Breaking Down Government Data Silos: New Rules on Inter-Agency Sharing of Personal Information

A new Royal Decree has established a legal framework requiring government agencies to share personal information under their control with other government agencies for specified electronic data-linkage purposes.

The Royal Decree on Disclosure of Personal Information Controlled by Government Agencies to Other Government Agencies B.E. 2569 (2026) (the “Royal Decree”) represents an important development in the government’s efforts to move away from fragmented, agency-specific databases toward greater interoperability of public-sector information.

The measure is intended to enable government agencies to use more complete and accurate information in policymaking, public services and targeted welfare programs, while reducing the burden on individuals of repeatedly submitting information already held by the government. The framework is also intended to contribute to greater transparency and more effective law enforcement.

Legal basis for inter-agency disclosure:

The Royal Decree is issued pursuant to Section 24(9) of the Official Information Act B.E. 2540 (1997).

Section 24 of the Official Information Act establishes, as a general rule, that a government agency may not disclose personal information under its control to another government agency or another person without the prior or contemporaneous written consent of the person concerned, subject to specified statutory exceptions.

Section 24(9) permits disclosure in other cases prescribed by Royal Decree.

The new Royal Decree uses this statutory mechanism to provide a specific legal basis for government-to-government disclosure of personal information falling within its scope. As a result, qualifying disclosure under the Royal Decree does not depend on obtaining the individual’s written consent on each occasion.

This is important because large-scale government data interoperability would be difficult to implement if each transfer of information between government agencies required separate consent from every affected individual.

From isolated databases to connected government:

The policy underlying the Royal Decree is broader than simply permitting one government agency to send information to another.

Government agencies hold significant amounts of information about individuals, but that information has traditionally been maintained within separate administrative systems. Where relevant information is distributed among different agencies, the government may not have ready access to the complete information required for policymaking, public services or welfare administration.

The Royal Decree is intended to address this fragmentation by enabling electronic linkage of personal information held across government agencies.

The stated objectives include allowing government policies and measures, government services and targeted welfare programs to be based on accurate and complete information. Greater data linkage is also intended to improve the efficiency of government services, reduce administrative burdens on the public, promote transparency and enhance the effectiveness of law enforcement.

In practical terms, the framework supports a move toward the principle that individuals should not continually be required to provide one government agency with information that is already held by another government agency where the conditions for lawful data linkage are satisfied.

Government agencies may be required to disclose information:

A significant feature of the Royal Decree is that it does not merely provide government agencies with a general permission to share personal information.

It establishes a framework under which a government agency controlling personal information must disclose that information to another government agency where the information is requested for purposes falling within the Royal Decree.

The relevant data linkage is intended to support the preparation and provision of government services and the provision of targeted welfare through electronic means.

This gives the Royal Decree practical significance beyond an ordinary exception to a confidentiality rule. It provides the legal infrastructure for systematic government data interoperability.

The receiving agency also assumes obligations:

Greater availability of government-held information is accompanied by safeguards.

A government agency requesting and receiving personal information must safeguard that information. Importantly, it may not further disclose the information to an outside person.

This restriction is an important limitation on the scope of the new regime. The Royal Decree should therefore not be understood as making personal information freely transferable simply because it has entered an interconnected government information system.

The legal authorization concerns disclosure within the framework established by the Royal Decree. Once information has been received, the recipient agency remains responsible for protecting it and complying with the restrictions applicable to its subsequent disclosure.

The required safeguards are also linked to criteria and conditions prescribed by the competent authority and cybersecurity requirements. Consequently, implementation of the Royal Decree is as much an information-governance issue as a data-access issue.

Targeted welfare and government services:

One of the clearest practical applications of government data linkage is the provision of targeted welfare.

Eligibility for government assistance may depend on information maintained by several different authorities. Without data linkage, individuals may have to obtain documents from one agency and submit them to another, while the agency administering the benefit may have difficulty independently establishing a complete picture of the applicant’s circumstances.

Electronic linkage can potentially change this process.

Where legally permitted, the administering agency may obtain relevant information directly from government data already available elsewhere. This can make eligibility assessment more accurate, reduce duplicate documentation and enable welfare programs to be directed more effectively toward intended recipients.

The same principle can apply more broadly to government services. Greater interoperability can reduce repeated requests for information and allow government agencies to make administrative decisions using more complete information.

Transparency and law enforcement:

The Royal Decree also has implications beyond welfare and administrative services.

The stated rationale includes increasing transparency within government and improving the effectiveness of law enforcement. Information that appears unremarkable when held in a single agency’s database may have greater significance when lawfully linked with information held by other agencies.

Inter-agency data linkage can therefore provide government authorities with a more complete information base for identifying inconsistencies, verifying information and carrying out their statutory functions.

This capability may be particularly relevant where investigations or enforcement activities require information held by several government bodies.

However, the Royal Decree should not be characterized as creating a general law-enforcement database or an unrestricted investigative power. Its significance lies in providing a statutory mechanism for disclosure and electronic data linkage within the scope established by the Royal Decree.

Data sharing does not mean unrestricted data use:

An important compliance point is the distinction between access to information and freedom to use or disclose that information.

The fact that one government agency is legally entitled to obtain information from another does not mean that information becomes unrestricted once transferred.

Government agencies implementing data-linkage arrangements should therefore consider controls covering at least:

  • the authority and purpose for requesting information;
  • identification of the information required;
  • authentication of requesting agencies and authorized personnel;
  • access controls within the receiving agency;
  • secure electronic transmission;
  • logging and traceability of access and transfers;
  • cybersecurity safeguards;
  • retention and management of linked information; and
  • controls preventing unauthorized onward disclosure.

These controls are particularly important because increased interoperability can increase the consequences of inadequate security. A weakness in one interconnected system may potentially expose information originating from several agencies.

Relationship with personal data protection requirements:

The Royal Decree should also be understood within the broader legal framework governing personal information.

Its immediate statutory basis is the Official Information Act, and it establishes a specific mechanism permitting inter-agency disclosure that would otherwise be subject to the restrictions in Section 24 of that Act.

However, the existence of a statutory basis for disclosure should not automatically be equated with unlimited authority to process the information for any subsequent purpose.

Government agencies participating in data-linkage arrangements should therefore identify the legal authority supporting each stage of the information lifecycle—including collection, disclosure, receipt, use, retention, security and any subsequent disclosure—and consider other applicable personal data protection and cybersecurity requirements.

The distinction is particularly important as government systems become increasingly interconnected. Legal authority to receive information is only one component of lawful and responsible data governance.

A significant step toward data-driven government:

The Royal Decree represents a structural change in the management of government-held personal information.

The traditional model in which each government agency maintains its own information and individuals repeatedly provide substantially the same information to different authorities is increasingly being replaced by a model based on controlled interoperability.

If implemented effectively, the new framework should enable government agencies to make greater use of information already available within the public sector, improve the accuracy of public services and welfare programs, and reduce unnecessary administrative burdens on individuals.

The corresponding challenge is governance.

The more effectively government information systems are connected, the more important it becomes to ensure that access is authorized, purposes are properly defined, information is adequately protected and subsequent disclosure remains controlled.

The Royal Decree therefore represents not simply an expansion of government access to data, but a move toward a more integrated model of public-sector data governance.

Key Takeaways:

  • The Royal Decree marks an important shift from government data held in separate institutional silos toward controlled, interoperable public-sector data infrastructure.
  • The Royal Decree establishes a statutory mechanism for the disclosure of personal information between government agencies for qualifying electronic data-linkage purposes.
  • Its legal basis is Section 24(9) of the Official Information Act, which allows exceptions to the general restriction on disclosure of government-controlled personal information without written consent.
  • The framework goes beyond merely permitting voluntary data sharing and supports systematic interoperability between government information systems.
  • A government agency receiving information under the framework must safeguard the information and is restricted from further disclosure to an outside person.
  • The framework is intended to support more accurate policymaking, more efficient government services and targeted welfare, reduced administrative burdens on the public, greater transparency and more effective law enforcement.
  • Government agencies should not treat authorization to receive information as unrestricted authority to use or further disclose it. Purpose limitation, access controls, cybersecurity and information governance remain central to implementation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

From Voluntary Guidance to Legal Accountability: The Changing Rules for Digital Platforms

Digital platform regulation is entering a new phase. Recent developments indicate a shift from a framework centered largely on registration, disclosure, and risk management toward a more substantive model addressing platform conduct, seller accountability, fee transparency, and potentially the allocation of liability between platforms and businesses operating through them.

Two developments illustrate this direction particularly well. The first is the proposed Digital Platform Economy Act, which is being developed as a broader statutory framework for the platform economy. The second is the Electronic Transactions Development Agency (ETDA) Guideline on Transparency and Fairness in Digital Platform Service Fees, which establishes voluntary best practices for the disclosure and adjustment of platform fees. Although the guideline is not mandatory and the proposed Act has not yet been enacted, considered together they provide a useful indication of the regulatory principles increasingly shaping oversight of digital platforms: transparency, fairness, accountability, and greater protection for users and consumers.

A New Regulatory Framework for Digital Platforms:

Digital platform services are currently regulated under the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification. The existing regime establishes notification requirements and imposes various obligations depending on the nature, size, and risk profile of a platform. The proposed Digital Platform Economy Act would represent a significant further development. The government has accelerated work on the legislation, with the current policy timetable contemplating submission to the Cabinet before the draft proceeds to Parliament. As the legislation remains under development, however, both its provisions and legislative timetable remain subject to change.

The emerging framework indicates several areas that platform operators should monitor closely. These include registration and disclosure of information concerning platform operations and revenue, as well as measures intended to give regulators greater visibility over businesses participating in the platform economy. Territorial scope will be particularly important for multinational businesses, since a platform providing services into the local market may potentially become subject to regulatory requirements even where the operator does not have a conventional physical presence in the jurisdiction.

Another important area concerns businesses and individuals offering goods or services through platforms. The regulatory direction increasingly places platforms in the position of gatekeepers rather than merely passive intermediaries. Existing regulatory measures already require certain platforms to obtain and verify seller information and implement risk-management measures concerning goods and services offered through their systems. The proposed legislation appears likely to develop this approach further, making seller onboarding, identity verification, record keeping, monitoring, and enforcement increasingly important compliance functions rather than merely commercial processes.

The Emerging Question of Platform Liability:

Perhaps the most significant issue to monitor is the extent to which a platform may bear responsibility for harm arising from transactions conducted through its service. Platform operators have traditionally characterized themselves as intermediaries connecting independent sellers with customers, and their terms and conditions commonly distinguish the platform from the seller responsible for the underlying goods or services.

The proposed regulatory approach may reduce the practical significance of that distinction. Discussions surrounding the Digital Platform Economy Act contemplate circumstances in which platforms could bear joint responsibility for consumer harm, particularly where the platform fails to perform duties imposed on it. The precise scope of any liability will depend on the final statutory language, including the conduct that triggers liability, available defenses, and the relationship between the new regime and existing consumer protection laws.

If enacted broadly, such liability could materially alter the allocation of risk in the platform economy. Seller verification and monitoring would no longer be viewed simply as regulatory procedures; they could become directly relevant to a platform’s financial exposure when consumers suffer loss. Contractual provisions placing responsibility on sellers, including indemnities, may remain important but would not necessarily protect a platform from independent statutory liability. Platform operators should therefore monitor the liability provisions particularly closely as the draft progresses.

Fee Transparency and Fairness:

While the proposed Act represents the potential development of mandatory statutory obligations, ETDA has adopted a softer regulatory approach to another significant platform issue: fees. Its Guideline on Transparency and Fairness in Digital Platform Service Fees is intended as voluntary best practice rather than direct price regulation. The guideline does not prescribe maximum commissions or other charges. Instead, it focuses on whether users can understand what they are being charged, what services they receive in return, and how changes to those charges are made.

Platforms are encouraged to present fee information clearly and in an accessible manner, including an explanation of individual fee items, the services or benefits associated with them, and the basis or method used to calculate the charges. This is particularly relevant where the actual cost of participating on a platform extends beyond a headline commission and may include advertising, promotional, affiliate, payment-related, or other service fees. The regulatory concern is therefore not simply whether a particular commission is high or low, but whether users can reasonably determine and evaluate the overall economic cost of using the platform.

The guideline also addresses changes to platform fees. It recommends that users receive at least 15 days’ advance notice of fee changes, together with information concerning the reason for the change, its scope and potential impact, and channels for inquiries or feedback. The guideline also contemplates a consultation process in connection with fee changes. Platforms should therefore distinguish between merely notifying users that a fee will change and maintaining a process that reflects the broader principles of transparency, consultation, and fairness contemplated by the guideline.

Fairness extends beyond disclosure. Platforms are encouraged to avoid unnecessary duplication of charges and to distinguish clearly between compulsory fees and charges for additional services. Optional services should correspond to genuine additional benefits rather than becoming effectively mandatory through the design or operation of the platform. The objective is not direct government control of platform pricing, but a framework in which platforms can explain how fees are determined and users can understand the true costs of participating in the platform ecosystem.

From Voluntary Guidance to Legal Accountability:

Considered separately, the proposed Digital Platform Economy Act and the fee guideline address different regulatory issues. Considered together, however, they reveal a broader trajectory. The fee guideline represents soft regulation, under which regulators articulate expectations concerning fair market conduct and encourage platforms voluntarily to incorporate those principles into their business practices. The proposed legislation points toward harder regulatory intervention, potentially involving registration, disclosure, seller verification, statutory duties, enforcement mechanisms, and greater responsibility for consumer harm.

This distinction is important for businesses. Voluntary guidance should not necessarily be treated as irrelevant simply because it does not create directly enforceable obligations. Such guidance may establish regulatory expectations concerning reasonable industry conduct, identify practices receiving regulatory scrutiny, and indicate areas in which more formal intervention could eventually follow if voluntary measures prove insufficient.

The broader development is therefore not simply an increase in the number of rules applicable to digital platforms. It reflects a gradual change in the regulatory conception of the platform itself. As platforms exercise greater control over seller admission, product visibility, payment mechanisms, fees, and transactions, regulators increasingly expect them to accept corresponding responsibilities for how those ecosystems operate.

Preparing for the Next Stage of Platform Regulation:

Platform operators need not wait for the proposed legislation to be enacted before reviewing their compliance architecture. Seller onboarding and verification procedures should be assessed to determine what information is collected, how identities and business credentials are verified, how information is updated, and what happens when inaccurate information or unlawful activity is detected. Systems should also retain sufficient records to demonstrate that verification, monitoring, complaints, and enforcement procedures have actually been followed.

Fee structures warrant similar attention. Platforms should consider whether users can readily identify the overall economic cost of using their services and whether compulsory fees, optional services, promotional charges, advertising costs, and other charges are adequately explained. Procedures for changing fees should also be reviewed against the transparency, advance-notice, and consultation principles reflected in ETDA’s guideline.

Finally, contractual arrangements with sellers should be considered together with operational compliance. If the new legislation imposes independent statutory duties on platforms, contractual provisions allocating responsibility entirely to sellers may have limited effect against claims brought directly against the platform. Indemnities, suspension rights, seller information obligations, insurance arrangements, record keeping, and mechanisms for recovering losses should therefore form part of a broader risk-management framework rather than being treated as substitutes for regulatory compliance.

Key Takeaways:

  • Digital platform regulation is moving beyond registration and disclosure toward greater operational accountability.
  • The proposed Digital Platform Economy Act may expand requirements concerning platform registration, business information, seller verification, platform conduct, and consumer protection. Its final provisions should be monitored as the legislative process progresses.
  • Potential joint liability for consumer harm may be one of the most significant developments because it could alter the traditional allocation of responsibility between platforms and independent sellers.
  • ETDA’s fee guideline remains voluntary and does not constitute direct price regulation, but it establishes regulatory expectations concerning fee transparency, fairness, advance notice, and consultation.
  • Platform operators should consider reviewing seller verification, monitoring, fee disclosures, change-management procedures, contractual risk allocation, and record-keeping systems before the new statutory framework is finalized.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand-Australia Strategic Partnership 2026–2029: Advancing Cybersecurity, Economic Resilience, Cross-Border Crime Cooperation, and Support for SMEs and Startups

Earlier, Thailand’s Cabinet approved the Joint Plan of Action to Implement the Thailand-Australia Strategic Partnership for 2026–2029. The four-year framework succeeds the 2022–2025 Plan and will be signed during the Thai Prime Minister’s official visit to Australia on 17–20 August 2026. It reaffirms the Strategic Partnership elevated in 2020 and provides a practical roadmap for cooperation across five pillars: political and security affairs; economic and trade relations; sectoral collaboration; people-to-people links; and regional and sub-regional engagement (including ASEAN, the Mekong, and the Indo-Pacific).

Two accompanying Joint Statements—one on combating transnational crime and one on strengthening economic cooperation—were approved in parallel. Together they signal a pragmatic, results-oriented deepening of ties with direct relevance for businesses, technology firms, and innovation ecosystems in both countries.

Cybersecurity and Digital Cooperation within the Security Pillar:

The political and security pillar explicitly covers defense cooperation, non-traditional security challenges (including cyber), good governance, and critical technologies. This builds on the existing Memorandum of Understanding on Cyber and Digital Cooperation between Thailand’s Ministry of Digital Economy and Society and Australia’s Department of Foreign Affairs and Trade. That MoU promotes information exchange, best-practice sharing on cybersecurity strategies and laws, protection of critical infrastructure, and a secure, open internet that supports digital trade and innovation.

The new Plan is expected to operationalize these commitments further, creating opportunities for Australian cybersecurity providers, Thai digital-security firms, and joint public-private initiatives focused on threat intelligence, capacity building, and resilience of critical infrastructure. In a region facing rising cyber risks, closer bilateral alignment also strengthens Thailand’s position within ASEAN and Indo-Pacific cyber frameworks.

Joint Statement on Transnational Crime: Targeting Online Scams and Related Threats

The dedicated Joint Statement on combating transnational crime prioritizes online scams/fraud, narcotics trafficking, human trafficking, and money laundering. Cooperation will proceed through bilateral channels and ASEAN mechanisms. This reflects the reality that sophisticated cyber-enabled crime—particularly large-scale online investment and romance scams operating from the region—has become a shared security and economic threat.

Existing operational links between the Royal Thai Police and the Australian Federal Police, including intelligence sharing and joint operations against cybercrime and financial crime networks, provide a foundation. The new Statement is likely to expand structured coordination, capacity building, and disruption of illicit financial flows. For the private sector this translates into stronger expectations around know-your-customer and anti-money-laundering compliance, potential public-private partnerships on fraud detection, and reduced exposure of legitimate businesses and consumers to scam ecosystems.

Economic and Trade Pillar: Resilience, Clean Energy, and Multilateral Trade:

The economic pillar emphasizes growth, resilient supply chains capable of withstanding global volatility, the clean-energy transition, and a robust multilateral trading system. It sits alongside long-standing instruments—the Thailand-Australia Free Trade Agreement (TAFTA), the Regional Comprehensive Economic Partnership (RCEP), and the Strategic Economic Cooperation Arrangement (SECA), which was renewed in late 2025 through 2028.

Two-way goods and services trade reached approximately A$32.4 billion in 2025, underscoring the commercial weight of the relationship. The Plan and the parallel Joint Statement on economic cooperation are expected to facilitate further trade facilitation, agricultural collaboration, and digital-economy linkages while supporting diversification of supply chains.

Opportunities for SMEs and Startups:

Although the full Plan has not yet been published in detail, official summaries highlight support for startups and SMEs, particularly through science, technology, innovation, and digital cooperation. This continues themes already present in the original Strategic Partnership Declaration, which called for extensive digital-economy collaboration to accelerate business growth, including for startups and SMEs, and to develop a digital-ready workforce.

Sectoral cooperation under the Plan spans agriculture, education, climate action, energy, infrastructure, science and innovation, public health, environment, disaster management, and gender equality/social welfare. For technology-oriented SMEs and startups these areas open concrete avenues:

•  Digital and cyber solutions for agriculture, supply-chain resilience, and clean-energy systems.

•  Innovation partnerships, research collaboration, and technology transfer with Australian counterparts.

•  Access to capacity-building, skills development, and potential co-investment or market-entry support under SECA and related mechanisms.

•  Participation in people-to-people exchanges that build networks and talent pipelines.

Australian firms offering cybersecurity tools, digital platforms, agritech, cleantech, or fintech solutions, and Thai startups seeking capital, technology, or export pathways to Australia and the broader Indo-Pacific, stand to benefit from the clearer policy framework and high-level political endorsement.

Looking Ahead

The Joint Plan of Action is a political framework rather than a legally binding treaty. Its value will be realized through concrete projects, dialogues, and private-sector engagement after the formal signing in mid-August 2026. Businesses and legal practitioners should monitor implementing arrangements under the cyber MoU, SECA work programs, and any new working groups on digital economy, innovation, or transnational crime.

For companies operating at the intersection of technology, trade, and compliance, the 2026–2029 Plan reinforces Thailand-Australia cooperation as a practical platform for managing cyber risk, building resilient commercial relationships, and accessing opportunities in a strategically important bilateral partnership.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Moves Toward a Dedicated Regulatory Framework for Data Centers

Thailand may soon take a significant step toward regulating its rapidly expanding data center industry. According to recent reports, the government is preparing a Prime Minister’s Office Regulation that would establish a dedicated framework for overseeing data center operations, with particular emphasis on resource management, environmental impacts, and centralized regulatory oversight. While the proposed regulation has not yet been issued, it signals a potential shift from Thailand’s current investment-driven approach toward a more comprehensive regulatory model for the sector.

Background:

Thailand has become an increasingly attractive destination for data center investment due to strong government incentives, growing cloud adoption, and its strategic location in Southeast Asia. However, the rapid expansion of large-scale facilities has also raised concerns regarding infrastructure capacity, particularly electricity and water consumption.

According to the reported proposal, the government intends to introduce a dedicated regulatory mechanism to better coordinate oversight of the industry and manage its broader impacts on national resources.

Proposed regulatory framework:

The reported proposal indicates that the Prime Minister’s Office Regulation would establish a new committee responsible for supervising data center activities. Its responsibilities would reportedly include:

  • overseeing the overall development of the data center industry;
  • assessing the impacts of data center investments;
  • monitoring resource consumption, particularly electricity and water usage;
  • coordinating regulatory oversight among relevant government agencies; and
  • supervising approvals, permits, and compliance monitoring.

Although further details have not yet been published, the proposal suggests that the government intends to create a more centralized oversight structure than currently exists.

Addressing fragmented regulation:

At present, data center projects typically interact with multiple government agencies depending on the nature of the project. Investors may require approvals or incentives from different authorities, while utility arrangements are often negotiated separately.

The reported proposal appears intended to address this fragmented regulatory landscape by introducing a dedicated governance mechanism specifically focused on data centers.

Greater focus on infrastructure and resource management:

A notable feature of the proposal is its emphasis on resource planning.

According to the reports, the government has identified several concerns, including:

  • increasing electricity demand from large-scale data centers;
  • substantial water consumption required for cooling systems;
  • challenges in forecasting future resource demand; and
  • overlapping arrangements for water supply that may complicate national infrastructure planning.

The proposal therefore appears to reflect a policy objective of integrating data center development with broader infrastructure and environmental planning rather than regulating the industry solely from an investment perspective.

Different treatment for existing and future projects:

The reported framework would distinguish among three categories of data centers:

Existing operating facilities

Existing operators may become subject to audits or assessments focusing on matters such as resource consumption, temperature management, and noise impacts.

Approved projects under development

Projects that have already received approvals but are not yet operational may be required to comply with additional regulatory conditions before commencing operations.

Future applicants

New projects may become subject to a comprehensive regulatory regime addressing matters such as:

  • sustainable water management;
  • reserve water sources;
  • environmental impacts; and
  • measures designed to reduce adverse impacts on surrounding communities.

This tiered approach suggests that the government is seeking to avoid disrupting ongoing investments while progressively strengthening regulatory requirements for future developments.

Potential changes to location planning:

The reports also indicate that the government is considering a more strategic approach to determining where future data centers should be located.

Rather than concentrating additional facilities in existing investment hubs, policymakers are reportedly evaluating locations with stronger electricity and water infrastructure, including areas near major power generation facilities. The government has also indicated that supporting digital infrastructure, such as fiber-optic networks, could be expanded if new data center clusters are developed.

What investors should watch:

Although the proposal remains at the policy stage, investors and operators should monitor several issues as the framework develops:

  • the legal authority under which the new committee will operate;
  • whether additional licensing or approval requirements will be introduced;
  • technical standards relating to electricity, water use, and environmental impacts;
  • transitional requirements applicable to existing operators; and
  • the interaction between the new framework and existing approvals issued by sector-specific regulators.

The final regulatory approach will determine whether the proposed framework primarily serves as a coordination mechanism or introduces substantive compliance obligations for the industry.

Key takeaways:

  • Thailand is reportedly preparing a dedicated regulatory framework for data centers through a proposed Prime Minister’s Office Regulation.
  • The proposal reflects increasing government attention to electricity consumption, water usage, and environmental impacts associated with large-scale data center investments.
  • A new committee may be established to coordinate oversight of approvals, compliance, and resource management.
  • Existing facilities, projects under development, and future investments could become subject to different regulatory requirements.
  • Although the proposal has not yet been formally issued, investors planning data center projects in Thailand should closely monitor further regulatory developments, as they may significantly affect project planning, compliance obligations, and site selection.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Parliament Considers Carbon-Credit Sales from Community Forests

A member-sponsored bill before Parliament could provide a clearer statutory basis for the sale of carbon credits generated from community forests. The Draft Community Forest Act Amendment was proposed by members of the House of Representatives, and its official description identifies its purpose as adding provisions concerning the sale of carbon credits. The proposal is currently undergoing public consultation under Section 77 of the Constitution and is not yet binding law. It remains subject to the legislative process and may be revised before enactment.

The proposal is nevertheless significant because community-forest carbon-credit activities already exist in practice, while the Community Forest Act was principally designed to regulate community participation in forest conservation, restoration, management, and sustainable use rather than transactions in carbon assets. The amendment should therefore not be understood as creating community-forest carbon projects for the first time. Its significance lies in seeking to place the sale of carbon credits more expressly within the statutory framework governing community forests.

Ownership, authority, and community approval:

One of the most important issues is the legal entitlement to carbon credits generated from a community forest. Ownership or control of the underlying land, statutory rights to manage the forest, responsibility for maintaining carbon stocks, entitlement to register a carbon project, and ownership of the resulting carbon credits are not necessarily the same thing. For project developers and purchasers, the relevant question is therefore not simply whether credits have been issued under a recognized carbon program, but whether the seller has a sufficient legal basis to claim and transfer them.

Closely related is the question of who has authority to approve a carbon project and sell the resulting credits. Community forests operate through statutory community-management structures, while carbon projects may involve commitments extending over many years. Project agreements may cover project registration, monitoring and verification, responsibility for development costs, allocation of credits, exclusivity, forest-management obligations, sale of credits, and distribution of revenues. The authority of the community representatives entering into those arrangements is therefore important, particularly where a developer is granted long-term or exclusive rights.

The final legislation will also need to be considered carefully in relation to community approval. A decision to enter into a long-term carbon project may have consequences extending beyond ordinary forest management, particularly where future carbon revenues or carbon rights are committed to a private developer. Any statutory requirements concerning community meetings, resolutions, voting, disclosure, or government approval could therefore become relevant not only to regulatory compliance but also to the validity and bankability of the project.

Revenue allocation and project agreements:

Benefit sharing will be another central issue. Community-forest carbon projects already operate against a background of administrative arrangements dealing with carbon-credit revenues and community benefits, so the proposed amendment will need to be read together with the existing framework. An important point to watch is whether the amended Act itself establishes principles for allocating proceeds from carbon-credit sales or leaves the details to subordinate regulations.

The commercial implications are substantial. Developers may bear the costs of feasibility studies, project design, carbon measurement, registration, verification, monitoring, and financing, while communities provide the forest stewardship and management activities on which the carbon benefits depend. Project-development agreements therefore need to deal clearly with project costs, entitlement to issued credits, authority to market and sell those credits, allocation of revenues, reporting obligations, and the duration of the developer’s rights. They should also address the particular risks of forest-carbon projects, including fire, illegal logging, natural disasters, changes in forest management, and other events that may reduce credit generation or result in carbon reversal.

If the amendment introduces mandatory rules on approval, sales, or benefit sharing, existing contractual models may need to change. Developers negotiating new projects should therefore avoid relying on broad provisions simply assigning all “carbon rights” to the developer without examining whether those rights can legally be granted, by whom, for what period, and subject to what approvals.

Existing projects and corporate purchasers:

The treatment of existing projects will be particularly important. Community-forest carbon projects may already be governed by agreements among communities, developers, government agencies, and other participants. If the amended Act introduces new requirements concerning authority, approval, sale, or revenue allocation, the question will be whether those requirements apply only to future projects or also affect existing arrangements. The final legislation and any transitional provisions should therefore be reviewed carefully. Existing agreements may also need to be assessed for change-in-law provisions and for clauses dealing with ownership and allocation of credits, exclusivity, benefit sharing, duration, and termination.

For companies purchasing community-forest carbon credits, a clearer statutory framework could improve legal certainty, but it should not replace transaction-level due diligence. Buyers should establish the legal status of the community forest, the authority through which the project was approved, compliance with applicable community and government approval requirements, the developer’s entitlement to the credits, applicable benefit-sharing arrangements, and whether the credits have previously been sold, allocated, pledged, or otherwise committed.

There is also an important distinction between carbon-program eligibility and legal entitlement to transact. Registration or issuance under a recognized carbon standard demonstrates compliance with the requirements of that program, but should not necessarily be regarded as conclusive evidence that all underlying questions of ownership, community authorization, or contractual authority have been resolved. This is especially relevant to long-term off-take arrangements for future credits, where the purchaser assumes project-development and regulatory risks in addition to ordinary delivery risk.

What to watch:

The proposal remains a member-sponsored parliamentary bill rather than a change in current law. Businesses should therefore not restructure existing projects on the assumption that it will be enacted in its present form. Its progress is nevertheless worth following because it addresses an increasingly important intersection between community forest management and the carbon market.

If enacted, a clearer statutory framework could strengthen the basis on which communities derive economic benefits from forest conservation, provide greater certainty for developers investing in community-forest carbon projects, and make the resulting credits easier for corporate purchasers to diligence. Much will depend on how the final legislation addresses ownership, authority to sell, community approval, revenue allocation, benefit sharing, and existing projects.

Key takeaways:

  • Corporate purchasers should examine the underlying legal entitlement to community-forest credits rather than relying solely on their registration or issuance under a carbon standard.
  • The proposed amendment was initiated by members of the House of Representatives and specifically addresses the sale of carbon credits from community forests. It is undergoing public consultation under Section 77 of the Constitution and is not yet binding law.
  • Community-forest carbon-credit activities already exist. The proposal is significant because it could provide a more express statutory foundation for the sale of those credits.
  • Carbon-credit ownership, authority to sell, and community approval are separate legal issues and will be important for both project structuring and buyer due diligence.
  • Project-development agreements may need to address statutory requirements concerning approval and benefit sharing, as well as project costs, allocation of credits, exclusivity, carbon-reversal risks, and changes in law.
  • Existing projects should monitor the final legislation and any transitional provisions to determine whether current contractual arrangements will need to be reviewed.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

United States Finalizes Section 301 Tariff Framework Based on Forced Labor Enforcement: Thailand Subject to a 12.5% Tariff

In our previous article (USTR Section 301 Forced-Labor Determinations: Implications for Thailand – The Legal Co., Ltd.), we discussed the U.S. Section 301 investigation involving approximately 60 trading partners, including Thailand, and Thailand’s response to the proposed tariff measures through trade negotiations and domestic regulatory reforms.

The Office of the United States Trade Representative (“USTR“) has now concluded that review, announcing the final tariff framework under Section 301 of the Trade Act of 1974 on 23 July 2026. The framework imposes additional tariffs ranging from 10% to 12.5% on imports from approximately 60 trading partners, effective from 24 July 2026.

Although Thailand actively participated in the consultation process and sought both a reduction in the proposed tariff rate and additional product-specific exemptions, it remains subject to the higher 12.5% tariff, which took effect immediately upon the expiry of the preceding tariff measures.

The final framework is significant not only for the additional tariffs it introduces, but also for what it signals: the United States’ continued use of trade policy as a lever to address forced labor concerns and to encourage stronger labor standards and supply chain governance among its trading partners.

Overview of the Final Tariff Framework

The final framework adopts a tiered approach, with tariff rates determined by the USTR’s assessment of each trading partner’s efforts to prevent goods produced using forced labor from entering the U.S. market.

  • 10% tariff — applies to countries that (i) already prohibit imports of goods produced using forced labor, (ii) have committed to implementing such measures through reciprocal trade arrangements, or (iii) have introduced measures offering some protection against such imports. Countries in this category include Argentina, Bangladesh, Cambodia, Canada, Ecuador, El Salvador, Guatemala, Honduras, India, Indonesia, Jordan, Malaysia, Mexico, Pakistan, Sri Lanka, Trinidad and Tobago, and the United Kingdom.
  • 12.5% tariff — applies to countries the United States considers not to have implemented sufficiently effective measures to prevent goods produced using forced labor from entering U.S. supply chains. Thailand falls within this category, alongside China, Hong Kong, Japan, the Philippines, Singapore, and Vietnam, among other trading partners.

According to the USTR, the final framework applies to trading partners representing approximately 99.4% of total U.S. imports. Certain products remain exempt, including oil, natural gas, and goods that cannot be sourced domestically in the United States.

Legal Significance

Beyond the tariff rates themselves, the legal basis for the framework carries equal significance.

According to publicly available reports, the United States introduced the final tariff framework after the U.S. Supreme Court ruled that tariffs previously imposed under emergency powers were unlawful. Rather than relying on those emergency powers, the U.S. government has instead invoked Section 301 of the Trade Act of 1974, which authorizes the USTR to act against foreign government policies or practices considered unfair or burdensome to U.S. commerce.

This development demonstrates that, notwithstanding new limits on the use of emergency powers, the United States continues to rely on existing trade legislation to pursue its broader trade policy objectives. It also reflects a growing trend in which labor standards, human rights, and supply chain governance are increasingly treated as matters of international trade compliance, rather than solely as corporate social responsibility or ESG considerations.

Business Implications

The practical implications of the final tariff framework extend beyond the tariffs themselves.

Businesses exporting to the United States — including manufacturers, suppliers, and other participants in global supply chains — should expect increased requests from customers and business partners to demonstrate that their products are free from forced labor and that appropriate due diligence has been conducted throughout the supply chain.

Businesses should therefore consider:

  • reviewing supplier due diligence procedures;
  • strengthening supply chain traceability;
  • maintaining documentation on product origin and manufacturing processes; and
  • monitoring developments in U.S. trade policy, as well as Thailand’s proposed Human Rights Due Diligence (HRDD) framework.

Taking these steps early may help businesses respond more effectively to evolving customer expectations, reduce compliance risk, and minimize disruption to cross-border trade.

Key Considerations for Businesses

The final tariff framework reinforces the growing convergence between international trade policy, labor standards, and supply chain governance. While the immediate consequence is the additional 12.5% tariff imposed on imports from Thailand, the broader implication is that businesses should expect increasing scrutiny of their supply chains and rising expectations around responsible sourcing and human rights due diligence.

Businesses with operations or supply chains connected to the United States should review their existing compliance programmers, strengthen supplier due diligence and traceability measures, and continue monitoring regulatory developments in both the United States and Thailand to remain prepared for evolving trade compliance requirements.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Tomorrowland Thailand 2026: Business Opportunities and Operational Readiness for Local Investors

WeAreOne.World (Thailand) Co., Ltd., a Thai-Belgian joint venture, has received investment promotion approval from the Board of Investment (BOI) to organize Tomorrowland Thailand, a world-class electronic dance music (EDM) festival. The event will take place at Wisdom Valley, Chonburi Province, from December 11 to 13, 2026, marking the festival’s first-ever edition in Asia and featuring a star-studded lineup of internationally renowned artists and DJs.

The project is a joint venture between TL International BV, a subsidiary of the Belgium-based Tomorrowland Group, and Thailand’s One Asia Ventures Co., Ltd. TL International BV brings more than two decades of experience organizing EDM festivals worldwide, while One Asia Ventures has produced major music events in Thailand.

All 50,000 daily tickets — 150,000 in total across the three-day event — have officially sold out. Over 85% of attendees, or approximately 127,500 people, are expected to be international visitors, led by primary markets including Malaysia (8.5%), Singapore (7.5%), and Australia (6.5%), alongside secondary markets in Europe (8%) and the United States (3.5%).

Benefits for Thai Business Operators and Local Investors

The festival is projected to generate 6.13 billion Baht (approximately EUR 159 million) in immediate economic value, with a potential contribution exceeding 21,386 million Baht over its planned five-year run (2026–2030). This positions Thailand as a global event hub, driving revenue across hotels, accommodation, restaurants, transportation, and regional service providers.

1. Tourism, Hotels, and Accommodation Ticket sales have already driven more than 22,000 ticket-and-accommodation package bookings, along with over 250 pre and post-festival travel itineraries designed to extend visitor stays by one to two weeks. These offerings are well positioned to capture high-spending, long-stay travelers, allowing Thailand’s tourism sector to fully benefit from the event.

2. Creative and Music Industry Government representatives anticipate long-term advantages for Thailand’s creative sectors. By bringing world-class staging, acoustics, lighting, and visual production technology to the country, the event will give local designers and crew hands-on experience with international-standard setups — supporting Thailand’s long-term capability to host major global events.

3. Local Suppliers and Service Providers (Direct Impact) Event organizers will procure and contract directly with Thai suppliers and service providers, with an allocated budget exceeding 1,092 million Baht (EUR 28 million). This spans production and infrastructure, food and beverage, workforce and staffing, logistics and transportation, hospitality, venue management, and other local services.

4. Retail, Restaurant, and Transport Sector (Indirect Impact) Local businesses stand to benefit from more than 5,309 million Baht (EUR 131 million) in indirect economic circulation, generated by visitor spending on retail, local travel, and extended stays in neighboring provinces.

5. Job Creation The festival is expected to generate up to 21,386 jobs across tourism, events, logistics, and hospitality, beginning with 1,900 positions in its first year, with priority given to Thai personnel. Knowledge-transfer initiatives — including a DJ Academy and Festival Academy — will further build local expertise in festival management.

Preparation for Thai Business Operators and Investors

To capitalize effectively on the capital circulation generated by Tomorrowland Thailand, local businesses should prepare across five key areas:

1. Service Standards and Multilingual Support With international visitors making up the majority of attendees, hotel, restaurant, and transport operators should train staff in English and key ASEAN languages, and ensure full integration of international payment gateways (credit cards, digital wallets, and e-payment systems).

2. Long-Stay Travel Packages As the event falls in December, many attendees are likely to extend their stay by one to two weeks. Tourism operators in Chonburi, Rayong, and surrounding provinces — including Bangkok and Chiang Mai — should develop experiential travel packages, airport transfer services, and premium programs tailored to high-spending travelers.

3. Supplier and Production Readiness Businesses in events, production, lighting, audio, logistics, F&B, and security should upgrade operational, hygiene, and safety standards to international levels to compete for direct-procurement subcontracts. Commercial agreements should be drafted clearly and enforceably to protect business interests.

4. Cross-Border Business and Contractual Readiness Businesses pursuing joint ventures, co-branding, or merchandise sales at the event should establish robust JV agreement structures and carefully review trademark licensing requirements to avoid intellectual property infringement.

5. Regulatory Compliance Operators should review all applicable laws for large-scale festival operations and establish clear compliance frameworks, including:

  • Food, Beverage, and Alcohol Control Laws: Temporary liquor sales permits must be obtained from the Excise Department for on-site sales points, with strict age-verification (20 years and older, as required by law).
  • Personal Data Protection Act (PDPA): Operators collecting customer data, using ticket or room scanning systems, or capturing photos/video for promotional use must provide proper privacy notices and implement valid consent mechanisms.

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

Integrating Cybersecurity, Fraud Response, and PDPA Compliance: Practical Implications of the Proposed Digital Channel Security Framework

The Bank of Thailand (BOT) has released a proposed Digital Channel Security framework that would strengthen expectations for authentication, fraud prevention, incident response, and the governance of digital financial services. While the proposal focuses primarily on enhancing the security and resilience of digital channels, financial institutions should not view these requirements in isolation.

In practice, a single cybersecurity incident frequently triggers multiple legal and regulatory obligations simultaneously. For example, an account takeover resulting from a phishing attack may require an institution to activate its cybersecurity incident response procedures, implement fraud mitigation measures, assess whether a personal data breach has occurred under the Personal Data Protection Act (PDPA), evaluate outsourcing or third-party service provider involvement, and make appropriate internal and regulatory notifications.

Although these obligations arise from different legal and regulatory sources, organizations may benefit from managing them through a coordinated incident response framework. This article examines the practical implications of the proposed BOT framework alongside existing obligations under the PDPA and broader operational governance practices.

From cybersecurity to operational resilience:

The proposed framework reflects an increasing regulatory emphasis on operational resilience rather than viewing cybersecurity solely as an information technology function. It places greater focus on preventing, detecting, responding to, and recovering from threats affecting digital financial services while maintaining the continuity and integrity of critical operations.

At the same time, financial institutions should recognize that cybersecurity incidents rarely occur in isolation. A single event may involve operational disruption, attempted fraud, compromise of customer credentials, unauthorized disclosure of personal data, and third-party service providers. As a practical matter, organizations may therefore benefit from adopting governance arrangements capable of addressing these interconnected risks through a unified response process.

Governance beyond information technology:

The proposed framework emphasizes that responsibility for digital channel security extends beyond information security teams.

Boards of directors and senior management are expected to establish appropriate governance, oversee digital risks, allocate adequate resources, monitor security performance, and ensure that significant incidents are escalated appropriately.

From a broader governance perspective, institutions should also consider ensuring that legal, compliance, privacy, operational risk, business continuity, and customer service functions are integrated into incident management processes. This cross-functional approach can help organizations address multiple regulatory obligations efficiently when significant incidents occur.

Fraud prevention as part of digital channel security:

The BOT proposal places significant emphasis on fraud prevention through enhanced digital channel security. Proposed measures include stronger customer authentication, monitoring of suspicious activities, behavioral analysis, device identification, protection against phishing and social engineering attacks, and mechanisms for responding to suspicious transactions.

These expectations primarily seek to reduce fraud risks affecting digital financial services. However, successful fraud attacks frequently have wider legal implications. Unauthorized access to customer accounts may also involve compromised personal data, contractual issues with service providers, customer remediation, and regulatory reporting obligations. Institutions should therefore consider integrating fraud response procedures into broader cybersecurity governance rather than treating fraud management as a separate operational function.

Incident response across multiple regulatory frameworks:

The proposed framework expects institutions to establish formal incident response procedures covering detection, escalation, containment, investigation, recovery, and post-incident review.

In practice, these procedures should also enable organizations to identify other legal and regulatory obligations that may arise from the same incident. Depending on the circumstances, an incident may require parallel consideration of fraud management, operational resilience measures, contractual obligations, outsourcing arrangements, and personal data protection requirements.

Developing coordinated response procedures may help reduce duplication of effort, improve decision-making, and ensure that regulatory obligations are addressed consistently across different functions.

Interaction with the Personal Data Protection Act:

The proposed BOT framework does not replace or modify existing obligations under the PDPA. Rather, the two regimes operate alongside one another.

Where a cybersecurity incident involves unauthorized access to, disclosure of, alteration of, or loss of personal data, organizations should assess their obligations under the PDPA independently of the BOT framework. This may include determining whether a personal data breach has occurred, evaluating notification obligations, preserving relevant evidence, documenting response measures, and implementing appropriate remediation.

Accordingly, organizations may wish to ensure that privacy officers, legal counsel, and cybersecurity teams participate jointly in incident response planning and tabletop exercises so that both operational and data protection considerations are addressed from the outset.

Third-party risk management:

Digital financial services increasingly depend on cloud service providers, payment processors, managed service providers, software vendors, and other external partners.

The proposed framework reinforces expectations regarding oversight of third-party service providers throughout the outsourcing lifecycle. Institutions should conduct appropriate due diligence, establish contractual security requirements, monitor vendor performance, and ensure that incident reporting and business continuity arrangements are clearly defined.

Because cybersecurity incidents involving third parties may also raise fraud and personal data protection issues, organizations should consider aligning vendor management processes with their broader incident response and compliance frameworks.

Documentation and evidence of compliance:

The proposed framework places considerable emphasis on governance, accountability, and demonstrating that appropriate controls are in place.

Organizations should maintain comprehensive records of cybersecurity governance, risk assessments, incident response activities, testing, training, vendor oversight, and business continuity exercises. From a broader compliance perspective, documentation should also support obligations arising under other applicable legal frameworks, including the PDPA and contractual commitments relating to outsourced services.

Maintaining complete records may facilitate regulatory engagement, internal investigations, and post-incident reviews while demonstrating that reasonable organizational and technical measures have been implemented.

Practical considerations:

As organizations prepare for the proposed framework, they may wish to assess not only technical cybersecurity controls but also how different compliance functions interact during a significant incident.

Areas for review may include:

  • governance and board oversight;
  • coordination among cybersecurity, legal, compliance, privacy, and operational teams;
  • fraud detection and response procedures;
  • customer authentication controls;
  • third-party risk management;
  • incident reporting and escalation processes;
  • documentation and recordkeeping; and
  • operational resilience testing and tabletop exercises.

An integrated approach may improve organizational readiness while reducing the risk that separate regulatory obligations are managed through disconnected processes.

Key takeaways:

  • The proposed BOT Digital Channel Security framework primarily addresses digital channel security, fraud prevention, governance, and operational resilience.
  • Existing obligations under the PDPA continue to apply independently where cybersecurity incidents involve personal data.
  • A single cyber incident may simultaneously trigger cybersecurity, fraud management, personal data protection, outsourcing, and operational governance obligations.
  • Although these obligations arise under different legal and regulatory frameworks, organizations may benefit from managing them through an integrated incident response framework.
  • Financial institutions should consider reviewing governance structures, cross-functional coordination, and documentation practices to improve operational resilience and regulatory compliance.

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

PDPA Insights: Building Effective Privacy Governance

PDPA: AI Is Not Replacing Privacy Law—It Is Changing How We Apply It

Artificial intelligence has rapidly become part of everyday business operations. Recommendation engines personalize online shopping experiences, chatbots answer customer enquiries, fraud detection systems identify suspicious transactions, recruitment platforms screen job applicants, and generative AI assists with customer service, marketing and document preparation.

As AI adoption accelerates, organizations frequently ask whether the Personal Data Protection Act (PDPA) contains special rules governing AI.

The answer is both simple and nuanced.

Thailand’s PDPA does not establish a standalone regulatory framework for artificial intelligence. Unlike some jurisdictions that have introduced AI-specific legislation, the PDPA remains technology neutral. The same legal principles governing all personal data processing—including lawfulness, purpose limitation, transparency, data minimization, security, and accountability—continue to apply regardless of whether personal data is processed manually or through sophisticated AI systems.

Nevertheless, the Personal Data Protection Committee’s (PDPC) recent consultation on marketing and direct marketing demonstrates that the regulator increasingly recognizes AI-assisted personalization, profiling, and automated decision-making as ordinary components of modern business operations rather than exceptional technologies. This signals an important evolution in regulatory expectations. The question is no longer whether AI falls within the scope of the PDPA. Instead, organizations should consider how existing privacy principles should operate when personal data is processed at unprecedented speed and scale.

AI changes the scale—not the legal principles:

One misconception is that AI requires an entirely new compliance framework.

In reality, the core legal questions remain familiar.

Why is personal data being processed?

Is there an appropriate legal basis?

Have individuals been informed?

Is the processing proportionate?

Are appropriate safeguards in place?

These questions existed before AI and remain the foundation of PDPA compliance.

What AI changes is the scale and complexity of those questions.

A marketing employee might manually analyze one hundred customer records to recommend products.

An AI system may analyze ten million records every day, continuously refining customer profiles and generating individualized recommendations without direct human intervention.

The legal principles remain the same.

The governance challenge becomes significantly greater.

Organizations should focus on the processing—not the technology:

Discussions about AI frequently focus on algorithms.

Privacy law focuses on personal data.

Organizations should therefore avoid beginning compliance discussions with technical questions such as:

“Are we using AI?”

Instead, they should ask:

“How is personal data being collected, analyzed, combined, retained and disclosed?”

This shift in perspective has practical consequences.

An AI system recommending products based upon purchasing history raises different privacy considerations from an AI system screening job applicants or detecting fraudulent transactions.

The technology may be identical.

The processing purposes are not.

Organizations should therefore evaluate each AI use case separately rather than adopting a single enterprise-wide conclusion regarding AI compliance.

Profiling is becoming an ordinary business activity:

One of the most significant aspects of the PDPC’s recent consultation is the inclusion of profiling alongside AI-assisted marketing and automated decision-making.

This reflects commercial reality.

Retailers profile customers to recommend products.

Banks profile spending behaviour to identify suitable financial services.

Hotels profile travel patterns.

Streaming platforms profile viewing preferences.

Insurance companies profile claims histories.

Profiling has become routine.

The regulatory focus is therefore shifting away from asking whether profiling exists toward examining whether organizations understand, govern and explain how profiling operates.

Transparency becomes particularly important where profiling materially influences commercial decisions affecting individuals.

Explainability is becoming a governance issue:

Many AI systems are capable of generating sophisticated outputs while providing limited insight into how those outputs were produced.

This creates a practical challenge.

Organizations may be able to explain what an AI system does without fully understanding why it reached a particular recommendation.

The PDPA does not require organizations to explain complex algorithms.

However, organizations should be capable of explaining much more fundamental issues.

What personal data does the AI system use?

Why is that information necessary?

What business objective does the system support?

Who reviews significant outputs?

What safeguards exist to identify inappropriate outcomes?

These governance questions are likely to become increasingly important as AI adoption expands.

Vendor governance is becoming AI governance:

Few organizations develop AI systems internally.

Most rely on external providers.

Large language models.

Cloud AI services.

Marketing automation platforms.

Customer relationship management systems.

Fraud detection software.

Human resources platforms.

Consequently, AI governance increasingly depends upon vendor governance.

Organizations should understand:

  • where personal data is processed;
  • whether overseas transfers occur;
  • whether providers use customer data to train models;
  • whether subcontractors process personal data;
  • how security is maintained;
  • how long information is retained.

Vendor due diligence therefore becomes an essential component of AI governance under the PDPA.

Human oversight still matters:

AI enables organizations to automate decisions at unprecedented scale.

Automation, however, should not eliminate accountability.

Organizations should identify situations where meaningful human review remains appropriate.

Examples may include:

  1. rejecting employment applications;
  2. detecting suspected fraud;
  3. evaluating insurance claims;
  4. determining customer eligibility for significant commercial benefits.

The appropriate level of oversight will depend upon the context and the potential impact on individuals.

Organizations should therefore design governance frameworks that ensure AI supports decision-making without entirely replacing human judgement where significant interests are involved.

AI governance is ultimately privacy governance:

Perhaps the most important lesson is that organizations should resist creating isolated AI compliance programs.

Instead, AI should be incorporated into existing privacy governance.

Records of Processing Activities should identify AI-supported processing.

Privacy notices should accurately describe AI-related processing where appropriate.

Legal basis assessments should consider AI processing explicitly.

Vendor management should address AI providers.

Privacy impact assessments should evaluate AI risks.

Training programs should include AI governance.

In other words, organizations should integrate AI into their existing accountability framework rather than building a separate compliance structure.

Looking ahead:

Artificial intelligence will continue to reshape business operations.

The more significant challenge under the PDPA, however, is unlikely to be the technology itself.

It will be governance.

Organizations capable of explaining why AI is used, what personal data supports it, how risks are managed, and how decisions remain accountable are likely to be better prepared than organizations focusing exclusively on technical innovation.

The PDPC’s recent consultation suggests that this is the direction in which Thailand’s privacy regime is evolving. AI is becoming an ordinary business tool. As a result, organizations should treat AI governance as an ordinary component of privacy governance.

Key takeaways:

  1. The PDPA does not establish separate legal principles for AI; existing privacy obligations continue to apply regardless of the technology used.
  2. AI increases the scale and complexity of personal data processing but does not replace the need for lawful basis, transparency, purpose limitation, and accountability.
  3. Organizations should assess individual AI use cases rather than treating all AI deployments identically.
  4. Profiling and AI-assisted decision-making are becoming mainstream regulatory concerns and should be supported by appropriate governance and transparency.
  5. Vendor management is increasingly inseparable from AI governance because many AI capabilities are provided by third-party platforms.

The organizations best prepared for future regulation will be those that integrate AI into existing privacy governance rather than treating it as a separate compliance project.


Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

Billing Software Requirements vs. Electronic Invoicing Requirements

Executive Summary:

As governments continue to digitalize tax administration, businesses are increasingly expected to adopt electronic invoicing solutions that comply with evolving regulatory requirements. Although the terms billing software and electronic invoicing are often used interchangeably, they represent distinct concepts that serve different commercial and legal functions.

In Thailand, billing software is not subject to a dedicated statutory or regulatory framework. Businesses are generally free to select accounting, billing, or enterprise resource planning (ERP) systems that best support their commercial operations, provided they comply with the Revenue Code and other applicable laws. Electronic invoicing, by contrast, is governed by the Revenue Department’s e-Tax Invoice & e-Receipt framework, which establishes the legal and technical requirements for issuing electronic tax invoices recognized for VAT purposes.

Understanding the distinction between these concepts is important for businesses implementing digital invoicing solutions. A billing system that efficiently generates commercial invoices does not necessarily satisfy the legal requirements for issuing electronic tax invoices. Businesses should therefore evaluate their invoicing systems not only from an operational perspective but also from a tax compliance standpoint.

Introduction:

Digital transformation has fundamentally changed the way businesses prepare invoices, maintain accounting records, and comply with tax obligations. Around the world, tax authorities have introduced electronic invoicing regimes to improve tax compliance, enhance transparency, and reduce administrative burdens for both taxpayers and regulators.

Although electronic invoicing has become an increasingly common feature of modern tax systems, countries have adopted different regulatory approaches. Some jurisdictions regulate the software used to generate invoices, while others focus on the legal validity and technical characteristics of the electronic tax documents themselves.

Thailand follows the latter approach. Rather than regulating billing software as a separate category of software, Thai law establishes a framework governing the issuance of electronic tax invoices through the Revenue Department’s e-Tax Invoice & e-Receipt system. Consequently, businesses remain free to use their preferred accounting or ERP software, provided that the electronic tax documents generated by those systems comply with the applicable legal and technical requirements.

For businesses operating in Thailand, particularly multinational enterprises implementing global ERP platforms, understanding the distinction between billing software and electronic invoicing is essential. While both are integral components of modern financial management, they perform different functions and are subject to different legal considerations.

Billing Software:

Billing software generally refers to applications used by businesses to prepare invoices, calculate taxes, record payments, manage customer accounts, and maintain accounting records. These functions support day-to-day commercial operations and are commonly integrated into accounting software or ERP systems.

Unlike some jurisdictions that regulate invoicing software, Thailand does not currently impose a dedicated legal or regulatory regime governing billing software itself. There is no statutory requirement for billing software to be licensed, certified, or approved by the Revenue Department before it can be used by businesses. Instead, Thai law focuses on the legal sufficiency of the invoices and accounting records generated by the software.

This does not mean that businesses have complete discretion in how billing systems are used. Regardless of the software selected, businesses remain responsible for ensuring that invoices comply with the Revenue Code, VAT is correctly calculated where applicable, accounting records are properly maintained, and supporting documentation is available for inspection by the tax authorities.

Accordingly, compliance under Thai law depends not on the software itself, but on whether the business uses that software in a manner that satisfies its statutory obligations. A business may therefore choose from a wide range of commercial accounting platforms, cloud-based invoicing applications, or ERP systems without obtaining prior approval from the Revenue Department.

Electronic Invoicing:

Electronic invoicing serves a different purpose. Rather than facilitating internal billing processes, it establishes the legal framework under which electronic tax invoices are recognized for VAT purposes.

Thailand’s electronic invoicing regime is principally governed by the Revenue Code, supplemented by the Electronic Transactions Act, Ministerial Regulation No. 384, and Revenue Department notifications prescribing the technical standards for electronic tax documents. Collectively, these instruments enable tax invoices and receipts to be created, transmitted, and retained electronically while ensuring their authenticity, integrity, and reliability.

Businesses wishing to issue electronic tax invoices under the Revenue Department’s e-Tax Invoice & e-Receipt framework must comply with prescribed legal and technical requirements. These include registration with the Revenue Department, generation of electronic tax documents in the prescribed format, use of appropriate electronic authentication mechanisms, transmission through approved channels where applicable, and maintenance of electronic records in accordance with the Revenue Department’s requirements.

An important characteristic of the Thai framework is that it regulates the electronic tax document rather than the accounting software used to produce it. Consequently, businesses may continue using their existing accounting or ERP systems, provided those systems are capable of generating electronic tax invoices that comply with the Revenue Department’s technical specifications. In practice, many businesses achieve this through system localization or integration with specialized e-Tax solutions or authorized service providers.

Thailand currently provides two principal electronic invoicing models. The e-Tax Invoice & e-Receipt system is designed for businesses requiring full electronic integration, while the e-Tax Invoice by Email system provides a simplified alternative for eligible businesses. Although both systems enable businesses to issue legally recognized electronic tax invoices, they differ in their technical implementation and authentication methods.

Key Takeaways:

  • Thailand does not regulate billing software as a separate legal category or require billing software to be certified or approved by the Revenue Department.
  • The Revenue Department’s e-Tax Invoice & e-Receipt framework governs the issuance of legally recognized electronic tax invoices and establishes the applicable technical and procedural requirements.
  • A commercial invoice generated by billing software does not automatically constitute an electronic tax invoice for VAT purposes.
  • Businesses implementing accounting or ERP systems should evaluate both operational functionality and compliance with Thailand’s e-Tax requirements.
  • Early coordination among finance, tax, legal, and information technology functions can help ensure a successful implementation of electronic invoicing while supporting long-term digital tax compliance.

Source: International Comparison July 2026: Global Legal Market Analysis

Read Full Article