BOT Framework for Safeguarding the Financial Sector from Illicit Activities: New Supervisory Expectations for Financial Institutions and Payment Providers

The Bank of Thailand (BOT), together with financial institutions and regulated financial service providers, has formally launched the Framework for Safeguarding the Financial Sector from Illicit Activities, a sector-wide initiative intended to prevent the financial system from being used to facilitate technology-enabled crime, corruption, money laundering, fraud, and other illicit activities. The Framework represents a significant supervisory development for banks, payment service providers, e-money operators, foreign exchange businesses, and non-bank lenders. While the Framework itself is principally a cooperation and policy framework rather than a standalone regulation imposing penalties, the BOT has expressly indicated that it will strengthen regulations, minimum standards, and supervisory oversight to promote consistent implementation across the financial sector. Accordingly, regulated entities should view the Framework not merely as a statement of policy, but as an indication of the direction in which future supervisory expectations and regulatory requirements are likely to develop.

Five Core Principles:

The Framework is built around five principles that participating institutions are expected to apply in a manner appropriate to their business models and risk profiles. First, preventing misuse of the financial sector should form part of leadership and corporate governance, with boards and senior management responsible for establishing policies, strategic direction, oversight arrangements, and adequate resources. Second, institutions should translate those commitments into effective standards and execution, including appropriate minimum standards for monitoring, detection, and risk response, with periodic review as risks evolve. Third, institutions are expected to develop expertise and data-driven capabilities, using data, technology, and specialized knowledge to improve monitoring and detection. Fourth, the Framework emphasizes collaboration and collective intelligence, including exchanges of information, intelligence, fraud typologies, risk indicators, and best practices among financial institutions, government authorities, private-sector organizations, and other relevant stakeholders, subject to applicable legal frameworks. Finally, preventive measures should pursue balanced objectives, taking into account financial inclusion, fair competition, innovation, customer convenience, and the need to avoid unnecessary burdens on legitimate users.

From Policy Framework to Operational Controls:

The significance of the Framework becomes clearer when the commitments of the BOT and participating industry groups are considered. The BOT intends to strengthen KYC, Customer Due Diligence (CDD), and Enhanced Due Diligence (EDD) standards, including end-to-end controls against mule accounts. It also plans to strengthen Know Your Merchant (KYM) requirements and oversight of high-risk merchants, particularly in payment acceptance services. Other areas identified for enhanced controls include high-value cash transactions, conversion of illicit proceeds into assets that are more difficult to trace, digital financial service security, and standards applicable to non-bank operators.

Financial institutions and industry associations have correspondingly committed to stronger customer identification and due diligence, greater scrutiny of high-risk accounts and cash transactions, and increased use of data and technology to identify unusual transactions and behavioral patterns. Banks are expected to integrate internal information with trusted external sources and use customer profiles, behavioral information, and transaction inflow/outflow patterns to identify links among accounts and suspicious activity. Payment service providers are expected to strengthen KYM throughout the merchant lifecycle, including enhanced merchant screening and behavioral monitoring, while non-bank lenders are expected to strengthen their assessment of customers, related parties, transactions, and sources of funds. The Framework also contemplates databases of high-risk persons and merchants, links with the Central Fraud Registry, and development of industry-wide AML/CFT operational guidelines.

Data Sharing Becomes a Central Compliance Issue:

One of the most consequential elements of the Framework is its emphasis on information sharing. The BOT intends to analyze linkages and share risk patterns, behavioral indicators, and information concerning individuals, legal entities, and merchants identified as high risk. It also envisages greater data exchange and collaborative analytics involving regulatory authorities, law enforcement agencies, and other government bodies. Financial institutions and payment providers will likewise be expected to contribute relevant information, including unusual transaction patterns, merchant information, fraud intelligence, and other indicators that may assist in identifying misuse of the financial system.

This creates an important intersection between financial-crime prevention and personal data protection. The Framework expressly recognizes that information exchange must occur within applicable legal frameworks. Consequently, an expectation or request to share information for fraud prevention purposes should not automatically be treated as removing the need for analysis under the Personal Data Protection Act (PDPA). Institutions should identify an appropriate lawful basis for each relevant processing and disclosure activity, determine whether the data collected and shared are necessary and proportionate to the stated purpose, establish appropriate retention periods, and implement access controls and security safeguards. Data accuracy will be particularly important where information is used to classify a person or merchant as high risk or to restrict access to financial services.

High-Risk and Blacklist Databases Require Particular Attention:

The contemplated development and sharing of high-risk-person and merchant information raises additional governance considerations. A risk indicator used merely to trigger additional review is materially different from a blacklist that automatically results in account restrictions, rejection of onboarding, termination of services, or other adverse consequences. Institutions should therefore consider establishing clear criteria for inclusion and removal, defining the evidentiary threshold required for a high-risk designation, controlling who may submit or amend records, periodically reviewing whether information remains accurate and relevant, and establishing escalation or review procedures where a designation may materially affect a customer.

These issues become more significant as databases are interconnected across institutions or with centralized fraud information systems. Incorrect, outdated, or insufficiently verified information could potentially propagate across the financial sector and affect an individual or business beyond the institution that originally generated the risk indicator. Governance of shared databases should therefore address not only cybersecurity and access management but also data provenance, accuracy, correction procedures, retention, accountability, and the distinction between intelligence suggesting risk and verified findings of unlawful conduct.

What Financial Institutions and Payment Providers Should Do Now

Although detailed minimum standards will continue to develop, regulated entities should consider conducting a readiness assessment against the Framework now rather than waiting for individual implementing measures. This should include reviewing whether board and senior-management oversight adequately covers financial-crime and fraud risks; mapping existing KYC/CDD/EDD and KYM controls against the emerging supervisory direction; assessing high-value cash and unusual-transaction monitoring; reviewing the use of AI, behavioral analytics, and external data sources; and identifying existing or planned information-sharing arrangements with other institutions, industry bodies, regulators, and law-enforcement agencies. Particular attention should be given to the interface between financial-crime controls and the institution’s PDPA, cybersecurity, data governance, outsourcing, and third-party risk frameworks.

Institutions should also document the legal and governance architecture supporting fraud-related data processing before broader industry sharing becomes operational. This may include reviewing privacy notices, records of processing activities, data-sharing agreements or protocols, retention schedules, access matrices, security controls, procedures for correcting inaccurate risk information, and the allocation of responsibilities among compliance, AML, fraud, privacy, cybersecurity, legal, and business teams. Where automated tools or risk-scoring systems are used to identify high-risk customers or transactions, institutions should also consider whether their governance arrangements provide sufficient human oversight and mechanisms to manage false positives and unintended customer impacts.

Key Takeaways:

The Framework marks a shift toward a more coordinated, intelligence-led approach to protecting the financial sector from illicit activities. Although it is not, by itself, a standalone penal regulation, the BOT has expressly signaled further development of regulations, minimum standards, and supervisory oversight, making the Framework an important indicator of future compliance expectations.

For financial institutions, payment providers, and other regulated non-banks, the immediate priorities are to assess existing KYC/CDD/EDD and KYM controls, strengthen technology-based detection and high-risk transaction monitoring, and prepare for substantially greater information sharing across the financial ecosystem. At the same time, fraud prevention and financial-crime objectives must be reconciled with PDPA requirements, cybersecurity controls, proportionality, data accuracy, retention, and appropriate governance of high-risk and blacklist databases.

The next major development to monitor will be the BOT’s issuance or enhancement of minimum standards, regulations, supervisory guidelines, or operational requirements implementing the Framework. Those measures are likely to determine when the Framework moves from a high-level sector commitment to more concrete and enforceable compliance expectations.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Bangkok Blueprint: A New Framework for Protecting the Financial Sector from Illicit Activities

The Bank of Thailand (BOT) is moving toward a broader and more coordinated approach to preventing the financial system from being used for fraud and other illicit activities. As part of this initiative, the BOT, together with relevant financial-sector stakeholders, is preparing the Framework on Safeguarding the Financial Sector from Illicit Activities, while the BOT, the International Monetary Fund (IMF), and the World Bank Group are also advancing the Bangkok Blueprint for Fraud-Resilient Financial Services.

Although the final text of the Framework has not yet been separately published in the official materials reviewed for this article, the initiatives signal an important development in financial-sector supervision: fraud prevention and the prevention of illicit financial flows are increasingly being treated as responsibilities extending across the financial ecosystem rather than as matters confined to individual institutions or conventional anti-money laundering controls.

The Bangkok Blueprint:

The Bangkok Blueprint is intended to strengthen the resilience of financial services against fraud and scams in the digital age. The BOT has described the initiative as being developed with the IMF and World Bank Group and as providing a practical reference for strengthening coordinated responses to digital financial fraud.

This direction reflects the changing nature of financial crime. Digitalization has made payments faster and financial services more accessible, but it has also allowed fraud proceeds to move rapidly between accounts, institutions, payment channels, and potentially other asset classes. An effective response therefore increasingly depends on coordination among financial institutions and other participants in the financial ecosystem.

The BOT has already taken measures addressing unauthorized payment fraud and, more recently, authorized push payment fraud. These measures have included controls relating to mule accounts, tracing of fund flows, use of customer behavioral information, risk-based transaction limits, and shared-responsibility principles. The Bangkok Blueprint appears to place these developments within a broader policy framework focused on making financial services more resilient against fraud.

Safeguarding the Financial Sector from Illicit Activities

Alongside the Bangkok Blueprint, the BOT is coordinating the Framework on Safeguarding the Financial Sector from Illicit Activities. According to the BOT’s official announcement, this is intended to be a sector-wide initiative aimed at preventing the financial system from being misused for illegal and fraudulent activities.

The significance of the Framework is its potentially broad institutional reach. The policy direction described publicly extends beyond commercial banks and reflects the need for controls across different points through which illicit funds may enter, move through, or leave the financial system.

Public statements surrounding the initiative indicate an emphasis on strengthening customer due diligence, identifying higher-risk transactions, improving information sharing, and reinforcing anti-money laundering controls. However, until the final Framework is officially published, these matters should not be treated as new binding regulatory requirements merely by reason of the Framework itself.

From Individual Compliance to Ecosystem Responsibility:

The more important development may be the shift in regulatory philosophy. Traditional compliance programs tend to focus on whether an individual institution has properly identified its customer, monitored transactions, reported suspicious activity, and complied with applicable restrictions. Digital fraud demonstrates the limitations of an institution-by-institution approach because funds can move through several accounts and service providers within a very short period.

The emerging approach therefore places greater importance on the ability of institutions to identify suspicious behavior rapidly, connect information from different sources, exchange relevant fraud intelligence, and intervene before illicit funds disappear from the regulated financial system.

For banks and other regulated financial businesses, this could eventually affect the design of onboarding controls, customer risk classification, transaction-monitoring systems, mule-account detection, escalation procedures, information-sharing arrangements, and internal governance. It may also increase expectations that management can demonstrate not merely formal compliance with existing rules, but the effectiveness of controls in preventing the institution’s products and infrastructure from facilitating illicit activity.

What Financial Institutions Should Watch:

The practical significance of the Framework will depend on the final text and any subsequent BOT rules, guidelines, supervisory expectations, or industry commitments implementing it. In particular, financial institutions should monitor whether the initiative results in more specific expectations concerning mule-account identification and management, customer and merchant onboarding, enhanced due diligence for higher-risk customers, transaction monitoring, cross-institution information sharing, rapid restriction or suspension of suspicious transactions, and governance responsibility for financial-crime controls.

Institutions should also consider the interaction between these measures and their existing obligations concerning anti-money laundering, cybersecurity, fraud prevention, consumer protection, and personal data protection. Greater information sharing can improve fraud detection, but institutions will need appropriate legal bases, governance, security measures, access controls, retention policies, and safeguards governing the use and disclosure of customer information.

Key Takeaways:

The Bangkok Blueprint and the Framework on Safeguarding the Financial Sector from Illicit Activities indicate a move toward a more integrated approach to financial crime, linking fraud prevention, illicit-fund detection, customer due diligence, transaction monitoring, and cooperation across the financial ecosystem.

For regulated financial businesses, the key issue will be whether the final Framework remains principally a statement of collective commitment or develops into concrete supervisory expectations. If detailed obligations or commitments are introduced, institutions may need to reassess their customer onboarding, mule-account controls, transaction-monitoring capabilities, information-sharing arrangements, escalation procedures, and governance structures.

Until the final Framework is officially available, however, institutions should distinguish between the BOT’s announced policy direction and legally or regulatory binding requirements. The publication of the final Framework—and any subsequent implementing measures—will therefore be important in determining the immediate compliance impact on banks, payment service providers, non-bank lenders, foreign exchange businesses, and other regulated financial-sector participants.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Social Media Advertising: New Advertiser Verification Requirements Take Effect Soon

A significant compliance deadline is approaching for businesses involved in social media advertising. From 1 November 2026, social media service providers offering paid advertising will be required to verify the identity of advertisers before advertisements are published in Thailand under the Notification of the Electronic Transactions Commission on Measures for the Prevention of Technology Crime for Social Media Service Providers (No. 2) (the Notification). With the effective date approaching, platforms should now move beyond legal assessment and ensure that their advertiser onboarding, identity verification, payment, and record-retention systems are operationally ready.

Advertiser Verification and Record Retention:

Where an advertisement is published in Thailand through social media and the social media service provider receives payment for the advertising service, whether from the advertiser or another person, the provider must verify the identity of the advertiser before publication. Verification may be conducted using government-issued identification that can be checked against a reliable source, together with a method of establishing the connection between the advertiser and the identification evidence, or through a Digital ID verification and authentication system meeting the applicable standards of the Electronic Transactions Commission. The requirement should therefore not be understood simply as a mandatory “face scan” rule. Importantly, verification generally does not need to be repeated where the advertiser has already been verified within the preceding one year, allowing platforms to maintain verified-advertiser systems rather than conducting a completely new verification exercise for every advertisement.

The Notification also requires platforms to retain prescribed information identifying the advertiser, including relevant identification, corporate and contact information. Where advertising charges are paid by a person other than the advertiser, information concerning the payer must also be retained. This is particularly relevant to advertising agencies, media buyers, corporate groups, and centralized advertising arrangements where the entity funding an advertising campaign may differ from the advertiser or the person operating the advertising account. The required information must generally be retained for at least 90 days after the advertising service ends.

Why the New Requirements Matter:

The Notification should be considered within the broader shared-responsibility framework under the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes. Under that framework, social media service providers may be required to participate in responsibility for losses resulting from technology crime unless they can demonstrate compliance with the applicable preventive standards or measures prescribed by the relevant regulator. Advertiser verification is therefore more than an administrative KYC exercise. Platforms should maintain systems and evidence capable of demonstrating that the required verification, information collection, and related preventive measures were properly carried out if fraudulent advertising subsequently results in losses.

Although the principal regulatory obligations fall on social media service providers, the practical impact will extend throughout the advertising ecosystem. Advertising agencies operating accounts for clients may be asked to establish the identity of the underlying advertiser, the legal entity represented, and the person funding the campaign. Foreign advertisers may face additional onboarding requirements involving passports, foreign corporate documents, authorized representatives, and cross-border payment arrangements. Businesses using agencies or regional media-buying structures should therefore review whether their documentation and authorization arrangements will allow platforms to identify the relevant parties without delaying campaigns.

Data Protection and Implementation:

The new regime also has an important PDPA dimension. Identity verification may involve national identification documents, passports, corporate representatives’ information, contact details, and potentially facial images used for verification. Platforms should therefore ensure that the collection and retention of this information complies not only with the Notification but also with the Personal Data Protection Act, including requirements concerning lawful processing, privacy information, security, access controls, and appropriate retention and deletion. A regulatory requirement to collect or retain particular information does not displace the broader obligations applicable to the processing of personal data.

Before the effective date, social media platforms should test the complete advertising workflow rather than simply adding a KYC step. This includes determining when advertising falls within the Notification, establishing appropriate verification methods for individuals and legal entities, recording when an advertiser was last verified, identifying third-party payers, maintaining the required information for the applicable period, and addressing situations involving agencies, foreign advertisers, corporate accounts, authorized representatives, and regional advertising arrangements. Advertisers and agencies should likewise review who is identified as the advertiser for each account, who actually pays the advertising charges, and whether the necessary identification, corporate, and authorization documents will be readily available. The practical deadline is therefore not simply 1 November 2026: businesses should have the necessary systems, procedures, and documentation in place before that date to avoid disruption when the requirements become mandatory.

Key Takeaways:

From 1 November 2026, paid social media advertising published in Thailand will be subject to stronger advertiser-identification requirements. Social media service providers must verify advertisers before publication, subject to the exception for advertisers verified within the preceding year, and retain prescribed identifying information for at least 90 days after the advertising service ends. Information concerning a third-party payer must also be retained where someone other than the advertiser pays for the advertising.

Although the legal obligations principally apply to social media service providers, their operational effects will extend to advertisers, agencies, media buyers, foreign businesses, and businesses using centralized payment arrangements. Most importantly, the requirements should not be treated merely as another KYC exercise: within the broader technology-crime liability framework, platforms should be able to demonstrate compliance with the required verification and preventive measures. Businesses participating in the social media advertising ecosystem should therefore review their verification, payment, record-retention, and data-protection processes now rather than waiting until the requirements become mandatory.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Revises Visa Exemption Scheme: 30-Day Stay and Revised List of Eligible Countries

1. Introduction

The Ministry of Interior has issued notification revising Thailand’s visa exemption arrangements for foreign nationals. The revised measures repeal the special 60-day visa exemption scheme introduced in July 2024 and establish an updated list of countries and territories whose passport or travel-document holders may enter the Kingdom without a visa for tourism purposes, for a period not exceeding 30 days.

The notifications were signed on 26 August 2026 and published in the Royal Gazette on 31 August 2026, and will take effect on 15 September 2026, being 15 days after publication.

2. Background: The Previous 60-Day Visa Exemption Scheme

Under the Ministry of Interior notification dated 15 July 2024, nationals of 93 countries and territories entering Thailand for tourism, work, or short-term business purposes were exempt from visa requirements and permitted to stay for up to 60 days.

3. The Revised 30-Day Visa Exemption Scheme

3.1 Scope

  • The revised notification sets out an updated list of countries and territories eligible for visa-free entry for tourism purposes with the permitted period of stay reduced from 60 days to 30 days.
  • The revised scheme covers 60 countries and territories in total: 59 retained from the previous list, plus the Kyrgyz Republic, which has been newly added.

3.2 Retained Countries and Territories (59)

  • Asia: Bahrain, Bhutan, Brunei Darussalam, Georgia, India, Indonesia, Israel, Japan, Jordan, Kuwait, Malaysia, Maldives, Oman, Philippines, Qatar, Saudi Arabia, Singapore, Taiwan, Türkiye, and the United Arab Emirates.
  • Europe: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland, Ukraine, and the United Kingdom.
  • Africa: South Africa.
  • North America: Canada and the United States.
  • Oceania: Australia, Fiji, and New Zealand.

3.3 Amended Countries and Territories Covered by the Revised 15-Day Scheme (2)

  • Africa: Seychelles and Mauritius 

Seychelles is not counted as retained Country and Territory as it never been in the Scheme while the Mauritius was in 30 – Day Scheme.

In addition, the Kyrgyz Republic has been newly added to the revised list as well as Seychelles on the Revised 15 – Day Scheme. 

3.4 Countries and Territories No Longer Covered by the Revised 30-Day Scheme (34)

  • Asia: Cambodia, China, Hong Kong, Kazakhstan, Korea (ROK), Laos, Macao, Mongolia, Sri Lanka, Uzbekistan, and Vietnam.
  • Europe: Albania, Andorra, Kosovo, Monaco, Russia, and San Marino.
  • Africa:  Mauritius and Morocco.
  • North, Central America and the Caribbean: Cuba, Dominica, the Dominican Republic, Guatemala, Jamaica, Mexico, Panama,Trinidad and Tobago.
  • South America: Brazil, Colombia, Ecuador, Peru, and Uruguay.
  • Oceania: Papua New Guinea and Tonga.

These countries and territories are no longer covered by the revised 30-day visa exemption scheme. Certain nationals among them are eligible for visa-free entry under separate arrangements.

4. Key Operational Requirements Under the Revised Scheme

4.1 Purpose of Entry

Whereas the previous notification permitted eligible nationals from a broader list of countries to enter Thailand for tourism purposes for up to 60 days, the revised notification limits the privilege to a reduced number of eligible countries and shortens the permitted stay to 30 days.

4.2 Land-Border Entry Limitations

  • Visa-exempt entry through land-border immigration checkpoints for the nationals listed in Item 3.2 is limited to no more than two entries per calendar year, except for nationals of Malaysia, Brunei Darussalam, Indonesia, and Singapore, and any other countries as may be further designated by the Ministry of Interior.

5. Effect on Nationals Removed From the Previous Scheme

Once the revised measures take effect, nationals of countries and territories removed from the previous list will no longer be entitled to the former 60-day exemption and also this 30-day exemption. However, some may nonetheless remain eligible for visa-free entry under separate bilateral arrangements. The applicable entry requirements and permitted period of stay therefore depend on the specific legal basis applicable to each foreign national.

  • Required to obtain a visa prior to entry (21 from 34 countries): Albania, Andorra, Colombia, Cuba, Dominica, the Dominican Republic, Ecuador, Guatemala, Jamaica, Kosovo, Mexico, Monaco, Morocco, Panama, Papua New Guinea, San Marino, Sri Lanka, Tonga, Trinidad and Tobago, Uruguay, and Uzbekistan.
  • Covered under separate bilateral arrangements (11 countries and territories): Cambodia, China, Hong Kong, Kazakhstan, Korea (ROK), Laos, Macao, Mongolia, Russia, Vietnam, and Mauritius continue to be governed by their respective bilateral frameworks. For example, Chinese nationals continue to be eligible for visa-exempt entry under the agreement between Thailand and the People’s Republic of China on mutual visa exemption, allowing a stay of up to 30 days per entry, subject to the terms and conditions of the agreement.

6. Key Takeaways

  • The permitted period of visa-exempt stay under the general scheme has been reduced from 60 days to 30 days.
  • The number of countries and territories eligible under the general visa exemption has decreased from 93 to 60.
  • Nationals of countries removed from the list will no longer benefit from the former 60-day exemption, however, subject to any separate bilateral or country-specific arrangements.
  • The revised measures take effect on 15 September 2026. Travellers admitted before that date retain the period of stay granted under the rules in force on their date of arrival.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPA: When CCTV Becomes Biometric Processing

CCTV vs. Biometric Data:

The increasing use of facial recognition systems in office buildings, condominiums, hospitals, retail premises and other facilities raises an important question under the Personal Data Protection Act B.E. 2562 (2019) (PDPA): when does ordinary CCTV become processing of sensitive personal data? An identifiable image recorded by conventional CCTV will generally constitute personal data, but it should not automatically be regarded as sensitive biometric data merely because a person’s face is visible. The position changes where technology is applied to facial characteristics for the purpose of uniquely identifying or authenticating an individual. The PDPA treats biometric data resulting from such processing as sensitive personal data under section 26, with facial templates, iris templates and fingerprint templates being recognized examples.

Legal Basis for CCTV and Facial Recognition:

For ordinary CCTV, an organization must identify an appropriate legal basis and comply with requirements concerning transparency, purpose limitation, security, retention and data subject rights. For private organizations, CCTV installed for genuine security purposes may potentially rely on legitimate interests under section 24(5), subject to balancing those interests against the rights and freedoms of the individuals being recorded. Other grounds may apply depending on the circumstances, including compliance with a legal obligation under section 24(6), while public authorities may in appropriate cases rely on processing necessary for a task carried out in the public interest or exercise of official authority under section 24(4). Importantly, however, a legal basis that supports conventional CCTV does not automatically authorize facial recognition. Once facial images are processed as biometric data for unique identification, the organization must separately satisfy the requirements applicable to sensitive personal data under section 26.

Consent and Alternative Access:

This distinction is particularly important for facial recognition used to control access to condominiums, offices and other premises. A business may have a legitimate interest in protecting its premises, residents, employees and property, but the existence of a legitimate security objective does not necessarily establish that biometric identification is necessary to achieve it. Where no section 26 exception applies and explicit consent is relied upon, the organization should consider whether that consent is genuinely voluntary. If a resident, employee or tenant who refuses facial recognition cannot reasonably access the premises, the validity of that consent may be questionable. Providing a workable non-biometric alternative, such as an access card, physical key, PIN or mobile credential, can therefore be an important compliance measure. This should not be treated as an absolute rule requiring an alternative in every biometric deployment; the assessment depends on the applicable legal basis, necessity of the processing and circumstances in which consent is obtained.

Public Authorities and Large-Scale Processing:

Public authorities require a different analysis. They may have statutory functions or public-interest grounds supporting particular processing activities, but the existence of a public function does not itself provide unlimited authority to process biometric information. The authority should identify the specific statutory function and applicable section 26 exception and assess whether biometric processing is necessary and proportionate to that function. This is particularly important for large-scale identity verification systems involving transportation, border control, healthcare and public digital services. Similarly, organizations carrying out large-scale biometric identification or systematic monitoring should consider whether the nature, scale and risks of the processing require or justify a data protection impact assessment before implementation.

Transparency and Retention:

Transparency and retention also require particular attention. CCTV notices should be displayed appropriately before individuals enter monitored areas and should provide, or direct individuals to, information concerning the controller, purposes, legal basis, retention, disclosures, data subject rights and relevant contact channels. Where facial recognition is used, a generic notice stating merely that “CCTV is in operation” may not adequately describe the biometric processing taking place. Retention should likewise be determined by necessity and purpose rather than an assumed universal period such as 30 days. Particular footage may be preserved for longer where reasonably required for investigation, litigation or other legitimate purposes, while biometric templates warrant greater caution because biometric characteristics cannot readily be replaced if compromised.

What Businesses Should Review:

Businesses already using facial recognition should therefore reassess their systems rather than treating them merely as enhanced CCTV. The review should determine what information the technology actually generates, whether facial templates or other biometric identifiers are created, the section 26 basis relied upon, whether consent is genuinely voluntary where consent is used, and whether less intrusive technology could reasonably achieve the same purpose. Vendor arrangements should also be examined to determine where biometric data is stored and processed, who can access it, whether vendors retain or reuse the information, whether overseas transfers occur, and whether the data is used to develop or train the vendor’s technology. The critical compliance question is therefore no longer simply whether an organization may install CCTV, but what the system does with the images after they are captured.

Key Takeaways:

  • Ordinary CCTV images are personal data but are not automatically sensitive biometric data.
  • Facial recognition used for unique identification or authentication may constitute biometric processing under section 26.
  • A legal basis for conventional CCTV does not automatically authorize facial recognition.
  • Where biometric processing relies on consent, organizations should assess whether consent is genuinely voluntary and whether a practical non-biometric alternative should be available.
  • Public authorities must still identify an applicable legal basis for sensitive biometric processing and consider necessity and proportionality.
  • Retention periods should reflect necessity and purpose rather than an assumed fixed period.
  • Introducing facial recognition or AI analytics into an existing CCTV system should trigger a fresh PDPA compliance assessment.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Cabinet Approves Draft Bills Expanding Thai Labor Court Jurisdiction to Criminal Cases, Excluding Human Trafficking

On August 25, 2026, the Cabinet of Thailand (the “Cabinet“) has approved two draft acts, reviewed by the Office of the Council of State and proposed by the Office of the Judiciary:

  1. The Draft Act on the Establishment of Labor Courts and Labor Court Procedure (No. ..), B.E. …. (the “Draft Labor Court Act“); and
  2. The Draft Human Trafficking Procedure Act (No. ..), B.E. …. (the “Draft Human Trafficking Act“).

Background

  • Criminal liability under labor law has distinct characteristics that differ from general criminal liability under the Criminal Code or other statutes. At present, however, the Labor Court’s jurisdiction is limited to labor disputes and does not extend to criminal cases arising under labor-related laws. This limitation is inconsistent with the fundamental principle underlying labor adjudication—namely, that such cases should be heard by judges with specialized knowledge, expertise, and genuine understanding of labor issues.
  • Under the current system, the civil aspects of a labor case are heard in the Labor Court while the related criminal aspects are heard in other Courts of Justice. This bifurcated process results in the following:
    • It increases the burden on litigants, who must pursue proceedings in two separate courts;
    • It requires judges and litigants to spend additional time re-examining evidence for the criminal proceedings, even though most of the relevant facts already appear in the Labor Court case file; and
    • It creates a risk that judicial discretion in sentencing for criminal labor cases will vary from court to court.
  • The Draft Human Trafficking Act expressly excludes human trafficking cases from the jurisdiction of the Labor Court, even where such cases involve elements of forced labor or services. Because human trafficking offenses are severe, carry substantial penalties, and may be connected to other criminal offenses, the Human Trafficking Procedure Act, B.E. 2559 (2016), is being amended concurrently with the Draft Labor Court Act to prohibit the Labor Court from accepting cases involving charges under the law on the prevention and suppression of human trafficking.

Key Changes

1. Draft Labor Court Act

The Draft Labor Court Act amends the Act on the Establishment of the Labor Court and Labor Procedure, B.E. 2522 (1979), to expand the Labor Court’s jurisdiction to include criminal labor cases. Previously, the Labor Court’s jurisdiction covered labor cases only, expressly excluding criminal matters. The key changes are as follows:

1.1 Expanded criminal jurisdiction The Labor Court will have jurisdiction to try and adjudicate criminal cases involving offenses under the following labor-related laws:

  • The law on homeworkers’ protection;
  • The law on labor protection;
  • The law on labor protection in sea fishery work;
  • The law on employment and job-seeker protection;
  • The law on the management of foreign workers’ employment;
  • The law on social security;
  • The law on occupational safety, health, and working environment;
  • The law on workmen’s compensation;
  • The law on maritime labor;
  • The law on state enterprise labor relations;
  • The law on labor relations; and
  • Other laws as prescribed by Royal Decree.

Cases falling within the jurisdiction of the Juvenile and Family Court remain excluded from the jurisdiction of the Labor Court.

1.2 Joinder of offenses Where a single act constitutes multiple offenses and at least one falls within the Labor Court’s jurisdiction, the Labor Court has authority to try and adjudicate the related offenses as well. Where multiple interconnected acts are involved, the Labor Court may either adjudicate them jointly or transfer the case to a competent court, having primary regard to convenience and the interests of justice.

1.3 Applicable procedure For criminal proceedings before the Labor Court, the Draft Labor Court Act provides that the Criminal Procedure Code, or the law on the establishment of Magistrate Courts and criminal procedure therein, shall apply, as applicable. The Criminal Procedure Code shall likewise apply to proceedings at both the appellate and Supreme Court levels.

1.4 Procedural rule-making authority The Chief Judge of the Central Labor Court has the authority to issue procedural regulations governing criminal proceedings, subject to the approval of the President of the Supreme Court. Such regulations must not conflict with the Criminal Procedure Code or diminish a defendant’s right to a defense below the standard prescribed by law. Where necessary, the Labor Court may also appoint another court of first instance to carry out procedural acts on its behalf, excluding the final adjudication of the dispute.

1.5 Composition of the bench The composition of the judicial panel authorized to try criminal cases shall conform to the law on the Organization of the Courts of Justice.

1.6 Transitional provision Criminal cases pending before the effective date of the Draft Labor Court Act shall remain under the jurisdiction of the original court until final judgment.

2. Draft Human Trafficking Act

The Draft Human Trafficking Act amends the Human Trafficking Procedure Act, B.E. 2559 (2016). Under the current law, the Intellectual Property and International Trade Court and the Central Bankruptcy Court are prohibited from accepting cases involving charges under the law on the prevention and suppression of human trafficking. The Draft Human Trafficking Act adds the Labor Court to this list, thereby also prohibiting the Labor Court from accepting such cases.

Key Takeaways

  • The principal objective of this legislative reform is to allow criminal cases arising under labor law to be brought directly before courts with specialized expertise in labor matters. Under the current framework, the civil and criminal aspects of a labor dispute must be handled separately in different courts. This reform is intended to promote greater continuity in the assessment of the underlying facts and the nuances of the employment relationship, while reducing the procedural burden on litigants.
  • At the same time, these amendments prohibit the Labor Court from hearing human trafficking cases—even those involving forced labor—thereby keeping these high-severity offenses within the jurisdiction of the general criminal courts.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Digital Platform Fees: New Guidance on Transparency and Fairness

Thailand’s regulation of digital platform services is continuing to develop beyond basic registration and disclosure obligations. The Electronic Transactions Development Agency (ETDA) has issued a new guideline addressing transparency and fairness in the fees charged by digital platform service providers. The guideline is intended to address growing concerns surrounding unpredictable fee structures, hidden costs, frequent changes to charges, and contractual arrangements that make it difficult for businesses using platforms to determine their actual cost of doing business.

The guideline does not impose a statutory cap on platform fees or prescribe particular prices. Instead, it establishes a best-practice framework under which platform operators are encouraged to make their fee structures transparent, understandable, predictable, and fair. Although the guideline is voluntary in nature, it provides an important indication of the regulatory standards that ETDA considers appropriate for the digital platform sector and should therefore be considered when platform operators design or review their terms and conditions and commercial arrangements.

Transparency of Platform Fees:

A central principle of the guideline is that users should be able to understand the total financial burden associated with using a platform.

Platform operators are encouraged to present fee information in a centralized and readily accessible location rather than requiring users to search through multiple pages, policies, or contractual documents. Information should clearly identify the different categories of fees, explain what each fee represents and what service or benefit the user receives in return, and provide sufficient information regarding the basis for calculating the fee.

Where a fee is calculated according to a formula or percentage, practical examples should be provided where appropriate so that users can reasonably estimate the amount they will be required to pay.

This approach is particularly relevant to platforms where the overall cost imposed on merchants or service providers consists of several components. Depending on the business model, these may include commissions, transaction charges, payment-processing fees, advertising expenses, promotional program charges, affiliate fees, logistics charges, or charges for additional platform services.

The regulatory concern is therefore not limited to the headline commission rate. A fee structure may create transparency concerns where individual charges appear understandable in isolation but users cannot readily determine their aggregate cost.

Changes to Fees Should Be Predictable:

The guideline also addresses changes to platform fees. ETDA recommends that platform operators provide users with advance notice of changes, with the guideline contemplating at least 15 days’ prior notice.

This principle is significant for merchants and other business users because frequent or unexpected changes to fees may affect their ability to calculate margins, determine prices, or decide whether continued participation on a platform remains commercially viable.

From a compliance perspective, platform operators should therefore consider establishing an internal change-management process for fee adjustments. Before introducing or increasing a fee, operators should identify the affected users, prepare an understandable explanation of the change, determine how and when notice will be delivered, and maintain appropriate records showing that the required communication has taken place.

The issue should also be considered together with the existing regulatory framework governing changes to the terms and conditions of digital platform services. Fee changes should not be treated merely as an accounting matter where they effectively alter the commercial terms governing the relationship between the platform and its users.

Fairness Is More Than Disclosure:

Transparency alone does not necessarily make a fee fair. The guideline therefore establishes a separate fairness principle.

Among other things, platform operators are encouraged to avoid duplicative charges and to ensure that fees have a reasonable relationship with the relevant costs or value provided. Users should generally not be compelled to purchase ancillary services merely as a practical condition of obtaining the core platform service.

Additional fees should similarly correspond to genuine additional value or services received by users rather than operating as unavoidable charges presented as optional services.

These principles are particularly relevant to platform ecosystems in which merchants may technically be free not to purchase advertising, participate in promotions, use affiliate programs, or acquire other supplementary services, but where the commercial architecture of the platform could make participation practically necessary to remain visible or competitive.

Accordingly, platform operators reviewing compliance should consider the economic substance of their fee arrangements rather than relying exclusively on how a charge is described in the contract.

Relationship With Competition Law:

The guideline also has an important competition-law dimension. In ETDA’s discussion of the new framework, the Trade Competition Commission of Thailand emphasized that regulatory scrutiny is not simply concerned with whether a fee is “high” or “low.” Relevant concerns can include whether the pricing structure is reasonable and transparent and whether the operator can explain the basis on which particular fees are determined.

Competition concerns may potentially arise in circumstances involving excessive charges, predatory pricing, or coordinated or parallel pricing behavior unsupported by legitimate cost considerations.

The regulatory approach therefore appears to favor transparency and market discipline rather than direct government determination of platform prices. This distinction is important: the objective of the guideline is not to establish a uniform fee structure across platforms, whose business models and cost structures may differ substantially, but to encourage operators to be able to explain and justify how their charges operate.

What Platform Operators Should Review:

The guideline provides a useful opportunity for platform operators to conduct a broader review of their commercial arrangements with users. In particular, operators should consider whether users can easily identify every material fee applicable to them; whether the purpose and calculation method of each fee are adequately explained; whether optional services are genuinely optional in practice; whether fees for similar services overlap; and whether procedures exist for providing adequate advance notice of fee changes.

Operators should also consider whether their internal records provide a reasonable explanation for the commercial basis of material fees. This may become increasingly important where complaints regarding platform charges raise issues not only under the digital platform regulatory framework but also under consumer-protection or competition laws.

For businesses operating multiple digital services, fee governance may therefore merit treatment as a compliance function rather than simply a commercial pricing decision.

A Broader Direction in Platform Regulation:

The new guideline should also be viewed in the broader context of Thailand’s regulatory framework for digital platform services. The Royal Decree on the Operation of Digital Platform Service Businesses Subject to Prior Notification already establishes obligations intended to improve transparency and fairness in platform operations.

ETDA’s increasing use of detailed guidelines and sector-specific measures indicates a movement toward more substantive expectations concerning how platforms interact with users, rather than regulation being confined to notification requirements.

The fee guideline is formally framed as best practice. Nevertheless, voluntary regulatory guidance can influence market expectations, contractual practices, complaint handling, and the way regulators assess whether platform conduct is transparent and fair. Platform operators should therefore consider the guideline when drafting new fee structures and when reviewing existing terms and conditions.

Key Takeaways:

  • ETDA has introduced a best-practice framework for transparency and fairness in digital platform fees rather than imposing price controls or statutory fee caps.
  • Platform operators are encouraged to consolidate fee information, explain the purpose and calculation of charges, and enable users to understand their overall cost of using the platform.
  • Changes to fees should be communicated in advance, with the guideline recommending at least 15 days’ notice.
  • Fairness requires more than disclosure: duplicative charges, compulsory ancillary services, and fees that do not reasonably correspond to costs or value may raise concerns.
  • Platform fee structures may also have implications under competition and consumer-protection laws.
  • Even though the guideline operates as voluntary guidance, platform operators should consider incorporating its principles into their terms and conditions, pricing governance, and compliance procedures.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

ETDA: Proposed Overhaul of Thailand’s Electronic Transactions Act – Modernizing for the Digital Economy

Thailand’s existing Electronic Transactions Act B.E. 2544 (2001, as amended) has served as the foundational legal framework for electronic transactions for over two decades. Enacted in an earlier era of digital adoption, it primarily addressed basic electronic signatures, data messages, and recognition of electronic records. However, it increasingly struggles to accommodate rapid technological advancements, including automated contracting systems, electronic transferable instruments (such as e-bills of lading), cloud-based data storage, digital identity solutions, and complex cross-border digital platforms.

Limitations in the current law—such as uncertainty around the reliability and evidentiary weight of electronic data, rigid requirements that do not flexibly support emerging technologies without additional regulations, and enforcement gaps—hinder full digital transformation. This creates friction for businesses adopting paperless processes, e-commerce, fintech, logistics, and other innovative models central to Thailand 4.0 and the broader digital economy.

Many jurisdictions have proactively updated their frameworks to address these challenges. The United Nations Commission on International Trade Law (UNCITRAL) Model Laws on Electronic Commerce, Electronic Signatures, and Electronic Transferable Records have influenced reforms worldwide. Countries like Singapore, the EU (with eIDAS and related directives), and others have introduced technology-neutral rules, enhanced trust services, liability frameworks for service providers, and specific provisions for electronic equivalents of negotiable instruments. These updates boost legal certainty, reduce compliance burdens, facilitate international trade, and stimulate innovation while maintaining consumer and business protections.

Key Changes in the Draft Act and UNCITRAL Alignment:

The Electronic Transactions Development Agency (ETDA) has proposed a comprehensive Draft Electronic Transactions Act for public hearing (comments due by June 15, 2026). The draft represents a substantial rewrite rather than a simple amendment. It shifts Thailand toward a more technology-neutral, principles-based, and trust-oriented framework, building on the original law’s foundations while incorporating newer UNCITRAL instruments.

Major Changes from the Current Law:

Broader Legal Recognition of Electronic Data and Transactions: Electronic records that are accessible, reusable, and retain integrity will satisfy requirements for “writing,” originals, retention, and evidence across civil, criminal, and procedural contexts. Electronic transactions become the default/preferred mode. This significantly expands functional equivalence beyond the 2001 Act’s more limited scope.

Electronic Signatures, Seals, Timestamps, and Notices: Reliable electronic methods (or ETDA-prescribed ones) fulfill signature, seal, timestamp, and registered mail requirements. Public announcements can shift to verified online platforms. New emphasis on electronic seals and reliable timestamps strengthens evidentiary value.

Reliable Methods, Certification, and Burden of Proof: Introduction of “reliable electronic methods” with ETDA recognition/certification. When approved systems are used, the burden and cost of disproving reliability shift to the challenger. This provides stronger legal certainty and incentivizes certified solutions.

Automated and Electronic Contracting: Explicit validation of contracts formed by automated systems (with or without human intervention), plus detailed rules on attribution, receipt acknowledgment, timing/place of dispatch, input error correction, and verification methods.

New Regime for Electronic Transferable Instruments: A dedicated framework for e-bills of lading, warehouse receipts, promissory notes, etc., including exclusive control (equivalent to possession), transfer, endorsement, amendment, integrity, and paper-electronic conversion. This is a major addition.

Regulation of Service Providers: Broader coverage of identity proofing, e-signatures, timestamping, data storage, and related services. Replaces rigid licensing with a voluntary certification (“trust mark”) scheme, risk management, cybersecurity, and complaint-handling obligations. Liability protections for compliant providers, with transitional recognition for existing licensees.

Strong UNCITRAL Alignment:

Builds on the original Act’s foundation in the Model Law on Electronic Commerce (1996) and Electronic Signatures (2001).

Incorporates the Electronic Communications Convention (ECC, 2005) — Thailand acceded in 2025 — for automated contracting and international rules.

Adopts principles from the Model Law on Electronic Transferable Records (MLETR, 2017) for e-transferable instruments.

Aligns with the Model Law on Electronic Identity and Trust Services (MLIT, 2022) through trust services, certification, and technology-neutral identity frameworks.

Supports overall technology neutrality and functional equivalence, enhancing interoperability under initiatives like the Framework Agreement on Cross-border Paperless Trade (CPTA).

Business Impacts and Preparation Steps:

The Draft Act would lower barriers to digital operations, reduce paper dependency, streamline contracting and record-keeping, and improve cross-border compatibility. Sectors like trade finance, logistics, e-commerce, fintech, cloud services, and digital identity providers stand to benefit significantly.

New compliance expectations include system reliability, risk management, cybersecurity, audits, and vendor due diligence. Businesses may need to update processes, contracts, policies, and user interfaces.

Businesses should prepare by:

Reviewing current electronic systems against emerging “reliable method” standards.

Assessing exposure as service providers or users.

Monitoring ETDA subordinate regulations, certifications, and guidance.

Updating contracts, terms, privacy notices, and record-retention policies.

Enhancing cyber security and complaint-handling mechanisms.

Current Status and Next Steps:

The Draft Act is currently in the public hearing phase (comments due by June 15, 2026). Following consultation, it will undergo refinement, Cabinet approval, parliamentary review, and publication in the Government Gazette.

Implementation is not immediate: The law would generally take effect 180 days after Gazette publication, with ETDA issuing subordinate rules, standards, and certification procedures (targeted within 180 days post-publication, though effective timelines may extend). Full industry adaptation and technical rollout could span months to years. Existing providers receive transitional support.

Key Takeaways:

The Draft Act modernizes Thailand’s electronic transactions framework through broader recognition, new instruments for digital trade, and a flexible certification model — strongly aligned with evolving UNCITRAL standards.

It addresses longstanding limitations while promoting trust, innovation, and paperless processes across private and public sectors.

Businesses should proactively assess impacts, strengthen systems, and participate in the ongoing public consultation.

Successful implementation will enhance Thailand’s digital economy competitiveness, though it requires coordinated regulatory and industry efforts over the coming years.

Author: Panisa Suwanmatajarn, Managing Partner.

Source: International Business August 2026 : Antea

Read Full Article

Cabinet Approves Four Draft Bills Modernizing Thailand’s Capital Market Legislation

Introduction

The Cabinet has approved four draft bills proposed by the Ministry of Finance (“MOF”) and reviewed by the Office of the Council of State (“OCS”), pursuant to the Cabinet resolution of 14 February 2023 (B.E. 2566). The bills amend:

  • the Securities and Exchange Act B.E. 2535 (1992) (“SEA”);
  • the Derivatives Act B.E. 2546 (2003) (“DA”);
  • the Trust for Transactions in Capital Market Act B.E. 2550 (2007) (“TTA”); and
  • the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018) (“DAB”).

The case for reform is that provisions across all four instruments have fallen out of step with current market conditions, do not adequately accommodate rapid technological change, are inconsistent with one another on matters of shared subject matter, and in places lack the clarity needed for consistent interpretation.

Together, the draft bills address six areas:

  • Promotion of the digital capital market;
  • Supervision of business operators;
  • Supervision of the secondary market and related organizations;
  • Fundraising and the supervision of audit firms and capital market service providers;
  • Enforcement and penalties; and
  • The supervisory structure.

Two bodies are principally involved in the reforms: the Securities and Exchange Commission (“SEC”), which has the power and duty to set policy for the promotion and development of the Thai capital market, and the Office of the Securities and Exchange Commission (“SEC Office”), which implements that policy on the SEC’s behalf. The amendments under each of the four draft bills are summarized below.

1. The Draft Securities and Exchange Act (No. ..) B.E. .… (“Draft SEA”)

1.1 Capital market promotion

a. Preparing, sending, receiving, and storing information and documents, and advertising, disclosing, or distributing them, by electronic means will be expressly lawful. The SEA currently contains no such provision, although the practice is already well established.

b. A prospectus may be published through means other than printing, which is currently the only channel the SEA recognizes.

c. Where certificated securities are pledged as collateral, enforcement will be available through means outside the Thai Civil and Commercial Code. Where the instrument has a stated maturity and the debt has fallen due, the pledgee may collect on the due date without prior notice.

1.2 Supervision of securities companies

a. Major shareholder approval requirements move into the Draft SEA. A person holding, or benefiting from, shares carrying more than 10 percent of total voting rights must obtain SEC Office approval. This requirement currently sits in subordinate legislation.

b. The Minister of Finance may impose conditions requiring a securities company whose license has been revoked to take steps to protect investors’ interests.

c. Securities companies must prepare financial statements for both six-month and twelve-month periods, audited and opined on by an auditor, in the form the SEC Office prescribes. Under the current SEA, only six-month statements are required.

d. Supervision of auditors and audit firms, financial advisers, property valuers, credit rating agencies, offshore service providers, securities business personnel, and other service providers will be set out in the Draft SEA itself rather than in subordinate instruments, raising the standard applied to capital market personnel.

1.3 Trading venues and the secondary market

a. Securities trading centers are classified into two categories: licensed centers, open to general investors, and registered centers, open only to institutional investors, with the level of supervision depending on the degree of investor protection required.

b. Ownership of deposited securities is clarified. A depositor must maintain a list of the owners of securities deposited with the Stock Exchange of Thailand (SET), and a person named on that list is deemed the owner entitled to the securities of the class, type, and quantity recorded. The current SEA leaves the position of depositors’ clients unclear.

c. Associations connected with the securities business may invest their funds or income in debt instruments or other securities prescribed by the SEC, subject to SEC Office supervision, giving them an additional income channel.

1.4 Auditors, service providers, and critical systems

a. Financial reports must be audited by auditors and audit firms approved by the SEC Office, and capital market service providers must obtain SEC Office approval.

b. Significant system providers to the capital market become subject to supervision, including a requirement to hold sufficient funding to support their operations and associated risks.

c. Control over management and continuity is strengthened. Such a provider may appoint a director or manager, or contract out all or part of its management authority, only with SEC Office approval. The SEC may restrain conduct capable of causing serious damage to the public interest and may address the cessation of the provider’s business.

1.5 Enforcement and penalties

a. SEC Office officials will be able to conduct investigations alongside inquiry officials and special case inquiry officials in categories of offence that may seriously damage confidence in the capital market or affect the national economy.

b. Criminal penalties and administrative fines will be revised, with criminal liability retained only for serious offences or those contrary to good morals.

1.6 The supervisory structure

a. The Secretary-General of the Office of Insurance Commission joins the SEC as an ex officio member.

b. The Minister of Finance, the SEC, and the SEC Office each gain the power to reduce or waive fees for registration and capital market services.

c. The affairs of the SEC Office are placed outside social security legislation, aligning its position with that of other regulators such as the Bank of Thailand (BOT).

2. The Draft Derivatives Act (No. ..) B.E. .… (“Draft DA”)

2.1 Capital market promotion

a. See Section 1.1(a) above.

2.2 Supervision of securities companies

a. See Section 1.2(a) above.

b. The scope and characteristics of persons acting as investment consultants, investment analysts, investment planners, derivatives investment managers, or other functions notified by the Capital Market Supervisory Board (“CMSB”) will be prescribed. Such matters were previously prescribed in subordinate legislation.

c. Provisions will be introduced on the supervision of major shareholders, directors, and persons with management authority of a derivatives exchange. A person may hold shares in, or benefit from shares of, a derivatives exchange in excess of the threshold notified by the SEC only upon obtaining SEC Office approval, in accordance with criteria, conditions, and procedures notified by the SEC. Under the current DA, shareholding is capped at 5 percent.

2.3 Auditors, service providers, and critical systems

a. Derivatives business operators — other than derivatives advisors who are natural persons (a category not previously specified) — will be required to prepare accounts showing the results of their operations and their financial position as these actually stand, in accordance with professional accounting standards under the law on accounting professions and any additional requirements notified by the SEC.

b. Derivatives business operators will be required to prepare financial statements and submit them to the SEC Office, audited and opined on by a certified public accountant in accordance with criteria notified by the SEC and approved by the SEC Office.

2.4 Enforcement and penalties

a. See Section 1.5(a) above.

b. Administrative penalties will be prescribed for a derivatives exchange that contravenes or fails to comply with criteria, orders, or conditions prescribed by law.

2.5 The supervisory structure

a. Additional powers and duties are conferred on the SEC and the SEC Office to reduce or waive fees for applications for a license, registration, or approval; for the issuance of a license, acceptance of a registration, or grant of an approval; or for carrying on a licensed, registered, or approved business, in accordance with notified criteria and conditions.

3. The Draft Trust for Transactions in Capital Market Act (No. ..) B.E. .… (“Draft TTA”)

3.1 Capital market promotion

a. See Section 1.1(a) above.

3.2 Supervision of securities companies

a. Additional powers and duties are conferred on the SEC to reduce or waive fees for applications for permission, the granting of permission, or the carrying on of business under the Draft TTA, in accordance with notified criteria and conditions.

b. Regulations, rules, notifications, orders, or requirements issued under the Draft TTA by the CMSB and having general application will take effect upon publication in the Government Gazette, whereas the current TTA applies this requirement only to instruments issued by the SEC Board and the SEC Office.

4. The Draft Emergency Decree on Digital Asset Businesses (No. ..) B.E. …. (“Draft DAB”)

4.1 Capital market promotion

a. See Section 1.1(a) above.

4.2 Enforcement and penalties

a. See Section 1.5(a) above.

4.3 The supervisory structure

a. See Section 1.6(b) above.

Legal Basis and Objectives

The four draft bills are brought forward under Section 77 of the Constitution of the Kingdom of Thailand, which provides that the State should, without delay, revise laws that are no longer suited to prevailing circumstances or that obstruct the pursuit of an occupation, so that they do not burden the people.

Beyond this constitutional duty, the stated objectives are to accommodate the use of appropriate technology in capital market transactions, to create clarity in supervision, to improve enforcement in line with international regulatory standards, to remove duplicative processes, to advance State policy and capital market plans, and to raise the level of investor protection.

Consultation and Impact Assessment

The OCS and the SEC Office consulted state agencies, the private sector, and the public on all four draft bills, through both online submissions and focus group sessions. An impact analysis was prepared in accordance with the Cabinet resolution of 19 November 2019 (B.E. 2562), and both the consultation results and the analysis have been published online.

The MOF has also submitted a plan for the subordinate legislation to be issued under the four draft bills, including the intended timeframe and a framework of key content. That subordinate legislation comprises 183 instruments.

Key Takeaways

  • The Draft SEA, DA, TTA, and DAB have cleared Cabinet and Council of State review and now proceed through the parliamentary process.
  • The most immediate practical change is the statutory recognition of electronic documents and non-print advertising, which brings the SEA into line with existing market practice.
  • Several matters move from subordinate legislation into the acts themselves, notably approval of major shareholders in securities companies and supervision of capital market service providers.
  • Two newly regulated categories of person are introduced: capital market service providers (including auditors, financial advisers, and valuers) and significant system providers to the capital market.
  • Enforcement is strengthened through joint investigation powers, while criminal liability is narrowed to serious offences, with other conduct shifting to civil administrative fines.
  • The MOF has flagged 183 subordinate instruments to be issued under the four draft bills, meaning enactment will mark the start rather than the end of the reform process.
  • Affected businesses should assess now whether they fall within the newly regulated categories, since approval requirements, funding thresholds, and management appointment controls will apply once the draft bills are enacted.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Legal Update: Thailand Named in the White House Transshipment Report — Legal Exposure and the Government’s Response

Introduction

On 13 August 2026, the White House Office of Trade and Manufacturing Policy published a report entitled The Great Transshipment Scam (the “Report”). The Report identifies more than 40 jurisdictions said to present elevated risk of illegal transshipment of Chinese-origin goods into the United States and places Thailand in the second of three risk tiers.

The Thai Government responded within days, on 15 August 2026, confirmed that technical tariff negotiations with the United States would proceed at the end of August, and on 17 August 2026, the Department of Foreign Trade (“DFT”), Ministry of Commerce (“MOC”), set out the measures Thailand has taken on origin verification and its position on the underlying analysis.

The Report is not a legal instrument: it imposes no duty and creates no liability. Nonetheless, it consolidates a documented U.S. Government position that will inform enforcement targeting, trade remedy proceedings, and the negotiation of an Agreement on Reciprocal Trade (“ART”).

Thailand’s Classification under the Report

The Report groups the identified jurisdictions into three tiers. The first comprises diversified economies with large volumes of China-linked goods and comparatively strong customs systems, including Canada, the European Union, India, Israel, Japan, Mexico, South Korea, and Taiwan. The third comprises smaller economies said to offer specific weak-link advantages, such as low-cost labor, permissive free zones, or limited customs capacity.

Thailand is placed in the second tier, described as economies combining significant transshipment volumes with deep integration into China-linked supply chains, alongside Brazil, Indonesia, Malaysia, Turkey, and Vietnam. The Report characterizes Thailand, Vietnam, Malaysia, and Indonesia as major platforms for electronics, machinery, plastics, footwear, apparel, and components incorporating Chinese-origin inputs.

Thailand is named specifically in two contexts, and the two carry different legal weight.

The first is the Report’s “ugly sister city” analysis, which pairs foreign industrial corridors with U.S. regions producing the same goods, on the premise that work gained in one is work lost in the other. Thailand’s entry pairs the Ayutthaya–Samut Prakan corridor — linked to thermostats under HS 903210 — with the Minneapolis–St. Paul instruments sector. This is an inference drawn from trade statistics rather than a finding against any specific company, and the Report itself describes the pairings as illustrative. It nonetheless signals to U.S. Customs and Border Protection (“CBP”) which product code and geographic area warrant closer scrutiny.

The second reference concerns a decided case. The Report cites circumvention findings on solar cells and modules, in which the U.S. Department of Commerce determined that duties on Chinese goods were being evaded through final processing in Cambodia, Malaysia, Thailand, and Vietnam. Thailand therefore already has an enforcement record on this issue.

Thailand’s Response

According to MOC figures cited on 15 August 2026, approximately 72 percent of Thai product lines under Section 301 and Section 232 measures are already exempt, leaving roughly 28 percent still subject to the additional tariff. The exemptions span eight industry groups:

  • Electronic equipment and electrical machinery;
  • Machinery and components;
  • Iron and steel;
  • Articles of iron or steel;
  • Plastics and plastic products;
  • Vehicles and components;
  • Copper and copper products; and
  • Measuring, medical, and optical instruments.

Four of these groups fall under Section 232. As explained below, their inclusion reflects a distinction: goods in those categories are excluded from Section 301 to prevent double charging, rather than relieved of duty altogether.

Thailand is responding on three fronts.

Origin verification: The DFT has reported that the watch list operated jointly with CBP has been expanded from 49 items covering 194 tariff lines to 67 items covering 274 tariff lines, effective 1 June 2026. The DFT is developing an AI-assisted origin risk assessment system, has trained more than 2,000 operators on rules of origin and local content requirements, and has increased factory inspections, retrospective origin audits, and data linkage with the Customs Department, the Department of Industrial Works, and provincial commercial offices. The DFT and the Customs Department were scheduled to meet the Office of the United States Trade Representative (“USTR”) between 28 and 31 August 2026.

Negotiation: The Government confirmed on 15 August 2026 that technical tariff discussions would take place at the end of August, led by the Deputy Prime Minister and Minister of Commerce. It cited Thai private-sector investment in the United States of close to USD 20 billion as evidence of mutual economic interest, and denied reports that the negotiations were linked to any security or military arrangement.

The trade surplus: Thailand exports more to the United States than it imports, but at least 30 percent of those exports are produced by U.S. companies operating manufacturing bases in Thailand. On Thailand’s analysis, the bilateral surplus therefore measures the depth of a shared supply chain rather than a one-sided advantage, and cannot be read from the headline figure alone. It must instead be assessed together with investment flows, the location of production, and the broader scope of economic activity between the two countries.

Key Takeaways

  • The Report places Thailand in Tier 2 of a three-tier transshipment risk classification, alongside Brazil, Indonesia, Malaysia, Turkey, and Vietnam.
  • The Report is analytical rather than legal. It imposes no measure and expressly acknowledges that the trade patterns it identifies do not, by themselves, establish illegal transshipment.
  • Thailand has expanded its CBP watch list to 67 items and 274 tariff lines effective 1 June 2026, is deploying AI-assisted origin risk assessment, and met with the USTR between 28 and 31 August 2026.
  • Approximately 72 percent of Thai product lines under Section 301 and Section 232 are already exempt, with roughly 28 percent remaining exposed.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles