Integrating Cybersecurity, Fraud Response, and PDPA Compliance: Practical Implications of the Proposed Digital Channel Security Framework

The Bank of Thailand (BOT) has released a proposed Digital Channel Security framework that would strengthen expectations for authentication, fraud prevention, incident response, and the governance of digital financial services. While the proposal focuses primarily on enhancing the security and resilience of digital channels, financial institutions should not view these requirements in isolation.

In practice, a single cybersecurity incident frequently triggers multiple legal and regulatory obligations simultaneously. For example, an account takeover resulting from a phishing attack may require an institution to activate its cybersecurity incident response procedures, implement fraud mitigation measures, assess whether a personal data breach has occurred under the Personal Data Protection Act (PDPA), evaluate outsourcing or third-party service provider involvement, and make appropriate internal and regulatory notifications.

Although these obligations arise from different legal and regulatory sources, organizations may benefit from managing them through a coordinated incident response framework. This article examines the practical implications of the proposed BOT framework alongside existing obligations under the PDPA and broader operational governance practices.

From cybersecurity to operational resilience:

The proposed framework reflects an increasing regulatory emphasis on operational resilience rather than viewing cybersecurity solely as an information technology function. It places greater focus on preventing, detecting, responding to, and recovering from threats affecting digital financial services while maintaining the continuity and integrity of critical operations.

At the same time, financial institutions should recognize that cybersecurity incidents rarely occur in isolation. A single event may involve operational disruption, attempted fraud, compromise of customer credentials, unauthorized disclosure of personal data, and third-party service providers. As a practical matter, organizations may therefore benefit from adopting governance arrangements capable of addressing these interconnected risks through a unified response process.

Governance beyond information technology:

The proposed framework emphasizes that responsibility for digital channel security extends beyond information security teams.

Boards of directors and senior management are expected to establish appropriate governance, oversee digital risks, allocate adequate resources, monitor security performance, and ensure that significant incidents are escalated appropriately.

From a broader governance perspective, institutions should also consider ensuring that legal, compliance, privacy, operational risk, business continuity, and customer service functions are integrated into incident management processes. This cross-functional approach can help organizations address multiple regulatory obligations efficiently when significant incidents occur.

Fraud prevention as part of digital channel security:

The BOT proposal places significant emphasis on fraud prevention through enhanced digital channel security. Proposed measures include stronger customer authentication, monitoring of suspicious activities, behavioral analysis, device identification, protection against phishing and social engineering attacks, and mechanisms for responding to suspicious transactions.

These expectations primarily seek to reduce fraud risks affecting digital financial services. However, successful fraud attacks frequently have wider legal implications. Unauthorized access to customer accounts may also involve compromised personal data, contractual issues with service providers, customer remediation, and regulatory reporting obligations. Institutions should therefore consider integrating fraud response procedures into broader cybersecurity governance rather than treating fraud management as a separate operational function.

Incident response across multiple regulatory frameworks:

The proposed framework expects institutions to establish formal incident response procedures covering detection, escalation, containment, investigation, recovery, and post-incident review.

In practice, these procedures should also enable organizations to identify other legal and regulatory obligations that may arise from the same incident. Depending on the circumstances, an incident may require parallel consideration of fraud management, operational resilience measures, contractual obligations, outsourcing arrangements, and personal data protection requirements.

Developing coordinated response procedures may help reduce duplication of effort, improve decision-making, and ensure that regulatory obligations are addressed consistently across different functions.

Interaction with the Personal Data Protection Act:

The proposed BOT framework does not replace or modify existing obligations under the PDPA. Rather, the two regimes operate alongside one another.

Where a cybersecurity incident involves unauthorized access to, disclosure of, alteration of, or loss of personal data, organizations should assess their obligations under the PDPA independently of the BOT framework. This may include determining whether a personal data breach has occurred, evaluating notification obligations, preserving relevant evidence, documenting response measures, and implementing appropriate remediation.

Accordingly, organizations may wish to ensure that privacy officers, legal counsel, and cybersecurity teams participate jointly in incident response planning and tabletop exercises so that both operational and data protection considerations are addressed from the outset.

Third-party risk management:

Digital financial services increasingly depend on cloud service providers, payment processors, managed service providers, software vendors, and other external partners.

The proposed framework reinforces expectations regarding oversight of third-party service providers throughout the outsourcing lifecycle. Institutions should conduct appropriate due diligence, establish contractual security requirements, monitor vendor performance, and ensure that incident reporting and business continuity arrangements are clearly defined.

Because cybersecurity incidents involving third parties may also raise fraud and personal data protection issues, organizations should consider aligning vendor management processes with their broader incident response and compliance frameworks.

Documentation and evidence of compliance:

The proposed framework places considerable emphasis on governance, accountability, and demonstrating that appropriate controls are in place.

Organizations should maintain comprehensive records of cybersecurity governance, risk assessments, incident response activities, testing, training, vendor oversight, and business continuity exercises. From a broader compliance perspective, documentation should also support obligations arising under other applicable legal frameworks, including the PDPA and contractual commitments relating to outsourced services.

Maintaining complete records may facilitate regulatory engagement, internal investigations, and post-incident reviews while demonstrating that reasonable organizational and technical measures have been implemented.

Practical considerations:

As organizations prepare for the proposed framework, they may wish to assess not only technical cybersecurity controls but also how different compliance functions interact during a significant incident.

Areas for review may include:

  • governance and board oversight;
  • coordination among cybersecurity, legal, compliance, privacy, and operational teams;
  • fraud detection and response procedures;
  • customer authentication controls;
  • third-party risk management;
  • incident reporting and escalation processes;
  • documentation and recordkeeping; and
  • operational resilience testing and tabletop exercises.

An integrated approach may improve organizational readiness while reducing the risk that separate regulatory obligations are managed through disconnected processes.

Key takeaways:

  • The proposed BOT Digital Channel Security framework primarily addresses digital channel security, fraud prevention, governance, and operational resilience.
  • Existing obligations under the PDPA continue to apply independently where cybersecurity incidents involve personal data.
  • A single cyber incident may simultaneously trigger cybersecurity, fraud management, personal data protection, outsourcing, and operational governance obligations.
  • Although these obligations arise under different legal and regulatory frameworks, organizations may benefit from managing them through an integrated incident response framework.
  • Financial institutions should consider reviewing governance structures, cross-functional coordination, and documentation practices to improve operational resilience and regulatory compliance.

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

Consumer Enforcement Intensifies for EV Businesses as Complaint Cases Rise and Labeling Expectations Increase

Thailand’s consumer protection regulator has signaled a more assertive enforcement approach toward the electric vehicle (EV) sector through two related developments. First, it has indicated its readiness to initiate legal proceedings on behalf of consumers in appropriate EV dispute cases. Second, it has issued new guidance consolidating labeling requirements for automobiles, electric vehicles, and used cars.

Although neither development introduces new legislation, together they demonstrate heightened regulatory scrutiny of the automotive industry and provide valuable insight into the regulator’s current enforcement priorities. Manufacturers, importers, distributors, dealers, service centers, and online vehicle marketplaces should treat these developments as an opportunity to reassess their compliance and dispute management frameworks.

Increased Enforcement Risk from EV Consumer Complaints:

The Office of the Consumer Protection Board (OCPB) has reported a significant number of consumer complaints relating to electric vehicles, with a substantial portion already progressing through legal procedures. The agency has confirmed that it has begun issuing formal demand letters in cases supported by sufficient documentation and has reiterated its statutory authority to commence legal proceedings on behalf of consumers where the legal requirements are satisfied.

This represents an important enforcement signal. Rather than merely facilitating mediation between consumers and businesses, the regulator has indicated its willingness to escalate suitable cases into formal litigation.

The risk is particularly significant where multiple complaints arise from the same product model, manufacturing issue, software defect, battery performance concern, warranty practice, or recurring after-sales service problem. A pattern of similar complaints may increase regulatory attention and expose businesses to coordinated enforcement actions, representative litigation, or broader product liability claims.

Businesses operating within the EV supply chain should therefore review whether existing complaint-handling mechanisms are capable of identifying systemic issues before they evolve into regulatory investigations or court proceedings.

Strengthened Expectations for Vehicle Label Compliance:

Separately, the OCPB has published an electronic handbook consolidating labeling requirements applicable to automobiles, electric vehicles, and used vehicles.

The publication emphasizes information that consumers commonly rely upon when making purchasing decisions, including battery specifications, driving range, testing standards, pricing information, warranty coverage, and the disclosure of material vehicle history for used vehicles.

Although the handbook itself is not legally binding, it provides a clear indication of the regulator’s compliance expectations. It reinforces that automobiles and electric vehicles remain controlled labeling products under consumer protection law and that incomplete, inaccurate, or misleading information may expose businesses to regulatory enforcement.

The guidance also illustrates that compliance extends beyond physical labels. Regulators are increasingly likely to examine whether information presented across all customer-facing channels remains accurate and consistent.

Businesses should therefore review:

  • labels displayed at dealerships and points of sale;
  • information published on corporate websites and online marketplaces;
  • brochures and sales presentations used by sales personnel;
  • representations concerning driving range and the testing methodology used, such as WLTP or NEDC;
  • battery capacity, expected degradation, warranty scope, and warranty exclusions;
  • disclosures relating to collision history, flood damage, major repairs, and battery replacement for used vehicles; and
  • consistency between information published by manufacturers, importers, dealers, and affiliated sales channels.

Claims relating to vehicle performance, battery longevity, operating costs, sustainability, resale value, or environmental benefits should be supported by appropriate technical evidence and internal documentation before publication.

Litigation Readiness and Document Preservation:

These developments also highlight the importance of litigation preparedness.

Businesses should consider establishing a centralized process for collecting and analyzing customer complaints to determine whether recurring issues indicate broader product or service risks.

At the same time, organizations should preserve relevant evidence, including:

  • sales documentation;
  • warranty records;
  • repair histories;
  • technical diagnostic reports;
  • replacement part records;
  • communications with customers;
  • call center recordings;
  • email correspondence;
  • mobile application records; and
  • connected vehicle diagnostic data.

Where disputes may reasonably be anticipated, organizations should consider implementing litigation hold procedures to reduce the risk of inadvertent deletion of potentially relevant evidence.

Companies should also review contractual risk allocation among overseas manufacturers, importers, dealers, distributors, and service centers, including indemnity provisions and responsibilities for handling product defects, recalls, warranty claims, and consumer litigation.

Data Protection Considerations:

Responding to consumer complaints frequently requires the collection and sharing of customer information, vehicle service histories, location information, and connected vehicle diagnostic data. Much of this information may constitute personal data under the Personal Data Protection Act.

Organizations should ensure that internal investigations and litigation response procedures incorporate appropriate data governance measures, including clearly defined access controls, documented processing purposes, retention periods, and secure mechanisms for sharing information with external counsel, technical experts, and other authorized parties.

Integrating consumer protection compliance with data governance can reduce both regulatory and litigation risks while supporting more effective dispute management.

Key Takeaways:

  • Organizations should strengthen complaint management, evidence preservation, document retention, contractual risk allocation, and data governance processes to prepare for increased regulatory scrutiny and potential consumer litigation.
  • The OCPB’s indication that it is prepared to commence litigation on behalf of consumers represents a significant escalation in consumer protection enforcement affecting the EV industry.
  • Businesses should not view repeated consumer complaints as isolated customer service matters but as potential regulatory and litigation risks requiring centralized oversight.
  • The newly published vehicle labeling handbook, although not legally binding, demonstrates higher regulatory expectations regarding the accuracy, completeness, and consistency of vehicle-related information across all sales channels.
  • Automotive businesses should review advertising claims, warranty disclosures, battery-related representations, and used vehicle disclosures to ensure they are fully substantiated.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

TCCT Establishes Two Subcommittees to Strengthen Trade Competition Oversight

The Trade Competition Commission of Thailand (“TCCT”) has appointed two subcommittees to oversee digital platform businesses and to establish competition rules for modern wholesale and retail businesses (“Modern Trade”). The move is intended to curb unfair trade practices and strengthen law enforcement in step with rapidly evolving trade dynamics.

1. Subcommittee on Considering Guidelines for the Oversight and Deterrence of Trade Practices in Digital Platform Businesses

This subcommittee’s primary mandate is to study, analyze, and collect data on the business models, commercial conditions, and trade practices of digital platform businesses, and to assess their impact on trade competition, business operators, consumers, and other stakeholders. It will drive more intensive regulatory measures for digital platform businesses and prepare proposals, guidelines, codes of conduct, criteria, announcements, regulations, and policy recommendations for the TCCT’s consideration.

The subcommittee will also coordinate with government agencies, the private sector, business operators, and other relevant stakeholders across all sectors to oversee and deter trade practices that may affect competition in digital platform businesses, and to promote free and fair competition more broadly.

2. Subcommittee on Determining Guidelines and Action Plans Regarding Competitive Conditions in Modern Wholesale and Retail Businesses

This subcommittee is tasked with studying, analyzing, and monitoring the market structure of modern wholesale and retail businesses; building a database to analyze retail market concentration and its impact on small-scale operators; and recommending guidelines and measures for overseeing competition in the retail sector.

Objectives of the Subcommittees

The subcommittees will study trade practices in digital platforms and in the modern wholesale-retail market to keep pace with shifting business dynamics and to investigate practices with anti-competitive effects. Each subcommittee will determine oversight guidelines and accelerate the promotion of fair trade so all parties can compete on equal terms.

The subcommittees will integrate efforts across relevant agencies, apply existing law to address exploitation or competitive pressure affecting the majority of business operators nationwide, and enforce compliance with guidelines the TCCT has already issued — notably the TCCT Notification on Guidelines for Considering Unfair Trade Practices and Acts that Monopolize, Reduce, or Restrict Competition in Multi-Sided Platform Business Operations for Digital Platform Services of Goods or Services (E-Commerce), in effect since March 25, 2026. They will also continue overseeing platform service businesses and Modern Trade going forward.

Background

Rapidly shifting competitive conditions and an influx of foreign capital have affected domestic operators, particularly SMEs and small-scale retailers. This has driven a sharp rise in complaints to the TCCT concerning online trading practices and the expansion of retail formats into community areas.

A particular concern is the continued increase in Gross Profit (GP) fees — the revenue-share or fee percentages that merchants pay to platforms. Higher GP rates compress net margins for SMEs, which may in turn force price increases that are ultimately passed on to consumers.

According to TCCT data:

  • E-commerce platforms and Modern Trade are currently among the leading competition concerns for small-scale operators at the grassroots of the Thai economy. In the first six months of this year alone, 21 platform-related complaints were filed, involving transactions collectively worth hundreds of billions of baht.
  • During fiscal year 2025 (October 1, 2024 – September 30, 2025), the TCCT received 78 complaints in total. Of these, 40 were not accepted for consideration, 9 were settled, and the remaining 29 are under investigation — most involving platforms, franchises, logistics and transport, digital platforms, and general commerce.

Through its Mobile Competition Clinic project, the TCCT has previously conducted on-site visits in several provinces to hear directly from business operators. Findings included:

Krabi Province:

  1. Online platform issues, including being forced to use specific transport providers and reduced product visibility due to algorithmic ranking.
  2. Online Travel Agency (OTA) platform issues, including price-parity clauses that prohibit hotels from listing lower rates on their own websites than on OTAs.
  3. Unfair trade practices between SMEs and Modern Trade operators, including redundant fee charges and additional GP fees imposed without prior notice.
  4. Palm oil pricing structure issues affecting local farmers.

Chiang Mai and Lamphun Provinces:

  1. Online platform issues, including algorithmic ranking practices that favor a platform’s own affiliated transport services.
  2. Unfair trade practices between SMEs and Modern Trade operators, including credit-term disputes, GP fee collection, and unfair contract terms.
  3. Pricing issues in agricultural product procurement.

Current Priorities and Enforcement Timeline

The TCCT is accelerating proactive oversight across four key business groups: (1) digital platforms, (2) wholesale and Modern Trade, (3) ride-hailing platform services, and (4) online travel booking platforms (OTAs). The newly formed subcommittees will study, analyze, and propose oversight guidelines, and investigate practices affecting competition across all four groups, with findings due by the fourth quarter of 2026. This will include updated operational guidelines designed to keep pace with evolving trade practices.

This initiative marks a deliberate shift in the TCCT’s enforcement approach — from a largely reactive, complaint-driven model to proactive market inspections that do not wait for formal complaints. On-site visits to gather in-depth input from business operators will remain central to this approach, with the TCCT aiming to demonstrate tangible results within the next six months.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

NBTC Issues AI Governance Guidelines for Telecom Licensees

Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has issued new guidelines setting out its expectations for the responsible use of artificial intelligence (AI) by telecommunications licensees. Although the guidelines are not legally binding, they establish a comprehensive risk-based framework for AI governance and provide a clear indication of the regulatory standards that the NBTC expects telecom operators to adopt when deploying AI in the provision of telecommunications services.

The guidelines reflect the increasing regulatory focus on AI governance and complement existing legal obligations relating to cybersecurity, personal data protection, and telecommunications. They also align with broader national efforts to develop a comprehensive AI regulatory framework.

Scope of the Guidelines:

The guidelines apply to holders of telecommunications business licenses under Thailand’s telecommunications licensing regime, but only in relation to AI systems used to provide licensed telecommunications services.

Organizations that are not telecommunications licensees are not directly subject to the guidelines. Nevertheless, AI developers, technology vendors, cloud service providers, and outsourced service providers may be indirectly affected because telecommunications licensees are expected to exercise oversight over third-party AI solutions used in their operations. As a result, contractual obligations and vendor due diligence are likely to become increasingly important for suppliers serving the telecommunications sector.

The guidelines should be considered alongside existing legal requirements, including the Personal Data Protection Act, the Cybersecurity Act, the Computer Crime Act, and the NBTC Notification on the Protection of Telecommunications Service Users’ Rights in relation to personal data, privacy, and the freedom of telecommunications. They also complement the broader AI legislation currently under development by the Electronic Transactions Development Agency (ETDA).

Strengthening AI Governance:

A central feature of the guidelines is the expectation that AI governance should extend beyond technical implementation and become an organizational responsibility.

Telecommunications licensees are encouraged to establish governance structures at both the policy and operational levels, such as AI committees, working groups, or designated responsible officers. These governance bodies should oversee AI strategy, establish internal policies, supervise risk management, and define accountability throughout the AI lifecycle.

The guidelines also emphasize that responsibilities should be clearly assigned not only to internal personnel but also to third-party AI solution providers and outsourced service providers. Licensees are expected to ensure that contractual arrangements clearly define each party’s obligations regarding AI governance, risk management, and regulatory compliance.

A Principles-Based Approach to Responsible AI:

Rather than prescribing detailed technical requirements, the guidelines adopt a principles-based approach centered on six core expectations.

First, AI systems should comply with applicable laws, ethical principles, and internationally recognized standards. AI should respect privacy, human dignity, and fundamental rights, and organizations should consider implementing appropriate safeguards, including content filtering, to reduce the risk of generating harmful or unlawful outputs.

Second, AI systems should operate fairly. This includes using representative and reliable training data, assessing potential bias, and taking appropriate measures to mitigate discriminatory outcomes.

Third, cybersecurity and privacy protections should be integrated into AI systems. The guidelines encourage the adoption of internationally recognized security standards and recommend technical safeguards such as encryption, anonymization, and access controls to protect personal data and system integrity.

Fourth, organizations should promote transparency by maintaining documentation regarding AI design, development, and operation, while providing consumers with appropriate information about how AI systems influence decisions or recommendations.

Fifth, accountability should be clearly established throughout the organization. Internal policies should define responsibility for AI outcomes, while consumers should have accessible channels to submit inquiries or complaints regarding AI-enabled services.

Finally, AI systems should be reliable and robust. The guidelines recommend testing AI models to ensure that they produce accurate and consistent results, including under unexpected operating conditions.

Governance Throughout the AI Lifecycle:

The guidelines emphasize that AI governance should be integrated throughout the entire AI lifecycle rather than focusing solely on deployment.

Licensees are expected to conduct risk assessments before development begins, evaluate the capabilities and reliability of third-party AI providers, and maintain appropriate standards for data quality and traceability. Before deployment, AI systems should undergo testing for reliability, fairness, and operational performance.

Once AI systems are operational, organizations should continuously monitor performance, maintain appropriate human oversight, and periodically evaluate whether AI systems continue to operate as intended. The guidelines also address the retirement of AI systems, encouraging secure decommissioning processes that protect data and maintain appropriate records throughout the system’s lifecycle.

This lifecycle-based approach reflects the growing international trend toward continuous AI governance rather than one-time compliance assessments.

Consumer Transparency and Organizational Readiness:

Consumer protection is another significant feature of the guidelines.

Telecommunications licensees are encouraged to notify consumers when they are interacting with AI systems, such as chatbots or voicebots. Where AI-generated recommendations may influence consumer decisions, organizations should provide appropriate disclosures and allow consumers to request assistance from a human representative where appropriate. Effective feedback and complaint mechanisms should also be maintained.

Internally, the guidelines recognize that responsible AI governance requires organization-wide awareness. Licensees are therefore encouraged to provide AI-related training across all levels of the organization. Employees who use AI systems should understand the associated legal and operational risks, while technical personnel and external developers should receive training on organizational AI policies, ethical principles, and applicable regulatory requirements.

Practical Implications:

Although the guidelines do not create new legal obligations, they provide valuable insight into the NBTC’s regulatory expectations and are likely to influence future regulatory supervision and industry best practices.

Telecommunications licensees should consider reviewing their existing AI governance frameworks to determine whether governance responsibilities are clearly assigned and appropriately documented. Organizations should also evaluate AI risk management procedures, update contracts with AI vendors and outsourced service providers, assess consumer disclosure mechanisms, and ensure that staff receive appropriate AI governance training.

The guidelines may also have implications for corporate transactions involving telecommunications businesses. As AI becomes increasingly integrated into telecommunications operations, AI governance maturity, data governance practices, and vendor oversight may become important considerations during legal and regulatory due diligence.

Key Takeaways:

  • Telecommunications licensees should review their governance frameworks, contractual arrangements, AI risk management processes, consumer disclosure practices, and staff training programs to align with the NBTC’s expectations.
  • The NBTC’s AI guidelines establish a comprehensive risk-based governance framework for telecommunications licensees and provide a clear indication of the regulator’s expectations for responsible AI deployment.
  • Although nonbinding, the guidelines are likely to influence regulatory supervision and industry best practices within Thailand’s telecommunications sector.
  • AI governance is expected to extend throughout the entire AI lifecycle, encompassing organizational governance, risk management, vendor oversight, cybersecurity, consumer protection, and ongoing monitoring.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Revises Visa Exemption Scheme: Shorter Stay Periods and a New Country-Based Category System

Introduction

On 14 July 2026, the Thai Cabinet approved a revision of Thailand’s visa exemption scheme. Under the revised framework, the current uniform 60-day visa exemption will be abolished and replaced with a country-based system that classifies eligible countries according to Thailand’s diplomatic relations and immigration risk assessment. Depending on the category assigned, eligible foreign nationals will be permitted to enter Thailand visa-free for stays of up to 30 or 15 days, or will remain eligible for a Visa on Arrival.

Background

In 2024, Thailand introduced a 60-day visa exemption for nationals of 93 countries and territories to stimulate tourism and support the country’s economic recovery following the COVID-19 pandemic. Since implementation, however, the government has identified several concerns associated with the scheme, including visa runs, illegal employment, nominee business arrangements, transnational crime, and visa overstays. In response, the government resolved to review and revise the existing visa exemption policy.

Key Changes

1. Introduction of a Tiered Visa Exemption Framework

30-Day Visa Exemption (59 Countries and Territories)

Nationals of 59 countries and territories will be eligible for visa-free entry for tourism purposes for stays of up to 30 days. The revised scheme extends this 30-day entitlement to six countries that were not previously covered:

  • India
  • Croatia
  • Bulgaria
  • Cyprus
  • Malta
  • Maldives

With these additions, all 27 European Union Member States will receive the same 30-day visa exemption entitlement, promoting greater consistency across Thailand’s visa policy. The government expects this measure to strengthen diplomatic relations, support future discussions on Schengen visa exemptions for Thai nationals, and facilitate continued economic and trade cooperation with partner countries.

15-Day Visa Exemption (2 Countries)                                                                                                                                                                            

Nationals of Mauritius and Seychelles will be eligible for visa-free entry for stays of up to 15 days. The government intends to periodically review this entitlement based on tourism statistics and visitor spending patterns.

Visa on Arrival (3 Countries)

Nationals of the following three countries will remain eligible to obtain a Visa on Arrival at Thailand’s immigration checkpoints:

  • Azerbaijan
  • Belarus
  • Serbia

2. Implementation of the “One Country, One Entitlement” Policy

Under the revised framework, each country will be eligible for only one immigration privilege, and overlapping schemes will be eliminated. For example, India will no longer be eligible for a Visa on Arrival, as it has instead been granted 30-day visa exemption status.

3. Enhanced Border Screening

The government will strengthen the Thailand Digital Arrival Card (TDAC) system by integrating it with relevant government databases, improving immigration risk assessment, border screening, and monitoring of visa exemption usage.

The Cabinet resolution provides for a revised visa framework covering a reported total of 65 countries and territories across the categories described above. The complete list of eligible countries and territories in each category has not yet been officially published; further detail is expected in forthcoming Ministry of Interior notifications and related subordinate legislation.

Effective Date

The revised measures have not yet entered into force. They will take effect 15 days after the relevant Ministry of Interior notifications are published in the Royal Gazette. Until that time, the existing immigration rules remain in effect, and foreign nationals who enter Thailand before the change takes effect will be permitted to remain for the duration of their existing permitted stay.

Key Takeaways

  • The revised measures are pending implementation and will take effect 15 days after publication in the Royal Gazette.
  • Thailand will replace its uniform 60-day visa exemption scheme with a tiered, country-based system.
  • The revised scheme aims to balance tourism promotion and ease of international travel against the prevention of visa abuse and the strengthening of immigration control and national security.
  • Eligible countries will receive 30-day or 15-day visa-free entry, while three countries retain Visa on Arrival status; overlapping privileges are removed under the “one country, one entitlement” policy.
  • The TDAC system will be enhanced to strengthen immigration screening and monitoring.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Responds to U.S. Section 301 Review: Trade Negotiations, Regulatory Reforms and Business Implications

The United States has conducted a trade investigation under Section 301 of the Trade Act of 1974 into approximately 60 trading partners, including Thailand, concerning whether goods produced using forced labour are entering the U.S. market. Following its preliminary determination in June 2026, the United States proposed imposing an additional 12.5% tariff on certain imports from Thailand and invited affected trading partners to submit comments on the proposed tariff rate, product coverage and potential tariff exemptions. Thailand submitted its written response by the 6 July 2026 deadline.

Following a public consultation process, the United States issued its final determination on 23 July 2026, confirming a 12.5% Section 301 tariff on imports from Thailand that are not otherwise exempt. The measures took effect on 24 July 2026.

Prior to the final determination, Thailand’s negotiating team, led by Minister of Commerce Ms. Suphajee Suthumpun, travelled to the United States from 15 to 17 July 2026 to continue discussions with U.S. officials regarding the proposed tariff rate, revisions to the tariff list, product-specific exemptions, and U.S. concerns relating to labour standards, agricultural exports and sanitary and phytosanitary (SPS) measures.*

Key Issues Under the U.S. Review

The U.S. investigation focused on two principal concerns:

  • Forced labour – whether Thailand has an adequate legal and regulatory framework to prevent the use of forced labour throughout its supply chains; and
  • Trade circumvention – whether goods originating in China are being routed through, or undergo only minimal processing in, Thailand before being exported to the United States.

Thailand has rejected these allegations, maintaining that the products under review are genuinely manufactured in Thailand and contain between 70% and 90% local content, with no product containing less than 60% Thai content. At the same time, the Government has sought to address U.S. concerns through both ongoing negotiations and proposed domestic regulatory reforms.

The products reportedly under review are primarily drawn from the following sectors:

  • machinery;
  • automotive products; and
  • rubber products.

Proposed Tariff Exemptions

As part of the review, the United States proposed tariff exemptions covering 1,655 products across four categories:*

  • agricultural and food products;
  • electronics;
  • energy and mineral products; and
  • aircraft parts.

Thai exports expected to benefit include cassava products, natural rubber, hard disk drives, smartphones, integrated circuits, processed pineapple, coconut products, durian, other tropical fruits and aircraft components.

For textile products, the United States also proposed a quota-based mechanism under which reduced tariff rates would be linked to the volume of textile raw materials imported from the United States.

Thailand’s Negotiating Position

Thailand sought to reduce the proposed tariff rate from 12.5% to 10%, bringing it into line with the rate applied to certain neighboring countries that had committed to implementing stronger forced labor import prohibitions.

As part of the proposed Agreement on Reciprocal Trade (ART), Thailand also emphasized that more than 30% of its trade surplus with the United States is generated by U.S. companies operating manufacturing facilities in Thailand and exporting their products back to the U.S. market. Thailand further requested additional tariff exemptions, including for Thai jasmine rice, while explaining that higher tariffs on certain Thai exports could increase costs for U.S. consumers where comparable products cannot readily be produced domestically or sourced from alternative suppliers.

The Government also reaffirmed several key negotiating positions, including:

  • maintaining Thailand’s existing beta-agonist standards for meat products; and
  • preserving Thailand’s ability to maintain trade relations with all countries, including China, without accepting conditions that could undermine Thailand’s economic sovereignty.

Regulatory and Policy Developments

In parallel with the negotiations, Thailand is advancing a proposed Human Rights Due Diligence (HRDD) framework under the proposed Act on Support Business Operation with Responsibility.

If enacted, the legislation is expected to require businesses to identify, assess and manage human rights risks throughout their operations and supply chains. Depending on the final form of the legislation, businesses may also be required to implement appropriate governance measures, maintain records demonstrating compliance and strengthen supply chain traceability.

Thailand is also developing clearer procedures to verify that exported goods are manufactured without the use of forced labor. Collectively, these initiatives are intended to strengthen confidence in Thai exports, enhance supply chain transparency and align Thailand’s regulatory framework more closely with internationally recognized human rights and labor standards.

Key Takeaways

  • Businesses with operations or supply chains connected to Thailand should review their supply chain governance frameworks, strengthen traceability measures and monitor further developments in Thailand’s proposed HRDD legislation.
  • The United States has completed its Section 301 investigation into approximately 60 trading partners, including Thailand, concerning forced labor and supply chain enforcement.
  • Thailand submitted its written comments by the 6 July 2026 deadline. The United States issued its final determination on 23 July 2026, imposing a 12.5% tariff on most Thai imports that are not otherwise exempt.
  • During the consultation process, Thailand sought to reduce the proposed tariff rate to 10% and requested additional product-specific exemptions, including for Thai jasmine rice.
  • The U.S. investigation has accelerated Thailand’s efforts to strengthen its human rights due diligence framework and supply chain governance.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Managing Regulatory Due Diligence for Cross-Border Investors in Financial and Digital Asset Businesses

Introduction:

Cross-border investments in financial services and digital asset businesses present unique regulatory challenges that extend well beyond traditional legal or financial due diligence. Whether an investor is acquiring a licensed payment service provider, a securities business, a digital asset exchange, or a fintech company operating under sector-specific regulation, the value of the transaction can depend as much on the target’s regulatory standing as on its commercial performance.

Unlike ordinary commercial businesses, regulated entities operate under continuing supervision. Their ability to conduct business depends not only on maintaining the necessary licenses but also on demonstrating ongoing compliance with governance requirements, prudential standards, anti-money laundering obligations, cybersecurity controls, and consumer protection rules. A company with strong financial performance may nevertheless represent a significant acquisition risk if its regulatory compliance has deteriorated or if it is subject to undisclosed supervisory concerns.

For cross-border investors unfamiliar with the Thai regulatory landscape, regulatory due diligence is therefore not merely a legal exercise. It is an essential component of transaction risk assessment and should begin early in the acquisition process.

Looking Beyond the License:

One of the most common misconceptions among foreign investors is that verifying the existence of a regulatory license is sufficient. In reality, the existence of a license represents only the starting point of the analysis.

Many regulated businesses have evolved over time, expanding their products and services beyond the scope originally contemplated when their licenses were granted. A fintech company may initially have operated as an electronic payment platform before introducing digital lending, cross-border remittance services, or digital asset-related products. Each new business activity may require separate regulatory approval or may be subject to different supervisory requirements.

Regulatory due diligence should therefore examine whether every revenue-generating activity falls within the scope of the target’s existing licenses and whether any exemptions relied upon remain available. It is equally important to determine whether any license conditions have been imposed by regulators and whether the company has complied with those conditions throughout its operations.

Regulatory Approval May Determine Whether the Transaction Can Close:

Unlike acquisitions involving ordinary commercial companies, transactions involving regulated financial businesses frequently require regulatory approval before completion. In some sectors, a change in significant shareholding or control may not become legally effective until the relevant regulator has approved the transaction. Other regulatory regimes may require post-closing notifications or impose “fit and proper” assessments on incoming shareholders, directors, or senior management.

Consequently, regulatory due diligence should identify not only the approvals required for the target’s day-to-day operations but also those triggered by the proposed acquisition itself. Failure to identify these requirements early can delay completion, affect financing arrangements, or require restructuring of the transaction.

Cross-border investors should also consider whether foreign ownership restrictions, residency requirements, or limitations on board composition may influence the post-closing governance structure.

Compliance Culture Often Matters More Than Written Policies:

Modern financial regulators increasingly assess how compliance operates in practice rather than whether a company simply maintains a complete set of written policies.

Accordingly, regulatory due diligence should extend beyond reviewing compliance manuals and internal procedures. Investors should seek evidence that compliance functions are adequately resourced, that internal reporting mechanisms operate effectively, and that senior management actively oversees regulatory risk.

The company’s interactions with regulators may provide particularly valuable insight. Inspection reports, supervisory correspondence, warning letters, remediation plans, and historical enforcement actions often reveal recurring compliance weaknesses that are not apparent from corporate documentation alone. Even where no formal penalties have been imposed, repeated supervisory findings may indicate weaknesses in governance or internal controls that require significant remediation after closing.

Technology Risk Has Become a Core Regulatory Issue:

Technology is now central to regulatory supervision of financial institutions and digital asset businesses. Cybersecurity failures, operational disruptions, and weaknesses in technology governance increasingly attract regulatory attention regardless of whether they result in customer losses.

For investors, this means regulatory due diligence should include an assessment of cybersecurity governance, incident response procedures, disaster recovery planning, outsourcing arrangements, cloud service management, and operational resilience frameworks. Businesses operating digital asset platforms should also be assessed for wallet security, custody arrangements, transaction monitoring systems, and market surveillance capabilities.

Technology deficiencies may not immediately affect valuation but can require substantial investment after completion to satisfy regulatory expectations.

AML and Financial Crime Controls Remain High-Risk Areas:

Anti-money laundering and counter-terrorism financing compliance continues to be among the highest enforcement priorities for financial regulators. Deficiencies in customer due diligence, transaction monitoring, sanctions screening, or suspicious transaction reporting can expose regulated businesses to substantial regulatory sanctions and reputational damage.

Investors should therefore evaluate not only the target’s written AML policies but also the effectiveness of their implementation. Questions such as how high-risk customers are identified, how beneficial ownership is verified, and how suspicious transactions are escalated can provide a clearer picture of the target’s compliance maturity than policy documents alone.

Where previous regulatory inspections have identified AML deficiencies, investors should assess whether remediation has been completed and whether regulators remain satisfied with the company’s corrective measures.

Data Protection and Outsourcing Should Not Be Overlooked:

Financial institutions increasingly rely on external service providers for cloud infrastructure, customer verification, payment processing, and cybersecurity services. While outsourcing may improve operational efficiency, regulators continue to emphasize that responsibility for regulatory compliance ultimately remains with the licensed entity.

Accordingly, regulatory due diligence should review the contractual framework governing outsourced services, the company’s oversight of critical vendors, and its contingency planning should key service providers become unavailable.

Similarly, businesses handling significant volumes of customer information should be assessed for compliance with personal data protection requirements, particularly where customer information is transferred across borders or processed by third-party vendors.

Due Diligence Findings Should Shape Transaction Documents:

Regulatory due diligence should not end with the preparation of a report. Its findings should directly influence transaction structuring and the allocation of risk between buyer and seller.

Where significant compliance concerns are identified, investors may seek enhanced representations and warranties regarding licensing, regulatory compliance, anti-money laundering controls, cybersecurity, and data protection. Specific indemnities may be appropriate for known regulatory investigations or historical compliance failures. In some cases, buyers may also require identified deficiencies to be remediated as conditions precedent before closing.

Integrating regulatory due diligence into transaction documentation helps ensure that regulatory risks are appropriately allocated and reduces the likelihood of post-completion disputes.

Conclusion:

As financial regulation becomes increasingly complex and technology-driven, regulatory due diligence has evolved from a narrow licensing review into a comprehensive assessment of an institution’s regulatory health. For cross-border investors, understanding how a target interacts with regulators, manages compliance risks, and maintains operational resilience is often as important as evaluating its financial performance.

A well-executed regulatory due diligence exercise enables investors to identify hidden regulatory exposures, anticipate approval requirements, negotiate more effective contractual protections, and develop realistic post-acquisition integration plans. In regulated financial and digital asset sectors, it is often the quality of regulatory compliance—not simply the quality of the business—that ultimately determines whether an investment achieves its intended value.

Key Takeaways:

  • In acquisitions involving financial and digital asset businesses, robust regulatory due diligence is essential to preserving investment value and minimizing post-closing regulatory exposure.
  • Regulatory due diligence should evaluate the target’s overall regulatory health rather than simply confirming the existence of licenses.
  • Investors should assess governance, supervisory history, AML/CTF controls, cybersecurity, data protection, outsourcing arrangements, and change-of-control requirements alongside licensing compliance.
  • Early identification of regulatory risks helps facilitate transaction planning, regulatory approvals, and appropriate contractual risk allocation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

BOT: Bank of Thailand Introduces Stricter Rules on Large Cash Transactions to Combat Illicit Flows

The Bank of Thailand (BOT) is set to implement enhanced oversight on significant cash movements as part of efforts to address gray-area financial activities, reduce risks of money laundering, and promote greater transparency in the financial system.

Under the upcoming regulations, financial institutions will soon be required to perform detailed customer due diligence for any cash withdrawal exceeding 5 million baht in a single transaction. Customers must clearly explain the source of the funds and the intended purpose of the cash. If the explanation is unsatisfactory or unverifiable, banks may restrict or decline to process the transaction.

This measure primarily targets unusual or high-risk cash usage that could be linked to informal, unregulated, or illicit activities. In a later phase, similar requirements will apply to cash deposits of 5 million baht or more, where the origin of the funds must also be justified.

The BOT has indicated that legitimate needs—such as those of small and medium-sized enterprises (SMEs), individuals conducting regular business operations, or other verifiable purposes—will continue to be accommodated, provided appropriate documentation and explanations are provided. However, the rules aim to make large-scale cash handling more accountable and discourage reliance on physical currency for questionable purposes.

Looking ahead, after an initial implementation period and evaluation of impacts (including any effects on ordinary users), the threshold may be lowered to 3 million baht for both withdrawals and deposits to further strengthen controls.

These changes form part of broader initiatives to tackle structural economic vulnerabilities, encourage electronic payments where practical, and limit opportunities for crime or opaque transactions.

Impact on the Public:

Most everyday individuals and small businesses will remain largely unaffected, as transactions below the 5 million baht threshold face no new requirements, and legitimate large needs can proceed with proper justification.

People or entities accustomed to handling large cash amounts (e.g., for property deals, business purchases, or other high-value activities) will need to prepare explanations and supporting evidence in advance, potentially adding time and documentation steps at the bank.

Those involved in informal or gray-area dealings may find it significantly harder to move large sums in cash without scrutiny, increasing the risk of restrictions or reporting to authorities.

Overall, the shift promotes safer, more traceable financial habits while aiming to reduce crime risks associated with large cash volumes and ease burdens through related reviews of common banking fees.

Key Takeaways:

Implementation is expected in the near future (early to mid-March timeframe), giving the public time to adjust to more accountable cash handling practices.

Cash withdrawals over 5 million baht will require clear justification of purpose and source; unsatisfactory explanations may lead to restrictions.

The rules will later extend to large cash deposits and could lower the threshold to 3 million baht after review.

Legitimate users (e.g., SMEs and individuals with valid reasons) can continue transactions by providing details—no outright ban is intended.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Anti-Bribery: Digital Government Data Integration Raises Compliance Expectations

Thailand’s Cabinet has acknowledged progress on a series of anti-bribery initiatives designed to strengthen transparency and improve the government’s ability to detect corruption. While the measures remain at the policy and implementation stage, they indicate a clear direction toward greater use of digital government systems, cross-agency data integration, and risk-based monitoring.

For businesses that interact with government agencies, participate in public procurement, or operate in regulated industries, these developments are likely to increase compliance expectations even before new legal requirements are formally introduced.

Key Policy Developments:

The government’s anti-bribery initiatives contemplate a more integrated approach to corruption prevention through digital technologies and inter-agency cooperation. Key initiatives include:

  • Integration of financial, tax, and public procurement data across government agencies.
  • Greater public disclosure of government information through centralized digital platforms.
  • Expansion of end-to-end digital government services to reduce discretionary human interaction.
  • Use of data analytics and risk assessment tools to identify suspicious transactions and detect corruption proactively.
  • Consideration of incentive mechanisms to encourage greater private-sector participation in anti-corruption efforts.

Although these initiatives primarily reflect policy direction, they are consistent with Thailand’s broader digital government strategy and increasing reliance on technology to strengthen regulatory oversight.

Practical Implications for Businesses:

Businesses should anticipate that government agencies will increasingly be able to cross-reference information obtained from different regulatory systems. As digital integration expands, inconsistencies or unusual transaction patterns may become more visible.

Particular attention should be paid to:

Increased Cross-Database Verification:

Payments, tax filings, procurement records, licensing information, and other regulatory submissions may increasingly be compared across multiple government databases. Information that previously existed in separate systems may become easier for authorities to analyze collectively.

Higher Scrutiny of Third-Party Relationships:

Transactions involving consultants, agents, brokers, intermediaries, subcontractors, and other third parties are likely to attract greater regulatory attention. Authorities may increasingly examine whether such arrangements serve legitimate business purposes or could conceal improper payments or undisclosed benefits.

Enhanced Documentation of Business Hospitality and Related Expenditures:

Corporate hospitality, gifts, sponsorships, charitable contributions, travel expenses, and any facilitation-type payments should be supported by clear business justifications, documented approval processes, and appropriate accounting records. Well-documented decision-making will become increasingly important if government agencies rely on integrated digital records during investigations.

Greater Focus on Third-Party Due Diligence:

Businesses should expect growing emphasis on robust third-party risk management, including:

  • Appropriate due diligence before engaging intermediaries;
  • Verification of beneficial ownership where appropriate;
  • Ongoing monitoring of higher-risk business partners; and
  • Documentation demonstrating that compensation arrangements are commercially reasonable.

Recommended Compliance Actions:

Even in the absence of new mandatory legal obligations, organizations should consider reviewing whether their anti-corruption compliance framework remains appropriate for an increasingly data-driven enforcement environment.

Areas for review include:

  • Anti-bribery and anti-corruption policies;
  • Approval matrices for gifts, entertainment, sponsorships, donations, and government-related expenditures;
  • Conflict-of-interest declaration procedures;
  • Gift and hospitality registers;
  • Third-party due diligence procedures;
  • Beneficial ownership verification processes;
  • Record-keeping and supporting documentation standards; and
  • Whistleblowing channels and internal investigation procedures.

Particular attention should be given to employees who regularly interact with government officials, including sales personnel, business development teams, procurement staff, regulatory affairs personnel, and employees responsible for obtaining government approvals or participating in public procurement.

Looking Ahead:

The government’s continued investment in digital infrastructure suggests that anti-corruption enforcement may increasingly rely on data integration and analytical tools rather than solely on traditional investigations or complaints. As government agencies gain greater ability to connect information across multiple regulatory systems, businesses should expect higher standards of transparency, documentation, and governance.

Organizations that strengthen their compliance controls now will be better positioned to respond to increased regulatory scrutiny and demonstrate effective anti-bribery compliance as Thailand’s digital government initiatives continue to evolve.

Key Takeaways:

Businesses should review their anti-bribery policies, third-party due diligence procedures, conflict-of-interest controls, gift registers, and whistleblowing mechanisms to ensure they remain effective in an increasingly digital regulatory environment.

Government agencies are moving toward greater integration of financial, tax, procurement, and regulatory data.

Cross-agency data sharing is likely to increase the detection of inconsistent or high-risk transactions.

Third-party relationships, including consultants, agents, brokers, and subcontractors, are expected to receive greater scrutiny.

Gifts, hospitality, sponsorships, charitable contributions, and other government-related expenditures should be supported by clear documentation and approval records.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand and China Strengthen Cooperation on IP Enforcement

The Thai Cabinet has approved a draft Memorandum of Understanding (MOU) between the Ministry of Commerce of Thailand and China’s market regulatory authority to strengthen cooperation on intellectual property enforcement.

The proposed cooperation framework includes information sharing, coordination on IP enforcement, and cooperation in training and capacity building for enforcement officials. The MOU is intended to facilitate closer administrative cooperation between the two authorities and enhance enforcement effectiveness against IP infringement.

Practical implications for businesses:

The MOU does not create a mechanism allowing rights holders to file cross-border enforcement requests directly or alter existing enforcement procedures in either jurisdiction. Nevertheless, it reflects a policy direction toward closer administrative cooperation between Thailand and China.

Businesses that manufacture, distribute, or sell products in China, particularly through e-commerce platforms, should consider strengthening their cross-border IP enforcement strategy by:

  • ensuring that trademarks, patents, and other IP rights are separately registered in China, as protection in Thailand does not extend automatically to China;
  • maintaining evidence of ownership and use of IP rights, distribution channels, and suspected counterfeit products;
  • reviewing agreements with manufacturers, distributors, and online platform operators to ensure adequate IP protection and enforcement provisions; and
  • considering customs recordation and online takedown procedures as part of an integrated enforcement strategy, alongside civil or administrative actions where appropriate.

The development is particularly relevant for brand owners in consumer goods, fashion, cosmetics, food and beverage, and businesses that rely heavily on cross-border e-commerce.

Key takeaways:

Although the proposed MOU does not introduce new legal remedies for rights holders, it signals stronger institutional cooperation between Thai and Chinese enforcement authorities. Businesses with commercial activities in China should ensure that their IP portfolios and enforcement strategies are prepared to take advantage of enhanced cross-border administrative coordination as it develops

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles