Consumer Protection: Proposed Labeling Rules for Solar Panels, Inverters and Energy-Storage Batteries

The Office of the Consumer Protection Board (OCPB) has opened a public consultation on three draft notifications of the Committee on Labels covering solar panels, inverters used with solar panels, and batteries for storing energy generated from solar panels. The consultation runs from 13–27 August 2026. Although, the notifications remain in draft form, they are an important development for manufacturers, importers, distributors, dealers, installers, and businesses supplying rooftop-solar and energy-storage systems.

The Proposed Labeling Rules:

The three draft notifications would regulate labeling requirements for the principal components of a solar-energy system: solar panels, inverters, and energy-storage batteries. The initiative follows increased regulatory attention to consumer protection in the solar sector, including concerns regarding the quality and safety of solar equipment and installations.

Designation of these products as label-controlled products is significant because labeling under the Consumer Protection Act is more than a product-branding requirement. The regulatory framework is intended to ensure that consumers receive sufficient and accurate information about the products they purchase, including information prescribed by the Committee on Labels. The precise disclosures, language requirements, and presentation requirements will ultimately depend on the final wording of each notification.

For solar products, compliance can be particularly complex because consumers frequently purchase an entire rooftop-solar or solar-plus-storage system rather than individual components. The panels, inverter, and battery may be manufactured by different companies, imported by different entities, and supplied to the consumer through a distributor or installer. As a result, businesses should consider labeling compliance across the entire supply chain rather than treating it solely as a manufacturer’s responsibility.

Key Compliance Issues for Businesses:

Manufacturers and importers should be particularly attentive to the proposals because they generally control product specifications, labels, packaging, and accompanying documentation. Imported equipment may present additional challenges where the original labels and manuals are prepared for international markets. Importers should therefore assess whether Thai-language supplementary labels will be required and whether information on those labels is consistent with the manufacturer’s original product information.

This review should extend beyond literal translation. Product names, model numbers, technical specifications, manufacturer and importer details, instructions, warnings, and other required disclosures should be consistent across the product label, packaging, manuals, technical specifications, warranties, and other customer-facing materials. Inconsistencies between these materials can create both regulatory and consumer-dispute risks.

Distributors, dealers, and installers should also monitor the proposals closely. A rooftop-solar provider may purchase panels, an inverter, and a battery from different suppliers and then offer them to the consumer as a single installed system. Businesses operating this model should consider incorporating label verification into their procurement and installation procedures, including checking that required labels are present, correspond to the correct product model, and are not removed or obscured during installation.

The proposals may therefore have consequences beyond the physical product label. Depending on the final requirements, businesses may need to review packaging, Thai-language disclosures, product specification sheets, user instructions, warranties, quotations, sales proposals, online product descriptions, and information provided by dealers and installers. Not all of these materials will necessarily constitute regulated labels, but consistency between mandatory product information and commercial representations should form part of the compliance review.

Supply-Chain Contracts and Existing Inventory:

Businesses should also review how responsibility for labeling compliance is allocated contractually. Supply, import, distribution, dealer, and installation agreements often contain general obligations to comply with applicable law but may not specifically address responsibility for preparing Thai-language labels, verifying technical information, implementing regulatory changes, or bearing the cost of relabeling noncompliant products.

For importers dealing with overseas manufacturers, this can be commercially important. Changes to factory-applied labels or packaging may require manufacturing lead times and additional costs. Agreements should therefore be reviewed to determine who must implement regulatory changes, who bears the associated costs, and what remedies apply where products supplied into the market do not satisfy mandatory labeling requirements.

Existing inventory will be another important issue when the final notifications are issued. Businesses may already hold substantial stocks of solar panels, inverters, and batteries bearing existing labels, while additional products may be in transit or subject to outstanding purchase orders. Companies should monitor the final rules for their effective dates and any transitional provisions, including whether existing inventory can continue to be sold or whether supplementary labeling will be permitted. Businesses should not assume that existing products will automatically be grandfathered.

Labeling, Product Safety, and Enforcement:

The proposed rules should also be considered alongside broader product-safety regulation. The OCPB has previously highlighted consumer concerns relating to allegedly substandard solar installations and has emphasized the importance of consumers being able to identify relevant product, manufacturer, importer, origin, and standards information.

Labeling compliance and technical compliance should therefore be managed as related but distinct requirements. A product’s compliance with an applicable industrial or technical standard does not necessarily establish compliance with consumer-labeling requirements, while a correctly labeled product may still fail to satisfy separate product-safety requirements.

Noncompliance with labeling requirements can carry criminal consequences under the Consumer Protection Act. The OCPB has stated that a seller of a label-controlled product without the required label, or with an incorrect label where the seller knows or ought to know of the noncompliance, may face imprisonment for up to six months, a fine of up to THB 100,000, or both. For manufacturers producing goods for sale and persons ordering or importing goods for sale, the potential penalty may increase to imprisonment for up to one year, a fine of up to THB 200,000, or both.

What Businesses Should Do Now:

As the notifications remain in draft form, immediate changes to product labels may be premature. However, businesses can begin preparing by identifying affected product models and collecting their current labels, packaging, manuals, and Thai-language product information. Importers should determine which labeling changes can be made locally and which would require cooperation from overseas manufacturers.

Businesses should also map responsibility throughout their distribution networks, review supply and dealer agreements, and identify existing inventory that could be affected by the new requirements. Once the final notifications are issued, particular attention should be given to the exact product scope, mandatory disclosures, Thai-language requirements, effective dates, and transitional arrangements.

Key Takeaways:

  • The OCPB is consulting on three draft labeling notifications covering solar panels, solar inverters, and batteries used for solar-energy storage.
  • The proposals are relevant to manufacturers, importers, distributors, dealers, installers, and integrated rooftop-solar and energy-storage providers.
  • Businesses should review not only physical labels but also packaging, Thai-language product information, technical documentation, sales materials, and downstream dealer practices.
  • Importers should assess whether existing global labels and packaging can satisfy the proposed requirements or whether local supplementary labeling or factory changes may be necessary.
  • Supply-chain agreements should clearly allocate responsibility and costs for labeling compliance and regulatory changes.
  • Businesses holding substantial inventory should monitor effective dates and transitional provisions carefully.
  • Companies can use the consultation period to conduct a preliminary product and labeling audit so they are prepared to implement the final requirements efficiently.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Generative AI and Music: Copyright Risks Highlighted by the DIP

The growing use of generative artificial intelligence (AI) to create music is raising increasingly important copyright questions. AI tools can now generate songs, modify voices, create remixes and produce new musical content by reference to existing works, making the boundary between technological creation and the use of protected material increasingly significant.

The Department of Intellectual Property (DIP) has recently highlighted the copyright implications of using generative AI in music. While the DIP’s comments do not introduce new legislation or a separate legal regime for AI-generated content, they provide a useful practical signal: the use of AI does not remove the need to consider copyright in the material used as part of the creative process.

For businesses using generative AI for music, advertising and other commercial content, this has implications not only for copyright clearance but also for contracts with AI providers, internal policies and the management of infringement risk.

Existing copyright rules continue to apply:

The starting point is that generative AI does not operate outside the existing copyright framework. Under the Copyright Act, copyright owners have exclusive rights in relation to protected works, subject to applicable limitations and exceptions. Depending on the circumstances, reproducing, adapting or otherwise using a protected work without authorization may therefore constitute infringement.

The DIP has emphasized that where copyrighted material is used in connection with generative AI, users should consider whether they have the necessary rights and obtain permission where required. This is particularly relevant where an AI workflow involves identifiable existing material—for example, where a user supplies an existing song, recording or other protected content to an AI system to generate or modify musical content. The fact that AI technology performs part of the transformation does not, by itself, provide authorization to use the underlying copyrighted work.

AI-assisted music can involve several layers of rights:

Music-related AI applications can be legally complex because a single piece of music may involve multiple protected elements. A song may involve rights in the musical composition and lyrics, while a particular recording may involve separate rights in the sound recording. Depending on how an AI tool is used, more than one category of rights may therefore need to be considered.

For example, using an existing recording as an input for an AI-generated remix may raise different questions from merely instructing an AI system through text to create music of a particular genre. Similarly, an AI voice-conversion tool that processes an existing recording may involve different copyright considerations from a system generating an entirely new recording without the user supplying an existing protected work. Businesses should therefore avoid treating “AI-generated music” as a single legal category. The relevant copyright analysis depends significantly on what material enters the AI workflow, what the system does with that material and how the resulting content is subsequently used.

Copyright clearance should begin with the input:

For businesses, one of the most immediate implications of the DIP’s position is the importance of reviewing the material supplied to AI systems. Before employees, agencies or contractors upload music, recordings or other content to a generative AI platform, businesses should consider whether they own the relevant rights, have obtained an appropriate license or can otherwise lawfully make the intended use.

This is particularly important in advertising and marketing, where AI tools may be used to generate background music, modify existing tracks or rapidly produce multiple versions of creative content. A business may ultimately be responsible for content distributed under its name even where an external advertising agency, production company or AI provider performed much of the underlying creative work. Copyright clearance should therefore form part of the AI-content production process rather than being addressed only after the content has been generated.

AI provider contracts deserve closer scrutiny:

The copyright analysis should not stop with the underlying content. Businesses should also review the contractual terms governing the AI tools they use. Terms of service can differ considerably between platforms, particularly in relation to material uploaded to the platform, the provider’s ability to use customer content and the rights granted in generated outputs.

For commercial use, relevant contractual issues include rights and permissions relating to material submitted to the AI system, permitted use of customer-provided content by the AI provider, rights to use and commercialize generated outputs, intellectual property representations and warranties, indemnification for infringement claims, and procedures for responding to copyright complaints. Similar protections may be appropriate in agreements with advertising agencies, production companies and other contractors creating AI-assisted content.

Internal AI policies should address copyrighted content:

Businesses increasingly permit employees to use generative AI tools without necessarily treating that use as a formal intellectual property process. This can create risk where employees upload commercially released music or other third-party content to an AI platform, use copyrighted material as a reference, or use AI to modify content without considering whether the business has the necessary rights.

Internal AI policies should therefore address intellectual property alongside confidentiality, personal data and cybersecurity concerns. Organizations should consider establishing rules governing the types of third-party content that may be uploaded to AI systems, when copyright clearance is required and which AI platforms may be used for commercial content creation. For higher-risk uses, an internal approval process may also be appropriate before AI-generated material is released publicly or incorporated into a commercial campaign.

What the DIP’s position does—and does not—resolve:

The significance of the DIP’s comments should not be overstated. They provide a useful indication of how existing copyright principles should be approached when generative AI is used to create or modify music and reinforce the practical importance of obtaining authorization before using copyrighted works where permission is required.

However, the comments should not, without further legal or regulatory authority, be treated as establishing a definitive position on whether and under what circumstances copyrighted works may be used to train generative AI models. Nor should they be treated as conclusively determining whether, or under what circumstances, AI-generated output qualifies for copyright protection or who may own rights in such output. Those questions involve distinct legal issues concerning reproduction, exceptions to copyright, authorship, originality and the degree of human creative contribution.

Practical implications for businesses:

Companies using generative AI to create music or other commercial content should consider incorporating copyright review into their AI governance framework. A risk-based approach may be appropriate: generating content from text instructions without supplying identifiable third-party works may present a different risk profile from uploading existing songs or recordings, generating remixes or adaptations, or using protected material as a direct input or reference in the generation process.

Particular caution is appropriate where AI-generated content will be used in advertising, distributed commercially or incorporated into products. Businesses should also consider the complete contractual chain. An organization commissioning AI-generated music from an agency or contractor may wish to require appropriate warranties concerning the lawful use of source material rather than assuming that copyright compliance rests exclusively with the creator.

Key Takeaways:

  • Generative AI does not displace copyright law: Using an AI tool does not, by itself, authorize the reproduction, adaptation or other use of copyrighted material.
  • Inputs matter: Businesses should understand what copyrighted material is being supplied to an AI system and whether the necessary rights or permissions have been obtained.
  • Music can involve multiple rights: Compositions, lyrics and sound recordings may involve separate rights and require separate analysis.
  • Contracts should allocate AI-related copyright risk: Businesses should review AI-provider and agency agreements for input rights, output rights, warranties, indemnities and restrictions on the provider’s use of uploaded material.
  • Internal AI policies should cover intellectual property: Rules governing employee use of generative AI should address copyrighted inputs and commercial use of AI-generated content.
  • Important questions remain unresolved: The DIP’s comments should not be interpreted more broadly than their stated scope, particularly regarding AI training and copyright ownership of AI-generated output.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

From Grants to Equity: Government Innovation Agency Can Now Invest in Startups

A significant change to the legal framework for government support of innovation has opened the door to direct public-sector investment in startups and innovation businesses. The National Innovation Agency (Public Organization), the government agency responsible for promoting and supporting innovation (the “NIA”), has been granted expanded statutory powers to hold shares, become a partner, co-invest with other persons or entities, and participate in certain venture capital structures. This marks an important shift from the NIA’s traditional role as a provider of grants and financial support toward a model under which it may participate as an investor and acquire an economic interest in the businesses it supports.

The change was introduced by the Royal Decree Establishing the National Innovation Agency (Public Organization) (No. 3) B.E. 2569 (2026). In addition to expanding the NIA’s objectives to cover the development of innovation beyond the research and development stage toward commercialization, the amendment expressly authorizes the NIA to hold shares, become a partner, or participate in joint investments with individuals or legal entities in businesses connected with its statutory objectives. It may also invest in trusts established to conduct venture capital activities. Importantly, however, the NIA’s principal purpose in holding shares or participating in investments must not be the pursuit of profit, and the exercise of these investment powers is subject to criteria prescribed by the Council of Ministers.

From Funding Agency to Investor:

The distinction between a grant and an investment is significant. Under the traditional grant model, government funding supports a project or business without the government ordinarily acquiring an ownership interest. Equity investment creates a different relationship: the government agency may become part of the company’s capital structure, with its interest potentially affected by valuation, dilution, subsequent financing rounds, corporate restructurings, and an eventual exit. The amendment therefore does more than create another source of funding. It establishes the legal basis for the NIA itself to participate in the investment relationship.

This development may be particularly relevant for startups that have progressed beyond the stage at which grants alone can support their growth but remain too early or risky to attract sufficient private capital. The financing gap can be particularly significant for deep-tech and other innovation-driven businesses, where substantial capital may be required for product development, testing, regulatory approvals, manufacturing scale-up, intellectual property protection, and market entry before sustainable revenues are generated. Government equity or co-investment can potentially help bridge this gap and, by sharing part of the investment risk, encourage private investors to participate.

The NIA has announced that it intends to implement its expanded investment role through an initiative referred to as “NIA Venture,” using government funding as catalytic capital to encourage additional private investment. The announced framework includes investment through PE Trust structures, strategic investment through holding companies and other fund structures, and Corporate Co-Funding alongside qualified private investors, particularly for Seed to Series A businesses. The NIA has also announced an initial allocation model of approximately 40% for PE Trust, 30% for Holding Company, and 30% for Corporate Co-Funding. These investment channels and allocations are implementation measures announced by the NIA and should be distinguished from the statutory powers established by the Royal Decree itself.

What This Means for Startups and Investors:

The new powers do not give the NIA unrestricted authority to invest public funds in any startup. Investments must relate to the NIA’s statutory objectives, its principal purpose in participating in an investment must not be profit-seeking, and the relevant investment activities are subject to criteria prescribed by the Council of Ministers. Accordingly, the Royal Decree establishes the legal authority to invest, while the practical availability of NIA investment will depend on the applicable eligibility requirements, investment limits, approval procedures, governance arrangements, and other implementing conditions.

For founders, having a government organization on the cap table may create opportunities but also raises issues that should be considered at the outset. The investment terms will need to address valuation and dilution, the class and rights of shares acquired by the NIA, governance and information rights, and the company’s ability to raise subsequent financing. This is particularly important because later-stage venture capital investors may require preferred shares, liquidation preferences, anti-dilution protection, board representation, reserved matters, and other investor protections. An early government investment should therefore be structured in a way that does not unnecessarily complicate future financing rounds.

Exit arrangements may also require particular attention. Unlike a conventional venture capital fund, a public organization operates within a statutory and administrative framework governing its investments and assets. The ability of the NIA to sell, transfer, or otherwise realize its investment may therefore need to be considered when drafting shareholders’ agreements and investment documents, particularly in anticipation of a trade sale, secondary transaction, restructuring, or public offering. Startups should also anticipate potentially greater due diligence, reporting, and compliance requirements where public funds are involved.

The amendment is equally relevant to venture capital funds, corporate venture capital investors, and other private investors. Co-investment with the NIA could allow public and private capital to be combined in transactions that might otherwise be difficult to finance. However, the parties will need to consider how valuation is determined, whether investors subscribe for the same class of shares, how governance rights are allocated, how follow-on rounds are handled, and how exit decisions are made. Any conditions attached to government investment should also be assessed carefully to ensure that they do not unnecessarily restrict the company’s future operations, restructuring, overseas expansion, intellectual property arrangements, or ability to raise additional capital.

A New Model for Innovation Financing:

The amendment reflects a broader shift in the government’s approach to innovation financing. Grants and other forms of financial assistance remain important, particularly during research and early product-development stages, but they may not provide sufficient capital to take successful innovation from research to commercial scale. Allowing the government innovation agency to use equity and venture investment structures provides an additional tool for addressing that financing gap and may enable public capital to attract rather than replace private investment.

At the same time, the framework deliberately distinguishes the NIA from an ordinary commercial venture capital investor. Its investment activities must advance its statutory objectives, and profit cannot be the principal purpose of its participation. The success of the new model will therefore depend on achieving a balance between protecting public funds and providing sufficient commercial flexibility for startups to raise capital, grow, restructure, and eventually provide an exit for their investors.

Key Takeaways:

  • The government innovation agency now has express statutory authority to hold shares, become a partner, co-invest with other parties, and participate in specified venture capital structures.
  • This represents a shift from a model centered on grants and financial assistance toward one that can also include equity and co-investment.
  • The investment authority is subject to important limitations: investments must relate to the agency’s statutory objectives, profit must not be its principal purpose, and the exercise of the relevant powers is subject to criteria prescribed by the Council of Ministers.
  • The announced NIA Venture initiative includes PE Trust, Holding Company, and Corporate Co-Funding channels, but these are implementation arrangements rather than investment structures prescribed by the Royal Decree itself.
  • Startups should consider the effect of government investment on their cap table, governance, future fundraising, reporting obligations, and exit arrangements.
  • Private investors considering co-investment should assess how public-sector investment conditions interact with conventional venture capital terms and future financing rounds.
  • The practical impact of the reform will ultimately depend on the implementing criteria and the investment structures adopted under the new statutory framework.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Cabinet Approves Major Expansion of Home Worker Protections

The Cabinet has approved a draft amendment to the Home Workers Protection Act that would significantly expand the scope of protection for individuals performing work outside an employer’s or business operator’s premises.

The proposed amendments are particularly significant for businesses using remote workers, home-based workers, freelancers, and other individuals who perform assigned work away from business premises. Importantly, the proposed framework is intended to address modern working arrangements, including work assigned or performed through online systems.

The draft has been approved by the Cabinet but has not yet become law. It must proceed through the legislative process before enactment.

Broader Scope of Protected Work:

The existing Home Workers Protection Act principally focuses on work assigned by an industrial business operator to individuals or groups to produce or assemble goods outside the operator’s establishment.

The proposed amendments would substantially broaden this framework.

The concept of “work taken to be performed at home” would extend beyond traditional industrial production and cover work associated with a wider range of economic activities, including:

  • agriculture;
  • industry;
  • services; and
  • commerce.

The amendments would also expressly accommodate work arrangements involving electronic or online systems.

This change is potentially important for businesses operating through digital platforms or engaging individuals remotely. The relevant question may no longer be limited to whether a person physically takes materials or manufacturing work home. Businesses may need to consider whether work assigned digitally and performed outside their premises falls within the expanded statutory definition.

The legislation should therefore not be viewed as regulating only traditional home manufacturing or piecework. Its potential application could extend considerably further into the modern service and digital economy.

Minimum Compensation Protection:

The draft strengthens the statutory protection relating to compensation.

Compensation payable to a home worker would be required to meet the statutory minimum applicable under the legislation and could not fall below the minimum wage standard under labor protection law.

The amendments also reinforce the requirement that compensation be paid in Thai currency.

For businesses that calculate compensation on a project, output, piece-rate, or task basis, compliance may therefore require more than simply agreeing on a lump-sum fee with the worker. The compensation structure should be reviewed to ensure that it satisfies the statutory minimum requirements applicable to the work.

This could be particularly relevant to businesses using high-volume outsourcing models where individual workers are compensated according to completed tasks or units of production.

Increased Financial Consequences for Non-Payment:

The proposed amendments would strengthen the financial consequences for failing to make payments required under the Act.

Where a business fails to pay compensation or other amounts owed to a home worker, or fails to return security that it is legally required to return, the business may be required to pay interest at a rate of 15% per annum.

The relatively high statutory interest rate creates a significant incentive for businesses to establish reliable payment and reconciliation procedures.

Businesses that require workers to provide deposits or other forms of security should also review when such security must be returned and ensure that internal processes allow this to occur within the statutory requirements.

Stronger Protection Against Child Labor:

Another significant amendment concerns child labor.

The draft would prohibit the engagement of children under 15 years of age to perform homework.

This represents a material strengthening of the existing framework. Under the current legislation, the prohibition concerning children under 15 is focused on work that may be hazardous to their health and safety. The proposed amendment would establish a broader prohibition against engaging children below that age for home work.

Violation of the prohibition could result in substantial criminal penalties, including imprisonment for up to two years, a fine ranging from THB 400,000 to THB 800,000, or both.

Businesses using subcontractors, intermediaries, community production networks, or multi-tier outsourcing arrangements should pay particular attention to this requirement. Compliance mechanisms should extend beyond the immediate contractual counterparty where work may ultimately be distributed to individuals performing it at home.

Implications for Online and Platform-Based Work:

Perhaps the most consequential aspect of the proposed amendments is their potential application to work performed through online systems.

Traditional distinctions between employees, contractors, freelancers, platform workers, and home workers have become increasingly difficult to apply as businesses adopt remote and digitally mediated working models.

The amendments indicate a legislative intention to bring at least some forms of digitally assigned work within the home-worker protection framework.

This does not necessarily mean that every freelancer or remote contractor will automatically become a protected home worker. Whether the Act applies will depend on the statutory definitions and the particular structure of the working arrangement.

Nevertheless, businesses should avoid assuming that describing an individual as an “independent contractor,” “freelancer,” or “service provider” will by itself determine the legal position.

The substance of the arrangement—including how work is assigned, where it is performed, how compensation is calculated, and the relationship between the work and the business’s activities—may become increasingly important.

What Businesses Should Review:

Businesses that outsource work to individuals outside their premises should begin assessing their arrangements before the amendments become effective.

Particular attention should be given to:

  1. Worker classification – identifying individuals who may fall within the expanded definition of home workers.
  2. Digital work arrangements – reviewing work assigned, managed, submitted, or delivered through websites, applications, platforms, messaging systems, or other electronic channels.
  3. Compensation structures – ensuring that piece-rate, task-based, project-based, and similar payment arrangements satisfy applicable minimum compensation requirements.
  4. Payment procedures – establishing systems to ensure timely payment and avoid exposure to statutory interest.
  5. Security and deposits – reviewing whether security is collected from workers and establishing procedures for its lawful and timely return.
  6. Age verification – implementing appropriate controls to prevent individuals under 15 from being engaged to perform covered home work.
  7. Subcontracting arrangements – reviewing contractual protections and compliance mechanisms where work is distributed through agents, contractors, subcontractors, or other intermediaries.
  8. Contract documentation – updating contractor, outsourcing, and home-work agreements to reflect the expanded statutory requirements.

Effective Date:

The Cabinet-approved draft provides for the amendments generally to take effect 180 days after publication in the Government Gazette, although certain provisions concerning the preparation of subordinate legislation would take effect from the day following publication.

Businesses will therefore have a transition period once the legislation is enacted, but organizations with substantial outsourcing, home-working, or platform-based workforces may benefit from conducting an impact assessment before that period begins.

The draft remains subject to the legislative process, and its provisions may be revised before enactment.

Key Takeaways:

  • The proposed amendments represent a significant modernization of the home-worker protection regime.
  • Most importantly, protection would no longer be centered primarily on traditional industrial homework. The expanded framework would cover work connected with agriculture, industry, services, and commerce and would expressly respond to work arrangements conducted through online systems.
  • Businesses engaging individuals to perform work outside their premises should therefore reassess whether arrangements currently treated simply as outsourcing or freelance relationships could fall within the expanded legislation.
  • The proposed minimum compensation requirements, 15% statutory interest exposure, strengthened child labor prohibition, and potentially broader application to online work make this an important compliance development for businesses using decentralized or digitally managed workforces.
  • As the legislation remains in draft form, businesses should continue monitoring the legislative process and review the final text when enacted before implementing definitive compliance changes.      

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPA: New Section 30 Access Rules Put Data Subject Access Request Operations on a Compliance Clock

The Personal Data Protection Committee (PDPC) has issued a binding notification setting out detailed rules for data subjects exercising the right of access under section 30 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA).

Published in the Royal Gazette on 16 July 2026, the Notification will take effect after the expiration of 60 days from publication. It should therefore be treated as an immediate implementation project rather than simply a regulatory development to monitor.

The importance of the Notification lies in its operational detail. Section 30 already gives data subjects the right to access and obtain copies of personal data concerning them that is under a controller’s responsibility, as well as to request disclosure of the source from which personal data was obtained without their consent. The new rules now specify how requests must be received, verified, assessed, fulfilled, refused, charged for, and recorded.

For controllers, this moves data subject access requests (DSARs) firmly from privacy-notice language into operational compliance.

Controllers Must Make Relevant Information Accessible:

The Notification requires controllers to make available information that enables data subjects to exercise the section 30 right. This includes personal data collected directly from the data subject, personal data collected from other sources, and information concerning the source or acquisition of personal data obtained without the data subject’s consent.

The controller must also make accessible relevant information that it is required to provide under section 23 of the PDPA and relevant items contained in the controller’s records of processing under section 39 that the data subject is entitled to access.

This requirement makes data inventory and data mapping particularly important. A controller cannot respond effectively to an access request if it does not know where an individual’s data is stored, how it was obtained, and which systems or service providers hold it.

Mandatory Request Channels:

The Notification does not leave request channels entirely to the controller’s discretion.

At a minimum, controllers must permit requests to be submitted:

  • in person at the controller’s place of business or another contact location notified to data subjects under section 23; and
  • by registered mail sent to that location.

Controllers may provide additional electronic or other channels. A data subject may exercise the right personally or through an authorized representative.

This is a significant implementation point. An organization that currently accepts DSARs only by email or through an online privacy portal should review whether its procedure accommodates the channels expressly required by the Notification.

Controllers should also determine how requests received at reception desks, branch offices, HR functions, customer-service centers, or by post will be recognized as section 30 requests and routed immediately to the responsible team.

Requests Must Contain Prescribed Information:

A request must be made in writing or electronically and must contain specified information and supporting evidence.

Among other things, the request must identify the data subject, specify the requested access or copy and, where relevant, disclosure of the source of personal data obtained without consent, provide sufficient details of the data requested, and carry the signature or electronic signature of the data subject or authorized representative.

The Notification also sets out identity-verification requirements.

Where a data subject submits a request in person, official identification may be required. Where a request is made by registered mail, certified copies of relevant identification documents may be required. The controller may use alternative verification methods, but those methods must not create an unreasonable obstacle to the exercise of the right. Controllers may also request additional information where necessary to establish identity, verify the request, or communicate with the data subject, including identifiers and contact information already known to the data subject.

The practical challenge is to strike the correct balance. Insufficient authentication can result in disclosure of personal data to the wrong person, while excessive authentication requirements may improperly obstruct the exercise of the right.

Representatives Require Proper Authority:

The Notification expressly addresses requests submitted through representatives. An authorized representative must provide a power of attorney identifying the matter for which authority has been given, with the required stamp duty and signatures, together with appropriate identification documentation for the relevant parties. Alternative verification methods may again be used, provided they do not create an unreasonable obstacle.

Controllers should therefore review their procedures for requests submitted by lawyers, family members, guardians, employee representatives, and other authorized persons. A generic assumption that an email from a representative is sufficient may no longer be appropriate.

A 15-Day Initial Review Stage:

One of the most important procedural features of the Notification is an initial review stage.

After receiving a request, the controller must examine the request details, supporting documents, and whether the requester is the data subject or a genuinely authorized representative. This review must be completed without delay and no later than 15 days from receipt of the request. If the request or supporting documents are incorrect or incomplete, or if the controller cannot verify the requester, the controller must notify the requester to correct the request or provide additional documents.

The controller must provide a period of not less than 10 days for the requester to correct the deficiency. For purposes of the subsequent process, the request is treated as received when the corrected request or complete supporting documentation has been received. If the requester does not correct the deficiency within the specified period, the request is treated as abandoned. The controller must notify the requester accordingly, although the data subject remains entitled to submit a new request.

This makes DSAR intake more than a logging exercise. Controllers should be able to distinguish between receipt of an initial request, completion of the verification process, requests for additional information, and the point from which the substantive response period runs.

The Substantive Response Period Is 30 Days:

Where the request is complete, the requester has been verified, and no ground for refusal applies, the controller must fulfill the request without delay and no later than 30 days from receipt of the request. The Notification allows an extension where the request concerns a large volume of information or where another necessity prevents the controller from completing the request within the ordinary period.

Importantly, the permitted extension is no more than an additional 30 days. The controller must inform the data subject or authorized representative of the necessity for the extension and the relevant details. This corrects an important point appearing in some descriptions of the new regime: the official Notification does not provide for a further 60-day extension. For implementation purposes, organizations should therefore build their DSAR workflow around a 30-day substantive response period, with only a limited additional 30-day period where the conditions for extension are satisfied.

How Access Can Be Provided:

The Notification permits several methods of fulfilling a request.

A controller may:

  • allow the data subject to inspect relevant personal data;
  • prepare and provide copies of documents containing the relevant personal data; or
  • provide access, copies, or source information electronically or in another format agreed between the controller and the data subject.

Where the data subject submits the request electronically and does not request another format, the controller must provide the response electronically where this can reasonably be done. Controllers should therefore consider not only whether data can be found, but also whether it can be extracted into a format that can safely and intelligibly be provided to the requester.

Refusal Grounds Are Now More Operationally Defined:

The Notification provides greater detail concerning circumstances in which a controller may refuse to comply with a request.

A request may be refused where compliance would be contrary to law or a court order. Refusal may also be permitted where compliance would adversely affect the legally protected rights and freedoms of another person. The Notification expressly refers to matters including another person’s personal data, official secrets, trade secrets, copyright, and other intellectual property rights.

A controller may also refuse a request that is manifestly unfounded or that would impose an unreasonable burden on the controller. However, third-party information does not automatically justify refusing the entire request.

Where disclosure would affect another person’s rights and freedoms, the controller must comply with the request to the extent reasonably possible after balancing the relevant rights and interests. The Notification expressly contemplates deletion, redaction, or other measures that prevent disclosure of information that would adversely affect the third party. This makes document review and redaction a core part of DSAR compliance.

Employee DSARs May Become Particularly Significant:

For HR functions, the new rules could have substantial practical consequences.

Employee personal data is rarely located in a single personnel file. It may be distributed across HR information systems, payroll platforms, performance evaluations, email, internal messaging systems, access-control records, CCTV, workplace monitoring tools, expense systems, disciplinary records, and documents held by external service providers.

A section 30 request may therefore require coordination between HR, legal, IT, information security, facilities, and other business functions. The 30-day substantive response period means that organizations should establish internal search and escalation procedures before requests are received, rather than attempting to construct the process after the clock has started.

AI Systems Should Be Included in DSAR Readiness Testing:

Organizations deploying AI should also consider whether personal data contained in or processed through AI systems can actually be identified and retrieved when a section 30 request is received.

Depending on the architecture, relevant personal data may exist in prompts, uploaded documents, user profiles, interaction histories, logs, retrieved contextual information, generated outputs linked to identifiable individuals, or data stores supporting an AI application.

The Notification does not create separate rules for AI. The practical point is that the same access obligation applies where relevant personal data is held within an AI-enabled environment. Accordingly, it is not sufficient for a privacy notice simply to state that data-subject rights are available. The technical architecture must allow the organization to operationalize those rights within the applicable timetable.

Processor and Vendor Cooperation Should Be Tested:

The Notification places the legal obligation to respond on the controller, but much of the relevant personal data may be held by processors or other service providers.

Controllers should therefore review processor and vendor agreements to determine whether they contain adequate obligations concerning:

  • assistance with data-subject requests;
  • data searches and retrieval;
  • response times;
  • provision of copies in usable formats;
  • identification of relevant systems and repositories;
  • preservation of data during the request process; and
  • assistance with deletion, redaction, or other measures needed to protect third-party information.

A processor that is contractually permitted to take several weeks simply to begin searching for data may make it difficult for the controller to comply with its own regulatory timetable.

Fees Are Permitted Only in Defined Circumstances

The Notification also contains detailed rules on fees.

Where access is provided electronically and the controller does not need to prepare data in a special medium or incur direct delivery costs, the controller must not charge a fee. Fees may be charged in other cases, but they must be reasonable and must not exceed actual costs. Certain copying charges are also subject to maximum rates specified in the annex to the Notification.

Where requests are repetitive, involve large volumes of information, or impose a greater-than-normal burden, the controller may charge a reasonable fee having regard to its costs. The controller may also limit the scope or method of compliance to the extent necessary, taking into account both the data subject’s rights and the burden involved.

The Notification further permits controllers to waive or reduce fees for low-income data subjects or in other appropriate circumstances. If a fee will be charged, the controller must notify the data subject before or when exercising the right to charge it. Controllers should therefore avoid adopting a standard DSAR fee without first determining whether charging is permitted in the particular circumstances.

Record-keeping Is Mandatory:

Controllers must maintain records of requests, supporting documentation, and the action taken or refusal to act on each request for at least two years for verification and evidentiary purposes. Those records may be kept electronically.

Where a request is refused, the controller must notify the data subject or representative of the refusal and the reasons, and the refusal and its basis must also be recorded in the controller’s records maintained under section 39 of the PDPA.

This makes a DSAR register or case-management system increasingly important. The record should allow the controller to reconstruct the lifecycle of the request, including receipt, identity verification, deficiencies, internal searches, processor involvement, redactions, extensions, fees, disclosure, refusal, and final closure.

What Controllers Should Do Before the Notification Takes Effect:

Controllers should use the remaining implementation period to test whether their existing DSAR procedure can comply with the new rules in practice.

Priority areas include:

  • request channels — ensuring that in-person and registered-mail requests can be received, recognized, and logged, in addition to any electronic channels;
  • identity verification — establishing proportionate procedures for verifying data subjects and representatives;
  • initial review — implementing the 15-day assessment process and procedures for curing incomplete requests;
  • internal routing — identifying responsible contacts in HR, IT, marketing, customer service, security, legal, and other relevant functions;
  • data discovery — determining how personal data can be located across email, HR, CRM, cloud services, CCTV, monitoring systems, archives, and other repositories;
  • processor cooperation — testing whether processors and vendors can retrieve relevant information quickly enough;
  • third-party information — establishing review and redaction procedures;
  • deadline controls — monitoring the 30-day response period and any justified additional 30-day extension;
  • response formats — determining how inspection, copies, and electronic access will be provided;
  • fees — ensuring that charges are imposed only where permitted and within the applicable limits;
  • refusals — developing a documented process for assessing refusal grounds and issuing required explanations; and
  • records — maintaining evidence of requests and their handling for at least two years.

A practical way to test readiness is to run a mock DSAR involving an employee or customer whose information is spread across several systems and at least one external processor. That exercise is likely to identify operational weaknesses more effectively than simply reviewing the wording of the organization’s privacy notice.

Key Takeaways:

The new Notification materially changes the operational expectations surrounding section 30 access requests.

Controllers will need more than a general statement in their privacy notices that data subjects have a right of access. They need an end-to-end process capable of receiving requests through the required channels, verifying identity and authority, identifying deficiencies within the initial review period, locating data across internal and external systems, protecting third-party rights, producing the requested information, managing statutory deadlines, documenting refusals, applying fee rules correctly, and preserving evidence of compliance.

Two timing points deserve particular attention: the controller must conduct the initial review without delay and within 15 days, while a valid request that proceeds to fulfillment must generally be completed within 30 days, subject to a justified extension of no more than an additional 30 days.

For organizations with mature DSAR procedures, the immediate task should be a gap analysis against the Notification. For organizations that have treated access rights primarily as privacy-notice language, a more substantial operational implementation project is required. The key compliance question is now straightforward: if a real section 30 request arrived today, could the organization authenticate the requester, find the relevant personal data across all relevant systems and processors, review it for third-party information, provide it in the required manner, and demonstrate that every step was completed within the prescribed timetable?

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

Big Data: Thailand Approves National Strategy to Accelerate AI and Data-Driven Economy

Thailand’s Cabinet has acknowledged the draft National Big Data Strategy, establishing the country’s first comprehensive policy framework for the development and use of big data as a foundation for digital government, artificial intelligence (AI), and a data-driven economy.

The strategy is intended to provide a unified direction for government agencies to improve data management, strengthen digital infrastructure, and promote the practical use of data in both the public and private sectors.

Why the strategy matters:

Although the strategy is not legislation and does not itself impose new legal obligations, it signals the Government’s long-term policy direction. Businesses operating in Thailand—particularly technology companies, cloud service providers, AI developers, healthcare providers, financial institutions, and organizations handling government-related data—should expect increased public investment and regulatory attention in data governance and AI.

The strategy also reinforces the Government’s objective of using data as a strategic national asset to improve public administration, support economic growth, and enhance Thailand’s digital competitiveness.

Key objectives:

According to the announcement, the strategy seeks to:

  • establish an integrated national big data ecosystem;
  • improve evidence-based policy making through better use of government data;
  • support AI adoption across government and industry;
  • enhance Thailand’s digital competitiveness; and
  • promote responsible and systematic use of data.

The Government has also set measurable goals, including increasing the economic value generated from big data and positioning Thailand among the world’s leading countries in big data capability.

Four strategic pillars:

The strategy consists of four principal initiatives.

1. Building national data infrastructure

The Government plans to strengthen core digital infrastructure through initiatives such as:

  • Government Cloud;
  • Government Data Catalog; and
  • National Big Data Platform.

These projects are intended to improve interoperability and enable more effective data sharing among government agencies.

2. Expanding practical use of data

The strategy encourages wider use of data analytics to address national priorities, including:

  • healthcare;
  • tourism;
  • environmental management;
  • agriculture; and
  • trade and economic development.

This reflects the Government’s intention to move beyond data collection toward data-driven decision-making.

3. Accelerating AI adoption

A significant component of the strategy is the promotion of AI across the public and private sectors.

The Government intends to:

  • expand AI applications in government services and industry;
  • support development of Thai-language AI models; and
  • establish datasets suitable for AI development.

These initiatives may create opportunities for AI developers, cloud providers, data platform operators, and businesses offering AI-enabled solutions.

4. Developing human capital

Recognizing that technology alone is insufficient, the strategy also emphasizes workforce development by increasing the number of professionals with expertise in big data and AI.

The Government aims to significantly expand the pool of skilled personnel capable of supporting Thailand’s digital transformation.

Legal and regulatory implications:

The strategy itself does not amend Thailand’s existing legal framework, including laws governing personal data protection, cybersecurity, or digital government.

Nevertheless, it indicates that future regulatory and policy initiatives are likely to focus on:

  • enhanced government data governance;
  • improved standards for data interoperability;
  • greater integration of public-sector datasets;
  • expanded use of AI in government services; and
  • stronger digital infrastructure supporting government cloud and data-sharing initiatives.

Organizations participating in government projects or processing government-related data should therefore continue monitoring future implementing measures, technical standards, procurement requirements, and sector-specific regulations that may follow.

Looking ahead:

The National Big Data Strategy represents an important policy milestone in Thailand’s digital transformation agenda. While much of its implementation will depend on future projects, funding, and regulatory measures, the strategy demonstrates the Government’s commitment to treating data and AI as key drivers of economic development and public-sector modernization.

For businesses, the announcement suggests increasing opportunities in AI, cloud computing, digital infrastructure, and government technology, while reinforcing the importance of robust data governance and regulatory compliance.

Key takeaways:

  • Businesses involved in AI, cloud services, digital infrastructure, and government technology should monitor future implementing regulations, technical standards, and procurement initiatives arising from the strategy.
  • Thailand has adopted its first comprehensive national strategy for big data development.
  • The strategy serves as a policy framework rather than creating immediate legal obligations.
  • Four priorities include national data infrastructure, wider use of data analytics, AI adoption, and workforce development.
  • Government investment is expected to accelerate in cloud infrastructure, data platforms, and AI ecosystems.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand’s Response to the 12.5% U.S. Section 301 and the request for Further Exemptions

Introduction

On July 23, 2026, the Office of the United States Trade Representative (“USTR”) issued its final action under Section 301 of the Trade Act of 1974 in the Forced Labor Investigation, covering approximately 60 trading partners. Thailand was placed in the higher 12.5% tariff band, effective July 24, 2026, alongside Vietnam, the Philippines, and Singapore. Thailand received this rate because the United States found it had not adopted, committed to, or partially implemented a prohibition on the import of goods produced with forced labor, unlike a smaller group of trading partners assigned a 10% rate.

A separate and still-ongoing USTR proceeding, the Excess Capacity Investigation, covers 16 trading partners, including Thailand, and examines alleged structural excess capacity in manufacturing sectors. This investigation has not concluded and no tariff has yet been imposed under it. If the United States ultimately takes action on this second track as well, Thai exporters could face a further tariff, with some commentators estimating a combined exposure of up to 25% across both proceedings.

Domestically, Prime Minister Anutin Charnvirakul has directed six ministries and the Royal Thai Police to address both issues. Externally, the Ministry of Commerce (“MOC”) continues to negotiate an Agreement on Reciprocal Trade (“ART”) with the United States and has requested exemptions for a further 78 tariff lines, while stating that its negotiating position will not compromise the interests of farmers, the public, or businesses.

Key Concerns and Thailand’s Response

Following the Cabinet meeting of July 27, 2026, the Cabinet Secretariat issued an urgent instruction to the Ministries of Finance, Foreign Affairs, Agriculture and Cooperatives, Commerce, Labor, and Industry, and to the Commissioner-General of the Royal Thai Police. Each agency has been directed to prepare supporting data and response measures, identify the units responsible for each task, and set clear implementation timeframes.

1. Forced Labor

The United States has emphasized the need for stronger measures against goods produced with forced labor, including enhanced Human Rights Due Diligence (“HRDD”) and supply-chain traceability. The Ministry of Labor leads this response, together with the Ministries of Commerce and Industry. Their tasks are to accelerate enforcement of existing laws and regulations, compile lists of at-risk products and industries, and develop origin-certification and traceability systems covering the full production chain, so that Thailand can substantiate its position in discussions with the United States and other trading partners.

Thailand does not yet have directly enforceable legislation on this point. Thailand’s Ministry of Justice has been developing a draft Act on the Promotion of Responsible Business Conduct (also referred to as the mandatory Human Rights and Environmental Due Diligence, or “HRDD/mHREDD,” bill) since 2025, intended to align with the UN Guiding Principles on Business and Human Rights. The bill remains under development, and its legislative timeline, including submission to Parliament, has not been firmly fixed as of this update. Businesses should not wait for enactment before building supply-chain records.

2. Structural Excess Capacity

This issue is the subject of the separate, ongoing USTR Excess Capacity Investigation described above. It did not itself determine Thailand’s placement in the 12.5% forced-labor tariff band, though it could result in additional measures. The MOC leads Thailand’s response, with the Ministries of Industry, Agriculture and Cooperatives, and Finance. The agencies must compile risk lists at the product and industry level, integrating data on production capacity, inventory levels, government subsidies, price structures, export volumes, and country of origin. They must also investigate false origin claims and the use of Thailand as a trans-shipment point to evade trade measures imposed by importing countries.

Government support policy is also shifting direction. Future assistance is intended to target productivity, cost reduction, technology adoption, value addition, and greater use of local content. Subsidies that expand production capacity or increase supply beyond market demand are to be avoided, as they could themselves be cited as evidence of excess capacity. In discussions with USTR, Thailand has represented that domestic capacity utilization in the targeted industries generally runs between 70% and 90%, with no industry operating below 60%.

Exposure and Exemptions Secured

Thailand has obtained exemptions for 2,120 tariff lines under Annex II, Part A, representing approximately 61.6% of tariff lines and US$56.2 billion in exports, or roughly half the value of Thai goods exported to the United States. This is a substantial increase from the 471 items exempted under an earlier, preliminary list. Goods already subject to duties under Section 232 of the Trade Expansion Act of 1962 (for example, automobiles, steel, aluminum, and copper) are not subject to duplicate Section 301 duties. This overlap covers roughly US$7 billion of the remaining non-exempt goods.

Taking both the exemption list and the Section 232 overlap into account, the MOC estimates that approximately 28% of Thai exports to the United States remain exposed to the additional 12.5% tariff. Leading non-exempt industrial products include car and truck tires, machinery, cameras, air conditioners, and vehicle wheels and rims. Products such as jewelry, milled rice, pet food, canned tuna, and processed shrimp likewise remain outside the current exemption list and are among the items for which Thailand is now seeking relief (see below).

Solar cells and modules face particularly high cumulative exposure. In addition to the Section 301 tariff, U.S. antidumping duties on Thai-origin solar cells have been assessed at rates of up to approximately 203%, and countervailing duties at rates of up to approximately 800%, reflecting separate U.S. Commerce Department determinations on dumping and subsidization. Combined with the Section 301 tariff, total cumulative duties on affected solar shipments can substantially exceed 800%, and in the highest cases run well over 1,000%.

The Request for 78 Additional Tariff Lines

The MOC has submitted a proposal covering seven product groups and 78 tariff lines, which are agriculture and food security, consumer and household goods, medical and public-health products, electronics and semiconductors, vehicles and parts, machinery components and industrial equipment, and handicrafts and value-added products. Illustrative items include rice and Thai hom mali (jasmine) rice, maize, coconuts, orchids, cassava and cassava starch products, and fishery products, alongside jewelry, dog and cat food, milled rice, medical rubber gloves, tuna, processed bonito, fresh and cooked shrimp, and sauces and seasonings. The Commerce Ministry has separately referenced a further proposal covering 13 additional items, though it has not clarified whether these form part of the 78-line request or a distinct submission.

Thailand’s negotiating position is subject to three limits. It will not cross the interests of farmers, the interests of the public, or the rights of businesses. Thailand has indicated it is prepared for technical-level ART talks and is awaiting a determination from USTR, after which the MOC has suggested negotiations could conclude within a matter of weeks.

Key Takeaways

  • Solar cells are a particular outlier, combined Section 301, antidumping, and countervailing duties can push cumulative exposure well above 800%, in some cases exceeding 1,000%.
  • The 12.5% tariff under Section 301 currently in effect stems from the Forced Labor Investigation only. The separate Excess Capacity Investigation remains open and could result in an additional tariff if concluded against Thailand.
  • After accounting for the Annex II exemption list and the Section 232 overlap, approximately 28% of Thai exports to the United States remain exposed to the 12.5% tariff.
  • Six ministries and the Royal Thai Police have been directed to address forced labor and excess capacity concerns, with traceability and origin certification central to the response.
  • A mandatory human rights and environmental due diligence bill is under development by the Ministry of Justice, and its legislative timeline is not yet fixed. Businesses should not wait for enactment before building supply-chain records.
  • A request for 78 further exemption lines across seven product groups remains pending, and technical-level ART talks await a USTR determination.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Tightens Registration Requirements for Partnerships and Limited Companies with Foreign Participation

Nominees: A Threat to Thailand’s Economy

Nominee arrangements — in which Thai nationals hold shares or capital contributions on behalf of foreign investors — have remained a longstanding compliance concern under the Foreign Business Act B.E. 2542 (1999) (the “FBA”). The Department of Business Development (the “DBD”) has now shifted a significant part of that scrutiny to the registration stage itself.

The use of nominees is a major national concern that undermines Thailand’s economic and business security by distorting market competition, reducing tax revenue, and eroding investor confidence. Foreign operators who rely on nominees unfairly bypass statutory business restrictions, undercutting law-abiding foreign investors and overwhelming Thai small and medium-sized enterprises (SMEs) that cannot compete against superior capital and resources — ultimately contributing to job losses and business closures. Nominee structures also facilitate tax evasion, money laundering, and other illicit financial activity, which compromises state revenue collection and damages Thailand’s international reputation by exposing gaps in regulatory and legal enforcement.

For these reasons, the rigorous inspection of, and crackdown on, nominee arrangements is a critical measure to protect the country’s economic interests, ensure fair competition, and safeguard the long-term stability of the Thai economy.

Background

Initial screening at the company incorporation stage previously offered partial protection against nominee risk by verifying Thai investment capital. However, bad actors circumvented these controls through subsequent corporate amendments — transferring shares or directorships to foreign nationals only after the company had already secured initial approval.

Legal Basis

To close this loophole, the DBD issued the “Central Partnership and Company Registrar Order No. 2/2569, Prescribing the Criteria and Supporting Documents for Applications for the Registration of the Incorporation and Amendment of Partnerships and Limited Companies Where Foreign Nationals Participate in the Investment or Hold Signing Authority in Partnerships and Limited Companies” (the “Order”). The Order took effect on 1 August 2026.

The Order extends DBD oversight across the full business lifecycle — from incorporation through post-registration amendments — to prevent unauthorized structural changes, while imposing stricter documentation requirements on all relevant registration applications.

It consolidates existing requirements by repealing two earlier orders:

  1. Order No. 2/2568, dated 1 December 2025 (B.E. 2568), concerning the registration of incorporation involving foreign investment, foreign directors, or foreign authorized signatories in a legal entity; and
  2. Order No. 1/2569, dated 16 March 2026 (B.E. 2569), concerning amendment registrations admitting foreign nationals as partners or as authorized signatory directors.

According to its preamble, the Order is intended to enhance the credibility of the commercial register, to prevent the concealment or disguise of funds derived from unlawful conduct through nominee arrangements, and to deter Thai nationals from providing assistance or support to, or jointly operating a business with, foreign nationals in the nature of a nominee.

New Legal Requirements

1. Registration of Incorporation

The additional documentary requirements apply to an application for the registration of incorporation in either of the following cases:

  • a partnership or limited company in which a foreign partner or shareholder contributes, or holds, less than 50% of the capital contribution or registered capital; or
  • a limited company with no foreign shareholder, where a foreign national serves as a director authorized to sign — whether solely or jointly — so as to bind the company.

Supporting documents required at incorporation

Applicants falling within the above categories must submit a Letter of Clarification on Investment, in the form annexed to the Order, together with the following bank statements:

  • a statement of the account from which each Thai partner or shareholder made payment, covering the three months prior to the date of payment and evidencing a withdrawal or transfer consistent with the amount and date of payment;
  • a statement of the account of the managing partner or director who received the funds, evidencing receipts consistent with the amount and date of payment from each partner and shareholder; and
  • where the receiving account is also the account relied upon to evidence payment under the first item above, an additional statement covering the three months prior to the date of receipt.

The third requirement addresses situations in which the managing partner or director settles their own contribution from funds already held in the receiving account, rather than by a traceable transfer. In such cases, the source of those funds must be explained separately in the Letter of Clarification.

2. Amendment Registrations Involving Foreign Nationals

A Letter of Confirmation of Investment, also in the form annexed to the Order, must be submitted with an application to register an amendment admitting a foreign national as a partner, or appointing a foreign national as an authorized signatory director, in either of the following cases:

  • a partnership in which all partners were previously Thai nationals, or in which foreign partners held 50% or more of the capital contribution, where the amendment results in foreign partners holding less than 50% and no foreign national serving as managing partner; or
  • a limited company in which all directors authorized to bind the company were previously Thai nationals, where an amendment to the directors — or to the number or names of the directors signing to bind the company — results in a foreign national holding sole or joint signing authority.

3. Additional Requirements for Recently Incorporated Entities

Where a partnership or limited company incorporated on or after 1 August 2026 submits an amendment application of the type described above within one year of its registration as a juristic person, it must additionally submit the amendment version of the Letter of Clarification on Investment, together with a bank statement evidencing that the entity — or the managing partner or director on its behalf — received the full amount of the capital contributions or share payments called up at incorporation.

This requirement addresses the sequencing of transactions whereby an entity is incorporated with Thai partners or directors and a foreign national is introduced shortly thereafter.

Legal Significance

The Order does not introduce a new prohibition; nominee arrangements already constitute an offence under Section 36 of the FBA. Its significance instead lies in shifting the evidentiary burden to the point of registration, and in the personal declaration now required of the signatory.

Under the Letter of Confirmation of Investment, the managing partner or authorized director confirms that all partners have genuinely made and paid their capital contributions, that all shareholders have genuinely paid for their shares, and that no Thai national has provided assistance or support to, or jointly operated a business with, a foreign national in the nature of a nominee. The signatory further acknowledges the following penalties:

  • Section 36 of the FBA: imprisonment not exceeding 3 years, a fine of THB 100,000 to 1,000,000, or both;
  • Section 137 of the Criminal Code (false statements to an official): imprisonment not exceeding 6 months, a fine not exceeding THB 10,000, or both; and
  • Section 267 of the Criminal Code (causing a false entry in a public document): imprisonment not exceeding 3 years, a fine not exceeding THB 60,000, or both.

Key Takeaways

  • Existing entities are unaffected until they register a qualifying amendment, at which point the Order applies in full.
  • The Order took effect on 1 August 2026 and applies to partnerships and limited companies in which foreign participation is below 50%, and to limited companies in which a foreign national holds signing authority.
  • Documentary requirements now extend to bank statements evidencing both the payment and receipt of capital contributions and share payments, supported by a prescribed clarification letter.
  • Amendment registrations introducing a foreign partner or foreign signatory require a signed Letter of Confirmation of Investment, which carries personal criminal exposure for the signatory.
  • Entities incorporated on or after the effective date are subject to additional requirements if a qualifying amendment is registered within their first year.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Class-Action Signal Raises the Stakes for Online Consumer Complaints

Background:

Thailand’s Office of the Consumer Protection Board (OCPB) has announced that it is developing a national action plan to strengthen consumer protection for products sold through online channels. The initiative is intended to improve coordination among government agencies responsible for digital commerce, online marketplaces, direct-selling businesses, and consumer protection, while establishing clearer responsibilities and performance indicators.

Although the proposed action plan itself does not introduce new legal obligations, one aspect deserves particular attention from businesses. The OCPB has been directed to study the broader use of class-action proceedings where large numbers of consumers suffer substantially similar losses.

Thailand already recognizes class actions under the Civil Procedure Code, but they have historically been used relatively infrequently. The latest policy initiative indicates that consumer regulators are considering greater reliance on collective litigation as an enforcement mechanism where systemic consumer harm is identified, particularly in the rapidly expanding digital marketplace.

Why this matters:

The announcement does not create a new statutory cause of action or impose additional regulatory requirements on online platforms. However, it signals a possible shift in enforcement priorities.

Traditionally, consumer complaints have often been addressed individually through customer service channels or administrative dispute resolution. A greater emphasis on class actions would instead encourage regulators and claimants to examine recurring patterns of similar complaints across multiple consumers.

This approach could significantly increase litigation exposure where businesses fail to identify or address systemic issues affecting multiple customers.

Practical implications for businesses:

Online marketplaces, e-commerce operators, social-commerce platforms, direct-marketing businesses, manufacturers, importers, brand owners, payment providers, logistics companies, and merchants should consider strengthening internal governance before any formal policy changes occur.

Particular attention should be given to:

  • identifying recurring complaints involving the same product, seller, advertisement, or defect;
  • maintaining reliable seller identification and beneficial ownership information;
  • preserving documentation relating to product origin, regulatory approvals, and compliance certifications;
  • implementing effective notice-and-takedown procedures for unlawful or unsafe products;
  • escalating recurring safety or quality issues through documented internal processes;
  • reviewing refund, replacement, recall, and remediation procedures;
  • preserving evidence, including listings, livestreams, advertisements, customer communications, payment records, and delivery information; and
  • reviewing merchant agreements to ensure appropriate cooperation, indemnification, and information-sharing obligations.

Repeated complaints that appear insignificant when viewed individually may later be relied upon collectively to establish knowledge of defects, inadequate remediation, misleading advertising, or broader compliance failures.

Intellectual property considerations:

The proposed enforcement direction is also relevant for intellectual property owners.

Counterfeit and unauthorized products frequently give rise to overlapping legal issues extending beyond trademark or copyright infringement. A single product listing may simultaneously involve misleading advertising, product safety concerns, inaccurate labeling, warranty issues, and consumer protection violations.

Accordingly, brand owners should avoid treating online enforcement as solely an intellectual property exercise. Internal coordination between IP, consumer protection, product compliance, marketplace enforcement, and litigation teams will become increasingly important where multiple consumer complaints concern the same products or sellers.

Data privacy considerations:

Any increase in collective consumer litigation is likely to require broader preservation and analysis of personal data.

Businesses may need to process information relating to customers, merchants, payment transactions, logistics providers, communications, complaint histories, and digital evidence. Such processing should continue to comply with Thailand’s Personal Data Protection Act.

Organizations should therefore review:

  • legal bases supporting evidence preservation and regulatory disclosures;
  • access controls for complaint and investigation datasets;
  • secure information-sharing procedures with regulators and external advisers;
  • contractual obligations imposed on processors, including marketplaces, call centers, logistics providers, and cloud service providers;
  • document retention policies and litigation-hold procedures; and
  • incident response plans addressing potential personal data breaches involving consolidated claimant information.

Importantly, the prospect of consumer enforcement should not be interpreted as permitting unrestricted disclosure of customer or merchant data. Any disclosure should remain subject to applicable legal authority, proportionality, security safeguards, and appropriate documentation.

Looking ahead:

The OCPB’s announcement remains a policy initiative rather than a binding regulatory change. Nevertheless, it provides an early indication that consumer enforcement may increasingly focus on systemic patterns of misconduct affecting multiple consumers rather than isolated disputes.

Businesses that rely on digital sales channels should therefore begin assessing whether existing compliance, complaint-handling, and evidence-preservation processes would adequately support regulatory investigations or collective litigation involving large groups of consumers.

Key takeaways:

  • Organizations should ensure that complaint investigations and evidence preservation continue to comply with Thailand’s Personal Data Protection Act, particularly where large volumes of personal data are involved.
  • The OCPB is considering greater use of class-action proceedings for widespread consumer harm arising from online commerce.
  • No new legal obligations have been introduced, but the initiative signals a potentially significant shift in enforcement priorities.
  • Businesses should strengthen systems for identifying recurring complaints and preserving evidence relating to products, sellers, and customer interactions.
  • Online platforms and brand owners should integrate consumer protection, product compliance, and intellectual property enforcement rather than treating them as separate functions.

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

Breaking Down Government Data Silos: New Rules on Inter-Agency Sharing of Personal Information

A new Royal Decree has established a legal framework requiring government agencies to share personal information under their control with other government agencies for specified electronic data-linkage purposes.

The Royal Decree on Disclosure of Personal Information Controlled by Government Agencies to Other Government Agencies B.E. 2569 (2026) (the “Royal Decree”) represents an important development in the government’s efforts to move away from fragmented, agency-specific databases toward greater interoperability of public-sector information.

The measure is intended to enable government agencies to use more complete and accurate information in policymaking, public services and targeted welfare programs, while reducing the burden on individuals of repeatedly submitting information already held by the government. The framework is also intended to contribute to greater transparency and more effective law enforcement.

Legal basis for inter-agency disclosure:

The Royal Decree is issued pursuant to Section 24(9) of the Official Information Act B.E. 2540 (1997).

Section 24 of the Official Information Act establishes, as a general rule, that a government agency may not disclose personal information under its control to another government agency or another person without the prior or contemporaneous written consent of the person concerned, subject to specified statutory exceptions.

Section 24(9) permits disclosure in other cases prescribed by Royal Decree.

The new Royal Decree uses this statutory mechanism to provide a specific legal basis for government-to-government disclosure of personal information falling within its scope. As a result, qualifying disclosure under the Royal Decree does not depend on obtaining the individual’s written consent on each occasion.

This is important because large-scale government data interoperability would be difficult to implement if each transfer of information between government agencies required separate consent from every affected individual.

From isolated databases to connected government:

The policy underlying the Royal Decree is broader than simply permitting one government agency to send information to another.

Government agencies hold significant amounts of information about individuals, but that information has traditionally been maintained within separate administrative systems. Where relevant information is distributed among different agencies, the government may not have ready access to the complete information required for policymaking, public services or welfare administration.

The Royal Decree is intended to address this fragmentation by enabling electronic linkage of personal information held across government agencies.

The stated objectives include allowing government policies and measures, government services and targeted welfare programs to be based on accurate and complete information. Greater data linkage is also intended to improve the efficiency of government services, reduce administrative burdens on the public, promote transparency and enhance the effectiveness of law enforcement.

In practical terms, the framework supports a move toward the principle that individuals should not continually be required to provide one government agency with information that is already held by another government agency where the conditions for lawful data linkage are satisfied.

Government agencies may be required to disclose information:

A significant feature of the Royal Decree is that it does not merely provide government agencies with a general permission to share personal information.

It establishes a framework under which a government agency controlling personal information must disclose that information to another government agency where the information is requested for purposes falling within the Royal Decree.

The relevant data linkage is intended to support the preparation and provision of government services and the provision of targeted welfare through electronic means.

This gives the Royal Decree practical significance beyond an ordinary exception to a confidentiality rule. It provides the legal infrastructure for systematic government data interoperability.

The receiving agency also assumes obligations:

Greater availability of government-held information is accompanied by safeguards.

A government agency requesting and receiving personal information must safeguard that information. Importantly, it may not further disclose the information to an outside person.

This restriction is an important limitation on the scope of the new regime. The Royal Decree should therefore not be understood as making personal information freely transferable simply because it has entered an interconnected government information system.

The legal authorization concerns disclosure within the framework established by the Royal Decree. Once information has been received, the recipient agency remains responsible for protecting it and complying with the restrictions applicable to its subsequent disclosure.

The required safeguards are also linked to criteria and conditions prescribed by the competent authority and cybersecurity requirements. Consequently, implementation of the Royal Decree is as much an information-governance issue as a data-access issue.

Targeted welfare and government services:

One of the clearest practical applications of government data linkage is the provision of targeted welfare.

Eligibility for government assistance may depend on information maintained by several different authorities. Without data linkage, individuals may have to obtain documents from one agency and submit them to another, while the agency administering the benefit may have difficulty independently establishing a complete picture of the applicant’s circumstances.

Electronic linkage can potentially change this process.

Where legally permitted, the administering agency may obtain relevant information directly from government data already available elsewhere. This can make eligibility assessment more accurate, reduce duplicate documentation and enable welfare programs to be directed more effectively toward intended recipients.

The same principle can apply more broadly to government services. Greater interoperability can reduce repeated requests for information and allow government agencies to make administrative decisions using more complete information.

Transparency and law enforcement:

The Royal Decree also has implications beyond welfare and administrative services.

The stated rationale includes increasing transparency within government and improving the effectiveness of law enforcement. Information that appears unremarkable when held in a single agency’s database may have greater significance when lawfully linked with information held by other agencies.

Inter-agency data linkage can therefore provide government authorities with a more complete information base for identifying inconsistencies, verifying information and carrying out their statutory functions.

This capability may be particularly relevant where investigations or enforcement activities require information held by several government bodies.

However, the Royal Decree should not be characterized as creating a general law-enforcement database or an unrestricted investigative power. Its significance lies in providing a statutory mechanism for disclosure and electronic data linkage within the scope established by the Royal Decree.

Data sharing does not mean unrestricted data use:

An important compliance point is the distinction between access to information and freedom to use or disclose that information.

The fact that one government agency is legally entitled to obtain information from another does not mean that information becomes unrestricted once transferred.

Government agencies implementing data-linkage arrangements should therefore consider controls covering at least:

  • the authority and purpose for requesting information;
  • identification of the information required;
  • authentication of requesting agencies and authorized personnel;
  • access controls within the receiving agency;
  • secure electronic transmission;
  • logging and traceability of access and transfers;
  • cybersecurity safeguards;
  • retention and management of linked information; and
  • controls preventing unauthorized onward disclosure.

These controls are particularly important because increased interoperability can increase the consequences of inadequate security. A weakness in one interconnected system may potentially expose information originating from several agencies.

Relationship with personal data protection requirements:

The Royal Decree should also be understood within the broader legal framework governing personal information.

Its immediate statutory basis is the Official Information Act, and it establishes a specific mechanism permitting inter-agency disclosure that would otherwise be subject to the restrictions in Section 24 of that Act.

However, the existence of a statutory basis for disclosure should not automatically be equated with unlimited authority to process the information for any subsequent purpose.

Government agencies participating in data-linkage arrangements should therefore identify the legal authority supporting each stage of the information lifecycle—including collection, disclosure, receipt, use, retention, security and any subsequent disclosure—and consider other applicable personal data protection and cybersecurity requirements.

The distinction is particularly important as government systems become increasingly interconnected. Legal authority to receive information is only one component of lawful and responsible data governance.

A significant step toward data-driven government:

The Royal Decree represents a structural change in the management of government-held personal information.

The traditional model in which each government agency maintains its own information and individuals repeatedly provide substantially the same information to different authorities is increasingly being replaced by a model based on controlled interoperability.

If implemented effectively, the new framework should enable government agencies to make greater use of information already available within the public sector, improve the accuracy of public services and welfare programs, and reduce unnecessary administrative burdens on individuals.

The corresponding challenge is governance.

The more effectively government information systems are connected, the more important it becomes to ensure that access is authorized, purposes are properly defined, information is adequately protected and subsequent disclosure remains controlled.

The Royal Decree therefore represents not simply an expansion of government access to data, but a move toward a more integrated model of public-sector data governance.

Key Takeaways:

  • The Royal Decree marks an important shift from government data held in separate institutional silos toward controlled, interoperable public-sector data infrastructure.
  • The Royal Decree establishes a statutory mechanism for the disclosure of personal information between government agencies for qualifying electronic data-linkage purposes.
  • Its legal basis is Section 24(9) of the Official Information Act, which allows exceptions to the general restriction on disclosure of government-controlled personal information without written consent.
  • The framework goes beyond merely permitting voluntary data sharing and supports systematic interoperability between government information systems.
  • A government agency receiving information under the framework must safeguard the information and is restricted from further disclosure to an outside person.
  • The framework is intended to support more accurate policymaking, more efficient government services and targeted welfare, reduced administrative burdens on the public, greater transparency and more effective law enforcement.
  • Government agencies should not treat authorization to receive information as unrestricted authority to use or further disclose it. Purpose limitation, access controls, cybersecurity and information governance remain central to implementation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles