DBD Opens Consultation on Exempting Five Business Categories from Foreign Business Licensing
Introduction
The Department of Business Development (the “DBD”) has published an announcement inviting public comments on the principles of a draft Ministerial Regulation Prescribing Businesses Not Requiring a License for the Operation of Business by Foreigners, B.E. …. (the “Draft Regulation”).
The Draft Regulation would allow foreign nationals to operate five categories of business without obtaining a license under the Foreign Business Act B.E. 2542 (1999) (the “FBA”). All five categories are already supervised by a sector regulator under specific legislation, reflecting the removal of duplicate licensing rather than the liberalization of previously unregulated activity.
Background
Section 9 of the FBA requires the Foreign Business Committee (the “Committee”) to review the restricted business categories under the lists annexed to the FBA at least once a year. Following its reviews for 2024 (B.E. 2567) and 2025 (B.E. 2568), the Committee resolved to propose removing five business activities from the restricted categories. The Committee reasoned that the businesses concerned are already supervised by specific agencies under specific laws, so removing them would reduce duplication in state oversight. It also considered that the exemptions are consistent with economic development and with the readiness of Thai operators to compete; further, because certain of the activities are provided only to affiliated companies, exempting them would reduce costs and facilitate business operations without exposing Thai operators to new competition.
Consultation
The consultation itself reflects a recent procedural change. Section 5 of the Act on Legislative Drafting and Evaluation of Law B.E. 2562 (2019) requires state agencies to conduct consultation and impact analysis before enacting any law, to disclose the results, and to take them into account at every stage of the process; this requirement applies to ministerial regulations by analogy.
On 10 March 2026 (B.E. 2569), the Cabinet approved recommendations of the Law Development Commission extending the minimum consultation period from not less than 15 days to not less than 30 days, and requiring agencies to consult on the principles of a law before it is drafted, in addition to consulting on the drafted text.
The present exercise is therefore a first-stage consultation on principles. The text of the Draft Regulation has not yet been produced, and a further consultation on the drafted provisions is expected to follow.
The consultation period runs from 10 August 2026 to 30 September 2026 (B.E. 2569). Comments may be submitted through the Central Legal System website and the DBD website.
The Five Proposed Categories
1. Businesses related to, supporting, or necessary for securities or derivatives business
A foreign national conducting any of these activities must already be licensed by the Office of the Securities and Exchange Commission (the “SEC Office”) to operate a securities business under the securities and exchange law, or a derivatives business under the derivatives law, and must obtain the SEC Office’s approval before commencing the additional activity.
2. Aircraft maintenance services
This covers the maintenance of aircraft, aircraft major components, appliances, and aircraft parts under the air navigation law. The Air Navigation Act B.E. 2497 (1954) (the “ANA”) requires a repair station certificate, issued in three types corresponding respectively to aircraft, aircraft major components, and appliances and parts. The ANA prohibits operating a repair station without such a certificate and requires applicants to meet prescribed qualifications. The certificate is issued by the Director of the Civil Aviation Authority of Thailand (“CAAT”), which would become the single licensing authority for the activity.
3. Procuring customers to offer financial products of companies within a financial business group
Please see details of explanation in Item 4.
4. Debt collection services provided to companies within a financial business group
For categories 3 and 4, the foreign operator must itself be a company within a financial business group and may provide the relevant services only to other companies within that group. The term “financial business group” follows the Bank of Thailand (“BOT”) notification, which covers a commercial bank together with its parent company, subsidiaries at every tier, and joint ventures, whether domestic or foreign. Both activities constitute a supporting business, and where the group company is itself a commercial bank, they fall within the “other services” framework.
One qualification applies to debt collection: where collection is made from a debtor who is a natural person, the activity constitutes a debt collection business under the Debt Collection Act B.E. 2558 (2015) and must be registered in accordance with the criteria, methods, and conditions prescribed under that Act and its associated Ministerial Regulation.
5. Service business where a state enterprise is the counterparty
This category differs in nature from the others: it is not a new exemption but a correction to an existing one.
The business already appears in the Ministerial Regulation Prescribing Service Businesses Not Requiring a License for Foreigners (No. 3), B.E. 2560 (2017), which was issued when the applicable budget legislation was the Budget Procedure Act B.E. 2502 (1959) (the “2502 BPA”). The Budget Procedure Act B.E. 2561 (2018) (the “2561 BPA”) subsequently narrowed the definition of “state enterprise” by excluding limited companies and public limited companies in which state enterprises hold more than 50 percent of the capital. The transitional provision of the 2561 BPA, however, provides that references to “state enterprise” in pre-existing legislation continue to carry the meaning under the 2502 BPA.
As a result, the term used in the 2017 Ministerial Regulation still bears the older, wider meaning, which is inconsistent with the definition now in force. The DBD proposes to align the reference with the 2561 BPA, together with a transitional provision preserving the rights of foreign nationals already providing services to state enterprises under the former definition before the Draft Regulation takes effect.
Legal Significance
The exemption removes the requirement to obtain the FBL. However, a foreign national or entity relying on it must still obtain the licenses and approvals from the other agencies regulating such activities as follows:
SEC Office licensing and approval for the securities-related activities;
A CAAT repair station certificate for aircraft maintenance;
The BOT financial business group framework for the two financial support services; and
Registration under the Debt Collection Act where collection is made from natural persons.
The scope conditions are also narrow and should be read closely. Categories 3 and 4 are available only to a company within a financial business group serving other companies within the same group — a limitation expressly intended to confine the commercial reach of the exemption so that Thai operators are not affected. Category 1 is confined to management, marketing, human resources, and information technology services, and to a defined class of recipients.
For category 5, the practical question runs the other way. Because the definition of “state enterprise” has narrowed, some foreign operators currently serving state-enterprise subsidiaries may fall outside the exemption once the reference is updated. The proposed transitional provision is intended to address this, and its drafting will matter to those affected.
Key Takeaways
The DBD is consulting on the principles of a Draft Regulation that would exempt five business categories from FBA licensing. The proposal remains subject to the legislative process and does not yet have legal effect.
The proposal aims to reduce regulatory duplication in areas where specific sectoral laws and regulators already apply.
Comments are open until 30 September 2026. This is a principles-stage consultation, and a second consultation on the drafted text is expected before the Draft Regulation is finalized.
Telemedicine Practices and Data Protection Compliance in Thailand: Legal Brief
I. Introduction to Telemedicine in Thailand:
Telemedicine has emerged as one of the most transformative innovations in healthcare. By leveraging modern communication technologies, telemedicine enables the delivery of medical services regardless of geographic barriers. As the global demand for accessible, efficient, and cost-effective healthcare increases, many countries have embraced telemedicine to overcome traditional challenges such as distance, cost, and limited access to medical expertise.
Thailand, with its rapidly developing digital infrastructure and progressive approach to healthcare, is becoming a prominent destination for telemedicine providers. However, alongside its tremendous growth potential, Thailand presents unique challenges, particularly in the realm of data protection and privacy. For both local and international telemedicine platforms, understanding and complying with the local legal environment is critical. The country’s evolving legal landscape, especially concerning data protection, patient privacy, and healthcare standards, requires providers to implement robust compliance measures. Doing so not only safeguards sensitive patient information but also builds trust with users, ensuring sustainable business growth in a competitive market.
In this guide, we delve into the key considerations for data compliance, discuss the relevant regulatory frameworks under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), and outline practical steps for telemedicine platforms to navigate these regulations. By doing so, telemedicine providers can effectively mitigate risks, secure patient data, and maintain a competitive edge in the Thai market.
II. Health Information Protection Before the Enforcement of the Personal Data Protection Law:
The National Health Act and Ministerial Regulation:
Thailand’s regulatory framework for data protection has undergone significant evolution over recent years. Prior to the enactment of the PDPA in 2019, Thailand relied on a combination of the Thai Constitution, the Thai Civil and Commercial Code, and sector-specific regulations like the National Health Act B.E. 2550 (2007) (“National Health Act”). The National Health Act mandated that personal health information be kept confidential. Specifically, Section 7 of the National Health Act required that such information not be disclosed in a manner that could harm the data subject, except when authorized by the individual or required by law.
The Ministerial Regulation on the Protection and Management of Personal Health Information B.E. 2561 (2018) (“MR”) provided further details on the scope and nature of personal health information. Clause 4 of the MR defined personal health information as encompassing a variety of documents, case files, reports, and other materials capable of identifying an individual’s health status. Clause 11 offered an exhaustive list of items considered personal health information, such as:
Health History: Such as height, weight, blood type, and body shape.
Medical Records: Such as nursing records, laboratory examinations, and x-ray films.
Related Documents: Any documents or objects that relate to the above data.
Photographic Evidence: Images of medical personnel or actions during treatment.
Additional Information: Any further information as specified by the Personal Health Data Protection and Management Committee.
Penalties for Non-Compliance:
Before the PDPA’s enactment, violations regarding the unlawful or unauthorized disclosure of personal health information were met with penalties prescribed under the NHA. Under Section 49 of the National Health Act, such violations could result in imprisonment of up to six months, fines of up to 10,000 THB, or both. Moreover, wrongful use of personal data was addressed under Section 420 of the Civil and Commercial Code, which provided for civil liability in cases where data misuse resulted in harm to the data subject.
Transition to the PDPA:
In 2019, the PDPA was published in the Royal Gazette, marking a significant shift in Thailand’s data protection landscape. With its comprehensive framework, the PDPA rendered the earlier MR obsolete. The Medical Council of Thailand subsequently issued a new Ministerial Regulation on the Revocation of the MR B.E. 2565 (2022). This evolution represents Thailand’s commitment to aligning its data protection standards with international best practices.
III. What Is Health Information?
As a result of the MR revocation, Thailand no longer has a statutory definition of health information, which is crucial in terms of personal data protection and compliance with obligations under the PDPA. Telemedicine platforms need to understand the personal data in their possession and handle such data according to the PDPA.
In the absence of subordinate regulations, directives, or guidelines to clarify the extent and scope of health information under the PDPA, it is worth exploring the definition given under the European Union General Data Protection Regulations (2016/679) (“EU GDPR”), which was a core foundation of the Thai PDPA, containing many similar provisions tailored to Thailand’s contexts.
Article 4 (15) of the EU GDPR defines ‘data concerning health’ as personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status. Additionally, the European Parliament and the Council of the European Union opined that ‘personal data concerning health’ should include all data pertaining to the health status of a data subject, including information collected during registration or provision of health care services, testing results, disease history, clinical treatments, or physiological states.
By this principle, personal data that may not obviously qualify as health information could still be considered health information depending on the context of personal data processing activities.
IV. Overview of PDPA Compliance for Telemedicine Platforms:
The PDPA extends its reach not only to local businesses but also to international data controllers who process the personal data of Thai residents. This extraterritorial effect means that even telemedicine platforms headquartered outside Thailand must comply with the PDPA if they process the personal data of individuals located in the country.
Extraterritorial Applicability:
According to Section 5, Paragraph 2 of the PDPA, foreign data controllers are subject to the PDPA if any of the following criteria are met:
The offering of goods or services to the data subjects who are in the Kingdom of Thailand, irrespective of whether the payment is made by the data subject, or
The monitoring of the data subject’s behavior, where the behavior takes place in the Kingdom of Thailand.
Obligations for Telemedicine Providers:
Once the PDPA applies, telemedicine providers (whether local or international) must adhere to various obligations under the PDPA, some of which include:
Data Collection and Processing: Ensure that personal data is collected, used, and disclosed with legal bases supporting each processing activity.
Privacy Notices: Clearly communicate to data subjects how their personal data will be used.
Security Measures: Implement appropriate technical and organizational measures to safeguard personal data.
Data Subject Rights: Provide mechanisms for data subjects to exercise their rights (e.g., access, correction, deletion).
Breach Notification: Establish procedures to notify both the regulatory authority and affected data subjects in the event of a data breach.
Record-Keeping: Maintain a Record of Processing Activities (ROPA) to document data processing practices.
V. Privacy Notice / Privacy Policy Under the PDPA:
One of the foundational requirements under the PDPA is the preparation and dissemination of a comprehensive privacy notice or privacy policy. This document serves to inform data subjects about how their personal data is collected, processed, stored, and shared.
Content of Privacy Policy:
Under Section 23 of the PDPA, data controllers must notify data subjects of the purposes of data collection prior to or at the time of collection. Common practices include written notices, electronic pop-ups on websites or applications, or verbal communications as applicable.
Best Practices for Drafting a Privacy Policy:
For telemedicine platforms, drafting a privacy policy involves a deep understanding of the personal data flows within the organization. Understanding the customer journey is vital for telemedicine platforms in preparing the privacy policy, as each touchpoint involves the collection and processing of personal data.
Sign-Up / Registration:
During the initial sign-up process, users are generally required to provide basic personal data such as their name, age, contact details, and, in some cases, initial health information, such as their height, weight, medical history, passport or national identification card, contact information, and information relating to personal allergies. This stage sets the foundation for subsequent interactions and must be handled with the highest level of security and clarity regarding data usage.
Know Your Customer (KYC) and Confirming the Identity of the Data Subject: To ensure compliance with Thailand’s PDPA and safeguard sensitive personal data, telemedicine platforms must implement robust KYC procedures during the sign-up phase. These procedures are designed to verify the identity of the data subject and establish trust between the platform and its users.
Verification of Identity: Platforms should require users to provide a valid
identification documents, such as a national ID card, passport, or other government-issued IDs, to confirm their identity.
The verification process may involve uploading scanned copies of these documents or using digital identity verification tools that comply with Thai legal standards.
Biometric Verification (Optional):
For enhanced security, telemedicine platforms may opt to incorporate biometric verification methods, such as facial recognition or fingerprint scanning, where applicable and permitted by law.
Data Matching:
Once the user submits their identification details, the platform should cross-check this information against official databases (e.g., government records) to ensure accuracy and prevent fraud.
Explicit Consent:
During the registration process, explicit consent must be obtained from the user for the collection, use, and disclosure of both general personal data and sensitive personal data. This includes clear explanations of how their data will be processed, stored, and shared.
If the user is under 20 years of age, additional consent from their legal representative, guardian, or curator may be required under Section 20 of the PDPA.
Booking / Appointment Scheduling:
Once registered, users schedule appointments with healthcare providers. The booking process may involve selecting a healthcare professional based on specialty, availability, or patient reviews. Additional forms might be used to capture medical history or current health conditions.
Consultation:
Consultations are the core of telemedicine services. Whether conducted via video calls, chat sessions, or telephone, these interactions involve real-time exchange of sensitive health information. Data from these sessions may include verbal communications, visual data, and records of diagnosis and treatment.
Post-Consultation Services:
After the consultation, several processes may occur:
Payments: Patients make payments through integrated or third-party payment gateways. This process generally involves third-party service providers.
Insurance Claims: In some cases, patients may file insurance claims. Telemedicine platforms might assist in this process by forwarding relevant health information to insurers.
Medicine Delivery: If medication is prescribed, delivery logistics come into play. This may involve sharing personal data (such as address and contact information) with third-party courier services.
Follow-up Appointments: Follow-up consultations or treatment plans may be scheduled, requiring further data collection.
Feedback and Reviews: Post-consultation feedback is often solicited to improve service quality. While this may involve general data, any health-related feedback is treated with heightened sensitivity
n)
VI. Legal Bases for Each Activity:
Different stages of the customer journey require distinct legal bases under the PDPA. For example:
Activity
General Personal Data
Sensitive Personal Data
Sign-up / Registration
Necessary to enter into / Performance of a contract (Section 24 (3))
Explicit Consent (Section 26)
Booking / Appointment
Necessary to enter into / Performance of a contract (Section 24 (3))
Explicit Consent (Section 26)
Consultation
Necessary to enter into / Performance of a contract (Section 24 (3))
Necessary for compliance with a law with respect to the provision of health or social care / Explicit Consent (Section 26 (5)(a) / Section 26)
Payment and Billing
Necessary to enter into / Performance of a contract (Section 24 (3))
Explicit Consent (Section 26)
Insurance Claims
Legitimate interest (Section 24 (5))
Explicit Consent (Section 26)
Medicine Delivery
Necessary to enter into / Performance of a contract (Section 24 (3))
Explicit Consent (Section 26)
Feedback / Reviews
Legitimate interest (Section 24 (5))
Explicit Consent (Section 26)
Important Remark: Please note that the table above shall only be used as a reference. The actual legal basis for each activity may differ based on the specific facts and circumstances.
VII. Processing Personal Data of Minors, Quasi-Incompetent Persons, or Incompetent Persons:
Where a patient is under 20 years of age or is a quasi-incompetent person or incompetent person, Section 20 of the PDPA requires their consent to be accompanied by consent from their respective legal representatives, guardians, or curators. However, if the patient is under 10 years of age, sole consent from the legal representative is sufficient.
Section 24 of the Thai Civil and Commercial Code provides an exemption for acts deemed suitable for a minor’s reasonable needs. Therefore, a minor (between 10 and 20 years of age) may give sole consent for telemedicine consultation purposes, as it deems suitable and actually required for their reasonable needs.
VIII. Data Subject Rights and Request Compliance Under the PDPA:
The PDPA enshrines several rights for data subjects. Telemedicine platforms must have robust processes to facilitate these rights.
A. Overview of Data Subject Rights:
The PDPA grants data subjects the following rights:
Right to Access: Data subjects may request copies of their personal data.
Right to Data Portability: Individuals can obtain their personal data in a structured, commonly used format.
Right to Object: Data subjects may object to certain personal data processing activities.
Right to Delete: Also known as the “right to be forgotten,” this allows data subjects to request deletion or anonymization of their personal data.
Right to Restrict Processing: In certain circumstances, processing may be limited or suspended.
Right to Rectification: Data subjects can have inaccurate or incomplete personal data corrected.
Right to Lodge a Complaint: Data subjects can lodge complaints with regulatory authorities.
Right to Withdraw Consent: Where processing is based on consent, data subjects may withdraw that consent at any time.
B. Procedures for Data Subject Rights Requests (DSRR):
Upon receiving a data subject request, telemedicine platforms should follow a set of protocols:
Verification: Confirm the identity of the data subject or their representative.
Clarification: Request additional information if the request is ambiguous.
Documentation: Record all details of the request.
Data Retrieval: Locate and compile the relevant data.
Review for Exemptions: Determine if any exemptions apply.
Response: Communicate a clear response—either fulfilling the request, rejecting it, or outlining why an exception applies.
Record-Keeping: Maintain records of the requests and responses for regulatory audits.
IX. Record of Processing Activities (ROPA):
Maintaining a detailed ROPA is a regulatory requirement under Section 39 of the PDPA.
A comprehensive ROPA should include,
the collected personal data;
the purpose of the collection of personal data in each category;
details of the data controller;
the retention period of personal data;
rights and methods for accessing personal data, including conditions for exercising these rights;
the use or disclosure of personal data;
rejection or objection to the data subject’s rights request; and
explanation of the appropriate security measures.
However, SMEs may be exempt from maintaining a full ROPA if they employ fewer than 100 people and have an annual revenue of no more than 300,000,000 THB. Nevertheless, telemedicine platforms handling sensitive personal data must maintain a full ROPA due to the risks involved.
X. Appropriate Security Measures for Telemedicine Platforms:
Prescribed under Section 37 (1) of the PDPA, where a data controller is required to provide appropriate security measures to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data. In this regard, the appropriate security measures for the telemedicine platforms shall focus on the maintenance of personal data’s confidentiality, integrity, and availability.
According to the PDPC’s Announcement on Security Measures for Personal Data, the security measures should contain at least the following mechanism: (1) access controls, allowing access to personal data only on a need-to-know basis provided that there shall also be an identity proofing, authentication, and authorization procedure; (2) user access management including registration and de-registration of access provision; (3) user responsibilities shall be prescribed; (4) implement an audit trail to enable the reviewing of access, change, alteration, or deletion of personal data.
The duty to implement appropriate security measures shall be extended to the imposition of obligations on the data processor of the telemedicine platforms (such as medicine delivery service providers), to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data.
XI. Personal Data Breach and Breach Notification Procedures:
Despite security measures, data breaches can occur. The PDPA requires prompt action in response to breaches.
A. Definition:
A personal data breach is defined as a breach of security measures resulting in the loss, access, use, alteration, modification, or disclosure of personal data without authorization or unlawfully.
B. Procedures:
Assess the reliability of the breach report and investigate the facts.
Notify the PDPC within 72 hours if the breach affects the rights and freedoms of data subjects.
Notify affected data subjects without delay if the breach poses a high risk.
Mitigate the situation and review security measures to prevent future breaches.
XII. Processing of Sensitive Personal Data by Data Processors:
Throughout the customer journey, a data processor may be involved in processes such as medicine delivery. A data controller must prepare a Data Processing Agreement (DPA) to control the activities of the data processor. Key provisions of a DPA include:
Restriction on use or disclosure of personal data.
Implementation of appropriate security measures.
Recording of personal data processing activities.
Notification of personal data breaches.
XIII. Designating a Representative and a Data Protection Officer (DPO) in Thailand:
A. Designating a Representative for Foreign Providers:
Foreign telemedicine providers offering services to Thai residents must designate a representative in Thailand under Section 5, Paragraph 2 of the PDPA.
B. Appointment of a Data Protection Officer (DPO):
Telemedicine platforms are obligated to designate a DPO if their core activities involve processing sensitive personal data. External or outsourced DPOs may be appointed for SMEs.
XIV. Use of Sensitive Personal Data (Health Information) for Telemarketing Purposes:
Sensitive personal data cannot be used for marketing purposes without explicit consent. Instead, telemedicine platforms may rely on general personal data (e.g., email addresses) for mass communications, provided an opt-out mechanism is available.
XV. Frequently Asked Questions (FAQs)
Q1: Does Weight and Height Qualify as Health Information?
Weight and height information may qualify as either general personal data or sensitive personal data, depending on the context. For example, in telemedicine services, weight and height may play a vital role in medical analysis and thus could be considered sensitive personal data.
Q2: Can a Patient Request Deletion of Their Health Information?
Patients have the right to request deletion of their personal data under certain conditions. However, telemedicine platforms are required to retain medical records for at least 5 years in accordance with the National Health Act.
XVI. Conclusion
As telemedicine continues to revolutionize the healthcare industry, ensuring robust compliance with data protection laws like the PDPA is critical. Health information, being sensitive personal data, demands the highest level of security and compliance to protect patient privacy and maintain trust in digital healthcare services.
For telemedicine platforms operating in Thailand, navigating the interplay between local regulations and international frameworks necessitates a meticulous approach to data processing. Failure to comply can lead to reputational damage, regulatory penalties, and legal liabilities. By adopting best practices such as transparent privacy policies, strong security measures, and compliance with data subject rights, telemedicine providers can create a safe and legally compliant environment.
In conclusion, the landscape of health information regulation is complex and continuously evolving. Telemedicine platform providers must proactively update their policies and compliance strategies to align with changing regulations, ensuring that patient rights remain protected while fostering innovation in digital healthcare solutions. By doing so, they can contribute to a more secure, efficient, and globally compliant telemedicine ecosystem.
Government Support for Small and Medium Enterprises (SMEs): Four New Economic Working Groups
Introduction
On 10 August 2026, Ms. Suphajee Suthumpun, Deputy Prime Minister and Minister of Commerce (“MOC”), chaired the first 2026 meeting of the Sub-Committee on the Development of Trade, Tourism and the Community Economy (the “Sub-Committee”). The Sub-Committee resolved to establish four specialized working groups tasked with restructuring the Thai economy across four dimensions:
the creative and visitor economy;
high-value agriculture and food security;
the community economy and SMEs; and
international trade.
The initiative is built on a two-tier delivery model:
Quick Big Win (short-term): targets measurable results within 6 to 12 months, principally by reviewing and removing regulatory requirements that obstruct business. This tier is deliberately confined to measures achievable without amending primary legislation and without requiring substantial budget allocation.
Big Win (long-term): targets structural reform over a two-to-four-year horizon to strengthen Thailand’s international competitiveness.
For businesses — particularly SMEs — the initiative carries particular significance. The MOC has identified small operators as accounting for approximately 35 percent of total national income, and the working group dedicated to the community economy and SMEs has been given an express mandate covering the entire entrepreneurial lifecycle, from business formation through to scale-up.
The initiative also places strong emphasis on regulatory and administrative reform. In particular, the Quick Big Win framework is intended to deliver practical improvements through measures that can generally be implemented without amendments to primary legislation.
The Four Working Groups
Creative Economy and Visitor Economy This group aims to extend the policy frame beyond conventional tourism to a broader visitor economy that includes those travelling to Thailand for education, business, and wellness purposes. Its work draws on Thailand’s cultural capital, identity, and visitor experience, and seeks to connect secondary cities and local communities to visitor spending.
Agricultural Products, Food Security, and High-Value Agriculture This group addresses the agricultural sector across the full value chain — upstream production, midstream processing, and downstream marketing — with the goal of moving Thai agriculture toward higher-value output, linking the sector more closely to industry and investment, and reinforcing food security.
Community Economy and Small and Medium Enterprises (SMEs) This group covers the entrepreneurial ecosystem as a whole: reducing licensing burdens, streamlining permit processes, building operator knowledge, upgrading goods and services, and promoting both scale-up and fair competition. Wholesale and retail trade is treated as a connected dimension of the same mandate. The group’s focus reflects the Government’s broader objective of improving the business environment for SMEs through practical regulatory and administrative reform.
International Trade This group focuses on promoting a more balanced import-export position, opening new markets, increasing utilization of existing free trade agreements, and responding to geopolitical pressure and non-tariff measures. It also carries the specific objectives of increasing SMEs’ share of the export structure and reducing dependency on any single market, thereby strengthening the resilience and international competitiveness of Thai businesses.
Legal and Regulatory Context
The Quick Big Win initiative is expected to be implemented through existing legal and administrative mechanisms, including:
Facilitation of Licensing and Public Services Consideration Act B.E. 2569 (2026): streamlines licensing procedures and public service delivery through new administrative mechanisms, replacing and expanding the earlier framework under the Facilitation of Official Licensing Consideration Act B.E. 2558 (2015).
Act on Legislative Drafting and Evaluation of Law B.E. 2562 (2019): facilitates stakeholder participation in the law-making and regulatory reform process.
SME Promotion Act B.E. 2543 (2000): provides the institutional framework for SME development and policy coordination.
These instruments provide the legal and administrative foundation for implementing the Quick Big Win agenda, particularly in relation to licensing simplification, regulatory reform, public service efficiency, and SME development.
Key Takeaways
The initiative underscores the strategic importance of SMEs in driving inclusive and sustainable economic growth.
The Quick Big Win framework aims to deliver measurable regulatory and administrative improvements within 6 to 12 months, primarily through reforms that do not require legislative amendment.
The Community Economy and SMEs Working Group has been tasked with supporting businesses throughout the entrepreneurial lifecycle — from establishment and compliance to expansion and competitiveness.
Businesses should closely monitor developments over the next 6 to 12 months and take advantage of opportunities to raise regulatory concerns as reforms are implemented.
Although the initiative does not create binding legal obligations, it offers an early indication of the Government’s priorities for future economic and regulatory reform.
Cabinet Approves Draft Ministerial Regulation Introducing Per-Item Fees for DBD Data Linkage Services
On August 7, 2026, The Deputy Government Spokesperson announced that the Cabinet of Thailand (“Cabinet”) has approved in principle a draft Ministerial Regulation Prescribing Fee Rates and Fee Exemptions for Registration, Requests for Document Inspection, Requests for Certified Copies, and Other Fees Relating to Partnerships and Limited Companies B.E. …. (“Draft Regulation”), as proposed by the Ministry of Commerce (“MOC”). The Draft Regulation has been referred to and is currently under the Office of the Council of State’s review. The Cabinet also instructed the MOC to take into account comments from the Office of the National Economic and Social Development Council regarding this Draft Regulation.
Background
Members of the public and businesses can currently verify juristic person information through a data linkage between the Department of Business Development (“DBD”) computer network and the user’s own system. Under the Ministerial Regulation Prescribing Fee Rates, Fee Reductions and Fee Exemptions Relating to Partnerships and Limited Companies B.E. 2563 (2020) (the “2563 Regulation”), a fee of THB 30 is charged per data set, with each set comprising six items:
name of the partnership or limited company
director information
number and names of authorized directors
registered capital
head office and branch locations
corporate objectives
The current system does not permit partial data requests: a user seeking only a single item — for example, registered capital — must nevertheless pay THB 30 for the full data set. The MOC considers this structure an unnecessary cost burden on both the public and private sectors, an obstacle to digital government development, and inconsistent with modern business practices that call for selective data access.
The Draft Regulation therefore aims to lower data-linkage service costs for juristic person verification by the public and private sectors. It also seeks to encourage corporate transactions through reliable electronic platforms, accelerate digital transformation in government, facilitate inter-agency data integration, and enable the DBD to expand its service coverage.
Key Changes
Introduction of a per-item fee. A new fee of THB 5 per individual item will apply to company certificate data. Users may still request the complete data set at the existing rate of THB 30, while the installation fee for the data linkage program remains THB 3,000 per instance. This allows users to select and pay only for the items they require.
Removal of the expired e-Registration discount. Clause 4 of the 2563 Regulation — which granted a 50 percent reduction on certain registration fees for partnerships and limited companies filing through the electronic juristic person registration system between 1 January 2021 and 31 December 2023 — will be deleted, as the discount period has already lapsed.
Key Takeaways
Users of the DBD data linkage service will be able to obtain individual certificate items at THB 5 each, rather than paying THB 30 for the full six-item data set.
For a typical two-item request, cost will fall from THB 30 to THB 10.
The THB 3,000 installation fee and the THB 30 full-set option are retained; all other registration and document fees are unaffected.
The Draft Regulation remains subject to review by the Office of the Council of State and is not yet in force. Businesses relying on the data linkage service should monitor the Royal Gazette for the effective date.
Consumer Protection: Proposed Labeling Rules for Solar Panels, Inverters and Energy-Storage Batteries
The Office of the Consumer Protection Board (OCPB) has opened a public consultation on three draft notifications of the Committee on Labels covering solar panels, inverters used with solar panels, and batteries for storing energy generated from solar panels. The consultation runs from 13–27 August 2026. Although, the notifications remain in draft form, they are an important development for manufacturers, importers, distributors, dealers, installers, and businesses supplying rooftop-solar and energy-storage systems.
The Proposed Labeling Rules:
The three draft notifications would regulate labeling requirements for the principal components of a solar-energy system: solar panels, inverters, and energy-storage batteries. The initiative follows increased regulatory attention to consumer protection in the solar sector, including concerns regarding the quality and safety of solar equipment and installations.
Designation of these products as label-controlled products is significant because labeling under the Consumer Protection Act is more than a product-branding requirement. The regulatory framework is intended to ensure that consumers receive sufficient and accurate information about the products they purchase, including information prescribed by the Committee on Labels. The precise disclosures, language requirements, and presentation requirements will ultimately depend on the final wording of each notification.
For solar products, compliance can be particularly complex because consumers frequently purchase an entire rooftop-solar or solar-plus-storage system rather than individual components. The panels, inverter, and battery may be manufactured by different companies, imported by different entities, and supplied to the consumer through a distributor or installer. As a result, businesses should consider labeling compliance across the entire supply chain rather than treating it solely as a manufacturer’s responsibility.
Key Compliance Issues for Businesses:
Manufacturers and importers should be particularly attentive to the proposals because they generally control product specifications, labels, packaging, and accompanying documentation. Imported equipment may present additional challenges where the original labels and manuals are prepared for international markets. Importers should therefore assess whether Thai-language supplementary labels will be required and whether information on those labels is consistent with the manufacturer’s original product information.
This review should extend beyond literal translation. Product names, model numbers, technical specifications, manufacturer and importer details, instructions, warnings, and other required disclosures should be consistent across the product label, packaging, manuals, technical specifications, warranties, and other customer-facing materials. Inconsistencies between these materials can create both regulatory and consumer-dispute risks.
Distributors, dealers, and installers should also monitor the proposals closely. A rooftop-solar provider may purchase panels, an inverter, and a battery from different suppliers and then offer them to the consumer as a single installed system. Businesses operating this model should consider incorporating label verification into their procurement and installation procedures, including checking that required labels are present, correspond to the correct product model, and are not removed or obscured during installation.
The proposals may therefore have consequences beyond the physical product label. Depending on the final requirements, businesses may need to review packaging, Thai-language disclosures, product specification sheets, user instructions, warranties, quotations, sales proposals, online product descriptions, and information provided by dealers and installers. Not all of these materials will necessarily constitute regulated labels, but consistency between mandatory product information and commercial representations should form part of the compliance review.
Supply-Chain Contracts and Existing Inventory:
Businesses should also review how responsibility for labeling compliance is allocated contractually. Supply, import, distribution, dealer, and installation agreements often contain general obligations to comply with applicable law but may not specifically address responsibility for preparing Thai-language labels, verifying technical information, implementing regulatory changes, or bearing the cost of relabeling noncompliant products.
For importers dealing with overseas manufacturers, this can be commercially important. Changes to factory-applied labels or packaging may require manufacturing lead times and additional costs. Agreements should therefore be reviewed to determine who must implement regulatory changes, who bears the associated costs, and what remedies apply where products supplied into the market do not satisfy mandatory labeling requirements.
Existing inventory will be another important issue when the final notifications are issued. Businesses may already hold substantial stocks of solar panels, inverters, and batteries bearing existing labels, while additional products may be in transit or subject to outstanding purchase orders. Companies should monitor the final rules for their effective dates and any transitional provisions, including whether existing inventory can continue to be sold or whether supplementary labeling will be permitted. Businesses should not assume that existing products will automatically be grandfathered.
Labeling, Product Safety, and Enforcement:
The proposed rules should also be considered alongside broader product-safety regulation. The OCPB has previously highlighted consumer concerns relating to allegedly substandard solar installations and has emphasized the importance of consumers being able to identify relevant product, manufacturer, importer, origin, and standards information.
Labeling compliance and technical compliance should therefore be managed as related but distinct requirements. A product’s compliance with an applicable industrial or technical standard does not necessarily establish compliance with consumer-labeling requirements, while a correctly labeled product may still fail to satisfy separate product-safety requirements.
Noncompliance with labeling requirements can carry criminal consequences under the Consumer Protection Act. The OCPB has stated that a seller of a label-controlled product without the required label, or with an incorrect label where the seller knows or ought to know of the noncompliance, may face imprisonment for up to six months, a fine of up to THB 100,000, or both. For manufacturers producing goods for sale and persons ordering or importing goods for sale, the potential penalty may increase to imprisonment for up to one year, a fine of up to THB 200,000, or both.
What Businesses Should Do Now:
As the notifications remain in draft form, immediate changes to product labels may be premature. However, businesses can begin preparing by identifying affected product models and collecting their current labels, packaging, manuals, and Thai-language product information. Importers should determine which labeling changes can be made locally and which would require cooperation from overseas manufacturers.
Businesses should also map responsibility throughout their distribution networks, review supply and dealer agreements, and identify existing inventory that could be affected by the new requirements. Once the final notifications are issued, particular attention should be given to the exact product scope, mandatory disclosures, Thai-language requirements, effective dates, and transitional arrangements.
Key Takeaways:
The OCPB is consulting on three draft labeling notifications covering solar panels, solar inverters, and batteries used for solar-energy storage.
The proposals are relevant to manufacturers, importers, distributors, dealers, installers, and integrated rooftop-solar and energy-storage providers.
Businesses should review not only physical labels but also packaging, Thai-language product information, technical documentation, sales materials, and downstream dealer practices.
Importers should assess whether existing global labels and packaging can satisfy the proposed requirements or whether local supplementary labeling or factory changes may be necessary.
Supply-chain agreements should clearly allocate responsibility and costs for labeling compliance and regulatory changes.
Businesses holding substantial inventory should monitor effective dates and transitional provisions carefully.
Companies can use the consultation period to conduct a preliminary product and labeling audit so they are prepared to implement the final requirements efficiently.
Generative AI and Music: Copyright Risks Highlighted by the DIP
The growing use of generative artificial intelligence (AI) to create music is raising increasingly important copyright questions. AI tools can now generate songs, modify voices, create remixes and produce new musical content by reference to existing works, making the boundary between technological creation and the use of protected material increasingly significant.
The Department of Intellectual Property (DIP) has recently highlighted the copyright implications of using generative AI in music. While the DIP’s comments do not introduce new legislation or a separate legal regime for AI-generated content, they provide a useful practical signal: the use of AI does not remove the need to consider copyright in the material used as part of the creative process.
For businesses using generative AI for music, advertising and other commercial content, this has implications not only for copyright clearance but also for contracts with AI providers, internal policies and the management of infringement risk.
Existing copyright rules continue to apply:
The starting point is that generative AI does not operate outside the existing copyright framework. Under the Copyright Act, copyright owners have exclusive rights in relation to protected works, subject to applicable limitations and exceptions. Depending on the circumstances, reproducing, adapting or otherwise using a protected work without authorization may therefore constitute infringement.
The DIP has emphasized that where copyrighted material is used in connection with generative AI, users should consider whether they have the necessary rights and obtain permission where required. This is particularly relevant where an AI workflow involves identifiable existing material—for example, where a user supplies an existing song, recording or other protected content to an AI system to generate or modify musical content. The fact that AI technology performs part of the transformation does not, by itself, provide authorization to use the underlying copyrighted work.
AI-assisted music can involve several layers of rights:
Music-related AI applications can be legally complex because a single piece of music may involve multiple protected elements. A song may involve rights in the musical composition and lyrics, while a particular recording may involve separate rights in the sound recording. Depending on how an AI tool is used, more than one category of rights may therefore need to be considered.
For example, using an existing recording as an input for an AI-generated remix may raise different questions from merely instructing an AI system through text to create music of a particular genre. Similarly, an AI voice-conversion tool that processes an existing recording may involve different copyright considerations from a system generating an entirely new recording without the user supplying an existing protected work. Businesses should therefore avoid treating “AI-generated music” as a single legal category. The relevant copyright analysis depends significantly on what material enters the AI workflow, what the system does with that material and how the resulting content is subsequently used.
Copyright clearance should begin with the input:
For businesses, one of the most immediate implications of the DIP’s position is the importance of reviewing the material supplied to AI systems. Before employees, agencies or contractors upload music, recordings or other content to a generative AI platform, businesses should consider whether they own the relevant rights, have obtained an appropriate license or can otherwise lawfully make the intended use.
This is particularly important in advertising and marketing, where AI tools may be used to generate background music, modify existing tracks or rapidly produce multiple versions of creative content. A business may ultimately be responsible for content distributed under its name even where an external advertising agency, production company or AI provider performed much of the underlying creative work. Copyright clearance should therefore form part of the AI-content production process rather than being addressed only after the content has been generated.
AI provider contracts deserve closer scrutiny:
The copyright analysis should not stop with the underlying content. Businesses should also review the contractual terms governing the AI tools they use. Terms of service can differ considerably between platforms, particularly in relation to material uploaded to the platform, the provider’s ability to use customer content and the rights granted in generated outputs.
For commercial use, relevant contractual issues include rights and permissions relating to material submitted to the AI system, permitted use of customer-provided content by the AI provider, rights to use and commercialize generated outputs, intellectual property representations and warranties, indemnification for infringement claims, and procedures for responding to copyright complaints. Similar protections may be appropriate in agreements with advertising agencies, production companies and other contractors creating AI-assisted content.
Internal AI policies should address copyrighted content:
Businesses increasingly permit employees to use generative AI tools without necessarily treating that use as a formal intellectual property process. This can create risk where employees upload commercially released music or other third-party content to an AI platform, use copyrighted material as a reference, or use AI to modify content without considering whether the business has the necessary rights.
Internal AI policies should therefore address intellectual property alongside confidentiality, personal data and cybersecurity concerns. Organizations should consider establishing rules governing the types of third-party content that may be uploaded to AI systems, when copyright clearance is required and which AI platforms may be used for commercial content creation. For higher-risk uses, an internal approval process may also be appropriate before AI-generated material is released publicly or incorporated into a commercial campaign.
What the DIP’s position does—and does not—resolve:
The significance of the DIP’s comments should not be overstated. They provide a useful indication of how existing copyright principles should be approached when generative AI is used to create or modify music and reinforce the practical importance of obtaining authorization before using copyrighted works where permission is required.
However, the comments should not, without further legal or regulatory authority, be treated as establishing a definitive position on whether and under what circumstances copyrighted works may be used to train generative AI models. Nor should they be treated as conclusively determining whether, or under what circumstances, AI-generated output qualifies for copyright protection or who may own rights in such output. Those questions involve distinct legal issues concerning reproduction, exceptions to copyright, authorship, originality and the degree of human creative contribution.
Practical implications for businesses:
Companies using generative AI to create music or other commercial content should consider incorporating copyright review into their AI governance framework. A risk-based approach may be appropriate: generating content from text instructions without supplying identifiable third-party works may present a different risk profile from uploading existing songs or recordings, generating remixes or adaptations, or using protected material as a direct input or reference in the generation process.
Particular caution is appropriate where AI-generated content will be used in advertising, distributed commercially or incorporated into products. Businesses should also consider the complete contractual chain. An organization commissioning AI-generated music from an agency or contractor may wish to require appropriate warranties concerning the lawful use of source material rather than assuming that copyright compliance rests exclusively with the creator.
Key Takeaways:
Generative AI does not displace copyright law: Using an AI tool does not, by itself, authorize the reproduction, adaptation or other use of copyrighted material.
Inputs matter: Businesses should understand what copyrighted material is being supplied to an AI system and whether the necessary rights or permissions have been obtained.
Music can involve multiple rights: Compositions, lyrics and sound recordings may involve separate rights and require separate analysis.
Contracts should allocate AI-related copyright risk: Businesses should review AI-provider and agency agreements for input rights, output rights, warranties, indemnities and restrictions on the provider’s use of uploaded material.
Internal AI policies should cover intellectual property: Rules governing employee use of generative AI should address copyrighted inputs and commercial use of AI-generated content.
Important questions remain unresolved: The DIP’s comments should not be interpreted more broadly than their stated scope, particularly regarding AI training and copyright ownership of AI-generated output.
From Grants to Equity: Government Innovation Agency Can Now Invest in Startups
A significant change to the legal framework for government support of innovation has opened the door to direct public-sector investment in startups and innovation businesses. The National Innovation Agency (Public Organization), the government agency responsible for promoting and supporting innovation (the “NIA”), has been granted expanded statutory powers to hold shares, become a partner, co-invest with other persons or entities, and participate in certain venture capital structures. This marks an important shift from the NIA’s traditional role as a provider of grants and financial support toward a model under which it may participate as an investor and acquire an economic interest in the businesses it supports.
The change was introduced by the Royal Decree Establishing the National Innovation Agency (Public Organization) (No. 3) B.E. 2569 (2026). In addition to expanding the NIA’s objectives to cover the development of innovation beyond the research and development stage toward commercialization, the amendment expressly authorizes the NIA to hold shares, become a partner, or participate in joint investments with individuals or legal entities in businesses connected with its statutory objectives. It may also invest in trusts established to conduct venture capital activities. Importantly, however, the NIA’s principal purpose in holding shares or participating in investments must not be the pursuit of profit, and the exercise of these investment powers is subject to criteria prescribed by the Council of Ministers.
From Funding Agency to Investor:
The distinction between a grant and an investment is significant. Under the traditional grant model, government funding supports a project or business without the government ordinarily acquiring an ownership interest. Equity investment creates a different relationship: the government agency may become part of the company’s capital structure, with its interest potentially affected by valuation, dilution, subsequent financing rounds, corporate restructurings, and an eventual exit. The amendment therefore does more than create another source of funding. It establishes the legal basis for the NIA itself to participate in the investment relationship.
This development may be particularly relevant for startups that have progressed beyond the stage at which grants alone can support their growth but remain too early or risky to attract sufficient private capital. The financing gap can be particularly significant for deep-tech and other innovation-driven businesses, where substantial capital may be required for product development, testing, regulatory approvals, manufacturing scale-up, intellectual property protection, and market entry before sustainable revenues are generated. Government equity or co-investment can potentially help bridge this gap and, by sharing part of the investment risk, encourage private investors to participate.
The NIA has announced that it intends to implement its expanded investment role through an initiative referred to as “NIA Venture,” using government funding as catalytic capital to encourage additional private investment. The announced framework includes investment through PE Trust structures, strategic investment through holding companies and other fund structures, and Corporate Co-Funding alongside qualified private investors, particularly for Seed to Series A businesses. The NIA has also announced an initial allocation model of approximately 40% for PE Trust, 30% for Holding Company, and 30% for Corporate Co-Funding. These investment channels and allocations are implementation measures announced by the NIA and should be distinguished from the statutory powers established by the Royal Decree itself.
What This Means for Startups and Investors:
The new powers do not give the NIA unrestricted authority to invest public funds in any startup. Investments must relate to the NIA’s statutory objectives, its principal purpose in participating in an investment must not be profit-seeking, and the relevant investment activities are subject to criteria prescribed by the Council of Ministers. Accordingly, the Royal Decree establishes the legal authority to invest, while the practical availability of NIA investment will depend on the applicable eligibility requirements, investment limits, approval procedures, governance arrangements, and other implementing conditions.
For founders, having a government organization on the cap table may create opportunities but also raises issues that should be considered at the outset. The investment terms will need to address valuation and dilution, the class and rights of shares acquired by the NIA, governance and information rights, and the company’s ability to raise subsequent financing. This is particularly important because later-stage venture capital investors may require preferred shares, liquidation preferences, anti-dilution protection, board representation, reserved matters, and other investor protections. An early government investment should therefore be structured in a way that does not unnecessarily complicate future financing rounds.
Exit arrangements may also require particular attention. Unlike a conventional venture capital fund, a public organization operates within a statutory and administrative framework governing its investments and assets. The ability of the NIA to sell, transfer, or otherwise realize its investment may therefore need to be considered when drafting shareholders’ agreements and investment documents, particularly in anticipation of a trade sale, secondary transaction, restructuring, or public offering. Startups should also anticipate potentially greater due diligence, reporting, and compliance requirements where public funds are involved.
The amendment is equally relevant to venture capital funds, corporate venture capital investors, and other private investors. Co-investment with the NIA could allow public and private capital to be combined in transactions that might otherwise be difficult to finance. However, the parties will need to consider how valuation is determined, whether investors subscribe for the same class of shares, how governance rights are allocated, how follow-on rounds are handled, and how exit decisions are made. Any conditions attached to government investment should also be assessed carefully to ensure that they do not unnecessarily restrict the company’s future operations, restructuring, overseas expansion, intellectual property arrangements, or ability to raise additional capital.
A New Model for Innovation Financing:
The amendment reflects a broader shift in the government’s approach to innovation financing. Grants and other forms of financial assistance remain important, particularly during research and early product-development stages, but they may not provide sufficient capital to take successful innovation from research to commercial scale. Allowing the government innovation agency to use equity and venture investment structures provides an additional tool for addressing that financing gap and may enable public capital to attract rather than replace private investment.
At the same time, the framework deliberately distinguishes the NIA from an ordinary commercial venture capital investor. Its investment activities must advance its statutory objectives, and profit cannot be the principal purpose of its participation. The success of the new model will therefore depend on achieving a balance between protecting public funds and providing sufficient commercial flexibility for startups to raise capital, grow, restructure, and eventually provide an exit for their investors.
Key Takeaways:
The government innovation agency now has express statutory authority to hold shares, become a partner, co-invest with other parties, and participate in specified venture capital structures.
This represents a shift from a model centered on grants and financial assistance toward one that can also include equity and co-investment.
The investment authority is subject to important limitations: investments must relate to the agency’s statutory objectives, profit must not be its principal purpose, and the exercise of the relevant powers is subject to criteria prescribed by the Council of Ministers.
The announced NIA Venture initiative includes PE Trust, Holding Company, and Corporate Co-Funding channels, but these are implementation arrangements rather than investment structures prescribed by the Royal Decree itself.
Startups should consider the effect of government investment on their cap table, governance, future fundraising, reporting obligations, and exit arrangements.
Private investors considering co-investment should assess how public-sector investment conditions interact with conventional venture capital terms and future financing rounds.
The practical impact of the reform will ultimately depend on the implementing criteria and the investment structures adopted under the new statutory framework.
Cabinet Approves Major Expansion of Home Worker Protections
The Cabinet has approved a draft amendment to the Home Workers Protection Act that would significantly expand the scope of protection for individuals performing work outside an employer’s or business operator’s premises.
The proposed amendments are particularly significant for businesses using remote workers, home-based workers, freelancers, and other individuals who perform assigned work away from business premises. Importantly, the proposed framework is intended to address modern working arrangements, including work assigned or performed through online systems.
The draft has been approved by the Cabinet but has not yet become law. It must proceed through the legislative process before enactment.
Broader Scope of Protected Work:
The existing Home Workers Protection Act principally focuses on work assigned by an industrial business operator to individuals or groups to produce or assemble goods outside the operator’s establishment.
The proposed amendments would substantially broaden this framework.
The concept of “work taken to be performed at home” would extend beyond traditional industrial production and cover work associated with a wider range of economic activities, including:
agriculture;
industry;
services; and
commerce.
The amendments would also expressly accommodate work arrangements involving electronic or online systems.
This change is potentially important for businesses operating through digital platforms or engaging individuals remotely. The relevant question may no longer be limited to whether a person physically takes materials or manufacturing work home. Businesses may need to consider whether work assigned digitally and performed outside their premises falls within the expanded statutory definition.
The legislation should therefore not be viewed as regulating only traditional home manufacturing or piecework. Its potential application could extend considerably further into the modern service and digital economy.
Minimum Compensation Protection:
The draft strengthens the statutory protection relating to compensation.
Compensation payable to a home worker would be required to meet the statutory minimum applicable under the legislation and could not fall below the minimum wage standard under labor protection law.
The amendments also reinforce the requirement that compensation be paid in Thai currency.
For businesses that calculate compensation on a project, output, piece-rate, or task basis, compliance may therefore require more than simply agreeing on a lump-sum fee with the worker. The compensation structure should be reviewed to ensure that it satisfies the statutory minimum requirements applicable to the work.
This could be particularly relevant to businesses using high-volume outsourcing models where individual workers are compensated according to completed tasks or units of production.
Increased Financial Consequences for Non-Payment:
The proposed amendments would strengthen the financial consequences for failing to make payments required under the Act.
Where a business fails to pay compensation or other amounts owed to a home worker, or fails to return security that it is legally required to return, the business may be required to pay interest at a rate of 15% per annum.
The relatively high statutory interest rate creates a significant incentive for businesses to establish reliable payment and reconciliation procedures.
Businesses that require workers to provide deposits or other forms of security should also review when such security must be returned and ensure that internal processes allow this to occur within the statutory requirements.
Stronger Protection Against Child Labor:
Another significant amendment concerns child labor.
The draft would prohibit the engagement of children under 15 years of age to perform homework.
This represents a material strengthening of the existing framework. Under the current legislation, the prohibition concerning children under 15 is focused on work that may be hazardous to their health and safety. The proposed amendment would establish a broader prohibition against engaging children below that age for home work.
Violation of the prohibition could result in substantial criminal penalties, including imprisonment for up to two years, a fine ranging from THB 400,000 to THB 800,000, or both.
Businesses using subcontractors, intermediaries, community production networks, or multi-tier outsourcing arrangements should pay particular attention to this requirement. Compliance mechanisms should extend beyond the immediate contractual counterparty where work may ultimately be distributed to individuals performing it at home.
Implications for Online and Platform-Based Work:
Perhaps the most consequential aspect of the proposed amendments is their potential application to work performed through online systems.
Traditional distinctions between employees, contractors, freelancers, platform workers, and home workers have become increasingly difficult to apply as businesses adopt remote and digitally mediated working models.
The amendments indicate a legislative intention to bring at least some forms of digitally assigned work within the home-worker protection framework.
This does not necessarily mean that every freelancer or remote contractor will automatically become a protected home worker. Whether the Act applies will depend on the statutory definitions and the particular structure of the working arrangement.
Nevertheless, businesses should avoid assuming that describing an individual as an “independent contractor,” “freelancer,” or “service provider” will by itself determine the legal position.
The substance of the arrangement—including how work is assigned, where it is performed, how compensation is calculated, and the relationship between the work and the business’s activities—may become increasingly important.
What Businesses Should Review:
Businesses that outsource work to individuals outside their premises should begin assessing their arrangements before the amendments become effective.
Particular attention should be given to:
Worker classification – identifying individuals who may fall within the expanded definition of home workers.
Digital work arrangements – reviewing work assigned, managed, submitted, or delivered through websites, applications, platforms, messaging systems, or other electronic channels.
Compensation structures – ensuring that piece-rate, task-based, project-based, and similar payment arrangements satisfy applicable minimum compensation requirements.
Payment procedures – establishing systems to ensure timely payment and avoid exposure to statutory interest.
Security and deposits – reviewing whether security is collected from workers and establishing procedures for its lawful and timely return.
Age verification – implementing appropriate controls to prevent individuals under 15 from being engaged to perform covered home work.
Subcontracting arrangements – reviewing contractual protections and compliance mechanisms where work is distributed through agents, contractors, subcontractors, or other intermediaries.
Contract documentation – updating contractor, outsourcing, and home-work agreements to reflect the expanded statutory requirements.
Effective Date:
The Cabinet-approved draft provides for the amendments generally to take effect 180 days after publication in the Government Gazette, although certain provisions concerning the preparation of subordinate legislation would take effect from the day following publication.
Businesses will therefore have a transition period once the legislation is enacted, but organizations with substantial outsourcing, home-working, or platform-based workforces may benefit from conducting an impact assessment before that period begins.
The draft remains subject to the legislative process, and its provisions may be revised before enactment.
Key Takeaways:
The proposed amendments represent a significant modernization of the home-worker protection regime.
Most importantly, protection would no longer be centered primarily on traditional industrial homework. The expanded framework would cover work connected with agriculture, industry, services, and commerce and would expressly respond to work arrangements conducted through online systems.
Businesses engaging individuals to perform work outside their premises should therefore reassess whether arrangements currently treated simply as outsourcing or freelance relationships could fall within the expanded legislation.
The proposed minimum compensation requirements, 15% statutory interest exposure, strengthened child labor prohibition, and potentially broader application to online work make this an important compliance development for businesses using decentralized or digitally managed workforces.
As the legislation remains in draft form, businesses should continue monitoring the legislative process and review the final text when enacted before implementing definitive compliance changes.
Big Data: Thailand Approves National Strategy to Accelerate AI and Data-Driven Economy
Thailand’s Cabinet has acknowledged the draft National Big Data Strategy, establishing the country’s first comprehensive policy framework for the development and use of big data as a foundation for digital government, artificial intelligence (AI), and a data-driven economy.
The strategy is intended to provide a unified direction for government agencies to improve data management, strengthen digital infrastructure, and promote the practical use of data in both the public and private sectors.
Why the strategy matters:
Although the strategy is not legislation and does not itself impose new legal obligations, it signals the Government’s long-term policy direction. Businesses operating in Thailand—particularly technology companies, cloud service providers, AI developers, healthcare providers, financial institutions, and organizations handling government-related data—should expect increased public investment and regulatory attention in data governance and AI.
The strategy also reinforces the Government’s objective of using data as a strategic national asset to improve public administration, support economic growth, and enhance Thailand’s digital competitiveness.
Key objectives:
According to the announcement, the strategy seeks to:
establish an integrated national big data ecosystem;
improve evidence-based policy making through better use of government data;
support AI adoption across government and industry;
enhance Thailand’s digital competitiveness; and
promote responsible and systematic use of data.
The Government has also set measurable goals, including increasing the economic value generated from big data and positioning Thailand among the world’s leading countries in big data capability.
Four strategic pillars:
The strategy consists of four principal initiatives.
1. Building national data infrastructure
The Government plans to strengthen core digital infrastructure through initiatives such as:
Government Cloud;
Government Data Catalog; and
National Big Data Platform.
These projects are intended to improve interoperability and enable more effective data sharing among government agencies.
2. Expanding practical use of data
The strategy encourages wider use of data analytics to address national priorities, including:
healthcare;
tourism;
environmental management;
agriculture; and
trade and economic development.
This reflects the Government’s intention to move beyond data collection toward data-driven decision-making.
3. Accelerating AI adoption
A significant component of the strategy is the promotion of AI across the public and private sectors.
The Government intends to:
expand AI applications in government services and industry;
support development of Thai-language AI models; and
establish datasets suitable for AI development.
These initiatives may create opportunities for AI developers, cloud providers, data platform operators, and businesses offering AI-enabled solutions.
4. Developing human capital
Recognizing that technology alone is insufficient, the strategy also emphasizes workforce development by increasing the number of professionals with expertise in big data and AI.
The Government aims to significantly expand the pool of skilled personnel capable of supporting Thailand’s digital transformation.
Legal and regulatory implications:
The strategy itself does not amend Thailand’s existing legal framework, including laws governing personal data protection, cybersecurity, or digital government.
Nevertheless, it indicates that future regulatory and policy initiatives are likely to focus on:
enhanced government data governance;
improved standards for data interoperability;
greater integration of public-sector datasets;
expanded use of AI in government services; and
stronger digital infrastructure supporting government cloud and data-sharing initiatives.
Organizations participating in government projects or processing government-related data should therefore continue monitoring future implementing measures, technical standards, procurement requirements, and sector-specific regulations that may follow.
Looking ahead:
The National Big Data Strategy represents an important policy milestone in Thailand’s digital transformation agenda. While much of its implementation will depend on future projects, funding, and regulatory measures, the strategy demonstrates the Government’s commitment to treating data and AI as key drivers of economic development and public-sector modernization.
For businesses, the announcement suggests increasing opportunities in AI, cloud computing, digital infrastructure, and government technology, while reinforcing the importance of robust data governance and regulatory compliance.
Key takeaways:
Businesses involved in AI, cloud services, digital infrastructure, and government technology should monitor future implementing regulations, technical standards, and procurement initiatives arising from the strategy.
Thailand has adopted its first comprehensive national strategy for big data development.
The strategy serves as a policy framework rather than creating immediate legal obligations.
Four priorities include national data infrastructure, wider use of data analytics, AI adoption, and workforce development.
Government investment is expected to accelerate in cloud infrastructure, data platforms, and AI ecosystems.
Thailand’s Response to the 12.5% U.S. Section 301 and the request for Further Exemptions
Introduction
On July 23, 2026, the Office of the United States Trade Representative (“USTR”) issued its final action under Section 301 of the Trade Act of 1974 in the Forced Labor Investigation, covering approximately 60 trading partners. Thailand was placed in the higher 12.5% tariff band, effective July 24, 2026, alongside Vietnam, the Philippines, and Singapore. Thailand received this rate because the United States found it had not adopted, committed to, or partially implemented a prohibition on the import of goods produced with forced labor, unlike a smaller group of trading partners assigned a 10% rate.
A separate and still-ongoing USTR proceeding, the Excess Capacity Investigation, covers 16 trading partners, including Thailand, and examines alleged structural excess capacity in manufacturing sectors. This investigation has not concluded and no tariff has yet been imposed under it. If the United States ultimately takes action on this second track as well, Thai exporters could face a further tariff, with some commentators estimating a combined exposure of up to 25% across both proceedings.
Domestically, Prime Minister Anutin Charnvirakul has directed six ministries and the Royal Thai Police to address both issues. Externally, the Ministry of Commerce (“MOC”) continues to negotiate an Agreement on Reciprocal Trade (“ART”) with the United States and has requested exemptions for a further 78 tariff lines, while stating that its negotiating position will not compromise the interests of farmers, the public, or businesses.
Key Concerns and Thailand’s Response
Following the Cabinet meeting of July 27, 2026, the Cabinet Secretariat issued an urgent instruction to the Ministries of Finance, Foreign Affairs, Agriculture and Cooperatives, Commerce, Labor, and Industry, and to the Commissioner-General of the Royal Thai Police. Each agency has been directed to prepare supporting data and response measures, identify the units responsible for each task, and set clear implementation timeframes.
1. Forced Labor
The United States has emphasized the need for stronger measures against goods produced with forced labor, including enhanced Human Rights Due Diligence (“HRDD”) and supply-chain traceability. The Ministry of Labor leads this response, together with the Ministries of Commerce and Industry. Their tasks are to accelerate enforcement of existing laws and regulations, compile lists of at-risk products and industries, and develop origin-certification and traceability systems covering the full production chain, so that Thailand can substantiate its position in discussions with the United States and other trading partners.
Thailand does not yet have directly enforceable legislation on this point. Thailand’s Ministry of Justice has been developing a draft Act on the Promotion of Responsible Business Conduct (also referred to as the mandatory Human Rights and Environmental Due Diligence, or “HRDD/mHREDD,” bill) since 2025, intended to align with the UN Guiding Principles on Business and Human Rights. The bill remains under development, and its legislative timeline, including submission to Parliament, has not been firmly fixed as of this update. Businesses should not wait for enactment before building supply-chain records.
2. Structural Excess Capacity
This issue is the subject of the separate, ongoing USTR Excess Capacity Investigation described above. It did not itself determine Thailand’s placement in the 12.5% forced-labor tariff band, though it could result in additional measures. The MOC leads Thailand’s response, with the Ministries of Industry, Agriculture and Cooperatives, and Finance. The agencies must compile risk lists at the product and industry level, integrating data on production capacity, inventory levels, government subsidies, price structures, export volumes, and country of origin. They must also investigate false origin claims and the use of Thailand as a trans-shipment point to evade trade measures imposed by importing countries.
Government support policy is also shifting direction. Future assistance is intended to target productivity, cost reduction, technology adoption, value addition, and greater use of local content. Subsidies that expand production capacity or increase supply beyond market demand are to be avoided, as they could themselves be cited as evidence of excess capacity. In discussions with USTR, Thailand has represented that domestic capacity utilization in the targeted industries generally runs between 70% and 90%, with no industry operating below 60%.
Exposure and Exemptions Secured
Thailand has obtained exemptions for 2,120 tariff lines under Annex II, Part A, representing approximately 61.6% of tariff lines and US$56.2 billion in exports, or roughly half the value of Thai goods exported to the United States. This is a substantial increase from the 471 items exempted under an earlier, preliminary list. Goods already subject to duties under Section 232 of the Trade Expansion Act of 1962 (for example, automobiles, steel, aluminum, and copper) are not subject to duplicate Section 301 duties. This overlap covers roughly US$7 billion of the remaining non-exempt goods.
Taking both the exemption list and the Section 232 overlap into account, the MOC estimates that approximately 28% of Thai exports to the United States remain exposed to the additional 12.5% tariff. Leading non-exempt industrial products include car and truck tires, machinery, cameras, air conditioners, and vehicle wheels and rims. Products such as jewelry, milled rice, pet food, canned tuna, and processed shrimp likewise remain outside the current exemption list and are among the items for which Thailand is now seeking relief (see below).
Solar cells and modules face particularly high cumulative exposure. In addition to the Section 301 tariff, U.S. antidumping duties on Thai-origin solar cells have been assessed at rates of up to approximately 203%, and countervailing duties at rates of up to approximately 800%, reflecting separate U.S. Commerce Department determinations on dumping and subsidization. Combined with the Section 301 tariff, total cumulative duties on affected solar shipments can substantially exceed 800%, and in the highest cases run well over 1,000%.
The Request for 78 Additional Tariff Lines
The MOC has submitted a proposal covering seven product groups and 78 tariff lines, which are agriculture and food security, consumer and household goods, medical and public-health products, electronics and semiconductors, vehicles and parts, machinery components and industrial equipment, and handicrafts and value-added products. Illustrative items include rice and Thai hom mali (jasmine) rice, maize, coconuts, orchids, cassava and cassava starch products, and fishery products, alongside jewelry, dog and cat food, milled rice, medical rubber gloves, tuna, processed bonito, fresh and cooked shrimp, and sauces and seasonings. The Commerce Ministry has separately referenced a further proposal covering 13 additional items, though it has not clarified whether these form part of the 78-line request or a distinct submission.
Thailand’s negotiating position is subject to three limits. It will not cross the interests of farmers, the interests of the public, or the rights of businesses. Thailand has indicated it is prepared for technical-level ART talks and is awaiting a determination from USTR, after which the MOC has suggested negotiations could conclude within a matter of weeks.
Key Takeaways
Solar cells are a particular outlier, combined Section 301, antidumping, and countervailing duties can push cumulative exposure well above 800%, in some cases exceeding 1,000%.
The 12.5% tariff under Section 301 currently in effect stems from the Forced Labor Investigation only. The separate Excess Capacity Investigation remains open and could result in an additional tariff if concluded against Thailand.
After accounting for the Annex II exemption list and the Section 232 overlap, approximately 28% of Thai exports to the United States remain exposed to the 12.5% tariff.
Six ministries and the Royal Thai Police have been directed to address forced labor and excess capacity concerns, with traceability and origin certification central to the response.
A mandatory human rights and environmental due diligence bill is under development by the Ministry of Justice, and its legislative timeline is not yet fixed. Businesses should not wait for enactment before building supply-chain records.
A request for 78 further exemption lines across seven product groups remains pending, and technical-level ART talks await a USTR determination.