PDPA Insights: Building Effective Privacy Governance

PDPA: AI Is Not Replacing Privacy Law—It Is Changing How We Apply It

Artificial intelligence has rapidly become part of everyday business operations. Recommendation engines personalize online shopping experiences, chatbots answer customer enquiries, fraud detection systems identify suspicious transactions, recruitment platforms screen job applicants, and generative AI assists with customer service, marketing and document preparation.

As AI adoption accelerates, organizations frequently ask whether the Personal Data Protection Act (PDPA) contains special rules governing AI.

The answer is both simple and nuanced.

Thailand’s PDPA does not establish a standalone regulatory framework for artificial intelligence. Unlike some jurisdictions that have introduced AI-specific legislation, the PDPA remains technology neutral. The same legal principles governing all personal data processing—including lawfulness, purpose limitation, transparency, data minimization, security, and accountability—continue to apply regardless of whether personal data is processed manually or through sophisticated AI systems.

Nevertheless, the Personal Data Protection Committee’s (PDPC) recent consultation on marketing and direct marketing demonstrates that the regulator increasingly recognizes AI-assisted personalization, profiling, and automated decision-making as ordinary components of modern business operations rather than exceptional technologies. This signals an important evolution in regulatory expectations. The question is no longer whether AI falls within the scope of the PDPA. Instead, organizations should consider how existing privacy principles should operate when personal data is processed at unprecedented speed and scale.

AI changes the scale—not the legal principles:

One misconception is that AI requires an entirely new compliance framework.

In reality, the core legal questions remain familiar.

Why is personal data being processed?

Is there an appropriate legal basis?

Have individuals been informed?

Is the processing proportionate?

Are appropriate safeguards in place?

These questions existed before AI and remain the foundation of PDPA compliance.

What AI changes is the scale and complexity of those questions.

A marketing employee might manually analyze one hundred customer records to recommend products.

An AI system may analyze ten million records every day, continuously refining customer profiles and generating individualized recommendations without direct human intervention.

The legal principles remain the same.

The governance challenge becomes significantly greater.

Organizations should focus on the processing—not the technology:

Discussions about AI frequently focus on algorithms.

Privacy law focuses on personal data.

Organizations should therefore avoid beginning compliance discussions with technical questions such as:

“Are we using AI?”

Instead, they should ask:

“How is personal data being collected, analyzed, combined, retained and disclosed?”

This shift in perspective has practical consequences.

An AI system recommending products based upon purchasing history raises different privacy considerations from an AI system screening job applicants or detecting fraudulent transactions.

The technology may be identical.

The processing purposes are not.

Organizations should therefore evaluate each AI use case separately rather than adopting a single enterprise-wide conclusion regarding AI compliance.

Profiling is becoming an ordinary business activity:

One of the most significant aspects of the PDPC’s recent consultation is the inclusion of profiling alongside AI-assisted marketing and automated decision-making.

This reflects commercial reality.

Retailers profile customers to recommend products.

Banks profile spending behaviour to identify suitable financial services.

Hotels profile travel patterns.

Streaming platforms profile viewing preferences.

Insurance companies profile claims histories.

Profiling has become routine.

The regulatory focus is therefore shifting away from asking whether profiling exists toward examining whether organizations understand, govern and explain how profiling operates.

Transparency becomes particularly important where profiling materially influences commercial decisions affecting individuals.

Explainability is becoming a governance issue:

Many AI systems are capable of generating sophisticated outputs while providing limited insight into how those outputs were produced.

This creates a practical challenge.

Organizations may be able to explain what an AI system does without fully understanding why it reached a particular recommendation.

The PDPA does not require organizations to explain complex algorithms.

However, organizations should be capable of explaining much more fundamental issues.

What personal data does the AI system use?

Why is that information necessary?

What business objective does the system support?

Who reviews significant outputs?

What safeguards exist to identify inappropriate outcomes?

These governance questions are likely to become increasingly important as AI adoption expands.

Vendor governance is becoming AI governance:

Few organizations develop AI systems internally.

Most rely on external providers.

Large language models.

Cloud AI services.

Marketing automation platforms.

Customer relationship management systems.

Fraud detection software.

Human resources platforms.

Consequently, AI governance increasingly depends upon vendor governance.

Organizations should understand:

  • where personal data is processed;
  • whether overseas transfers occur;
  • whether providers use customer data to train models;
  • whether subcontractors process personal data;
  • how security is maintained;
  • how long information is retained.

Vendor due diligence therefore becomes an essential component of AI governance under the PDPA.

Human oversight still matters:

AI enables organizations to automate decisions at unprecedented scale.

Automation, however, should not eliminate accountability.

Organizations should identify situations where meaningful human review remains appropriate.

Examples may include:

  1. rejecting employment applications;
  2. detecting suspected fraud;
  3. evaluating insurance claims;
  4. determining customer eligibility for significant commercial benefits.

The appropriate level of oversight will depend upon the context and the potential impact on individuals.

Organizations should therefore design governance frameworks that ensure AI supports decision-making without entirely replacing human judgement where significant interests are involved.

AI governance is ultimately privacy governance:

Perhaps the most important lesson is that organizations should resist creating isolated AI compliance programs.

Instead, AI should be incorporated into existing privacy governance.

Records of Processing Activities should identify AI-supported processing.

Privacy notices should accurately describe AI-related processing where appropriate.

Legal basis assessments should consider AI processing explicitly.

Vendor management should address AI providers.

Privacy impact assessments should evaluate AI risks.

Training programs should include AI governance.

In other words, organizations should integrate AI into their existing accountability framework rather than building a separate compliance structure.

Looking ahead:

Artificial intelligence will continue to reshape business operations.

The more significant challenge under the PDPA, however, is unlikely to be the technology itself.

It will be governance.

Organizations capable of explaining why AI is used, what personal data supports it, how risks are managed, and how decisions remain accountable are likely to be better prepared than organizations focusing exclusively on technical innovation.

The PDPC’s recent consultation suggests that this is the direction in which Thailand’s privacy regime is evolving. AI is becoming an ordinary business tool. As a result, organizations should treat AI governance as an ordinary component of privacy governance.

Key takeaways:

  1. The PDPA does not establish separate legal principles for AI; existing privacy obligations continue to apply regardless of the technology used.
  2. AI increases the scale and complexity of personal data processing but does not replace the need for lawful basis, transparency, purpose limitation, and accountability.
  3. Organizations should assess individual AI use cases rather than treating all AI deployments identically.
  4. Profiling and AI-assisted decision-making are becoming mainstream regulatory concerns and should be supported by appropriate governance and transparency.
  5. Vendor management is increasingly inseparable from AI governance because many AI capabilities are provided by third-party platforms.

The organizations best prepared for future regulation will be those that integrate AI into existing privacy governance rather than treating it as a separate compliance project.


Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

Billing Software Requirements vs. Electronic Invoicing Requirements

Executive Summary:

As governments continue to digitalize tax administration, businesses are increasingly expected to adopt electronic invoicing solutions that comply with evolving regulatory requirements. Although the terms billing software and electronic invoicing are often used interchangeably, they represent distinct concepts that serve different commercial and legal functions.

In Thailand, billing software is not subject to a dedicated statutory or regulatory framework. Businesses are generally free to select accounting, billing, or enterprise resource planning (ERP) systems that best support their commercial operations, provided they comply with the Revenue Code and other applicable laws. Electronic invoicing, by contrast, is governed by the Revenue Department’s e-Tax Invoice & e-Receipt framework, which establishes the legal and technical requirements for issuing electronic tax invoices recognized for VAT purposes.

Understanding the distinction between these concepts is important for businesses implementing digital invoicing solutions. A billing system that efficiently generates commercial invoices does not necessarily satisfy the legal requirements for issuing electronic tax invoices. Businesses should therefore evaluate their invoicing systems not only from an operational perspective but also from a tax compliance standpoint.

Introduction:

Digital transformation has fundamentally changed the way businesses prepare invoices, maintain accounting records, and comply with tax obligations. Around the world, tax authorities have introduced electronic invoicing regimes to improve tax compliance, enhance transparency, and reduce administrative burdens for both taxpayers and regulators.

Although electronic invoicing has become an increasingly common feature of modern tax systems, countries have adopted different regulatory approaches. Some jurisdictions regulate the software used to generate invoices, while others focus on the legal validity and technical characteristics of the electronic tax documents themselves.

Thailand follows the latter approach. Rather than regulating billing software as a separate category of software, Thai law establishes a framework governing the issuance of electronic tax invoices through the Revenue Department’s e-Tax Invoice & e-Receipt system. Consequently, businesses remain free to use their preferred accounting or ERP software, provided that the electronic tax documents generated by those systems comply with the applicable legal and technical requirements.

For businesses operating in Thailand, particularly multinational enterprises implementing global ERP platforms, understanding the distinction between billing software and electronic invoicing is essential. While both are integral components of modern financial management, they perform different functions and are subject to different legal considerations.

Billing Software:

Billing software generally refers to applications used by businesses to prepare invoices, calculate taxes, record payments, manage customer accounts, and maintain accounting records. These functions support day-to-day commercial operations and are commonly integrated into accounting software or ERP systems.

Unlike some jurisdictions that regulate invoicing software, Thailand does not currently impose a dedicated legal or regulatory regime governing billing software itself. There is no statutory requirement for billing software to be licensed, certified, or approved by the Revenue Department before it can be used by businesses. Instead, Thai law focuses on the legal sufficiency of the invoices and accounting records generated by the software.

This does not mean that businesses have complete discretion in how billing systems are used. Regardless of the software selected, businesses remain responsible for ensuring that invoices comply with the Revenue Code, VAT is correctly calculated where applicable, accounting records are properly maintained, and supporting documentation is available for inspection by the tax authorities.

Accordingly, compliance under Thai law depends not on the software itself, but on whether the business uses that software in a manner that satisfies its statutory obligations. A business may therefore choose from a wide range of commercial accounting platforms, cloud-based invoicing applications, or ERP systems without obtaining prior approval from the Revenue Department.

Electronic Invoicing:

Electronic invoicing serves a different purpose. Rather than facilitating internal billing processes, it establishes the legal framework under which electronic tax invoices are recognized for VAT purposes.

Thailand’s electronic invoicing regime is principally governed by the Revenue Code, supplemented by the Electronic Transactions Act, Ministerial Regulation No. 384, and Revenue Department notifications prescribing the technical standards for electronic tax documents. Collectively, these instruments enable tax invoices and receipts to be created, transmitted, and retained electronically while ensuring their authenticity, integrity, and reliability.

Businesses wishing to issue electronic tax invoices under the Revenue Department’s e-Tax Invoice & e-Receipt framework must comply with prescribed legal and technical requirements. These include registration with the Revenue Department, generation of electronic tax documents in the prescribed format, use of appropriate electronic authentication mechanisms, transmission through approved channels where applicable, and maintenance of electronic records in accordance with the Revenue Department’s requirements.

An important characteristic of the Thai framework is that it regulates the electronic tax document rather than the accounting software used to produce it. Consequently, businesses may continue using their existing accounting or ERP systems, provided those systems are capable of generating electronic tax invoices that comply with the Revenue Department’s technical specifications. In practice, many businesses achieve this through system localization or integration with specialized e-Tax solutions or authorized service providers.

Thailand currently provides two principal electronic invoicing models. The e-Tax Invoice & e-Receipt system is designed for businesses requiring full electronic integration, while the e-Tax Invoice by Email system provides a simplified alternative for eligible businesses. Although both systems enable businesses to issue legally recognized electronic tax invoices, they differ in their technical implementation and authentication methods.

Key Takeaways:

  • Thailand does not regulate billing software as a separate legal category or require billing software to be certified or approved by the Revenue Department.
  • The Revenue Department’s e-Tax Invoice & e-Receipt framework governs the issuance of legally recognized electronic tax invoices and establishes the applicable technical and procedural requirements.
  • A commercial invoice generated by billing software does not automatically constitute an electronic tax invoice for VAT purposes.
  • Businesses implementing accounting or ERP systems should evaluate both operational functionality and compliance with Thailand’s e-Tax requirements.
  • Early coordination among finance, tax, legal, and information technology functions can help ensure a successful implementation of electronic invoicing while supporting long-term digital tax compliance.

Source: International Comparison July 2026: Global Legal Market Analysis

Read Full Article

Consumer Enforcement Intensifies for EV Businesses as Complaint Cases Rise and Labeling Expectations Increase

Thailand’s consumer protection regulator has signaled a more assertive enforcement approach toward the electric vehicle (EV) sector through two related developments. First, it has indicated its readiness to initiate legal proceedings on behalf of consumers in appropriate EV dispute cases. Second, it has issued new guidance consolidating labeling requirements for automobiles, electric vehicles, and used cars.

Although neither development introduces new legislation, together they demonstrate heightened regulatory scrutiny of the automotive industry and provide valuable insight into the regulator’s current enforcement priorities. Manufacturers, importers, distributors, dealers, service centers, and online vehicle marketplaces should treat these developments as an opportunity to reassess their compliance and dispute management frameworks.

Increased Enforcement Risk from EV Consumer Complaints:

The Office of the Consumer Protection Board (OCPB) has reported a significant number of consumer complaints relating to electric vehicles, with a substantial portion already progressing through legal procedures. The agency has confirmed that it has begun issuing formal demand letters in cases supported by sufficient documentation and has reiterated its statutory authority to commence legal proceedings on behalf of consumers where the legal requirements are satisfied.

This represents an important enforcement signal. Rather than merely facilitating mediation between consumers and businesses, the regulator has indicated its willingness to escalate suitable cases into formal litigation.

The risk is particularly significant where multiple complaints arise from the same product model, manufacturing issue, software defect, battery performance concern, warranty practice, or recurring after-sales service problem. A pattern of similar complaints may increase regulatory attention and expose businesses to coordinated enforcement actions, representative litigation, or broader product liability claims.

Businesses operating within the EV supply chain should therefore review whether existing complaint-handling mechanisms are capable of identifying systemic issues before they evolve into regulatory investigations or court proceedings.

Strengthened Expectations for Vehicle Label Compliance:

Separately, the OCPB has published an electronic handbook consolidating labeling requirements applicable to automobiles, electric vehicles, and used vehicles.

The publication emphasizes information that consumers commonly rely upon when making purchasing decisions, including battery specifications, driving range, testing standards, pricing information, warranty coverage, and the disclosure of material vehicle history for used vehicles.

Although the handbook itself is not legally binding, it provides a clear indication of the regulator’s compliance expectations. It reinforces that automobiles and electric vehicles remain controlled labeling products under consumer protection law and that incomplete, inaccurate, or misleading information may expose businesses to regulatory enforcement.

The guidance also illustrates that compliance extends beyond physical labels. Regulators are increasingly likely to examine whether information presented across all customer-facing channels remains accurate and consistent.

Businesses should therefore review:

  • labels displayed at dealerships and points of sale;
  • information published on corporate websites and online marketplaces;
  • brochures and sales presentations used by sales personnel;
  • representations concerning driving range and the testing methodology used, such as WLTP or NEDC;
  • battery capacity, expected degradation, warranty scope, and warranty exclusions;
  • disclosures relating to collision history, flood damage, major repairs, and battery replacement for used vehicles; and
  • consistency between information published by manufacturers, importers, dealers, and affiliated sales channels.

Claims relating to vehicle performance, battery longevity, operating costs, sustainability, resale value, or environmental benefits should be supported by appropriate technical evidence and internal documentation before publication.

Litigation Readiness and Document Preservation:

These developments also highlight the importance of litigation preparedness.

Businesses should consider establishing a centralized process for collecting and analyzing customer complaints to determine whether recurring issues indicate broader product or service risks.

At the same time, organizations should preserve relevant evidence, including:

  • sales documentation;
  • warranty records;
  • repair histories;
  • technical diagnostic reports;
  • replacement part records;
  • communications with customers;
  • call center recordings;
  • email correspondence;
  • mobile application records; and
  • connected vehicle diagnostic data.

Where disputes may reasonably be anticipated, organizations should consider implementing litigation hold procedures to reduce the risk of inadvertent deletion of potentially relevant evidence.

Companies should also review contractual risk allocation among overseas manufacturers, importers, dealers, distributors, and service centers, including indemnity provisions and responsibilities for handling product defects, recalls, warranty claims, and consumer litigation.

Data Protection Considerations:

Responding to consumer complaints frequently requires the collection and sharing of customer information, vehicle service histories, location information, and connected vehicle diagnostic data. Much of this information may constitute personal data under the Personal Data Protection Act.

Organizations should ensure that internal investigations and litigation response procedures incorporate appropriate data governance measures, including clearly defined access controls, documented processing purposes, retention periods, and secure mechanisms for sharing information with external counsel, technical experts, and other authorized parties.

Integrating consumer protection compliance with data governance can reduce both regulatory and litigation risks while supporting more effective dispute management.

Key Takeaways:

  • Organizations should strengthen complaint management, evidence preservation, document retention, contractual risk allocation, and data governance processes to prepare for increased regulatory scrutiny and potential consumer litigation.
  • The OCPB’s indication that it is prepared to commence litigation on behalf of consumers represents a significant escalation in consumer protection enforcement affecting the EV industry.
  • Businesses should not view repeated consumer complaints as isolated customer service matters but as potential regulatory and litigation risks requiring centralized oversight.
  • The newly published vehicle labeling handbook, although not legally binding, demonstrates higher regulatory expectations regarding the accuracy, completeness, and consistency of vehicle-related information across all sales channels.
  • Automotive businesses should review advertising claims, warranty disclosures, battery-related representations, and used vehicle disclosures to ensure they are fully substantiated.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

TCCT Establishes Two Subcommittees to Strengthen Trade Competition Oversight

The Trade Competition Commission of Thailand (“TCCT”) has appointed two subcommittees to oversee digital platform businesses and to establish competition rules for modern wholesale and retail businesses (“Modern Trade”). The move is intended to curb unfair trade practices and strengthen law enforcement in step with rapidly evolving trade dynamics.

1. Subcommittee on Considering Guidelines for the Oversight and Deterrence of Trade Practices in Digital Platform Businesses

This subcommittee’s primary mandate is to study, analyze, and collect data on the business models, commercial conditions, and trade practices of digital platform businesses, and to assess their impact on trade competition, business operators, consumers, and other stakeholders. It will drive more intensive regulatory measures for digital platform businesses and prepare proposals, guidelines, codes of conduct, criteria, announcements, regulations, and policy recommendations for the TCCT’s consideration.

The subcommittee will also coordinate with government agencies, the private sector, business operators, and other relevant stakeholders across all sectors to oversee and deter trade practices that may affect competition in digital platform businesses, and to promote free and fair competition more broadly.

2. Subcommittee on Determining Guidelines and Action Plans Regarding Competitive Conditions in Modern Wholesale and Retail Businesses

This subcommittee is tasked with studying, analyzing, and monitoring the market structure of modern wholesale and retail businesses; building a database to analyze retail market concentration and its impact on small-scale operators; and recommending guidelines and measures for overseeing competition in the retail sector.

Objectives of the Subcommittees

The subcommittees will study trade practices in digital platforms and in the modern wholesale-retail market to keep pace with shifting business dynamics and to investigate practices with anti-competitive effects. Each subcommittee will determine oversight guidelines and accelerate the promotion of fair trade so all parties can compete on equal terms.

The subcommittees will integrate efforts across relevant agencies, apply existing law to address exploitation or competitive pressure affecting the majority of business operators nationwide, and enforce compliance with guidelines the TCCT has already issued — notably the TCCT Notification on Guidelines for Considering Unfair Trade Practices and Acts that Monopolize, Reduce, or Restrict Competition in Multi-Sided Platform Business Operations for Digital Platform Services of Goods or Services (E-Commerce), in effect since March 25, 2026. They will also continue overseeing platform service businesses and Modern Trade going forward.

Background

Rapidly shifting competitive conditions and an influx of foreign capital have affected domestic operators, particularly SMEs and small-scale retailers. This has driven a sharp rise in complaints to the TCCT concerning online trading practices and the expansion of retail formats into community areas.

A particular concern is the continued increase in Gross Profit (GP) fees — the revenue-share or fee percentages that merchants pay to platforms. Higher GP rates compress net margins for SMEs, which may in turn force price increases that are ultimately passed on to consumers.

According to TCCT data:

  • E-commerce platforms and Modern Trade are currently among the leading competition concerns for small-scale operators at the grassroots of the Thai economy. In the first six months of this year alone, 21 platform-related complaints were filed, involving transactions collectively worth hundreds of billions of baht.
  • During fiscal year 2025 (October 1, 2024 – September 30, 2025), the TCCT received 78 complaints in total. Of these, 40 were not accepted for consideration, 9 were settled, and the remaining 29 are under investigation — most involving platforms, franchises, logistics and transport, digital platforms, and general commerce.

Through its Mobile Competition Clinic project, the TCCT has previously conducted on-site visits in several provinces to hear directly from business operators. Findings included:

Krabi Province:

  1. Online platform issues, including being forced to use specific transport providers and reduced product visibility due to algorithmic ranking.
  2. Online Travel Agency (OTA) platform issues, including price-parity clauses that prohibit hotels from listing lower rates on their own websites than on OTAs.
  3. Unfair trade practices between SMEs and Modern Trade operators, including redundant fee charges and additional GP fees imposed without prior notice.
  4. Palm oil pricing structure issues affecting local farmers.

Chiang Mai and Lamphun Provinces:

  1. Online platform issues, including algorithmic ranking practices that favor a platform’s own affiliated transport services.
  2. Unfair trade practices between SMEs and Modern Trade operators, including credit-term disputes, GP fee collection, and unfair contract terms.
  3. Pricing issues in agricultural product procurement.

Current Priorities and Enforcement Timeline

The TCCT is accelerating proactive oversight across four key business groups: (1) digital platforms, (2) wholesale and Modern Trade, (3) ride-hailing platform services, and (4) online travel booking platforms (OTAs). The newly formed subcommittees will study, analyze, and propose oversight guidelines, and investigate practices affecting competition across all four groups, with findings due by the fourth quarter of 2026. This will include updated operational guidelines designed to keep pace with evolving trade practices.

This initiative marks a deliberate shift in the TCCT’s enforcement approach — from a largely reactive, complaint-driven model to proactive market inspections that do not wait for formal complaints. On-site visits to gather in-depth input from business operators will remain central to this approach, with the TCCT aiming to demonstrate tangible results within the next six months.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

NBTC Issues AI Governance Guidelines for Telecom Licensees

Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has issued new guidelines setting out its expectations for the responsible use of artificial intelligence (AI) by telecommunications licensees. Although the guidelines are not legally binding, they establish a comprehensive risk-based framework for AI governance and provide a clear indication of the regulatory standards that the NBTC expects telecom operators to adopt when deploying AI in the provision of telecommunications services.

The guidelines reflect the increasing regulatory focus on AI governance and complement existing legal obligations relating to cybersecurity, personal data protection, and telecommunications. They also align with broader national efforts to develop a comprehensive AI regulatory framework.

Scope of the Guidelines:

The guidelines apply to holders of telecommunications business licenses under Thailand’s telecommunications licensing regime, but only in relation to AI systems used to provide licensed telecommunications services.

Organizations that are not telecommunications licensees are not directly subject to the guidelines. Nevertheless, AI developers, technology vendors, cloud service providers, and outsourced service providers may be indirectly affected because telecommunications licensees are expected to exercise oversight over third-party AI solutions used in their operations. As a result, contractual obligations and vendor due diligence are likely to become increasingly important for suppliers serving the telecommunications sector.

The guidelines should be considered alongside existing legal requirements, including the Personal Data Protection Act, the Cybersecurity Act, the Computer Crime Act, and the NBTC Notification on the Protection of Telecommunications Service Users’ Rights in relation to personal data, privacy, and the freedom of telecommunications. They also complement the broader AI legislation currently under development by the Electronic Transactions Development Agency (ETDA).

Strengthening AI Governance:

A central feature of the guidelines is the expectation that AI governance should extend beyond technical implementation and become an organizational responsibility.

Telecommunications licensees are encouraged to establish governance structures at both the policy and operational levels, such as AI committees, working groups, or designated responsible officers. These governance bodies should oversee AI strategy, establish internal policies, supervise risk management, and define accountability throughout the AI lifecycle.

The guidelines also emphasize that responsibilities should be clearly assigned not only to internal personnel but also to third-party AI solution providers and outsourced service providers. Licensees are expected to ensure that contractual arrangements clearly define each party’s obligations regarding AI governance, risk management, and regulatory compliance.

A Principles-Based Approach to Responsible AI:

Rather than prescribing detailed technical requirements, the guidelines adopt a principles-based approach centered on six core expectations.

First, AI systems should comply with applicable laws, ethical principles, and internationally recognized standards. AI should respect privacy, human dignity, and fundamental rights, and organizations should consider implementing appropriate safeguards, including content filtering, to reduce the risk of generating harmful or unlawful outputs.

Second, AI systems should operate fairly. This includes using representative and reliable training data, assessing potential bias, and taking appropriate measures to mitigate discriminatory outcomes.

Third, cybersecurity and privacy protections should be integrated into AI systems. The guidelines encourage the adoption of internationally recognized security standards and recommend technical safeguards such as encryption, anonymization, and access controls to protect personal data and system integrity.

Fourth, organizations should promote transparency by maintaining documentation regarding AI design, development, and operation, while providing consumers with appropriate information about how AI systems influence decisions or recommendations.

Fifth, accountability should be clearly established throughout the organization. Internal policies should define responsibility for AI outcomes, while consumers should have accessible channels to submit inquiries or complaints regarding AI-enabled services.

Finally, AI systems should be reliable and robust. The guidelines recommend testing AI models to ensure that they produce accurate and consistent results, including under unexpected operating conditions.

Governance Throughout the AI Lifecycle:

The guidelines emphasize that AI governance should be integrated throughout the entire AI lifecycle rather than focusing solely on deployment.

Licensees are expected to conduct risk assessments before development begins, evaluate the capabilities and reliability of third-party AI providers, and maintain appropriate standards for data quality and traceability. Before deployment, AI systems should undergo testing for reliability, fairness, and operational performance.

Once AI systems are operational, organizations should continuously monitor performance, maintain appropriate human oversight, and periodically evaluate whether AI systems continue to operate as intended. The guidelines also address the retirement of AI systems, encouraging secure decommissioning processes that protect data and maintain appropriate records throughout the system’s lifecycle.

This lifecycle-based approach reflects the growing international trend toward continuous AI governance rather than one-time compliance assessments.

Consumer Transparency and Organizational Readiness:

Consumer protection is another significant feature of the guidelines.

Telecommunications licensees are encouraged to notify consumers when they are interacting with AI systems, such as chatbots or voicebots. Where AI-generated recommendations may influence consumer decisions, organizations should provide appropriate disclosures and allow consumers to request assistance from a human representative where appropriate. Effective feedback and complaint mechanisms should also be maintained.

Internally, the guidelines recognize that responsible AI governance requires organization-wide awareness. Licensees are therefore encouraged to provide AI-related training across all levels of the organization. Employees who use AI systems should understand the associated legal and operational risks, while technical personnel and external developers should receive training on organizational AI policies, ethical principles, and applicable regulatory requirements.

Practical Implications:

Although the guidelines do not create new legal obligations, they provide valuable insight into the NBTC’s regulatory expectations and are likely to influence future regulatory supervision and industry best practices.

Telecommunications licensees should consider reviewing their existing AI governance frameworks to determine whether governance responsibilities are clearly assigned and appropriately documented. Organizations should also evaluate AI risk management procedures, update contracts with AI vendors and outsourced service providers, assess consumer disclosure mechanisms, and ensure that staff receive appropriate AI governance training.

The guidelines may also have implications for corporate transactions involving telecommunications businesses. As AI becomes increasingly integrated into telecommunications operations, AI governance maturity, data governance practices, and vendor oversight may become important considerations during legal and regulatory due diligence.

Key Takeaways:

  • Telecommunications licensees should review their governance frameworks, contractual arrangements, AI risk management processes, consumer disclosure practices, and staff training programs to align with the NBTC’s expectations.
  • The NBTC’s AI guidelines establish a comprehensive risk-based governance framework for telecommunications licensees and provide a clear indication of the regulator’s expectations for responsible AI deployment.
  • Although nonbinding, the guidelines are likely to influence regulatory supervision and industry best practices within Thailand’s telecommunications sector.
  • AI governance is expected to extend throughout the entire AI lifecycle, encompassing organizational governance, risk management, vendor oversight, cybersecurity, consumer protection, and ongoing monitoring.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Revises Visa Exemption Scheme: Shorter Stay Periods and a New Country-Based Category System

Introduction

On 14 July 2026, the Thai Cabinet approved a revision of Thailand’s visa exemption scheme. Under the revised framework, the current uniform 60-day visa exemption will be abolished and replaced with a country-based system that classifies eligible countries according to Thailand’s diplomatic relations and immigration risk assessment. Depending on the category assigned, eligible foreign nationals will be permitted to enter Thailand visa-free for stays of up to 30 or 15 days, or will remain eligible for a Visa on Arrival.

Background

In 2024, Thailand introduced a 60-day visa exemption for nationals of 93 countries and territories to stimulate tourism and support the country’s economic recovery following the COVID-19 pandemic. Since implementation, however, the government has identified several concerns associated with the scheme, including visa runs, illegal employment, nominee business arrangements, transnational crime, and visa overstays. In response, the government resolved to review and revise the existing visa exemption policy.

Key Changes

1. Introduction of a Tiered Visa Exemption Framework

30-Day Visa Exemption (59 Countries and Territories)

Nationals of 59 countries and territories will be eligible for visa-free entry for tourism purposes for stays of up to 30 days. The revised scheme extends this 30-day entitlement to six countries that were not previously covered:

  • India
  • Croatia
  • Bulgaria
  • Cyprus
  • Malta
  • Maldives

With these additions, all 27 European Union Member States will receive the same 30-day visa exemption entitlement, promoting greater consistency across Thailand’s visa policy. The government expects this measure to strengthen diplomatic relations, support future discussions on Schengen visa exemptions for Thai nationals, and facilitate continued economic and trade cooperation with partner countries.

15-Day Visa Exemption (2 Countries)                                                                                                                                                                            

Nationals of Mauritius and Seychelles will be eligible for visa-free entry for stays of up to 15 days. The government intends to periodically review this entitlement based on tourism statistics and visitor spending patterns.

Visa on Arrival (3 Countries)

Nationals of the following three countries will remain eligible to obtain a Visa on Arrival at Thailand’s immigration checkpoints:

  • Azerbaijan
  • Belarus
  • Serbia

2. Implementation of the “One Country, One Entitlement” Policy

Under the revised framework, each country will be eligible for only one immigration privilege, and overlapping schemes will be eliminated. For example, India will no longer be eligible for a Visa on Arrival, as it has instead been granted 30-day visa exemption status.

3. Enhanced Border Screening

The government will strengthen the Thailand Digital Arrival Card (TDAC) system by integrating it with relevant government databases, improving immigration risk assessment, border screening, and monitoring of visa exemption usage.

The Cabinet resolution provides for a revised visa framework covering a reported total of 65 countries and territories across the categories described above. The complete list of eligible countries and territories in each category has not yet been officially published; further detail is expected in forthcoming Ministry of Interior notifications and related subordinate legislation.

Effective Date

The revised measures have not yet entered into force. They will take effect 15 days after the relevant Ministry of Interior notifications are published in the Royal Gazette. Until that time, the existing immigration rules remain in effect, and foreign nationals who enter Thailand before the change takes effect will be permitted to remain for the duration of their existing permitted stay.

Key Takeaways

  • The revised measures are pending implementation and will take effect 15 days after publication in the Royal Gazette.
  • Thailand will replace its uniform 60-day visa exemption scheme with a tiered, country-based system.
  • The revised scheme aims to balance tourism promotion and ease of international travel against the prevention of visa abuse and the strengthening of immigration control and national security.
  • Eligible countries will receive 30-day or 15-day visa-free entry, while three countries retain Visa on Arrival status; overlapping privileges are removed under the “one country, one entitlement” policy.
  • The TDAC system will be enhanced to strengthen immigration screening and monitoring.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Responds to U.S. Section 301 Review: Trade Negotiations, Regulatory Reforms and Business Implications

The United States has conducted a trade investigation under Section 301 of the Trade Act of 1974 into approximately 60 trading partners, including Thailand, concerning whether goods produced using forced labour are entering the U.S. market. Following its preliminary determination in June 2026, the United States proposed imposing an additional 12.5% tariff on certain imports from Thailand and invited affected trading partners to submit comments on the proposed tariff rate, product coverage and potential tariff exemptions. Thailand submitted its written response by the 6 July 2026 deadline.

Following a public consultation process, the United States issued its final determination on 23 July 2026, confirming a 12.5% Section 301 tariff on imports from Thailand that are not otherwise exempt. The measures took effect on 24 July 2026.

Prior to the final determination, Thailand’s negotiating team, led by Minister of Commerce Ms. Suphajee Suthumpun, travelled to the United States from 15 to 17 July 2026 to continue discussions with U.S. officials regarding the proposed tariff rate, revisions to the tariff list, product-specific exemptions, and U.S. concerns relating to labour standards, agricultural exports and sanitary and phytosanitary (SPS) measures.*

Key Issues Under the U.S. Review

The U.S. investigation focused on two principal concerns:

  • Forced labour – whether Thailand has an adequate legal and regulatory framework to prevent the use of forced labour throughout its supply chains; and
  • Trade circumvention – whether goods originating in China are being routed through, or undergo only minimal processing in, Thailand before being exported to the United States.

Thailand has rejected these allegations, maintaining that the products under review are genuinely manufactured in Thailand and contain between 70% and 90% local content, with no product containing less than 60% Thai content. At the same time, the Government has sought to address U.S. concerns through both ongoing negotiations and proposed domestic regulatory reforms.

The products reportedly under review are primarily drawn from the following sectors:

  • machinery;
  • automotive products; and
  • rubber products.

Proposed Tariff Exemptions

As part of the review, the United States proposed tariff exemptions covering 1,655 products across four categories:*

  • agricultural and food products;
  • electronics;
  • energy and mineral products; and
  • aircraft parts.

Thai exports expected to benefit include cassava products, natural rubber, hard disk drives, smartphones, integrated circuits, processed pineapple, coconut products, durian, other tropical fruits and aircraft components.

For textile products, the United States also proposed a quota-based mechanism under which reduced tariff rates would be linked to the volume of textile raw materials imported from the United States.

Thailand’s Negotiating Position

Thailand sought to reduce the proposed tariff rate from 12.5% to 10%, bringing it into line with the rate applied to certain neighboring countries that had committed to implementing stronger forced labor import prohibitions.

As part of the proposed Agreement on Reciprocal Trade (ART), Thailand also emphasized that more than 30% of its trade surplus with the United States is generated by U.S. companies operating manufacturing facilities in Thailand and exporting their products back to the U.S. market. Thailand further requested additional tariff exemptions, including for Thai jasmine rice, while explaining that higher tariffs on certain Thai exports could increase costs for U.S. consumers where comparable products cannot readily be produced domestically or sourced from alternative suppliers.

The Government also reaffirmed several key negotiating positions, including:

  • maintaining Thailand’s existing beta-agonist standards for meat products; and
  • preserving Thailand’s ability to maintain trade relations with all countries, including China, without accepting conditions that could undermine Thailand’s economic sovereignty.

Regulatory and Policy Developments

In parallel with the negotiations, Thailand is advancing a proposed Human Rights Due Diligence (HRDD) framework under the proposed Act on Support Business Operation with Responsibility.

If enacted, the legislation is expected to require businesses to identify, assess and manage human rights risks throughout their operations and supply chains. Depending on the final form of the legislation, businesses may also be required to implement appropriate governance measures, maintain records demonstrating compliance and strengthen supply chain traceability.

Thailand is also developing clearer procedures to verify that exported goods are manufactured without the use of forced labor. Collectively, these initiatives are intended to strengthen confidence in Thai exports, enhance supply chain transparency and align Thailand’s regulatory framework more closely with internationally recognized human rights and labor standards.

Key Takeaways

  • Businesses with operations or supply chains connected to Thailand should review their supply chain governance frameworks, strengthen traceability measures and monitor further developments in Thailand’s proposed HRDD legislation.
  • The United States has completed its Section 301 investigation into approximately 60 trading partners, including Thailand, concerning forced labor and supply chain enforcement.
  • Thailand submitted its written comments by the 6 July 2026 deadline. The United States issued its final determination on 23 July 2026, imposing a 12.5% tariff on most Thai imports that are not otherwise exempt.
  • During the consultation process, Thailand sought to reduce the proposed tariff rate to 10% and requested additional product-specific exemptions, including for Thai jasmine rice.
  • The U.S. investigation has accelerated Thailand’s efforts to strengthen its human rights due diligence framework and supply chain governance.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Managing Regulatory Due Diligence for Cross-Border Investors in Financial and Digital Asset Businesses

Introduction:

Cross-border investments in financial services and digital asset businesses present unique regulatory challenges that extend well beyond traditional legal or financial due diligence. Whether an investor is acquiring a licensed payment service provider, a securities business, a digital asset exchange, or a fintech company operating under sector-specific regulation, the value of the transaction can depend as much on the target’s regulatory standing as on its commercial performance.

Unlike ordinary commercial businesses, regulated entities operate under continuing supervision. Their ability to conduct business depends not only on maintaining the necessary licenses but also on demonstrating ongoing compliance with governance requirements, prudential standards, anti-money laundering obligations, cybersecurity controls, and consumer protection rules. A company with strong financial performance may nevertheless represent a significant acquisition risk if its regulatory compliance has deteriorated or if it is subject to undisclosed supervisory concerns.

For cross-border investors unfamiliar with the Thai regulatory landscape, regulatory due diligence is therefore not merely a legal exercise. It is an essential component of transaction risk assessment and should begin early in the acquisition process.

Looking Beyond the License:

One of the most common misconceptions among foreign investors is that verifying the existence of a regulatory license is sufficient. In reality, the existence of a license represents only the starting point of the analysis.

Many regulated businesses have evolved over time, expanding their products and services beyond the scope originally contemplated when their licenses were granted. A fintech company may initially have operated as an electronic payment platform before introducing digital lending, cross-border remittance services, or digital asset-related products. Each new business activity may require separate regulatory approval or may be subject to different supervisory requirements.

Regulatory due diligence should therefore examine whether every revenue-generating activity falls within the scope of the target’s existing licenses and whether any exemptions relied upon remain available. It is equally important to determine whether any license conditions have been imposed by regulators and whether the company has complied with those conditions throughout its operations.

Regulatory Approval May Determine Whether the Transaction Can Close:

Unlike acquisitions involving ordinary commercial companies, transactions involving regulated financial businesses frequently require regulatory approval before completion. In some sectors, a change in significant shareholding or control may not become legally effective until the relevant regulator has approved the transaction. Other regulatory regimes may require post-closing notifications or impose “fit and proper” assessments on incoming shareholders, directors, or senior management.

Consequently, regulatory due diligence should identify not only the approvals required for the target’s day-to-day operations but also those triggered by the proposed acquisition itself. Failure to identify these requirements early can delay completion, affect financing arrangements, or require restructuring of the transaction.

Cross-border investors should also consider whether foreign ownership restrictions, residency requirements, or limitations on board composition may influence the post-closing governance structure.

Compliance Culture Often Matters More Than Written Policies:

Modern financial regulators increasingly assess how compliance operates in practice rather than whether a company simply maintains a complete set of written policies.

Accordingly, regulatory due diligence should extend beyond reviewing compliance manuals and internal procedures. Investors should seek evidence that compliance functions are adequately resourced, that internal reporting mechanisms operate effectively, and that senior management actively oversees regulatory risk.

The company’s interactions with regulators may provide particularly valuable insight. Inspection reports, supervisory correspondence, warning letters, remediation plans, and historical enforcement actions often reveal recurring compliance weaknesses that are not apparent from corporate documentation alone. Even where no formal penalties have been imposed, repeated supervisory findings may indicate weaknesses in governance or internal controls that require significant remediation after closing.

Technology Risk Has Become a Core Regulatory Issue:

Technology is now central to regulatory supervision of financial institutions and digital asset businesses. Cybersecurity failures, operational disruptions, and weaknesses in technology governance increasingly attract regulatory attention regardless of whether they result in customer losses.

For investors, this means regulatory due diligence should include an assessment of cybersecurity governance, incident response procedures, disaster recovery planning, outsourcing arrangements, cloud service management, and operational resilience frameworks. Businesses operating digital asset platforms should also be assessed for wallet security, custody arrangements, transaction monitoring systems, and market surveillance capabilities.

Technology deficiencies may not immediately affect valuation but can require substantial investment after completion to satisfy regulatory expectations.

AML and Financial Crime Controls Remain High-Risk Areas:

Anti-money laundering and counter-terrorism financing compliance continues to be among the highest enforcement priorities for financial regulators. Deficiencies in customer due diligence, transaction monitoring, sanctions screening, or suspicious transaction reporting can expose regulated businesses to substantial regulatory sanctions and reputational damage.

Investors should therefore evaluate not only the target’s written AML policies but also the effectiveness of their implementation. Questions such as how high-risk customers are identified, how beneficial ownership is verified, and how suspicious transactions are escalated can provide a clearer picture of the target’s compliance maturity than policy documents alone.

Where previous regulatory inspections have identified AML deficiencies, investors should assess whether remediation has been completed and whether regulators remain satisfied with the company’s corrective measures.

Data Protection and Outsourcing Should Not Be Overlooked:

Financial institutions increasingly rely on external service providers for cloud infrastructure, customer verification, payment processing, and cybersecurity services. While outsourcing may improve operational efficiency, regulators continue to emphasize that responsibility for regulatory compliance ultimately remains with the licensed entity.

Accordingly, regulatory due diligence should review the contractual framework governing outsourced services, the company’s oversight of critical vendors, and its contingency planning should key service providers become unavailable.

Similarly, businesses handling significant volumes of customer information should be assessed for compliance with personal data protection requirements, particularly where customer information is transferred across borders or processed by third-party vendors.

Due Diligence Findings Should Shape Transaction Documents:

Regulatory due diligence should not end with the preparation of a report. Its findings should directly influence transaction structuring and the allocation of risk between buyer and seller.

Where significant compliance concerns are identified, investors may seek enhanced representations and warranties regarding licensing, regulatory compliance, anti-money laundering controls, cybersecurity, and data protection. Specific indemnities may be appropriate for known regulatory investigations or historical compliance failures. In some cases, buyers may also require identified deficiencies to be remediated as conditions precedent before closing.

Integrating regulatory due diligence into transaction documentation helps ensure that regulatory risks are appropriately allocated and reduces the likelihood of post-completion disputes.

Conclusion:

As financial regulation becomes increasingly complex and technology-driven, regulatory due diligence has evolved from a narrow licensing review into a comprehensive assessment of an institution’s regulatory health. For cross-border investors, understanding how a target interacts with regulators, manages compliance risks, and maintains operational resilience is often as important as evaluating its financial performance.

A well-executed regulatory due diligence exercise enables investors to identify hidden regulatory exposures, anticipate approval requirements, negotiate more effective contractual protections, and develop realistic post-acquisition integration plans. In regulated financial and digital asset sectors, it is often the quality of regulatory compliance—not simply the quality of the business—that ultimately determines whether an investment achieves its intended value.

Key Takeaways:

  • In acquisitions involving financial and digital asset businesses, robust regulatory due diligence is essential to preserving investment value and minimizing post-closing regulatory exposure.
  • Regulatory due diligence should evaluate the target’s overall regulatory health rather than simply confirming the existence of licenses.
  • Investors should assess governance, supervisory history, AML/CTF controls, cybersecurity, data protection, outsourcing arrangements, and change-of-control requirements alongside licensing compliance.
  • Early identification of regulatory risks helps facilitate transaction planning, regulatory approvals, and appropriate contractual risk allocation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

BOT: Bank of Thailand Introduces Stricter Rules on Large Cash Transactions to Combat Illicit Flows

The Bank of Thailand (BOT) is set to implement enhanced oversight on significant cash movements as part of efforts to address gray-area financial activities, reduce risks of money laundering, and promote greater transparency in the financial system.

Under the upcoming regulations, financial institutions will soon be required to perform detailed customer due diligence for any cash withdrawal exceeding 5 million baht in a single transaction. Customers must clearly explain the source of the funds and the intended purpose of the cash. If the explanation is unsatisfactory or unverifiable, banks may restrict or decline to process the transaction.

This measure primarily targets unusual or high-risk cash usage that could be linked to informal, unregulated, or illicit activities. In a later phase, similar requirements will apply to cash deposits of 5 million baht or more, where the origin of the funds must also be justified.

The BOT has indicated that legitimate needs—such as those of small and medium-sized enterprises (SMEs), individuals conducting regular business operations, or other verifiable purposes—will continue to be accommodated, provided appropriate documentation and explanations are provided. However, the rules aim to make large-scale cash handling more accountable and discourage reliance on physical currency for questionable purposes.

Looking ahead, after an initial implementation period and evaluation of impacts (including any effects on ordinary users), the threshold may be lowered to 3 million baht for both withdrawals and deposits to further strengthen controls.

These changes form part of broader initiatives to tackle structural economic vulnerabilities, encourage electronic payments where practical, and limit opportunities for crime or opaque transactions.

Impact on the Public:

Most everyday individuals and small businesses will remain largely unaffected, as transactions below the 5 million baht threshold face no new requirements, and legitimate large needs can proceed with proper justification.

People or entities accustomed to handling large cash amounts (e.g., for property deals, business purchases, or other high-value activities) will need to prepare explanations and supporting evidence in advance, potentially adding time and documentation steps at the bank.

Those involved in informal or gray-area dealings may find it significantly harder to move large sums in cash without scrutiny, increasing the risk of restrictions or reporting to authorities.

Overall, the shift promotes safer, more traceable financial habits while aiming to reduce crime risks associated with large cash volumes and ease burdens through related reviews of common banking fees.

Key Takeaways:

Implementation is expected in the near future (early to mid-March timeframe), giving the public time to adjust to more accountable cash handling practices.

Cash withdrawals over 5 million baht will require clear justification of purpose and source; unsatisfactory explanations may lead to restrictions.

The rules will later extend to large cash deposits and could lower the threshold to 3 million baht after review.

Legitimate users (e.g., SMEs and individuals with valid reasons) can continue transactions by providing details—no outright ban is intended.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Moves to Expand Access to Altruistic Surrogacy Following Marriage Equality

Thailand is considering significant amendments to its legal framework governing surrogacy, with proposed reforms intended to broaden access to assisted reproductive technology while maintaining the country’s longstanding prohibition on commercial surrogacy.

The Ministry of Public Health and relevant government agencies are currently developing amendments to the Protection for Children Born through Assisted Reproductive Technologies Act B.E. 2558 (2015). The proposed changes follow the implementation of Thailand’s marriage equality legislation, which exposed inconsistencies between the country’s family law and the existing surrogacy regime.

The draft legislation has not yet been enacted. It remains subject to public consultation and further legislative consideration.

Why Reform Is Being Considered: 

The current surrogacy law was enacted before Thailand recognized same-sex marriage. As a result, several provisions governing intended parents continue to refer to a “husband” and “wife,” effectively limiting access to opposite-sex married couples.

Following the entry into force of the Marriage Equality Act, the government has acknowledged the need to align the assisted reproduction framework with the broader legal recognition of marriage regardless of gender. The proposed amendments are therefore intended to modernize the legislation by adopting gender-neutral terminology and expanding eligibility for lawful surrogacy arrangements.

Key Proposed Amendments:

Although the draft bill may continue to evolve during the legislative process, the principal proposals under discussion include:

  • extending eligibility for altruistic surrogacy to legally married same-sex couples;
  • replacing gender-specific references in the existing legislation with gender-neutral terminology consistent with the Marriage Equality Act; and
  • expanding eligibility for certain foreign married couples, subject to statutory conditions and safeguards that are still under consideration.
  • The final scope of these amendments, including any nationality, residency, or other qualifying requirements applicable to foreign couples, has not yet been finalized.

Current Legal Position:

Until the proposed amendments become law, the existing statutory framework remains fully effective.

The current legislation permits only altruistic surrogacy, under which a surrogate mother cannot receive financial compensation beyond expenses permitted by law. Commercial surrogacy remains strictly prohibited and is subject to criminal penalties.

The Act also imposes detailed eligibility requirements for intended parents and surrogate mothers, together with regulatory oversight designed to safeguard the interests of both surrogate mothers and children born through assisted reproductive technologies.

Practical Implications

If enacted, the amendments would represent the most significant reform of Thailand’s surrogacy regime since the legislation first came into force.

For married same-sex couples, the reforms would remove one of the remaining legal inconsistencies following the recognition of marriage equality by allowing access to lawful surrogacy under the same regulatory framework applicable to other eligible married couples.

The proposed extension to certain foreign married couples may also make Thailand’s regulatory framework more accessible in cross-border family-building cases. However, there is no indication that the government intends to relax its prohibition on commercial surrogacy or weaken existing safeguards designed to prevent exploitation and reproductive tourism. Any expansion of eligibility is expected to remain subject to stringent statutory controls.

Legislative Outlook:

The proposed amendments remain at the policy development and legislative drafting stage. Accordingly, prospective intended parents, fertility clinics, healthcare providers, and legal practitioners should continue to comply with the existing legal framework until any amendments are formally enacted and accompanying regulations are issued.

Key Takeaways:

  • Businesses and professionals involved in fertility services should monitor the progress of the legislation, as the final provisions may differ from the current draft.
  • Thailand is preparing amendments to its surrogacy legislation following the implementation of marriage equality.
  • The proposed reforms would allow legally married same-sex couples to access altruistic surrogacy under the statutory framework.
  • The draft bill also contemplates expanding eligibility for certain foreign married couples, although the applicable conditions have not yet been finalized.
  • The amendments remain under legislative consideration and have not yet entered into force.
  • The existing legal framework continues to apply, including the prohibition on commercial surrogacy.

Author: Panisa Suwanmatajarn, Motana Sumetsawat, Tanadol Rungruengnoravet, and Pannaphat Suwantharakorn

Other Articles