claims;
  • goods imported in violation of customs requirements; and
  • products sold in breach of consumer protection laws.

Businesses should therefore view the initiative as a comprehensive regulatory effort affecting multiple areas of compliance rather than solely an anti-counterfeiting measure.

Implications for Online Platforms:

Online marketplaces and social-commerce platforms are likely to face increased expectations regarding their governance of third-party sellers and product listings.

As regulatory cooperation expands, platforms may be expected to strengthen:

  • seller verification procedures;
  • mechanisms for removing unlawful listings;
  • monitoring of higher-risk products;
  • cooperation with government investigations; and
  • recordkeeping to support regulatory enforcement.

Platforms with effective compliance systems and transparent governance practices are likely to be better positioned as regulatory expectations evolve.

Considerations for Online Sellers:

Online sellers should ensure that products offered through digital channels comply with all applicable regulatory requirements.

Businesses should review whether regulated products possess the necessary registrations, approvals, certifications, or licenses. Marketing materials, product descriptions, pricing information, and labeling should also be assessed to ensure compliance with consumer protection requirements.

Businesses importing products into Thailand should also verify that customs documentation and import procedures are properly maintained, particularly if enforcement activities become more coordinated across agencies.

Logistics Providers and Payment Service Providers:

The proposed National Action Plan recognizes that effective enforcement may require cooperation from businesses supporting online transactions.

Logistics providers may receive requests from authorities to assist in tracing the movement of goods associated with unlawful online sales.

Similarly, payment service providers may be asked to cooperate in investigations involving transactions connected with illegal products or fraudulent online businesses.

Maintaining appropriate compliance procedures and responding promptly to lawful requests from competent authorities will remain important risk management measures.

Opportunities for Brand Owners:

For brand owners, the proposed framework may strengthen enforcement against counterfeit and infringing products sold online.

Closer coordination among consumer protection authorities, customs officials, intellectual property agencies, and law enforcement may facilitate more effective action against repeat offenders and organized distribution networks.

Nevertheless, businesses should continue monitoring online marketplaces, preserving evidence of infringement, utilizing platform reporting mechanisms, and pursuing civil or criminal remedies where appropriate.

Preparing for a More Coordinated Enforcement Environment:

Although the National Action Plan has not yet been finalized, businesses should consider reviewing their compliance programs in anticipation of increased regulatory cooperation.

Practical steps include:

  • conducting compliance reviews of products sold online;
  • strengthening seller onboarding and verification processes;
  • maintaining documentation demonstrating regulatory compliance;
  • reviewing procedures for responding to regulatory requests;
  • establishing effective complaint-handling and takedown procedures; and
  • providing compliance training for employees responsible for online sales and marketplace operations.

Early preparation may help businesses reduce regulatory risks once the coordinated framework is implemented.

Key takeaways:

  • The Office of the Consumer Protection Board is leading the development of a National Action Plan on online products following a nationwide consultation process.
  • The initiative is intended to strengthen coordination among agencies responsible for consumer protection, product safety, customs, taxation, intellectual property, and law enforcement.
  • The proposed framework extends beyond counterfeit goods to address broader regulatory and consumer protection issues relating to online product sales.
  • Online marketplaces, sellers, logistics providers, payment service providers, and brand owners should expect greater regulatory cooperation and more coordinated enforcement.
  • Businesses should review and strengthen their compliance programs in preparation for the evolving regulatory land

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

Negative Online Reviews and Defamation Claims: Lessons from a Recent Court of First Instance Decision

The proliferation of online review platforms has transformed the way consumers evaluate products and services. While positive reviews can enhance a business’s reputation, negative reviews—particularly those receiving significant online attention—may prompt businesses to consider legal action against dissatisfied customers. A recent judgment of a Thai Court of First Instance involving a dispute between a well-known bakery in Phuket and one of its customers provides a timely reminder of the legal and commercial considerations surrounding such claims.

The case has attracted considerable media attention because the bakery reportedly sought THB 5 million in damages after a customer posted a one-star review describing the cake as “not tasty” and “overpriced.” According to publicly available reports, the Court of First Instance dismissed the claim. As the judgment is that of the Court of First Instance, it may still be subject to appeal and should not yet be regarded as the final judicial position.

Background:

According to publicly available information, the dispute arose after a customer posted a one-star review on an online platform expressing dissatisfaction with the bakery’s products, commenting that the cake was not tasty and that the price was excessive.

The bakery subsequently contacted the customer requesting that the review be removed and later commenced legal proceedings seeking approximately THB 5 million in damages. The dispute quickly gained widespread attention on social media, generating extensive public discussion regarding the balance between consumer rights and protection of business reputation.

In July 2026, the Court of First Instance reportedly dismissed the bakery’s claim. Although the full written judgment has not yet been publicly circulated, the outcome has reignited debate regarding the extent to which businesses may rely on litigation in response to unfavourable online reviews.

The Growing Legal Challenge of Online Reviews:

Online reviews have become an integral part of modern commerce. Consumers frequently rely on reviews when selecting restaurants, hotels, healthcare providers, retailers and other service providers. At the same time, businesses increasingly view online reputation as a valuable commercial asset.

Consequently, disputes arising from customer reviews have become more common. While businesses are entitled to protect themselves against false and malicious allegations, not every negative review will give rise to a viable legal claim.

The recent dispute illustrates the importance of carefully distinguishing between statements that constitute protected opinion and those that may amount to actionable false statements of fact.

Opinion Versus Statements of Fact:

One of the central legal issues in disputes involving online reviews is whether the impugned statement represents a factual assertion or merely an expression of personal opinion.

Comments such as:

  • “I did not enjoy the cake”;
  • “The cake was overpriced”; or
  • “I would not return”

are generally subjective evaluations reflecting an individual’s personal experience.

By contrast, statements alleging objectively verifiable facts—such as accusations that a business uses unsafe ingredients, engages in fraudulent practices or violates legal requirements—may expose the reviewer to greater legal risk if such allegations are false and cause reputational harm.

This distinction is fundamental because courts generally recognize that consumers are entitled to express honestly held opinions regarding products and services, even where those opinions are critical.

Defamation Claims Require More Than Mere Dissatisfaction:

The case also serves as a reminder that a business seeking damages bears the burden of establishing the legal elements of its claim.

In practice, commencing legal proceedings simply because a review is unfavourable does not guarantee success. The claimant must establish the applicable legal requirements, including any necessary evidence regarding the allegedly unlawful statements and the resulting damage.

Where a review reflects a genuine customer experience rather than fabricated allegations, litigation may present significant evidentiary challenges.

Commercial Risks of Suing Customers:

Apart from legal considerations, businesses should also consider the broader commercial implications before commencing proceedings against customers.

Litigation concerning online reviews often attracts media attention that substantially exceeds the visibility of the original review itself. The dispute may be widely shared across social media platforms, leading to increased public scrutiny and reputational consequences that outweigh the impact of the initial criticism.

This phenomenon—often referred to internationally as the “Streisand Effect”—illustrates how attempts to suppress criticism may unintentionally amplify it.

Businesses should therefore carefully assess whether legal proceedings represent the most effective strategy for protecting their reputation.

Practical Considerations for Businesses:

Before initiating legal proceedings over an online review, businesses should consider:

  • whether the review constitutes a subjective opinion or an objectively false factual allegation;
  • whether there is sufficient evidence to establish the legal elements of a claim;
  • whether direct engagement with the customer may resolve the dispute without litigation;
  • whether the anticipated reputational consequences of litigation outweigh the potential legal remedies; and
  • whether alternative reputation management strategies may better serve the business’s long-term interests.

Legal action remains an appropriate response in cases involving knowingly false accusations, malicious campaigns or fabricated reviews. However, proceedings should generally be undertaken only after careful assessment of both the legal merits and the wider commercial implications.

Looking Ahead:

Although the recent dispute has generated substantial public interest, it is important to recognize that the reported decision is a judgment of the Court of First Instance. Unless and until the appellate process is exhausted or the appeal period expires, the judgment should not be treated as representing the final legal position.

Nevertheless, the case highlights an increasingly important issue for businesses operating in Thailand. As online reviews continue to influence consumer behaviour, businesses should develop appropriate internal strategies for responding to criticism, balancing the protection of commercial reputation with the legal rights of consumers to express honest opinions regarding their experiences.

Key Takeaways:

  • A negative online review does not automatically constitute unlawful defamation or give rise to a successful claim for damages.
  • Businesses should carefully distinguish between subjective opinions and objectively verifiable factual allegations before considering legal action.
  • Litigation over customer reviews may generate significant reputational and commercial consequences independent of the legal outcome.
  • The recent Phuket bakery dispute was decided by the Court of First Instance, and the decision may still be subject to appeal.
  • Businesses should adopt a measured and evidence-based approach to online reputation management, reserving litigation for cases involving genuinely false or malicious statements.

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

Integrating Cybersecurity, Fraud Response, and PDPA Compliance: Practical Implications of the Proposed Digital Channel Security Framework

The Bank of Thailand (BOT) has released a proposed Digital Channel Security framework that would strengthen expectations for authentication, fraud prevention, incident response, and the governance of digital financial services. While the proposal focuses primarily on enhancing the security and resilience of digital channels, financial institutions should not view these requirements in isolation.

In practice, a single cybersecurity incident frequently triggers multiple legal and regulatory obligations simultaneously. For example, an account takeover resulting from a phishing attack may require an institution to activate its cybersecurity incident response procedures, implement fraud mitigation measures, assess whether a personal data breach has occurred under the Personal Data Protection Act (PDPA), evaluate outsourcing or third-party service provider involvement, and make appropriate internal and regulatory notifications.

Although these obligations arise from different legal and regulatory sources, organizations may benefit from managing them through a coordinated incident response framework. This article examines the practical implications of the proposed BOT framework alongside existing obligations under the PDPA and broader operational governance practices.

From cybersecurity to operational resilience:

The proposed framework reflects an increasing regulatory emphasis on operational resilience rather than viewing cybersecurity solely as an information technology function. It places greater focus on preventing, detecting, responding to, and recovering from threats affecting digital financial services while maintaining the continuity and integrity of critical operations.

At the same time, financial institutions should recognize that cybersecurity incidents rarely occur in isolation. A single event may involve operational disruption, attempted fraud, compromise of customer credentials, unauthorized disclosure of personal data, and third-party service providers. As a practical matter, organizations may therefore benefit from adopting governance arrangements capable of addressing these interconnected risks through a unified response process.

Governance beyond information technology:

The proposed framework emphasizes that responsibility for digital channel security extends beyond information security teams.

Boards of directors and senior management are expected to establish appropriate governance, oversee digital risks, allocate adequate resources, monitor security performance, and ensure that significant incidents are escalated appropriately.

From a broader governance perspective, institutions should also consider ensuring that legal, compliance, privacy, operational risk, business continuity, and customer service functions are integrated into incident management processes. This cross-functional approach can help organizations address multiple regulatory obligations efficiently when significant incidents occur.

Fraud prevention as part of digital channel security:

The BOT proposal places significant emphasis on fraud prevention through enhanced digital channel security. Proposed measures include stronger customer authentication, monitoring of suspicious activities, behavioral analysis, device identification, protection against phishing and social engineering attacks, and mechanisms for responding to suspicious transactions.

These expectations primarily seek to reduce fraud risks affecting digital financial services. However, successful fraud attacks frequently have wider legal implications. Unauthorized access to customer accounts may also involve compromised personal data, contractual issues with service providers, customer remediation, and regulatory reporting obligations. Institutions should therefore consider integrating fraud response procedures into broader cybersecurity governance rather than treating fraud management as a separate operational function.

Incident response across multiple regulatory frameworks:

The proposed framework expects institutions to establish formal incident response procedures covering detection, escalation, containment, investigation, recovery, and post-incident review.

In practice, these procedures should also enable organizations to identify other legal and regulatory obligations that may arise from the same incident. Depending on the circumstances, an incident may require parallel consideration of fraud management, operational resilience measures, contractual obligations, outsourcing arrangements, and personal data protection requirements.

Developing coordinated response procedures may help reduce duplication of effort, improve decision-making, and ensure that regulatory obligations are addressed consistently across different functions.

Interaction with the Personal Data Protection Act:

The proposed BOT framework does not replace or modify existing obligations under the PDPA. Rather, the two regimes operate alongside one another.

Where a cybersecurity incident involves unauthorized access to, disclosure of, alteration of, or loss of personal data, organizations should assess their obligations under the PDPA independently of the BOT framework. This may include determining whether a personal data breach has occurred, evaluating notification obligations, preserving relevant evidence, documenting response measures, and implementing appropriate remediation.

Accordingly, organizations may wish to ensure that privacy officers, legal counsel, and cybersecurity teams participate jointly in incident response planning and tabletop exercises so that both operational and data protection considerations are addressed from the outset.

Third-party risk management:

Digital financial services increasingly depend on cloud service providers, payment processors, managed service providers, software vendors, and other external partners.

The proposed framework reinforces expectations regarding oversight of third-party service providers throughout the outsourcing lifecycle. Institutions should conduct appropriate due diligence, establish contractual security requirements, monitor vendor performance, and ensure that incident reporting and business continuity arrangements are clearly defined.

Because cybersecurity incidents involving third parties may also raise fraud and personal data protection issues, organizations should consider aligning vendor management processes with their broader incident response and compliance frameworks.

Documentation and evidence of compliance:

The proposed framework places considerable emphasis on governance, accountability, and demonstrating that appropriate controls are in place.

Organizations should maintain comprehensive records of cybersecurity governance, risk assessments, incident response activities, testing, training, vendor oversight, and business continuity exercises. From a broader compliance perspective, documentation should also support obligations arising under other applicable legal frameworks, including the PDPA and contractual commitments relating to outsourced services.

Maintaining complete records may facilitate regulatory engagement, internal investigations, and post-incident reviews while demonstrating that reasonable organizational and technical measures have been implemented.

Practical considerations:

As organizations prepare for the proposed framework, they may wish to assess not only technical cybersecurity controls but also how different compliance functions interact during a significant incident.

Areas for review may include:

  • governance and board oversight;
  • coordination among cybersecurity, legal, compliance, privacy, and operational teams;
  • fraud detection and response procedures;
  • customer authentication controls;
  • third-party risk management;
  • incident reporting and escalation processes;
  • documentation and recordkeeping; and
  • operational resilience testing and tabletop exercises.

An integrated approach may improve organizational readiness while reducing the risk that separate regulatory obligations are managed through disconnected processes.

Key takeaways:

  • The proposed BOT Digital Channel Security framework primarily addresses digital channel security, fraud prevention, governance, and operational resilience.
  • Existing obligations under the PDPA continue to apply independently where cybersecurity incidents involve personal data.
  • A single cyber incident may simultaneously trigger cybersecurity, fraud management, personal data protection, outsourcing, and operational governance obligations.
  • Although these obligations arise under different legal and regulatory frameworks, organizations may benefit from managing them through an integrated incident response framework.
  • Financial institutions should consider reviewing governance structures, cross-functional coordination, and documentation practices to improve operational resilience and regulatory compliance.

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

PDPA Insights: Building Effective Privacy Governance

PDPA: AI Is Not Replacing Privacy Law—It Is Changing How We Apply It

Artificial intelligence has rapidly become part of everyday business operations. Recommendation engines personalize online shopping experiences, chatbots answer customer enquiries, fraud detection systems identify suspicious transactions, recruitment platforms screen job applicants, and generative AI assists with customer service, marketing and document preparation.

As AI adoption accelerates, organizations frequently ask whether the Personal Data Protection Act (PDPA) contains special rules governing AI.

The answer is both simple and nuanced.

Thailand’s PDPA does not establish a standalone regulatory framework for artificial intelligence. Unlike some jurisdictions that have introduced AI-specific legislation, the PDPA remains technology neutral. The same legal principles governing all personal data processing—including lawfulness, purpose limitation, transparency, data minimization, security, and accountability—continue to apply regardless of whether personal data is processed manually or through sophisticated AI systems.

Nevertheless, the Personal Data Protection Committee’s (PDPC) recent consultation on marketing and direct marketing demonstrates that the regulator increasingly recognizes AI-assisted personalization, profiling, and automated decision-making as ordinary components of modern business operations rather than exceptional technologies. This signals an important evolution in regulatory expectations. The question is no longer whether AI falls within the scope of the PDPA. Instead, organizations should consider how existing privacy principles should operate when personal data is processed at unprecedented speed and scale.

AI changes the scale—not the legal principles:

One misconception is that AI requires an entirely new compliance framework.

In reality, the core legal questions remain familiar.

Why is personal data being processed?

Is there an appropriate legal basis?

Have individuals been informed?

Is the processing proportionate?

Are appropriate safeguards in place?

These questions existed before AI and remain the foundation of PDPA compliance.

What AI changes is the scale and complexity of those questions.

A marketing employee might manually analyze one hundred customer records to recommend products.

An AI system may analyze ten million records every day, continuously refining customer profiles and generating individualized recommendations without direct human intervention.

The legal principles remain the same.

The governance challenge becomes significantly greater.

Organizations should focus on the processing—not the technology:

Discussions about AI frequently focus on algorithms.

Privacy law focuses on personal data.

Organizations should therefore avoid beginning compliance discussions with technical questions such as:

“Are we using AI?”

Instead, they should ask:

“How is personal data being collected, analyzed, combined, retained and disclosed?”

This shift in perspective has practical consequences.

An AI system recommending products based upon purchasing history raises different privacy considerations from an AI system screening job applicants or detecting fraudulent transactions.

The technology may be identical.

The processing purposes are not.

Organizations should therefore evaluate each AI use case separately rather than adopting a single enterprise-wide conclusion regarding AI compliance.

Profiling is becoming an ordinary business activity:

One of the most significant aspects of the PDPC’s recent consultation is the inclusion of profiling alongside AI-assisted marketing and automated decision-making.

This reflects commercial reality.

Retailers profile customers to recommend products.

Banks profile spending behaviour to identify suitable financial services.

Hotels profile travel patterns.

Streaming platforms profile viewing preferences.

Insurance companies profile claims histories.

Profiling has become routine.

The regulatory focus is therefore shifting away from asking whether profiling exists toward examining whether organizations understand, govern and explain how profiling operates.

Transparency becomes particularly important where profiling materially influences commercial decisions affecting individuals.

Explainability is becoming a governance issue:

Many AI systems are capable of generating sophisticated outputs while providing limited insight into how those outputs were produced.

This creates a practical challenge.

Organizations may be able to explain what an AI system does without fully understanding why it reached a particular recommendation.

The PDPA does not require organizations to explain complex algorithms.

However, organizations should be capable of explaining much more fundamental issues.

What personal data does the AI system use?

Why is that information necessary?

What business objective does the system support?

Who reviews significant outputs?

What safeguards exist to identify inappropriate outcomes?

These governance questions are likely to become increasingly important as AI adoption expands.

Vendor governance is becoming AI governance:

Few organizations develop AI systems internally.

Most rely on external providers.

Large language models.

Cloud AI services.

Marketing automation platforms.

Customer relationship management systems.

Fraud detection software.

Human resources platforms.

Consequently, AI governance increasingly depends upon vendor governance.

Organizations should understand:

  • where personal data is processed;
  • whether overseas transfers occur;
  • whether providers use customer data to train models;
  • whether subcontractors process personal data;
  • how security is maintained;
  • how long information is retained.

Vendor due diligence therefore becomes an essential component of AI governance under the PDPA.

Human oversight still matters:

AI enables organizations to automate decisions at unprecedented scale.

Automation, however, should not eliminate accountability.

Organizations should identify situations where meaningful human review remains appropriate.

Examples may include:

  1. rejecting employment applications;
  2. detecting suspected fraud;
  3. evaluating insurance claims;
  4. determining customer eligibility for significant commercial benefits.

The appropriate level of oversight will depend upon the context and the potential impact on individuals.

Organizations should therefore design governance frameworks that ensure AI supports decision-making without entirely replacing human judgement where significant interests are involved.

AI governance is ultimately privacy governance:

Perhaps the most important lesson is that organizations should resist creating isolated AI compliance programs.

Instead, AI should be incorporated into existing privacy governance.

Records of Processing Activities should identify AI-supported processing.

Privacy notices should accurately describe AI-related processing where appropriate.

Legal basis assessments should consider AI processing explicitly.

Vendor management should address AI providers.

Privacy impact assessments should evaluate AI risks.

Training programs should include AI governance.

In other words, organizations should integrate AI into their existing accountability framework rather than building a separate compliance structure.

Looking ahead:

Artificial intelligence will continue to reshape business operations.

The more significant challenge under the PDPA, however, is unlikely to be the technology itself.

It will be governance.

Organizations capable of explaining why AI is used, what personal data supports it, how risks are managed, and how decisions remain accountable are likely to be better prepared than organizations focusing exclusively on technical innovation.

The PDPC’s recent consultation suggests that this is the direction in which Thailand’s privacy regime is evolving. AI is becoming an ordinary business tool. As a result, organizations should treat AI governance as an ordinary component of privacy governance.

Key takeaways:

  1. The PDPA does not establish separate legal principles for AI; existing privacy obligations continue to apply regardless of the technology used.
  2. AI increases the scale and complexity of personal data processing but does not replace the need for lawful basis, transparency, purpose limitation, and accountability.
  3. Organizations should assess individual AI use cases rather than treating all AI deployments identically.
  4. Profiling and AI-assisted decision-making are becoming mainstream regulatory concerns and should be supported by appropriate governance and transparency.
  5. Vendor management is increasingly inseparable from AI governance because many AI capabilities are provided by third-party platforms.

The organizations best prepared for future regulation will be those that integrate AI into existing privacy governance rather than treating it as a separate compliance project.


Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

Billing Software Requirements vs. Electronic Invoicing Requirements

Executive Summary:

As governments continue to digitalize tax administration, businesses are increasingly expected to adopt electronic invoicing solutions that comply with evolving regulatory requirements. Although the terms billing software and electronic invoicing are often used interchangeably, they represent distinct concepts that serve different commercial and legal functions.

In Thailand, billing software is not subject to a dedicated statutory or regulatory framework. Businesses are generally free to select accounting, billing, or enterprise resource planning (ERP) systems that best support their commercial operations, provided they comply with the Revenue Code and other applicable laws. Electronic invoicing, by contrast, is governed by the Revenue Department’s e-Tax Invoice & e-Receipt framework, which establishes the legal and technical requirements for issuing electronic tax invoices recognized for VAT purposes.

Understanding the distinction between these concepts is important for businesses implementing digital invoicing solutions. A billing system that efficiently generates commercial invoices does not necessarily satisfy the legal requirements for issuing electronic tax invoices. Businesses should therefore evaluate their invoicing systems not only from an operational perspective but also from a tax compliance standpoint.

Introduction:

Digital transformation has fundamentally changed the way businesses prepare invoices, maintain accounting records, and comply with tax obligations. Around the world, tax authorities have introduced electronic invoicing regimes to improve tax compliance, enhance transparency, and reduce administrative burdens for both taxpayers and regulators.

Although electronic invoicing has become an increasingly common feature of modern tax systems, countries have adopted different regulatory approaches. Some jurisdictions regulate the software used to generate invoices, while others focus on the legal validity and technical characteristics of the electronic tax documents themselves.

Thailand follows the latter approach. Rather than regulating billing software as a separate category of software, Thai law establishes a framework governing the issuance of electronic tax invoices through the Revenue Department’s e-Tax Invoice & e-Receipt system. Consequently, businesses remain free to use their preferred accounting or ERP software, provided that the electronic tax documents generated by those systems comply with the applicable legal and technical requirements.

For businesses operating in Thailand, particularly multinational enterprises implementing global ERP platforms, understanding the distinction between billing software and electronic invoicing is essential. While both are integral components of modern financial management, they perform different functions and are subject to different legal considerations.

Billing Software:

Billing software generally refers to applications used by businesses to prepare invoices, calculate taxes, record payments, manage customer accounts, and maintain accounting records. These functions support day-to-day commercial operations and are commonly integrated into accounting software or ERP systems.

Unlike some jurisdictions that regulate invoicing software, Thailand does not currently impose a dedicated legal or regulatory regime governing billing software itself. There is no statutory requirement for billing software to be licensed, certified, or approved by the Revenue Department before it can be used by businesses. Instead, Thai law focuses on the legal sufficiency of the invoices and accounting records generated by the software.

This does not mean that businesses have complete discretion in how billing systems are used. Regardless of the software selected, businesses remain responsible for ensuring that invoices comply with the Revenue Code, VAT is correctly calculated where applicable, accounting records are properly maintained, and supporting documentation is available for inspection by the tax authorities.

Accordingly, compliance under Thai law depends not on the software itself, but on whether the business uses that software in a manner that satisfies its statutory obligations. A business may therefore choose from a wide range of commercial accounting platforms, cloud-based invoicing applications, or ERP systems without obtaining prior approval from the Revenue Department.

Electronic Invoicing:

Electronic invoicing serves a different purpose. Rather than facilitating internal billing processes, it establishes the legal framework under which electronic tax invoices are recognized for VAT purposes.

Thailand’s electronic invoicing regime is principally governed by the Revenue Code, supplemented by the Electronic Transactions Act, Ministerial Regulation No. 384, and Revenue Department notifications prescribing the technical standards for electronic tax documents. Collectively, these instruments enable tax invoices and receipts to be created, transmitted, and retained electronically while ensuring their authenticity, integrity, and reliability.

Businesses wishing to issue electronic tax invoices under the Revenue Department’s e-Tax Invoice & e-Receipt framework must comply with prescribed legal and technical requirements. These include registration with the Revenue Department, generation of electronic tax documents in the prescribed format, use of appropriate electronic authentication mechanisms, transmission through approved channels where applicable, and maintenance of electronic records in accordance with the Revenue Department’s requirements.

An important characteristic of the Thai framework is that it regulates the electronic tax document rather than the accounting software used to produce it. Consequently, businesses may continue using their existing accounting or ERP systems, provided those systems are capable of generating electronic tax invoices that comply with the Revenue Department’s technical specifications. In practice, many businesses achieve this through system localization or integration with specialized e-Tax solutions or authorized service providers.

Thailand currently provides two principal electronic invoicing models. The e-Tax Invoice & e-Receipt system is designed for businesses requiring full electronic integration, while the e-Tax Invoice by Email system provides a simplified alternative for eligible businesses. Although both systems enable businesses to issue legally recognized electronic tax invoices, they differ in their technical implementation and authentication methods.

Key Takeaways:

  • Thailand does not regulate billing software as a separate legal category or require billing software to be certified or approved by the Revenue Department.
  • The Revenue Department’s e-Tax Invoice & e-Receipt framework governs the issuance of legally recognized electronic tax invoices and establishes the applicable technical and procedural requirements.
  • A commercial invoice generated by billing software does not automatically constitute an electronic tax invoice for VAT purposes.
  • Businesses implementing accounting or ERP systems should evaluate both operational functionality and compliance with Thailand’s e-Tax requirements.
  • Early coordination among finance, tax, legal, and information technology functions can help ensure a successful implementation of electronic invoicing while supporting long-term digital tax compliance.

Source: International Comparison July 2026: Global Legal Market Analysis

Read Full Article

Consumer Enforcement Intensifies for EV Businesses as Complaint Cases Rise and Labeling Expectations Increase

Thailand’s consumer protection regulator has signaled a more assertive enforcement approach toward the electric vehicle (EV) sector through two related developments. First, it has indicated its readiness to initiate legal proceedings on behalf of consumers in appropriate EV dispute cases. Second, it has issued new guidance consolidating labeling requirements for automobiles, electric vehicles, and used cars.

Although neither development introduces new legislation, together they demonstrate heightened regulatory scrutiny of the automotive industry and provide valuable insight into the regulator’s current enforcement priorities. Manufacturers, importers, distributors, dealers, service centers, and online vehicle marketplaces should treat these developments as an opportunity to reassess their compliance and dispute management frameworks.

Increased Enforcement Risk from EV Consumer Complaints:

The Office of the Consumer Protection Board (OCPB) has reported a significant number of consumer complaints relating to electric vehicles, with a substantial portion already progressing through legal procedures. The agency has confirmed that it has begun issuing formal demand letters in cases supported by sufficient documentation and has reiterated its statutory authority to commence legal proceedings on behalf of consumers where the legal requirements are satisfied.

This represents an important enforcement signal. Rather than merely facilitating mediation between consumers and businesses, the regulator has indicated its willingness to escalate suitable cases into formal litigation.

The risk is particularly significant where multiple complaints arise from the same product model, manufacturing issue, software defect, battery performance concern, warranty practice, or recurring after-sales service problem. A pattern of similar complaints may increase regulatory attention and expose businesses to coordinated enforcement actions, representative litigation, or broader product liability claims.

Businesses operating within the EV supply chain should therefore review whether existing complaint-handling mechanisms are capable of identifying systemic issues before they evolve into regulatory investigations or court proceedings.

Strengthened Expectations for Vehicle Label Compliance:

Separately, the OCPB has published an electronic handbook consolidating labeling requirements applicable to automobiles, electric vehicles, and used vehicles.

The publication emphasizes information that consumers commonly rely upon when making purchasing decisions, including battery specifications, driving range, testing standards, pricing information, warranty coverage, and the disclosure of material vehicle history for used vehicles.

Although the handbook itself is not legally binding, it provides a clear indication of the regulator’s compliance expectations. It reinforces that automobiles and electric vehicles remain controlled labeling products under consumer protection law and that incomplete, inaccurate, or misleading information may expose businesses to regulatory enforcement.

The guidance also illustrates that compliance extends beyond physical labels. Regulators are increasingly likely to examine whether information presented across all customer-facing channels remains accurate and consistent.

Businesses should therefore review:

  • labels displayed at dealerships and points of sale;
  • information published on corporate websites and online marketplaces;
  • brochures and sales presentations used by sales personnel;
  • representations concerning driving range and the testing methodology used, such as WLTP or NEDC;
  • battery capacity, expected degradation, warranty scope, and warranty exclusions;
  • disclosures relating to collision history, flood damage, major repairs, and battery replacement for used vehicles; and
  • consistency between information published by manufacturers, importers, dealers, and affiliated sales channels.

Claims relating to vehicle performance, battery longevity, operating costs, sustainability, resale value, or environmental benefits should be supported by appropriate technical evidence and internal documentation before publication.

Litigation Readiness and Document Preservation:

These developments also highlight the importance of litigation preparedness.

Businesses should consider establishing a centralized process for collecting and analyzing customer complaints to determine whether recurring issues indicate broader product or service risks.

At the same time, organizations should preserve relevant evidence, including:

  • sales documentation;
  • warranty records;
  • repair histories;
  • technical diagnostic reports;
  • replacement part records;
  • communications with customers;
  • call center recordings;
  • email correspondence;
  • mobile application records; and
  • connected vehicle diagnostic data.

Where disputes may reasonably be anticipated, organizations should consider implementing litigation hold procedures to reduce the risk of inadvertent deletion of potentially relevant evidence.

Companies should also review contractual risk allocation among overseas manufacturers, importers, dealers, distributors, and service centers, including indemnity provisions and responsibilities for handling product defects, recalls, warranty claims, and consumer litigation.

Data Protection Considerations:

Responding to consumer complaints frequently requires the collection and sharing of customer information, vehicle service histories, location information, and connected vehicle diagnostic data. Much of this information may constitute personal data under the Personal Data Protection Act.

Organizations should ensure that internal investigations and litigation response procedures incorporate appropriate data governance measures, including clearly defined access controls, documented processing purposes, retention periods, and secure mechanisms for sharing information with external counsel, technical experts, and other authorized parties.

Integrating consumer protection compliance with data governance can reduce both regulatory and litigation risks while supporting more effective dispute management.

Key Takeaways:

  • Organizations should strengthen complaint management, evidence preservation, document retention, contractual risk allocation, and data governance processes to prepare for increased regulatory scrutiny and potential consumer litigation.
  • The OCPB’s indication that it is prepared to commence litigation on behalf of consumers represents a significant escalation in consumer protection enforcement affecting the EV industry.
  • Businesses should not view repeated consumer complaints as isolated customer service matters but as potential regulatory and litigation risks requiring centralized oversight.
  • The newly published vehicle labeling handbook, although not legally binding, demonstrates higher regulatory expectations regarding the accuracy, completeness, and consistency of vehicle-related information across all sales channels.
  • Automotive businesses should review advertising claims, warranty disclosures, battery-related representations, and used vehicle disclosures to ensure they are fully substantiated.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

TCCT Establishes Two Subcommittees to Strengthen Trade Competition Oversight

The Trade Competition Commission of Thailand (“TCCT”) has appointed two subcommittees to oversee digital platform businesses and to establish competition rules for modern wholesale and retail businesses (“Modern Trade”). The move is intended to curb unfair trade practices and strengthen law enforcement in step with rapidly evolving trade dynamics.

1. Subcommittee on Considering Guidelines for the Oversight and Deterrence of Trade Practices in Digital Platform Businesses

This subcommittee’s primary mandate is to study, analyze, and collect data on the business models, commercial conditions, and trade practices of digital platform businesses, and to assess their impact on trade competition, business operators, consumers, and other stakeholders. It will drive more intensive regulatory measures for digital platform businesses and prepare proposals, guidelines, codes of conduct, criteria, announcements, regulations, and policy recommendations for the TCCT’s consideration.

The subcommittee will also coordinate with government agencies, the private sector, business operators, and other relevant stakeholders across all sectors to oversee and deter trade practices that may affect competition in digital platform businesses, and to promote free and fair competition more broadly.

2. Subcommittee on Determining Guidelines and Action Plans Regarding Competitive Conditions in Modern Wholesale and Retail Businesses

This subcommittee is tasked with studying, analyzing, and monitoring the market structure of modern wholesale and retail businesses; building a database to analyze retail market concentration and its impact on small-scale operators; and recommending guidelines and measures for overseeing competition in the retail sector.

Objectives of the Subcommittees

The subcommittees will study trade practices in digital platforms and in the modern wholesale-retail market to keep pace with shifting business dynamics and to investigate practices with anti-competitive effects. Each subcommittee will determine oversight guidelines and accelerate the promotion of fair trade so all parties can compete on equal terms.

The subcommittees will integrate efforts across relevant agencies, apply existing law to address exploitation or competitive pressure affecting the majority of business operators nationwide, and enforce compliance with guidelines the TCCT has already issued — notably the TCCT Notification on Guidelines for Considering Unfair Trade Practices and Acts that Monopolize, Reduce, or Restrict Competition in Multi-Sided Platform Business Operations for Digital Platform Services of Goods or Services (E-Commerce), in effect since March 25, 2026. They will also continue overseeing platform service businesses and Modern Trade going forward.

Background

Rapidly shifting competitive conditions and an influx of foreign capital have affected domestic operators, particularly SMEs and small-scale retailers. This has driven a sharp rise in complaints to the TCCT concerning online trading practices and the expansion of retail formats into community areas.

A particular concern is the continued increase in Gross Profit (GP) fees — the revenue-share or fee percentages that merchants pay to platforms. Higher GP rates compress net margins for SMEs, which may in turn force price increases that are ultimately passed on to consumers.

According to TCCT data:

  • E-commerce platforms and Modern Trade are currently among the leading competition concerns for small-scale operators at the grassroots of the Thai economy. In the first six months of this year alone, 21 platform-related complaints were filed, involving transactions collectively worth hundreds of billions of baht.
  • During fiscal year 2025 (October 1, 2024 – September 30, 2025), the TCCT received 78 complaints in total. Of these, 40 were not accepted for consideration, 9 were settled, and the remaining 29 are under investigation — most involving platforms, franchises, logistics and transport, digital platforms, and general commerce.

Through its Mobile Competition Clinic project, the TCCT has previously conducted on-site visits in several provinces to hear directly from business operators. Findings included:

Krabi Province:

  1. Online platform issues, including being forced to use specific transport providers and reduced product visibility due to algorithmic ranking.
  2. Online Travel Agency (OTA) platform issues, including price-parity clauses that prohibit hotels from listing lower rates on their own websites than on OTAs.
  3. Unfair trade practices between SMEs and Modern Trade operators, including redundant fee charges and additional GP fees imposed without prior notice.
  4. Palm oil pricing structure issues affecting local farmers.

Chiang Mai and Lamphun Provinces:

  1. Online platform issues, including algorithmic ranking practices that favor a platform’s own affiliated transport services.
  2. Unfair trade practices between SMEs and Modern Trade operators, including credit-term disputes, GP fee collection, and unfair contract terms.
  3. Pricing issues in agricultural product procurement.

Current Priorities and Enforcement Timeline

The TCCT is accelerating proactive oversight across four key business groups: (1) digital platforms, (2) wholesale and Modern Trade, (3) ride-hailing platform services, and (4) online travel booking platforms (OTAs). The newly formed subcommittees will study, analyze, and propose oversight guidelines, and investigate practices affecting competition across all four groups, with findings due by the fourth quarter of 2026. This will include updated operational guidelines designed to keep pace with evolving trade practices.

This initiative marks a deliberate shift in the TCCT’s enforcement approach — from a largely reactive, complaint-driven model to proactive market inspections that do not wait for formal complaints. On-site visits to gather in-depth input from business operators will remain central to this approach, with the TCCT aiming to demonstrate tangible results within the next six months.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

NBTC Issues AI Governance Guidelines for Telecom Licensees

Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has issued new guidelines setting out its expectations for the responsible use of artificial intelligence (AI) by telecommunications licensees. Although the guidelines are not legally binding, they establish a comprehensive risk-based framework for AI governance and provide a clear indication of the regulatory standards that the NBTC expects telecom operators to adopt when deploying AI in the provision of telecommunications services.

The guidelines reflect the increasing regulatory focus on AI governance and complement existing legal obligations relating to cybersecurity, personal data protection, and telecommunications. They also align with broader national efforts to develop a comprehensive AI regulatory framework.

Scope of the Guidelines:

The guidelines apply to holders of telecommunications business licenses under Thailand’s telecommunications licensing regime, but only in relation to AI systems used to provide licensed telecommunications services.

Organizations that are not telecommunications licensees are not directly subject to the guidelines. Nevertheless, AI developers, technology vendors, cloud service providers, and outsourced service providers may be indirectly affected because telecommunications licensees are expected to exercise oversight over third-party AI solutions used in their operations. As a result, contractual obligations and vendor due diligence are likely to become increasingly important for suppliers serving the telecommunications sector.

The guidelines should be considered alongside existing legal requirements, including the Personal Data Protection Act, the Cybersecurity Act, the Computer Crime Act, and the NBTC Notification on the Protection of Telecommunications Service Users’ Rights in relation to personal data, privacy, and the freedom of telecommunications. They also complement the broader AI legislation currently under development by the Electronic Transactions Development Agency (ETDA).

Strengthening AI Governance:

A central feature of the guidelines is the expectation that AI governance should extend beyond technical implementation and become an organizational responsibility.

Telecommunications licensees are encouraged to establish governance structures at both the policy and operational levels, such as AI committees, working groups, or designated responsible officers. These governance bodies should oversee AI strategy, establish internal policies, supervise risk management, and define accountability throughout the AI lifecycle.

The guidelines also emphasize that responsibilities should be clearly assigned not only to internal personnel but also to third-party AI solution providers and outsourced service providers. Licensees are expected to ensure that contractual arrangements clearly define each party’s obligations regarding AI governance, risk management, and regulatory compliance.

A Principles-Based Approach to Responsible AI:

Rather than prescribing detailed technical requirements, the guidelines adopt a principles-based approach centered on six core expectations.

First, AI systems should comply with applicable laws, ethical principles, and internationally recognized standards. AI should respect privacy, human dignity, and fundamental rights, and organizations should consider implementing appropriate safeguards, including content filtering, to reduce the risk of generating harmful or unlawful outputs.

Second, AI systems should operate fairly. This includes using representative and reliable training data, assessing potential bias, and taking appropriate measures to mitigate discriminatory outcomes.

Third, cybersecurity and privacy protections should be integrated into AI systems. The guidelines encourage the adoption of internationally recognized security standards and recommend technical safeguards such as encryption, anonymization, and access controls to protect personal data and system integrity.

Fourth, organizations should promote transparency by maintaining documentation regarding AI design, development, and operation, while providing consumers with appropriate information about how AI systems influence decisions or recommendations.

Fifth, accountability should be clearly established throughout the organization. Internal policies should define responsibility for AI outcomes, while consumers should have accessible channels to submit inquiries or complaints regarding AI-enabled services.

Finally, AI systems should be reliable and robust. The guidelines recommend testing AI models to ensure that they produce accurate and consistent results, including under unexpected operating conditions.

Governance Throughout the AI Lifecycle:

The guidelines emphasize that AI governance should be integrated throughout the entire AI lifecycle rather than focusing solely on deployment.

Licensees are expected to conduct risk assessments before development begins, evaluate the capabilities and reliability of third-party AI providers, and maintain appropriate standards for data quality and traceability. Before deployment, AI systems should undergo testing for reliability, fairness, and operational performance.

Once AI systems are operational, organizations should continuously monitor performance, maintain appropriate human oversight, and periodically evaluate whether AI systems continue to operate as intended. The guidelines also address the retirement of AI systems, encouraging secure decommissioning processes that protect data and maintain appropriate records throughout the system’s lifecycle.

This lifecycle-based approach reflects the growing international trend toward continuous AI governance rather than one-time compliance assessments.

Consumer Transparency and Organizational Readiness:

Consumer protection is another significant feature of the guidelines.

Telecommunications licensees are encouraged to notify consumers when they are interacting with AI systems, such as chatbots or voicebots. Where AI-generated recommendations may influence consumer decisions, organizations should provide appropriate disclosures and allow consumers to request assistance from a human representative where appropriate. Effective feedback and complaint mechanisms should also be maintained.

Internally, the guidelines recognize that responsible AI governance requires organization-wide awareness. Licensees are therefore encouraged to provide AI-related training across all levels of the organization. Employees who use AI systems should understand the associated legal and operational risks, while technical personnel and external developers should receive training on organizational AI policies, ethical principles, and applicable regulatory requirements.

Practical Implications:

Although the guidelines do not create new legal obligations, they provide valuable insight into the NBTC’s regulatory expectations and are likely to influence future regulatory supervision and industry best practices.

Telecommunications licensees should consider reviewing their existing AI governance frameworks to determine whether governance responsibilities are clearly assigned and appropriately documented. Organizations should also evaluate AI risk management procedures, update contracts with AI vendors and outsourced service providers, assess consumer disclosure mechanisms, and ensure that staff receive appropriate AI governance training.

The guidelines may also have implications for corporate transactions involving telecommunications businesses. As AI becomes increasingly integrated into telecommunications operations, AI governance maturity, data governance practices, and vendor oversight may become important considerations during legal and regulatory due diligence.

Key Takeaways:

  • Telecommunications licensees should review their governance frameworks, contractual arrangements, AI risk management processes, consumer disclosure practices, and staff training programs to align with the NBTC’s expectations.
  • The NBTC’s AI guidelines establish a comprehensive risk-based governance framework for telecommunications licensees and provide a clear indication of the regulator’s expectations for responsible AI deployment.
  • Although nonbinding, the guidelines are likely to influence regulatory supervision and industry best practices within Thailand’s telecommunications sector.
  • AI governance is expected to extend throughout the entire AI lifecycle, encompassing organizational governance, risk management, vendor oversight, cybersecurity, consumer protection, and ongoing monitoring.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles