ETDA: Proposed Overhaul of Thailand’s Electronic Transactions Act – Modernizing for the Digital Economy
Thailand’s existing Electronic Transactions Act B.E. 2544 (2001, as amended) has served as the foundational legal framework for electronic transactions for over two decades. Enacted in an earlier era of digital adoption, it primarily addressed basic electronic signatures, data messages, and recognition of electronic records. However, it increasingly struggles to accommodate rapid technological advancements, including automated contracting systems, electronic transferable instruments (such as e-bills of lading), cloud-based data storage, digital identity solutions, and complex cross-border digital platforms.
Limitations in the current law—such as uncertainty around the reliability and evidentiary weight of electronic data, rigid requirements that do not flexibly support emerging technologies without additional regulations, and enforcement gaps—hinder full digital transformation. This creates friction for businesses adopting paperless processes, e-commerce, fintech, logistics, and other innovative models central to Thailand 4.0 and the broader digital economy.
Many jurisdictions have proactively updated their frameworks to address these challenges. The United Nations Commission on International Trade Law (UNCITRAL) Model Laws on Electronic Commerce, Electronic Signatures, and Electronic Transferable Records have influenced reforms worldwide. Countries like Singapore, the EU (with eIDAS and related directives), and others have introduced technology-neutral rules, enhanced trust services, liability frameworks for service providers, and specific provisions for electronic equivalents of negotiable instruments. These updates boost legal certainty, reduce compliance burdens, facilitate international trade, and stimulate innovation while maintaining consumer and business protections.
Key Changes in the Draft Act and UNCITRAL Alignment:
The Electronic Transactions Development Agency (ETDA) has proposed a comprehensive Draft Electronic Transactions Act for public hearing (comments due by June 15, 2026). The draft represents a substantial rewrite rather than a simple amendment. It shifts Thailand toward a more technology-neutral, principles-based, and trust-oriented framework, building on the original law’s foundations while incorporating newer UNCITRAL instruments.
Major Changes from the Current Law:
Broader Legal Recognition of Electronic Data and Transactions: Electronic records that are accessible, reusable, and retain integrity will satisfy requirements for “writing,” originals, retention, and evidence across civil, criminal, and procedural contexts. Electronic transactions become the default/preferred mode. This significantly expands functional equivalence beyond the 2001 Act’s more limited scope.
Electronic Signatures, Seals, Timestamps, and Notices: Reliable electronic methods (or ETDA-prescribed ones) fulfill signature, seal, timestamp, and registered mail requirements. Public announcements can shift to verified online platforms. New emphasis on electronic seals and reliable timestamps strengthens evidentiary value.
Reliable Methods, Certification, and Burden of Proof: Introduction of “reliable electronic methods” with ETDA recognition/certification. When approved systems are used, the burden and cost of disproving reliability shift to the challenger. This provides stronger legal certainty and incentivizes certified solutions.
Automated and Electronic Contracting: Explicit validation of contracts formed by automated systems (with or without human intervention), plus detailed rules on attribution, receipt acknowledgment, timing/place of dispatch, input error correction, and verification methods.
New Regime for Electronic Transferable Instruments: A dedicated framework for e-bills of lading, warehouse receipts, promissory notes, etc., including exclusive control (equivalent to possession), transfer, endorsement, amendment, integrity, and paper-electronic conversion. This is a major addition.
Regulation of Service Providers: Broader coverage of identity proofing, e-signatures, timestamping, data storage, and related services. Replaces rigid licensing with a voluntary certification (“trust mark”) scheme, risk management, cybersecurity, and complaint-handling obligations. Liability protections for compliant providers, with transitional recognition for existing licensees.
Strong UNCITRAL Alignment:
Builds on the original Act’s foundation in the Model Law on Electronic Commerce (1996) and Electronic Signatures (2001).
Incorporates the Electronic Communications Convention (ECC, 2005) — Thailand acceded in 2025 — for automated contracting and international rules.
Adopts principles from the Model Law on Electronic Transferable Records (MLETR, 2017) for e-transferable instruments.
Aligns with the Model Law on Electronic Identity and Trust Services (MLIT, 2022) through trust services, certification, and technology-neutral identity frameworks.
Supports overall technology neutrality and functional equivalence, enhancing interoperability under initiatives like the Framework Agreement on Cross-border Paperless Trade (CPTA).
Business Impacts and Preparation Steps:
The Draft Act would lower barriers to digital operations, reduce paper dependency, streamline contracting and record-keeping, and improve cross-border compatibility. Sectors like trade finance, logistics, e-commerce, fintech, cloud services, and digital identity providers stand to benefit significantly.
New compliance expectations include system reliability, risk management, cybersecurity, audits, and vendor due diligence. Businesses may need to update processes, contracts, policies, and user interfaces.
Businesses should prepare by:
Reviewing current electronic systems against emerging “reliable method” standards.
Assessing exposure as service providers or users.
Monitoring ETDA subordinate regulations, certifications, and guidance.
Updating contracts, terms, privacy notices, and record-retention policies.
Enhancing cyber security and complaint-handling mechanisms.
Current Status and Next Steps:
The Draft Act is currently in the public hearing phase (comments due by June 15, 2026). Following consultation, it will undergo refinement, Cabinet approval, parliamentary review, and publication in the Government Gazette.
Implementation is not immediate: The law would generally take effect 180 days after Gazette publication, with ETDA issuing subordinate rules, standards, and certification procedures (targeted within 180 days post-publication, though effective timelines may extend). Full industry adaptation and technical rollout could span months to years. Existing providers receive transitional support.
Key Takeaways:
The Draft Act modernizes Thailand’s electronic transactions framework through broader recognition, new instruments for digital trade, and a flexible certification model — strongly aligned with evolving UNCITRAL standards.
It addresses longstanding limitations while promoting trust, innovation, and paperless processes across private and public sectors.
Businesses should proactively assess impacts, strengthen systems, and participate in the ongoing public consultation.
Successful implementation will enhance Thailand’s digital economy competitiveness, though it requires coordinated regulatory and industry efforts over the coming years.
Cabinet Approves Four Draft Bills Modernizing Thailand’s Capital Market Legislation
Introduction
The Cabinet has approved four draft bills proposed by the Ministry of Finance (“MOF”) and reviewed by the Office of the Council of State (“OCS”), pursuant to the Cabinet resolution of 14 February 2023 (B.E. 2566). The bills amend:
the Securities and Exchange Act B.E. 2535 (1992) (“SEA”);
the Derivatives Act B.E. 2546 (2003) (“DA”);
the Trust for Transactions in Capital Market Act B.E. 2550 (2007) (“TTA”); and
the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018) (“DAB”).
The case for reform is that provisions across all four instruments have fallen out of step with current market conditions, do not adequately accommodate rapid technological change, are inconsistent with one another on matters of shared subject matter, and in places lack the clarity needed for consistent interpretation.
Together, the draft bills address six areas:
Promotion of the digital capital market;
Supervision of business operators;
Supervision of the secondary market and related organizations;
Fundraising and the supervision of audit firms and capital market service providers;
Enforcement and penalties; and
The supervisory structure.
Two bodies are principally involved in the reforms: the Securities and Exchange Commission (“SEC”), which has the power and duty to set policy for the promotion and development of the Thai capital market, and the Office of the Securities and Exchange Commission (“SEC Office”), which implements that policy on the SEC’s behalf. The amendments under each of the four draft bills are summarized below.
1. The Draft Securities and Exchange Act (No. ..) B.E. .… (“Draft SEA”)
1.1 Capital market promotion
a. Preparing, sending, receiving, and storing information and documents, and advertising, disclosing, or distributing them, by electronic means will be expressly lawful. The SEA currently contains no such provision, although the practice is already well established.
b. A prospectus may be published through means other than printing, which is currently the only channel the SEA recognizes.
c. Where certificated securities are pledged as collateral, enforcement will be available through means outside the Thai Civil and Commercial Code. Where the instrument has a stated maturity and the debt has fallen due, the pledgee may collect on the due date without prior notice.
1.2 Supervision of securities companies
a. Major shareholder approval requirements move into the Draft SEA. A person holding, or benefiting from, shares carrying more than 10 percent of total voting rights must obtain SEC Office approval. This requirement currently sits in subordinate legislation.
b. The Minister of Finance may impose conditions requiring a securities company whose license has been revoked to take steps to protect investors’ interests.
c. Securities companies must prepare financial statements for both six-month and twelve-month periods, audited and opined on by an auditor, in the form the SEC Office prescribes. Under the current SEA, only six-month statements are required.
d. Supervision of auditors and audit firms, financial advisers, property valuers, credit rating agencies, offshore service providers, securities business personnel, and other service providers will be set out in the Draft SEA itself rather than in subordinate instruments, raising the standard applied to capital market personnel.
1.3 Trading venues and the secondary market
a. Securities trading centers are classified into two categories: licensed centers, open to general investors, and registered centers, open only to institutional investors, with the level of supervision depending on the degree of investor protection required.
b. Ownership of deposited securities is clarified. A depositor must maintain a list of the owners of securities deposited with the Stock Exchange of Thailand (SET), and a person named on that list is deemed the owner entitled to the securities of the class, type, and quantity recorded. The current SEA leaves the position of depositors’ clients unclear.
c. Associations connected with the securities business may invest their funds or income in debt instruments or other securities prescribed by the SEC, subject to SEC Office supervision, giving them an additional income channel.
1.4 Auditors, service providers, and critical systems
a. Financial reports must be audited by auditors and audit firms approved by the SEC Office, and capital market service providers must obtain SEC Office approval.
b. Significant system providers to the capital market become subject to supervision, including a requirement to hold sufficient funding to support their operations and associated risks.
c. Control over management and continuity is strengthened. Such a provider may appoint a director or manager, or contract out all or part of its management authority, only with SEC Office approval. The SEC may restrain conduct capable of causing serious damage to the public interest and may address the cessation of the provider’s business.
1.5 Enforcement and penalties
a. SEC Office officials will be able to conduct investigations alongside inquiry officials and special case inquiry officials in categories of offence that may seriously damage confidence in the capital market or affect the national economy.
b. Criminal penalties and administrative fines will be revised, with criminal liability retained only for serious offences or those contrary to good morals.
1.6 The supervisory structure
a. The Secretary-General of the Office of Insurance Commission joins the SEC as an ex officio member.
b. The Minister of Finance, the SEC, and the SEC Office each gain the power to reduce or waive fees for registration and capital market services.
c. The affairs of the SEC Office are placed outside social security legislation, aligning its position with that of other regulators such as the Bank of Thailand (BOT).
2. The Draft Derivatives Act (No. ..) B.E. .… (“Draft DA”)
2.1 Capital market promotion
a. See Section 1.1(a) above.
2.2 Supervision of securities companies
a. See Section 1.2(a) above.
b. The scope and characteristics of persons acting as investment consultants, investment analysts, investment planners, derivatives investment managers, or other functions notified by the Capital Market Supervisory Board (“CMSB”) will be prescribed. Such matters were previously prescribed in subordinate legislation.
c. Provisions will be introduced on the supervision of major shareholders, directors, and persons with management authority of a derivatives exchange. A person may hold shares in, or benefit from shares of, a derivatives exchange in excess of the threshold notified by the SEC only upon obtaining SEC Office approval, in accordance with criteria, conditions, and procedures notified by the SEC. Under the current DA, shareholding is capped at 5 percent.
2.3 Auditors, service providers, and critical systems
a. Derivatives business operators — other than derivatives advisors who are natural persons (a category not previously specified) — will be required to prepare accounts showing the results of their operations and their financial position as these actually stand, in accordance with professional accounting standards under the law on accounting professions and any additional requirements notified by the SEC.
b. Derivatives business operators will be required to prepare financial statements and submit them to the SEC Office, audited and opined on by a certified public accountant in accordance with criteria notified by the SEC and approved by the SEC Office.
2.4 Enforcement and penalties
a. See Section 1.5(a) above.
b. Administrative penalties will be prescribed for a derivatives exchange that contravenes or fails to comply with criteria, orders, or conditions prescribed by law.
2.5 The supervisory structure
a. Additional powers and duties are conferred on the SEC and the SEC Office to reduce or waive fees for applications for a license, registration, or approval; for the issuance of a license, acceptance of a registration, or grant of an approval; or for carrying on a licensed, registered, or approved business, in accordance with notified criteria and conditions.
3. The Draft Trust for Transactions in Capital Market Act (No. ..) B.E. .… (“Draft TTA”)
3.1 Capital market promotion
a. See Section 1.1(a) above.
3.2 Supervision of securities companies
a. Additional powers and duties are conferred on the SEC to reduce or waive fees for applications for permission, the granting of permission, or the carrying on of business under the Draft TTA, in accordance with notified criteria and conditions.
b. Regulations, rules, notifications, orders, or requirements issued under the Draft TTA by the CMSB and having general application will take effect upon publication in the Government Gazette, whereas the current TTA applies this requirement only to instruments issued by the SEC Board and the SEC Office.
4. The Draft Emergency Decree on Digital Asset Businesses (No. ..) B.E. …. (“Draft DAB”)
4.1 Capital market promotion
a. See Section 1.1(a) above.
4.2 Enforcement and penalties
a. See Section 1.5(a) above.
4.3 The supervisory structure
a. See Section 1.6(b) above.
Legal Basis and Objectives
The four draft bills are brought forward under Section 77 of the Constitution of the Kingdom of Thailand, which provides that the State should, without delay, revise laws that are no longer suited to prevailing circumstances or that obstruct the pursuit of an occupation, so that they do not burden the people.
Beyond this constitutional duty, the stated objectives are to accommodate the use of appropriate technology in capital market transactions, to create clarity in supervision, to improve enforcement in line with international regulatory standards, to remove duplicative processes, to advance State policy and capital market plans, and to raise the level of investor protection.
Consultation and Impact Assessment
The OCS and the SEC Office consulted state agencies, the private sector, and the public on all four draft bills, through both online submissions and focus group sessions. An impact analysis was prepared in accordance with the Cabinet resolution of 19 November 2019 (B.E. 2562), and both the consultation results and the analysis have been published online.
The MOF has also submitted a plan for the subordinate legislation to be issued under the four draft bills, including the intended timeframe and a framework of key content. That subordinate legislation comprises 183 instruments.
Key Takeaways
The Draft SEA, DA, TTA, and DAB have cleared Cabinet and Council of State review and now proceed through the parliamentary process.
The most immediate practical change is the statutory recognition of electronic documents and non-print advertising, which brings the SEA into line with existing market practice.
Several matters move from subordinate legislation into the acts themselves, notably approval of major shareholders in securities companies and supervision of capital market service providers.
Two newly regulated categories of person are introduced: capital market service providers (including auditors, financial advisers, and valuers) and significant system providers to the capital market.
Enforcement is strengthened through joint investigation powers, while criminal liability is narrowed to serious offences, with other conduct shifting to civil administrative fines.
The MOF has flagged 183 subordinate instruments to be issued under the four draft bills, meaning enactment will mark the start rather than the end of the reform process.
Affected businesses should assess now whether they fall within the newly regulated categories, since approval requirements, funding thresholds, and management appointment controls will apply once the draft bills are enacted.
Legal Update: Thailand Named in the White House Transshipment Report — Legal Exposure and the Government’s Response
Introduction
On 13 August 2026, the White House Office of Trade and Manufacturing Policy published a report entitled The Great Transshipment Scam (the “Report”). The Report identifies more than 40 jurisdictions said to present elevated risk of illegal transshipment of Chinese-origin goods into the United States and places Thailand in the second of three risk tiers.
The Thai Government responded within days, on 15 August 2026, confirmed that technical tariff negotiations with the United States would proceed at the end of August, and on 17 August 2026, the Department of Foreign Trade (“DFT”), Ministry of Commerce (“MOC”), set out the measures Thailand has taken on origin verification and its position on the underlying analysis.
The Report is not a legal instrument: it imposes no duty and creates no liability. Nonetheless, it consolidates a documented U.S. Government position that will inform enforcement targeting, trade remedy proceedings, and the negotiation of an Agreement on Reciprocal Trade (“ART”).
Thailand’s Classification under the Report
The Report groups the identified jurisdictions into three tiers. The first comprises diversified economies with large volumes of China-linked goods and comparatively strong customs systems, including Canada, the European Union, India, Israel, Japan, Mexico, South Korea, and Taiwan. The third comprises smaller economies said to offer specific weak-link advantages, such as low-cost labor, permissive free zones, or limited customs capacity.
Thailand is placed in the second tier, described as economies combining significant transshipment volumes with deep integration into China-linked supply chains, alongside Brazil, Indonesia, Malaysia, Turkey, and Vietnam. The Report characterizes Thailand, Vietnam, Malaysia, and Indonesia as major platforms for electronics, machinery, plastics, footwear, apparel, and components incorporating Chinese-origin inputs.
Thailand is named specifically in two contexts, and the two carry different legal weight.
The first is the Report’s “ugly sister city” analysis, which pairs foreign industrial corridors with U.S. regions producing the same goods, on the premise that work gained in one is work lost in the other. Thailand’s entry pairs the Ayutthaya–Samut Prakan corridor — linked to thermostats under HS 903210 — with the Minneapolis–St. Paul instruments sector. This is an inference drawn from trade statistics rather than a finding against any specific company, and the Report itself describes the pairings as illustrative. It nonetheless signals to U.S. Customs and Border Protection (“CBP”) which product code and geographic area warrant closer scrutiny.
The second reference concerns a decided case. The Report cites circumvention findings on solar cells and modules, in which the U.S. Department of Commerce determined that duties on Chinese goods were being evaded through final processing in Cambodia, Malaysia, Thailand, and Vietnam. Thailand therefore already has an enforcement record on this issue.
Thailand’s Response
According to MOC figures cited on 15 August 2026, approximately 72 percent of Thai product lines under Section 301 and Section 232 measures are already exempt, leaving roughly 28 percent still subject to the additional tariff. The exemptions span eight industry groups:
Electronic equipment and electrical machinery;
Machinery and components;
Iron and steel;
Articles of iron or steel;
Plastics and plastic products;
Vehicles and components;
Copper and copper products; and
Measuring, medical, and optical instruments.
Four of these groups fall under Section 232. As explained below, their inclusion reflects a distinction: goods in those categories are excluded from Section 301 to prevent double charging, rather than relieved of duty altogether.
Thailand is responding on three fronts.
Origin verification: The DFT has reported that the watch list operated jointly with CBP has been expanded from 49 items covering 194 tariff lines to 67 items covering 274 tariff lines, effective 1 June 2026. The DFT is developing an AI-assisted origin risk assessment system, has trained more than 2,000 operators on rules of origin and local content requirements, and has increased factory inspections, retrospective origin audits, and data linkage with the Customs Department, the Department of Industrial Works, and provincial commercial offices. The DFT and the Customs Department were scheduled to meet the Office of the United States Trade Representative (“USTR”) between 28 and 31 August 2026.
Negotiation: The Government confirmed on 15 August 2026 that technical tariff discussions would take place at the end of August, led by the Deputy Prime Minister and Minister of Commerce. It cited Thai private-sector investment in the United States of close to USD 20 billion as evidence of mutual economic interest, and denied reports that the negotiations were linked to any security or military arrangement.
The trade surplus: Thailand exports more to the United States than it imports, but at least 30 percent of those exports are produced by U.S. companies operating manufacturing bases in Thailand. On Thailand’s analysis, the bilateral surplus therefore measures the depth of a shared supply chain rather than a one-sided advantage, and cannot be read from the headline figure alone. It must instead be assessed together with investment flows, the location of production, and the broader scope of economic activity between the two countries.
Key Takeaways
The Report places Thailand in Tier 2 of a three-tier transshipment risk classification, alongside Brazil, Indonesia, Malaysia, Turkey, and Vietnam.
The Report is analytical rather than legal. It imposes no measure and expressly acknowledges that the trade patterns it identifies do not, by themselves, establish illegal transshipment.
Thailand has expanded its CBP watch list to 67 items and 274 tariff lines effective 1 June 2026, is deploying AI-assisted origin risk assessment, and met with the USTR between 28 and 31 August 2026.
Approximately 72 percent of Thai product lines under Section 301 and Section 232 are already exempt, with roughly 28 percent remaining exposed.
DBD Opens Consultation on Exempting Five Business Categories from Foreign Business Licensing
Introduction
The Department of Business Development (the “DBD”) has published an announcement inviting public comments on the principles of a draft Ministerial Regulation Prescribing Businesses Not Requiring a License for the Operation of Business by Foreigners, B.E. …. (the “Draft Regulation”).
The Draft Regulation would allow foreign nationals to operate five categories of business without obtaining a license under the Foreign Business Act B.E. 2542 (1999) (the “FBA”). All five categories are already supervised by a sector regulator under specific legislation, reflecting the removal of duplicate licensing rather than the liberalization of previously unregulated activity.
Background
Section 9 of the FBA requires the Foreign Business Committee (the “Committee”) to review the restricted business categories under the lists annexed to the FBA at least once a year. Following its reviews for 2024 (B.E. 2567) and 2025 (B.E. 2568), the Committee resolved to propose removing five business activities from the restricted categories. The Committee reasoned that the businesses concerned are already supervised by specific agencies under specific laws, so removing them would reduce duplication in state oversight. It also considered that the exemptions are consistent with economic development and with the readiness of Thai operators to compete; further, because certain of the activities are provided only to affiliated companies, exempting them would reduce costs and facilitate business operations without exposing Thai operators to new competition.
Consultation
The consultation itself reflects a recent procedural change. Section 5 of the Act on Legislative Drafting and Evaluation of Law B.E. 2562 (2019) requires state agencies to conduct consultation and impact analysis before enacting any law, to disclose the results, and to take them into account at every stage of the process; this requirement applies to ministerial regulations by analogy.
On 10 March 2026 (B.E. 2569), the Cabinet approved recommendations of the Law Development Commission extending the minimum consultation period from not less than 15 days to not less than 30 days, and requiring agencies to consult on the principles of a law before it is drafted, in addition to consulting on the drafted text.
The present exercise is therefore a first-stage consultation on principles. The text of the Draft Regulation has not yet been produced, and a further consultation on the drafted provisions is expected to follow.
The consultation period runs from 10 August 2026 to 30 September 2026 (B.E. 2569). Comments may be submitted through the Central Legal System website and the DBD website.
The Five Proposed Categories
1. Businesses related to, supporting, or necessary for securities or derivatives business
A foreign national conducting any of these activities must already be licensed by the Office of the Securities and Exchange Commission (the “SEC Office”) to operate a securities business under the securities and exchange law, or a derivatives business under the derivatives law, and must obtain the SEC Office’s approval before commencing the additional activity.
2. Aircraft maintenance services
This covers the maintenance of aircraft, aircraft major components, appliances, and aircraft parts under the air navigation law. The Air Navigation Act B.E. 2497 (1954) (the “ANA”) requires a repair station certificate, issued in three types corresponding respectively to aircraft, aircraft major components, and appliances and parts. The ANA prohibits operating a repair station without such a certificate and requires applicants to meet prescribed qualifications. The certificate is issued by the Director of the Civil Aviation Authority of Thailand (“CAAT”), which would become the single licensing authority for the activity.
3. Procuring customers to offer financial products of companies within a financial business group
Please see details of explanation in Item 4.
4. Debt collection services provided to companies within a financial business group
For categories 3 and 4, the foreign operator must itself be a company within a financial business group and may provide the relevant services only to other companies within that group. The term “financial business group” follows the Bank of Thailand (“BOT”) notification, which covers a commercial bank together with its parent company, subsidiaries at every tier, and joint ventures, whether domestic or foreign. Both activities constitute a supporting business, and where the group company is itself a commercial bank, they fall within the “other services” framework.
One qualification applies to debt collection: where collection is made from a debtor who is a natural person, the activity constitutes a debt collection business under the Debt Collection Act B.E. 2558 (2015) and must be registered in accordance with the criteria, methods, and conditions prescribed under that Act and its associated Ministerial Regulation.
5. Service business where a state enterprise is the counterparty
This category differs in nature from the others: it is not a new exemption but a correction to an existing one.
The business already appears in the Ministerial Regulation Prescribing Service Businesses Not Requiring a License for Foreigners (No. 3), B.E. 2560 (2017), which was issued when the applicable budget legislation was the Budget Procedure Act B.E. 2502 (1959) (the “2502 BPA”). The Budget Procedure Act B.E. 2561 (2018) (the “2561 BPA”) subsequently narrowed the definition of “state enterprise” by excluding limited companies and public limited companies in which state enterprises hold more than 50 percent of the capital. The transitional provision of the 2561 BPA, however, provides that references to “state enterprise” in pre-existing legislation continue to carry the meaning under the 2502 BPA.
As a result, the term used in the 2017 Ministerial Regulation still bears the older, wider meaning, which is inconsistent with the definition now in force. The DBD proposes to align the reference with the 2561 BPA, together with a transitional provision preserving the rights of foreign nationals already providing services to state enterprises under the former definition before the Draft Regulation takes effect.
Legal Significance
The exemption removes the requirement to obtain the FBL. However, a foreign national or entity relying on it must still obtain the licenses and approvals from the other agencies regulating such activities as follows:
SEC Office licensing and approval for the securities-related activities;
A CAAT repair station certificate for aircraft maintenance;
The BOT financial business group framework for the two financial support services; and
Registration under the Debt Collection Act where collection is made from natural persons.
The scope conditions are also narrow and should be read closely. Categories 3 and 4 are available only to a company within a financial business group serving other companies within the same group — a limitation expressly intended to confine the commercial reach of the exemption so that Thai operators are not affected. Category 1 is confined to management, marketing, human resources, and information technology services, and to a defined class of recipients.
For category 5, the practical question runs the other way. Because the definition of “state enterprise” has narrowed, some foreign operators currently serving state-enterprise subsidiaries may fall outside the exemption once the reference is updated. The proposed transitional provision is intended to address this, and its drafting will matter to those affected.
Key Takeaways
The DBD is consulting on the principles of a Draft Regulation that would exempt five business categories from FBA licensing. The proposal remains subject to the legislative process and does not yet have legal effect.
The proposal aims to reduce regulatory duplication in areas where specific sectoral laws and regulators already apply.
Comments are open until 30 September 2026. This is a principles-stage consultation, and a second consultation on the drafted text is expected before the Draft Regulation is finalized.
PDPA: Cross-Border Data Transfer Compliance for Bank Z Under Thailand’s Data Protection Law – Key Takeaways
Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) regulates the transfer of personal data abroad, imposing conditions to ensure adequate protection under Section 28. The Ad Hoc Subcommittee under the Personal Data Protection Committee has addressed Bank Z’s obligations when submitting directors’ personal data to comply with the Accounting and Corporate Regulatory Authority (ACRA) of Singapore and other foreign regulations. This analysis details the facts, the subcommittee’s rulings, and the resulting compliance framework.
Factual Background:
Bank Z must transmit directors’ personal data to meet ACRA requirements in Singapore and potentially other foreign laws. Under PDPA Section 28, cross-border data transfers require the recipient country or international organization to have adequate data protection standards, as determined by the Personal Data Protection Committee per Section 16(5), unless an exception applies. Bank Z faces uncertainty about whether “compliance with the law” under Section 28(1) includes foreign laws and, if not, how to proceed absent adequacy decisions for destination countries.
Subcommittee Decisions:
The subcommittee clarified Bank Z’s PDPA obligations as follows:
Scope of “Compliance with the Law” Under Section 28(1)
Cross-border data transfers are permissible only if the destination has adequate protection standards, per Section 28 and criteria set under Section 16(5). Exceptions under Section 28(1)–(6) or Section 29 may apply. For Section 28(1)—compliance with the law—the law must be Thai and legally binding on the data controller. Foreign laws, such as ACRA regulations, do not qualify as a basis under this provision. Thus, Bank Z cannot rely on Section 28(1) to justify transfers based on Singaporean or other foreign legal obligations.
Absence of Adequacy Decisions and Next Steps
No adequacy decisions exist under Section 16(5) and Section 28, as the committee has not yet designated any country or organization (e.g., Singapore) as having sufficient data protection standards. Without such designation, Bank Z must assess exceptions under Section 28(1)–(6). For instance, transferring directors’ data could fall under Section 28(3)—necessary to perform a contract where the director (data subject) is a party, such as employment or governance agreements—or pre-contractual steps requested by the director. If no exception applies (e.g., Sections 28(1), (3)–(6)), Bank Z must obtain explicit consent from directors per Section 28(2), informing them of the potentially inadequate protection standards in the destination country (e.g., Singapore) beforehand.
Implications for Compliance:
The subcommittee’s rulings restrict “compliance with the law” to Thai jurisdiction, excluding foreign mandates like ACRA’s as a direct basis. Absent adequacy decisions, Bank Z must either find a contractual or similar exception or secure directors’ informed consent, highlighting risks in destination countries. This dual approach balances legal obligations with data subject rights, pending future committee guidance on adequacy.
Key Takeaways:
Section 28(1) Is Thai-Law Specific: “Compliance with the law” applies only to Thai statutes, not foreign regulations like ACRA’s.
No Adequacy, No Free Pass: Without designated adequate destinations, transfers hinge on exceptions (e.g., Section 28(3)) or consent under Section 28(2).
Consent Requires Transparency: If consent is the basis, directors must be notified of inadequate protections in recipient jurisdictions.
Contractual Basis Offers Flexibility: Section 28(3) may cover director data transfers tied to governance duties, bypassing consent if applicable.
Bank Z’s scenario underscores PDPA’s stringent cross-border framework, prioritizing Thai legal authority and data subject awareness until adequacy standards are clarified. Compliance demands the strategic use of exceptions or proactive consent processes to align with international obligations.
Organizations increasingly remove names and other obvious identifiers from datasets before using the data for analytics, research, artificial intelligence development, or sharing it with third parties. A common assumption is that once names and identification numbers have been removed, the information is no longer personal data and therefore falls outside the Personal Data Protection Act B.E. 2562 (2019) (PDPA).
That assumption can be dangerous. Recent guidance from the Personal Data Protection Committee (PDPC) provides an important reminder: removing a person’s name does not, by itself, make data anonymous.
When does data become anonymous?
The key question is not simply whether direct identifiers have been deleted, but whether an individual can still be identified from the remaining information.
The PDPC’s approach indicates that data may be treated as anonymized where the data subject cannot be identified without additional information and appropriate technical and organizational measures have been implemented to ensure that identification is not reasonably possible in practice.
This distinction is particularly important where a dataset contains multiple indirect identifiers. Removing a person’s name while retaining information such as age, date of birth, location, gender, occupation, accident location, medical information, or other characteristics may still allow that person to be identified when those data points are considered together or combined with information from other sources.
Accordingly, de-identification is a question of substance, not merely the removal of specified fields.
Pseudonymization is not anonymization:
Organizations should also distinguish anonymization from pseudonymization.
If a person’s name is replaced with a code but the organization retains a separate table linking that code to the individual’s identity, the information remains capable of being attributed to that person. The dataset is therefore pseudonymized rather than truly anonymized.
Pseudonymization can be an important security and privacy measure, but it does not automatically take the data outside the PDPA. By contrast, properly anonymized information that can no longer reasonably be linked to an identifiable individual is no longer personal data for PDPA purposes.
This distinction has significant practical consequences. An organization cannot simply label a dataset “anonymous” or remove names and assume that the PDPA no longer applies.
Research provides a useful illustration:
The issue arose in the context of research into the causes of motorcycle accidents. Such research may involve ordinary personal data as well as sensitive personal data, particularly health information concerning injured persons.
The PDPA expressly recognizes research and statistical purposes as circumstances in which personal data may be processed without relying exclusively on consent. Section 24(1) provides a basis relating to research or statistical purposes, subject to appropriate safeguards protecting the rights and freedoms of data subjects. For sensitive personal data, Section 26(5)(d) similarly permits processing where necessary for scientific, historical or statistical research, or other public-interest purposes, subject to necessity and appropriate safeguards.
The PDPC has also prescribed specific safeguards for processing personal data for research and statistical purposes.
The practical significance is that organizations should not assume that anonymization is the only way to conduct research lawfully. Personal data may remain subject to the PDPA and nevertheless be processed for legitimate research purposes where the applicable statutory requirements and safeguards are satisfied.
What should organizations do in practice?
For organizations seeking to take datasets outside the scope of the PDPA, anonymization should be treated as a risk-based technical and governance process, rather than a simple data-cleaning exercise.
Direct identifiers should be removed, but organizations should also assess combinations of indirect identifiers and consider whether information could be matched against other reasonably available datasets. Where coded identifiers have been used, organizations should consider whether any linkage mechanism remains available. If a mapping table between codes and identities continues to exist, the resulting dataset is likely to remain pseudonymized rather than anonymous.
Depending on the nature of the dataset, additional techniques may be necessary, including aggregation, generalization, suppression, masking, reducing geographic or temporal precision, and other techniques designed to reduce re-identification risk.
Organizations should also document the anonymization process, the methodology used, the potential sources of re-identification, and the conclusion reached regarding residual risk. Technical measures should be accompanied by organizational controls restricting access and preventing attempts to re-identify individuals.
Why this matters for AI, analytics and data sharing:
The distinction has implications well beyond academic research.
Businesses increasingly want to use existing customer, employee, patient, transaction, location, behavioral, and operational datasets for AI development and training, statistical analysis, product improvement, or collaboration with external service providers and research institutions.
Where the information remains identifiable, the organization must continue to consider the PDPA requirements applicable to its collection, use, disclosure, retention, security, and other processing activities.
Where information has been effectively and irreversibly anonymized so that individuals are no longer reasonably identifiable in practice, however, the resulting dataset may fall outside the scope of the PDPA.
This makes anonymization potentially valuable for data-driven businesses, but it also means that organizations should be cautious about treating anonymization as a shortcut around data protection obligations. A dataset that can realistically be reconstructed, linked, or matched back to individuals remains exposed to PDPA risk regardless of what the organization calls it.
Key Takeaways:
Deleting names does not automatically anonymize personal data.
Organizations must consider whether individuals remain identifiable from other information or combinations of information in the dataset.
Pseudonymized data remains personal data where a person can be re-identified using additional information.
Proper anonymization requires technical and organizational measures designed to make re-identification impracticable.
Research and statistical processing may have specific legal bases under Sections 24(1) and 26(5)(d), subject to appropriate safeguards.
Organizations using data for AI, analytics, research or external data sharing should conduct and document a re-identification risk assessment before treating a dataset as outside the PDPA.
Anonymization should be viewed as an ongoing risk-management and governance exercise, not simply the deletion of names or identification numbers.
PDPA: Disclosure of Personal Data to Third Parties for Legal Proceedings
A recurring practical question under the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) is whether an organization may disclose personal data to a third party who needs the information to pursue a legal claim. Organizations often take a conservative position that personal data cannot be disclosed without the data subject’s consent. However, consent is only one of the legal bases under the PDPA, and the fact that information constitutes personal data does not, by itself, prohibit its disclosure. A recent opinion issued in response to a consultation by the Department of Land Transport (“DLT Opinion”) provides useful guidance on this issue and is particularly relevant to requests for personal data made for the purpose of exercising legal rights or pursuing legal proceedings.
Disclosure Does Not Necessarily Require Consent:
The DLT Opinion illustrates an important distinction between two questions: whether the information constitutes personal data and, if so, whether there is a lawful basis for its disclosure. Once information falls within the definition of personal data, its collection, use, or disclosure must comply with the PDPA, but this does not mean that disclosure is prohibited unless the data subject has given consent. Section 24 recognizes several legal bases for processing personal data without consent. Depending on the circumstances, disclosure to a third party may therefore be permissible where an appropriate legal basis exists. This is particularly important where the requesting party requires information to establish or exercise a legal right, claim damages, identify a responsible party, or commence legal proceedings. For example, a person who suffers damage involving a vehicle may know the vehicle registration number but may not know the identity of the person against whom a claim should be made. Similarly, a person injured in an incident recorded by CCTV may need the footage to establish the circumstances of the incident and pursue a claim. Treating the PDPA as an absolute prohibition against disclosure in such circumstances could prevent a person from effectively exercising legitimate legal rights.
Legitimate Interests and Legal Claims:
One potentially relevant legal basis is legitimate interests under Section 24(5) of the PDPA. This provision permits processing where it is necessary for the legitimate interests of the controller or another person, except where those interests are overridden by the fundamental rights of the data subject. A genuine need to obtain information for the establishment, exercise, or defense of a legal claim may constitute a significant legitimate interest. However, merely stating that information will be used in litigation should not automatically entitle a requester to obtain another person’s personal data. The controller should consider whether the claimed legal interest is genuine, whether disclosure of the requested information is necessary to pursue that interest, and whether the interests of the requester outweigh the privacy interests and fundamental rights of the data subject. In practical terms, this can be approached through a purpose–necessity–balancing analysis. The controller should first identify the legal purpose for which the information is requested; determine whether disclosure is reasonably necessary to achieve that purpose; and then balance that interest against the potential impact on the data subject. Supporting documents, such as a police report, evidence of damage, a demand letter, court documents, or other evidence demonstrating an actual or reasonably contemplated legal claim, may assist the controller in making and documenting this assessment.
The same reasoning has broader significance beyond vehicle-registration information. Government guidance discussing requests for CCTV footage has referred to the DLT Opinion by analogy when considering whether personal data may be disclosed to enable an injured person to exercise legal rights. This suggests that the Opinion may become an important reference point for third-party disclosure requests generally. Comparable issues arise frequently in the private sector: condominium juristic persons receive requests for CCTV footage following accidents or disputes; employers receive requests concerning former employees; insurers may hold information concerning parties to an accident; property owners may receive requests concerning tenants; and online service providers may receive requests for information identifying persons alleged to have committed a civil wrong. In each case, the correct question should not simply be whether the requested information is personal data, but whether the proposed disclosure has an appropriate legal basis and satisfies the requirements of necessity and proportionality.
Disclosure Should Be Limited to What Is Necessary:
Even where a lawful basis exists, the controller should not assume that all information in its possession may be disclosed. The scope of disclosure should be limited to information reasonably necessary for the stated legal purpose. If a requester needs information to identify a person against whom proceedings may be commenced, disclosure of the person’s name and information necessary for the relevant legal process may potentially be justified, while disclosure of unrelated information—such as identification numbers, telephone numbers, dates of birth, historical records, or other data not required for the claim—may not be. Redaction, partial disclosure, controlled access, or other safeguards should therefore be considered where appropriate. This distinction can be expressed simply as two separate questions: “Can the information lawfully be disclosed?” and “How much information is necessary to disclose?” Establishing a legal basis answers only the first question; the principles of necessity, proportionality, purpose limitation, and data minimization remain relevant to the second.
Organizations should also distinguish ordinary personal data under Section 24 from sensitive personal data under Section 26. Section 26 contains specific exceptions relating to processing necessary for the establishment, compliance, exercise, or defense of legal claims. Where sensitive personal data is involved, the requirements of Section 26 should therefore be considered separately rather than assuming that the legal basis applicable to ordinary personal data automatically applies. In all cases, organizations should consider implementing a documented Third-Party Personal Data Disclosure Request Procedure requiring verification of the requester’s identity, the purpose of the request, evidence supporting the claimed legal interest, the categories of information genuinely required, possible effects on the data subject, appropriate redaction or other safeguards, and a record of the reasons for approving or rejecting the request. Such documentation can be particularly important where the controller relies on legitimate interests and must subsequently demonstrate how the competing interests were assessed.
Key Takeaways:
The DLT Opinion is significant because it reinforces that the PDPA should not be treated as an automatic barrier to disclosure whenever personal data is involved. Consent is not the only legal basis for disclosure, and a genuine need to obtain information for the establishment, exercise, or defense of legal rights may support disclosure where the applicable requirements of the PDPA are satisfied. At the same time, an assertion that information is required for litigation does not create an unrestricted right of access to another person’s personal data. Controllers should assess the purpose, necessity, and balancing of interests, require appropriate evidence where necessary, limit disclosure to the minimum information reasonably required, and document the decision-making process. The broader lesson is that the PDPA is not intended to make personal data permanently inaccessible; rather, it establishes a framework for determining when disclosure is lawful, why it is necessary, and how much information may appropriately be disclosed.
PDPA: Applicability to a Facebook User’s Posting of Personal Data – Key Takeaways
Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) regulates systematic personal data handling, with exemptions for personal or familial use. The Ad Hoc Subcommittee under the Personal Data Protection Committee has evaluated whether a Facebook user’s posting of an allegedly defamatory image and text qualifies them as a data controller under PDPA, as raised by Police Station F in a criminal investigation. This analysis outlines the facts, the subcommittee’s rulings, and the compliance implications.
Factual Background:
Police Station F received a complaint alleging that a Facebook user posted an image of the complainant with text causing insult or hatred, prompting a criminal case. The prosecutor’s office (C) requested the station to investigate: (1) whether the post’s visibility settings (public symbols like a globe or people) made it accessible to the general public or a specific group, and (2) whether the suspect qualifies as a data controller under PDPA Section 6 for posting the complainant’s image and text.
Subcommittee Decisions:
The subcommittee addressed the issues as follows:
Post Visibility (Issue 1)
The question of whether the suspect’s Facebook post—with a globe or people symbol—was visible to the public or a limited group falls outside PDPA’s direct scope. PDPA defines “personal data” under Section 6 as information identifying a living individual, directly or indirectly (e.g., the complainant’s image). However, visibility settings pertain to evidence in a criminal investigation, not PDPA enforcement. The subcommittee deemed this a factual matter for the police to assess independently, unrelated to PDPA compliance.
Data Controller Status (Issue 2)
Under PDPA Section 6, a “data controller” is a person or entity with authority to decide on the collection, use, or disclosure of personal data, subject to duties like lawful bases (Sections 24, 26), notification (Section 23), security (Section 37), and rights responses (Sections 30–36). The law targets systematic or regular data processing, not isolated acts, per its intent and Section 4(1) exemption for personal or family use. The suspect, a natural person posting on Facebook, isn’t a data controller if the act was for personal purposes (e.g., expression) without systematic intent. Absent evidence of regular, organized data handling, PDPA doesn’t apply, per Section 4(1). However, the act may violate other laws (e.g., Computer Crime Act B.E. 2550, Penal Code defamation, or Civil Code torts under Section 420), which the police should pursue separately.
Implications for Compliance:
The suspect’s posting likely falls outside PDPA’s ambit as a one-off personal act, not subjecting them to data controller obligations (e.g., consent, security measures). Police Station F must focus on criminal or tort laws for liability, using post visibility as evidence, not a PDPA issue. PDPA applies to entities with structured data practices, not casual social media use.
Key Takeaways:
PDPA Targets Systematic Use: The suspect isn’t a data controller under Section 6 unless their posting reflects regular, purposeful data management, per Section 4(1) exemption.
Personal Acts Are Exempt: One-time social media posts for personal ends fall outside PDPA, per Section 4(1), unlike organizational data handling.
Other Laws Apply: Privacy breaches or defamation may trigger liability under the Computer Crime Act, Penal Code, or Civil Code, not PDPA.
Visibility Is Investigative: Post accessibility (public vs. private) is a factual issue for criminal evidence, not a PDPA concern.
This ruling clarifies PDPA’s scope, excluding personal social media acts from its framework, directing Police Station F to pursue alternative legal avenues for the complainant’s grievance.
Telemedicine Practices and Data Protection Compliance in Thailand: Legal Brief
I. Introduction to Telemedicine in Thailand:
Telemedicine has emerged as one of the most transformative innovations in healthcare. By leveraging modern communication technologies, telemedicine enables the delivery of medical services regardless of geographic barriers. As the global demand for accessible, efficient, and cost-effective healthcare increases, many countries have embraced telemedicine to overcome traditional challenges such as distance, cost, and limited access to medical expertise.
Thailand, with its rapidly developing digital infrastructure and progressive approach to healthcare, is becoming a prominent destination for telemedicine providers. However, alongside its tremendous growth potential, Thailand presents unique challenges, particularly in the realm of data protection and privacy. For both local and international telemedicine platforms, understanding and complying with the local legal environment is critical. The country’s evolving legal landscape, especially concerning data protection, patient privacy, and healthcare standards, requires providers to implement robust compliance measures. Doing so not only safeguards sensitive patient information but also builds trust with users, ensuring sustainable business growth in a competitive market.
In this guide, we delve into the key considerations for data compliance, discuss the relevant regulatory frameworks under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), and outline practical steps for telemedicine platforms to navigate these regulations. By doing so, telemedicine providers can effectively mitigate risks, secure patient data, and maintain a competitive edge in the Thai market.
II. Health Information Protection Before the Enforcement of the Personal Data Protection Law:
The National Health Act and Ministerial Regulation:
Thailand’s regulatory framework for data protection has undergone significant evolution over recent years. Prior to the enactment of the PDPA in 2019, Thailand relied on a combination of the Thai Constitution, the Thai Civil and Commercial Code, and sector-specific regulations like the National Health Act B.E. 2550 (2007) (“National Health Act”). The National Health Act mandated that personal health information be kept confidential. Specifically, Section 7 of the National Health Act required that such information not be disclosed in a manner that could harm the data subject, except when authorized by the individual or required by law.
The Ministerial Regulation on the Protection and Management of Personal Health Information B.E. 2561 (2018) (“MR”) provided further details on the scope and nature of personal health information. Clause 4 of the MR defined personal health information as encompassing a variety of documents, case files, reports, and other materials capable of identifying an individual’s health status. Clause 11 offered an exhaustive list of items considered personal health information, such as:
Health History: Such as height, weight, blood type, and body shape.
Medical Records: Such as nursing records, laboratory examinations, and x-ray films.
Related Documents: Any documents or objects that relate to the above data.
Photographic Evidence: Images of medical personnel or actions during treatment.
Additional Information: Any further information as specified by the Personal Health Data Protection and Management Committee.
Penalties for Non-Compliance:
Before the PDPA’s enactment, violations regarding the unlawful or unauthorized disclosure of personal health information were met with penalties prescribed under the NHA. Under Section 49 of the National Health Act, such violations could result in imprisonment of up to six months, fines of up to 10,000 THB, or both. Moreover, wrongful use of personal data was addressed under Section 420 of the Civil and Commercial Code, which provided for civil liability in cases where data misuse resulted in harm to the data subject.
Transition to the PDPA:
In 2019, the PDPA was published in the Royal Gazette, marking a significant shift in Thailand’s data protection landscape. With its comprehensive framework, the PDPA rendered the earlier MR obsolete. The Medical Council of Thailand subsequently issued a new Ministerial Regulation on the Revocation of the MR B.E. 2565 (2022). This evolution represents Thailand’s commitment to aligning its data protection standards with international best practices.
III. What Is Health Information?
As a result of the MR revocation, Thailand no longer has a statutory definition of health information, which is crucial in terms of personal data protection and compliance with obligations under the PDPA. Telemedicine platforms need to understand the personal data in their possession and handle such data according to the PDPA.
In the absence of subordinate regulations, directives, or guidelines to clarify the extent and scope of health information under the PDPA, it is worth exploring the definition given under the European Union General Data Protection Regulations (2016/679) (“EU GDPR”), which was a core foundation of the Thai PDPA, containing many similar provisions tailored to Thailand’s contexts.
Article 4 (15) of the EU GDPR defines ‘data concerning health’ as personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status. Additionally, the European Parliament and the Council of the European Union opined that ‘personal data concerning health’ should include all data pertaining to the health status of a data subject, including information collected during registration or provision of health care services, testing results, disease history, clinical treatments, or physiological states.
By this principle, personal data that may not obviously qualify as health information could still be considered health information depending on the context of personal data processing activities.
IV. Overview of PDPA Compliance for Telemedicine Platforms:
The PDPA extends its reach not only to local businesses but also to international data controllers who process the personal data of Thai residents. This extraterritorial effect means that even telemedicine platforms headquartered outside Thailand must comply with the PDPA if they process the personal data of individuals located in the country.
Extraterritorial Applicability:
According to Section 5, Paragraph 2 of the PDPA, foreign data controllers are subject to the PDPA if any of the following criteria are met:
The offering of goods or services to the data subjects who are in the Kingdom of Thailand, irrespective of whether the payment is made by the data subject, or
The monitoring of the data subject’s behavior, where the behavior takes place in the Kingdom of Thailand.
Obligations for Telemedicine Providers:
Once the PDPA applies, telemedicine providers (whether local or international) must adhere to various obligations under the PDPA, some of which include:
Data Collection and Processing: Ensure that personal data is collected, used, and disclosed with legal bases supporting each processing activity.
Privacy Notices: Clearly communicate to data subjects how their personal data will be used.
Security Measures: Implement appropriate technical and organizational measures to safeguard personal data.
Data Subject Rights: Provide mechanisms for data subjects to exercise their rights (e.g., access, correction, deletion).
Breach Notification: Establish procedures to notify both the regulatory authority and affected data subjects in the event of a data breach.
Record-Keeping: Maintain a Record of Processing Activities (ROPA) to document data processing practices.
V. Privacy Notice / Privacy Policy Under the PDPA:
One of the foundational requirements under the PDPA is the preparation and dissemination of a comprehensive privacy notice or privacy policy. This document serves to inform data subjects about how their personal data is collected, processed, stored, and shared.
Content of Privacy Policy:
Under Section 23 of the PDPA, data controllers must notify data subjects of the purposes of data collection prior to or at the time of collection. Common practices include written notices, electronic pop-ups on websites or applications, or verbal communications as applicable.
Best Practices for Drafting a Privacy Policy:
For telemedicine platforms, drafting a privacy policy involves a deep understanding of the personal data flows within the organization. Understanding the customer journey is vital for telemedicine platforms in preparing the privacy policy, as each touchpoint involves the collection and processing of personal data.
Sign-Up / Registration:
During the initial sign-up process, users are generally required to provide basic personal data such as their name, age, contact details, and, in some cases, initial health information, such as their height, weight, medical history, passport or national identification card, contact information, and information relating to personal allergies. This stage sets the foundation for subsequent interactions and must be handled with the highest level of security and clarity regarding data usage.
Know Your Customer (KYC) and Confirming the Identity of the Data Subject: To ensure compliance with Thailand’s PDPA and safeguard sensitive personal data, telemedicine platforms must implement robust KYC procedures during the sign-up phase. These procedures are designed to verify the identity of the data subject and establish trust between the platform and its users.
Verification of Identity: Platforms should require users to provide a valid
identification documents, such as a national ID card, passport, or other government-issued IDs, to confirm their identity.
The verification process may involve uploading scanned copies of these documents or using digital identity verification tools that comply with Thai legal standards.
Biometric Verification (Optional):
For enhanced security, telemedicine platforms may opt to incorporate biometric verification methods, such as facial recognition or fingerprint scanning, where applicable and permitted by law.
Data Matching:
Once the user submits their identification details, the platform should cross-check this information against official databases (e.g., government records) to ensure accuracy and prevent fraud.
Explicit Consent:
During the registration process, explicit consent must be obtained from the user for the collection, use, and disclosure of both general personal data and sensitive personal data. This includes clear explanations of how their data will be processed, stored, and shared.
If the user is under 20 years of age, additional consent from their legal representative, guardian, or curator may be required under Section 20 of the PDPA.
Booking / Appointment Scheduling:
Once registered, users schedule appointments with healthcare providers. The booking process may involve selecting a healthcare professional based on specialty, availability, or patient reviews. Additional forms might be used to capture medical history or current health conditions.
Consultation:
Consultations are the core of telemedicine services. Whether conducted via video calls, chat sessions, or telephone, these interactions involve real-time exchange of sensitive health information. Data from these sessions may include verbal communications, visual data, and records of diagnosis and treatment.
Post-Consultation Services:
After the consultation, several processes may occur:
Payments: Patients make payments through integrated or third-party payment gateways. This process generally involves third-party service providers.
Insurance Claims: In some cases, patients may file insurance claims. Telemedicine platforms might assist in this process by forwarding relevant health information to insurers.
Medicine Delivery: If medication is prescribed, delivery logistics come into play. This may involve sharing personal data (such as address and contact information) with third-party courier services.
Follow-up Appointments: Follow-up consultations or treatment plans may be scheduled, requiring further data collection.
Feedback and Reviews: Post-consultation feedback is often solicited to improve service quality. While this may involve general data, any health-related feedback is treated with heightened sensitivity
n)
VI. Legal Bases for Each Activity:
Different stages of the customer journey require distinct legal bases under the PDPA. For example:
Activity
General Personal Data
Sensitive Personal Data
Sign-up / Registration
Necessary to enter into / Performance of a contract (Section 24 (3))
Explicit Consent (Section 26)
Booking / Appointment
Necessary to enter into / Performance of a contract (Section 24 (3))
Explicit Consent (Section 26)
Consultation
Necessary to enter into / Performance of a contract (Section 24 (3))
Necessary for compliance with a law with respect to the provision of health or social care / Explicit Consent (Section 26 (5)(a) / Section 26)
Payment and Billing
Necessary to enter into / Performance of a contract (Section 24 (3))
Explicit Consent (Section 26)
Insurance Claims
Legitimate interest (Section 24 (5))
Explicit Consent (Section 26)
Medicine Delivery
Necessary to enter into / Performance of a contract (Section 24 (3))
Explicit Consent (Section 26)
Feedback / Reviews
Legitimate interest (Section 24 (5))
Explicit Consent (Section 26)
Important Remark: Please note that the table above shall only be used as a reference. The actual legal basis for each activity may differ based on the specific facts and circumstances.
VII. Processing Personal Data of Minors, Quasi-Incompetent Persons, or Incompetent Persons:
Where a patient is under 20 years of age or is a quasi-incompetent person or incompetent person, Section 20 of the PDPA requires their consent to be accompanied by consent from their respective legal representatives, guardians, or curators. However, if the patient is under 10 years of age, sole consent from the legal representative is sufficient.
Section 24 of the Thai Civil and Commercial Code provides an exemption for acts deemed suitable for a minor’s reasonable needs. Therefore, a minor (between 10 and 20 years of age) may give sole consent for telemedicine consultation purposes, as it deems suitable and actually required for their reasonable needs.
VIII. Data Subject Rights and Request Compliance Under the PDPA:
The PDPA enshrines several rights for data subjects. Telemedicine platforms must have robust processes to facilitate these rights.
A. Overview of Data Subject Rights:
The PDPA grants data subjects the following rights:
Right to Access: Data subjects may request copies of their personal data.
Right to Data Portability: Individuals can obtain their personal data in a structured, commonly used format.
Right to Object: Data subjects may object to certain personal data processing activities.
Right to Delete: Also known as the “right to be forgotten,” this allows data subjects to request deletion or anonymization of their personal data.
Right to Restrict Processing: In certain circumstances, processing may be limited or suspended.
Right to Rectification: Data subjects can have inaccurate or incomplete personal data corrected.
Right to Lodge a Complaint: Data subjects can lodge complaints with regulatory authorities.
Right to Withdraw Consent: Where processing is based on consent, data subjects may withdraw that consent at any time.
B. Procedures for Data Subject Rights Requests (DSRR):
Upon receiving a data subject request, telemedicine platforms should follow a set of protocols:
Verification: Confirm the identity of the data subject or their representative.
Clarification: Request additional information if the request is ambiguous.
Documentation: Record all details of the request.
Data Retrieval: Locate and compile the relevant data.
Review for Exemptions: Determine if any exemptions apply.
Response: Communicate a clear response—either fulfilling the request, rejecting it, or outlining why an exception applies.
Record-Keeping: Maintain records of the requests and responses for regulatory audits.
IX. Record of Processing Activities (ROPA):
Maintaining a detailed ROPA is a regulatory requirement under Section 39 of the PDPA.
A comprehensive ROPA should include,
the collected personal data;
the purpose of the collection of personal data in each category;
details of the data controller;
the retention period of personal data;
rights and methods for accessing personal data, including conditions for exercising these rights;
the use or disclosure of personal data;
rejection or objection to the data subject’s rights request; and
explanation of the appropriate security measures.
However, SMEs may be exempt from maintaining a full ROPA if they employ fewer than 100 people and have an annual revenue of no more than 300,000,000 THB. Nevertheless, telemedicine platforms handling sensitive personal data must maintain a full ROPA due to the risks involved.
X. Appropriate Security Measures for Telemedicine Platforms:
Prescribed under Section 37 (1) of the PDPA, where a data controller is required to provide appropriate security measures to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data. In this regard, the appropriate security measures for the telemedicine platforms shall focus on the maintenance of personal data’s confidentiality, integrity, and availability.
According to the PDPC’s Announcement on Security Measures for Personal Data, the security measures should contain at least the following mechanism: (1) access controls, allowing access to personal data only on a need-to-know basis provided that there shall also be an identity proofing, authentication, and authorization procedure; (2) user access management including registration and de-registration of access provision; (3) user responsibilities shall be prescribed; (4) implement an audit trail to enable the reviewing of access, change, alteration, or deletion of personal data.
The duty to implement appropriate security measures shall be extended to the imposition of obligations on the data processor of the telemedicine platforms (such as medicine delivery service providers), to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data.
XI. Personal Data Breach and Breach Notification Procedures:
Despite security measures, data breaches can occur. The PDPA requires prompt action in response to breaches.
A. Definition:
A personal data breach is defined as a breach of security measures resulting in the loss, access, use, alteration, modification, or disclosure of personal data without authorization or unlawfully.
B. Procedures:
Assess the reliability of the breach report and investigate the facts.
Notify the PDPC within 72 hours if the breach affects the rights and freedoms of data subjects.
Notify affected data subjects without delay if the breach poses a high risk.
Mitigate the situation and review security measures to prevent future breaches.
XII. Processing of Sensitive Personal Data by Data Processors:
Throughout the customer journey, a data processor may be involved in processes such as medicine delivery. A data controller must prepare a Data Processing Agreement (DPA) to control the activities of the data processor. Key provisions of a DPA include:
Restriction on use or disclosure of personal data.
Implementation of appropriate security measures.
Recording of personal data processing activities.
Notification of personal data breaches.
XIII. Designating a Representative and a Data Protection Officer (DPO) in Thailand:
A. Designating a Representative for Foreign Providers:
Foreign telemedicine providers offering services to Thai residents must designate a representative in Thailand under Section 5, Paragraph 2 of the PDPA.
B. Appointment of a Data Protection Officer (DPO):
Telemedicine platforms are obligated to designate a DPO if their core activities involve processing sensitive personal data. External or outsourced DPOs may be appointed for SMEs.
XIV. Use of Sensitive Personal Data (Health Information) for Telemarketing Purposes:
Sensitive personal data cannot be used for marketing purposes without explicit consent. Instead, telemedicine platforms may rely on general personal data (e.g., email addresses) for mass communications, provided an opt-out mechanism is available.
XV. Frequently Asked Questions (FAQs)
Q1: Does Weight and Height Qualify as Health Information?
Weight and height information may qualify as either general personal data or sensitive personal data, depending on the context. For example, in telemedicine services, weight and height may play a vital role in medical analysis and thus could be considered sensitive personal data.
Q2: Can a Patient Request Deletion of Their Health Information?
Patients have the right to request deletion of their personal data under certain conditions. However, telemedicine platforms are required to retain medical records for at least 5 years in accordance with the National Health Act.
XVI. Conclusion
As telemedicine continues to revolutionize the healthcare industry, ensuring robust compliance with data protection laws like the PDPA is critical. Health information, being sensitive personal data, demands the highest level of security and compliance to protect patient privacy and maintain trust in digital healthcare services.
For telemedicine platforms operating in Thailand, navigating the interplay between local regulations and international frameworks necessitates a meticulous approach to data processing. Failure to comply can lead to reputational damage, regulatory penalties, and legal liabilities. By adopting best practices such as transparent privacy policies, strong security measures, and compliance with data subject rights, telemedicine providers can create a safe and legally compliant environment.
In conclusion, the landscape of health information regulation is complex and continuously evolving. Telemedicine platform providers must proactively update their policies and compliance strategies to align with changing regulations, ensuring that patient rights remain protected while fostering innovation in digital healthcare solutions. By doing so, they can contribute to a more secure, efficient, and globally compliant telemedicine ecosystem.
Government Support for Small and Medium Enterprises (SMEs): Four New Economic Working Groups
Introduction
On 10 August 2026, Ms. Suphajee Suthumpun, Deputy Prime Minister and Minister of Commerce (“MOC”), chaired the first 2026 meeting of the Sub-Committee on the Development of Trade, Tourism and the Community Economy (the “Sub-Committee”). The Sub-Committee resolved to establish four specialized working groups tasked with restructuring the Thai economy across four dimensions:
the creative and visitor economy;
high-value agriculture and food security;
the community economy and SMEs; and
international trade.
The initiative is built on a two-tier delivery model:
Quick Big Win (short-term): targets measurable results within 6 to 12 months, principally by reviewing and removing regulatory requirements that obstruct business. This tier is deliberately confined to measures achievable without amending primary legislation and without requiring substantial budget allocation.
Big Win (long-term): targets structural reform over a two-to-four-year horizon to strengthen Thailand’s international competitiveness.
For businesses — particularly SMEs — the initiative carries particular significance. The MOC has identified small operators as accounting for approximately 35 percent of total national income, and the working group dedicated to the community economy and SMEs has been given an express mandate covering the entire entrepreneurial lifecycle, from business formation through to scale-up.
The initiative also places strong emphasis on regulatory and administrative reform. In particular, the Quick Big Win framework is intended to deliver practical improvements through measures that can generally be implemented without amendments to primary legislation.
The Four Working Groups
Creative Economy and Visitor Economy This group aims to extend the policy frame beyond conventional tourism to a broader visitor economy that includes those travelling to Thailand for education, business, and wellness purposes. Its work draws on Thailand’s cultural capital, identity, and visitor experience, and seeks to connect secondary cities and local communities to visitor spending.
Agricultural Products, Food Security, and High-Value Agriculture This group addresses the agricultural sector across the full value chain — upstream production, midstream processing, and downstream marketing — with the goal of moving Thai agriculture toward higher-value output, linking the sector more closely to industry and investment, and reinforcing food security.
Community Economy and Small and Medium Enterprises (SMEs) This group covers the entrepreneurial ecosystem as a whole: reducing licensing burdens, streamlining permit processes, building operator knowledge, upgrading goods and services, and promoting both scale-up and fair competition. Wholesale and retail trade is treated as a connected dimension of the same mandate. The group’s focus reflects the Government’s broader objective of improving the business environment for SMEs through practical regulatory and administrative reform.
International Trade This group focuses on promoting a more balanced import-export position, opening new markets, increasing utilization of existing free trade agreements, and responding to geopolitical pressure and non-tariff measures. It also carries the specific objectives of increasing SMEs’ share of the export structure and reducing dependency on any single market, thereby strengthening the resilience and international competitiveness of Thai businesses.
Legal and Regulatory Context
The Quick Big Win initiative is expected to be implemented through existing legal and administrative mechanisms, including:
Facilitation of Licensing and Public Services Consideration Act B.E. 2569 (2026): streamlines licensing procedures and public service delivery through new administrative mechanisms, replacing and expanding the earlier framework under the Facilitation of Official Licensing Consideration Act B.E. 2558 (2015).
Act on Legislative Drafting and Evaluation of Law B.E. 2562 (2019): facilitates stakeholder participation in the law-making and regulatory reform process.
SME Promotion Act B.E. 2543 (2000): provides the institutional framework for SME development and policy coordination.
These instruments provide the legal and administrative foundation for implementing the Quick Big Win agenda, particularly in relation to licensing simplification, regulatory reform, public service efficiency, and SME development.
Key Takeaways
The initiative underscores the strategic importance of SMEs in driving inclusive and sustainable economic growth.
The Quick Big Win framework aims to deliver measurable regulatory and administrative improvements within 6 to 12 months, primarily through reforms that do not require legislative amendment.
The Community Economy and SMEs Working Group has been tasked with supporting businesses throughout the entrepreneurial lifecycle — from establishment and compliance to expansion and competitiveness.
Businesses should closely monitor developments over the next 6 to 12 months and take advantage of opportunities to raise regulatory concerns as reforms are implemented.
Although the initiative does not create binding legal obligations, it offers an early indication of the Government’s priorities for future economic and regulatory reform.