Big Data: Thailand Approves National Strategy to Accelerate AI and Data-Driven Economy

Thailand’s Cabinet has acknowledged the draft National Big Data Strategy, establishing the country’s first comprehensive policy framework for the development and use of big data as a foundation for digital government, artificial intelligence (AI), and a data-driven economy.

The strategy is intended to provide a unified direction for government agencies to improve data management, strengthen digital infrastructure, and promote the practical use of data in both the public and private sectors.

Why the strategy matters:

Although the strategy is not legislation and does not itself impose new legal obligations, it signals the Government’s long-term policy direction. Businesses operating in Thailand—particularly technology companies, cloud service providers, AI developers, healthcare providers, financial institutions, and organizations handling government-related data—should expect increased public investment and regulatory attention in data governance and AI.

The strategy also reinforces the Government’s objective of using data as a strategic national asset to improve public administration, support economic growth, and enhance Thailand’s digital competitiveness.

Key objectives:

According to the announcement, the strategy seeks to:

  • establish an integrated national big data ecosystem;
  • improve evidence-based policy making through better use of government data;
  • support AI adoption across government and industry;
  • enhance Thailand’s digital competitiveness; and
  • promote responsible and systematic use of data.

The Government has also set measurable goals, including increasing the economic value generated from big data and positioning Thailand among the world’s leading countries in big data capability.

Four strategic pillars:

The strategy consists of four principal initiatives.

1. Building national data infrastructure

The Government plans to strengthen core digital infrastructure through initiatives such as:

  • Government Cloud;
  • Government Data Catalog; and
  • National Big Data Platform.

These projects are intended to improve interoperability and enable more effective data sharing among government agencies.

2. Expanding practical use of data

The strategy encourages wider use of data analytics to address national priorities, including:

  • healthcare;
  • tourism;
  • environmental management;
  • agriculture; and
  • trade and economic development.

This reflects the Government’s intention to move beyond data collection toward data-driven decision-making.

3. Accelerating AI adoption

A significant component of the strategy is the promotion of AI across the public and private sectors.

The Government intends to:

  • expand AI applications in government services and industry;
  • support development of Thai-language AI models; and
  • establish datasets suitable for AI development.

These initiatives may create opportunities for AI developers, cloud providers, data platform operators, and businesses offering AI-enabled solutions.

4. Developing human capital

Recognizing that technology alone is insufficient, the strategy also emphasizes workforce development by increasing the number of professionals with expertise in big data and AI.

The Government aims to significantly expand the pool of skilled personnel capable of supporting Thailand’s digital transformation.

Legal and regulatory implications:

The strategy itself does not amend Thailand’s existing legal framework, including laws governing personal data protection, cybersecurity, or digital government.

Nevertheless, it indicates that future regulatory and policy initiatives are likely to focus on:

  • enhanced government data governance;
  • improved standards for data interoperability;
  • greater integration of public-sector datasets;
  • expanded use of AI in government services; and
  • stronger digital infrastructure supporting government cloud and data-sharing initiatives.

Organizations participating in government projects or processing government-related data should therefore continue monitoring future implementing measures, technical standards, procurement requirements, and sector-specific regulations that may follow.

Looking ahead:

The National Big Data Strategy represents an important policy milestone in Thailand’s digital transformation agenda. While much of its implementation will depend on future projects, funding, and regulatory measures, the strategy demonstrates the Government’s commitment to treating data and AI as key drivers of economic development and public-sector modernization.

For businesses, the announcement suggests increasing opportunities in AI, cloud computing, digital infrastructure, and government technology, while reinforcing the importance of robust data governance and regulatory compliance.

Key takeaways:

  • Businesses involved in AI, cloud services, digital infrastructure, and government technology should monitor future implementing regulations, technical standards, and procurement initiatives arising from the strategy.
  • Thailand has adopted its first comprehensive national strategy for big data development.
  • The strategy serves as a policy framework rather than creating immediate legal obligations.
  • Four priorities include national data infrastructure, wider use of data analytics, AI adoption, and workforce development.
  • Government investment is expected to accelerate in cloud infrastructure, data platforms, and AI ecosystems.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Breaking Down Government Data Silos: New Rules on Inter-Agency Sharing of Personal Information

A new Royal Decree has established a legal framework requiring government agencies to share personal information under their control with other government agencies for specified electronic data-linkage purposes.

The Royal Decree on Disclosure of Personal Information Controlled by Government Agencies to Other Government Agencies B.E. 2569 (2026) (the “Royal Decree”) represents an important development in the government’s efforts to move away from fragmented, agency-specific databases toward greater interoperability of public-sector information.

The measure is intended to enable government agencies to use more complete and accurate information in policymaking, public services and targeted welfare programs, while reducing the burden on individuals of repeatedly submitting information already held by the government. The framework is also intended to contribute to greater transparency and more effective law enforcement.

Legal basis for inter-agency disclosure:

The Royal Decree is issued pursuant to Section 24(9) of the Official Information Act B.E. 2540 (1997).

Section 24 of the Official Information Act establishes, as a general rule, that a government agency may not disclose personal information under its control to another government agency or another person without the prior or contemporaneous written consent of the person concerned, subject to specified statutory exceptions.

Section 24(9) permits disclosure in other cases prescribed by Royal Decree.

The new Royal Decree uses this statutory mechanism to provide a specific legal basis for government-to-government disclosure of personal information falling within its scope. As a result, qualifying disclosure under the Royal Decree does not depend on obtaining the individual’s written consent on each occasion.

This is important because large-scale government data interoperability would be difficult to implement if each transfer of information between government agencies required separate consent from every affected individual.

From isolated databases to connected government:

The policy underlying the Royal Decree is broader than simply permitting one government agency to send information to another.

Government agencies hold significant amounts of information about individuals, but that information has traditionally been maintained within separate administrative systems. Where relevant information is distributed among different agencies, the government may not have ready access to the complete information required for policymaking, public services or welfare administration.

The Royal Decree is intended to address this fragmentation by enabling electronic linkage of personal information held across government agencies.

The stated objectives include allowing government policies and measures, government services and targeted welfare programs to be based on accurate and complete information. Greater data linkage is also intended to improve the efficiency of government services, reduce administrative burdens on the public, promote transparency and enhance the effectiveness of law enforcement.

In practical terms, the framework supports a move toward the principle that individuals should not continually be required to provide one government agency with information that is already held by another government agency where the conditions for lawful data linkage are satisfied.

Government agencies may be required to disclose information:

A significant feature of the Royal Decree is that it does not merely provide government agencies with a general permission to share personal information.

It establishes a framework under which a government agency controlling personal information must disclose that information to another government agency where the information is requested for purposes falling within the Royal Decree.

The relevant data linkage is intended to support the preparation and provision of government services and the provision of targeted welfare through electronic means.

This gives the Royal Decree practical significance beyond an ordinary exception to a confidentiality rule. It provides the legal infrastructure for systematic government data interoperability.

The receiving agency also assumes obligations:

Greater availability of government-held information is accompanied by safeguards.

A government agency requesting and receiving personal information must safeguard that information. Importantly, it may not further disclose the information to an outside person.

This restriction is an important limitation on the scope of the new regime. The Royal Decree should therefore not be understood as making personal information freely transferable simply because it has entered an interconnected government information system.

The legal authorization concerns disclosure within the framework established by the Royal Decree. Once information has been received, the recipient agency remains responsible for protecting it and complying with the restrictions applicable to its subsequent disclosure.

The required safeguards are also linked to criteria and conditions prescribed by the competent authority and cybersecurity requirements. Consequently, implementation of the Royal Decree is as much an information-governance issue as a data-access issue.

Targeted welfare and government services:

One of the clearest practical applications of government data linkage is the provision of targeted welfare.

Eligibility for government assistance may depend on information maintained by several different authorities. Without data linkage, individuals may have to obtain documents from one agency and submit them to another, while the agency administering the benefit may have difficulty independently establishing a complete picture of the applicant’s circumstances.

Electronic linkage can potentially change this process.

Where legally permitted, the administering agency may obtain relevant information directly from government data already available elsewhere. This can make eligibility assessment more accurate, reduce duplicate documentation and enable welfare programs to be directed more effectively toward intended recipients.

The same principle can apply more broadly to government services. Greater interoperability can reduce repeated requests for information and allow government agencies to make administrative decisions using more complete information.

Transparency and law enforcement:

The Royal Decree also has implications beyond welfare and administrative services.

The stated rationale includes increasing transparency within government and improving the effectiveness of law enforcement. Information that appears unremarkable when held in a single agency’s database may have greater significance when lawfully linked with information held by other agencies.

Inter-agency data linkage can therefore provide government authorities with a more complete information base for identifying inconsistencies, verifying information and carrying out their statutory functions.

This capability may be particularly relevant where investigations or enforcement activities require information held by several government bodies.

However, the Royal Decree should not be characterized as creating a general law-enforcement database or an unrestricted investigative power. Its significance lies in providing a statutory mechanism for disclosure and electronic data linkage within the scope established by the Royal Decree.

Data sharing does not mean unrestricted data use:

An important compliance point is the distinction between access to information and freedom to use or disclose that information.

The fact that one government agency is legally entitled to obtain information from another does not mean that information becomes unrestricted once transferred.

Government agencies implementing data-linkage arrangements should therefore consider controls covering at least:

  • the authority and purpose for requesting information;
  • identification of the information required;
  • authentication of requesting agencies and authorized personnel;
  • access controls within the receiving agency;
  • secure electronic transmission;
  • logging and traceability of access and transfers;
  • cybersecurity safeguards;
  • retention and management of linked information; and
  • controls preventing unauthorized onward disclosure.

These controls are particularly important because increased interoperability can increase the consequences of inadequate security. A weakness in one interconnected system may potentially expose information originating from several agencies.

Relationship with personal data protection requirements:

The Royal Decree should also be understood within the broader legal framework governing personal information.

Its immediate statutory basis is the Official Information Act, and it establishes a specific mechanism permitting inter-agency disclosure that would otherwise be subject to the restrictions in Section 24 of that Act.

However, the existence of a statutory basis for disclosure should not automatically be equated with unlimited authority to process the information for any subsequent purpose.

Government agencies participating in data-linkage arrangements should therefore identify the legal authority supporting each stage of the information lifecycle—including collection, disclosure, receipt, use, retention, security and any subsequent disclosure—and consider other applicable personal data protection and cybersecurity requirements.

The distinction is particularly important as government systems become increasingly interconnected. Legal authority to receive information is only one component of lawful and responsible data governance.

A significant step toward data-driven government:

The Royal Decree represents a structural change in the management of government-held personal information.

The traditional model in which each government agency maintains its own information and individuals repeatedly provide substantially the same information to different authorities is increasingly being replaced by a model based on controlled interoperability.

If implemented effectively, the new framework should enable government agencies to make greater use of information already available within the public sector, improve the accuracy of public services and welfare programs, and reduce unnecessary administrative burdens on individuals.

The corresponding challenge is governance.

The more effectively government information systems are connected, the more important it becomes to ensure that access is authorized, purposes are properly defined, information is adequately protected and subsequent disclosure remains controlled.

The Royal Decree therefore represents not simply an expansion of government access to data, but a move toward a more integrated model of public-sector data governance.

Key Takeaways:

  • The Royal Decree marks an important shift from government data held in separate institutional silos toward controlled, interoperable public-sector data infrastructure.
  • The Royal Decree establishes a statutory mechanism for the disclosure of personal information between government agencies for qualifying electronic data-linkage purposes.
  • Its legal basis is Section 24(9) of the Official Information Act, which allows exceptions to the general restriction on disclosure of government-controlled personal information without written consent.
  • The framework goes beyond merely permitting voluntary data sharing and supports systematic interoperability between government information systems.
  • A government agency receiving information under the framework must safeguard the information and is restricted from further disclosure to an outside person.
  • The framework is intended to support more accurate policymaking, more efficient government services and targeted welfare, reduced administrative burdens on the public, greater transparency and more effective law enforcement.
  • Government agencies should not treat authorization to receive information as unrestricted authority to use or further disclose it. Purpose limitation, access controls, cybersecurity and information governance remain central to implementation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

From Voluntary Guidance to Legal Accountability: The Changing Rules for Digital Platforms

Digital platform regulation is entering a new phase. Recent developments indicate a shift from a framework centered largely on registration, disclosure, and risk management toward a more substantive model addressing platform conduct, seller accountability, fee transparency, and potentially the allocation of liability between platforms and businesses operating through them.

Two developments illustrate this direction particularly well. The first is the proposed Digital Platform Economy Act, which is being developed as a broader statutory framework for the platform economy. The second is the Electronic Transactions Development Agency (ETDA) Guideline on Transparency and Fairness in Digital Platform Service Fees, which establishes voluntary best practices for the disclosure and adjustment of platform fees. Although the guideline is not mandatory and the proposed Act has not yet been enacted, considered together they provide a useful indication of the regulatory principles increasingly shaping oversight of digital platforms: transparency, fairness, accountability, and greater protection for users and consumers.

A New Regulatory Framework for Digital Platforms:

Digital platform services are currently regulated under the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification. The existing regime establishes notification requirements and imposes various obligations depending on the nature, size, and risk profile of a platform. The proposed Digital Platform Economy Act would represent a significant further development. The government has accelerated work on the legislation, with the current policy timetable contemplating submission to the Cabinet before the draft proceeds to Parliament. As the legislation remains under development, however, both its provisions and legislative timetable remain subject to change.

The emerging framework indicates several areas that platform operators should monitor closely. These include registration and disclosure of information concerning platform operations and revenue, as well as measures intended to give regulators greater visibility over businesses participating in the platform economy. Territorial scope will be particularly important for multinational businesses, since a platform providing services into the local market may potentially become subject to regulatory requirements even where the operator does not have a conventional physical presence in the jurisdiction.

Another important area concerns businesses and individuals offering goods or services through platforms. The regulatory direction increasingly places platforms in the position of gatekeepers rather than merely passive intermediaries. Existing regulatory measures already require certain platforms to obtain and verify seller information and implement risk-management measures concerning goods and services offered through their systems. The proposed legislation appears likely to develop this approach further, making seller onboarding, identity verification, record keeping, monitoring, and enforcement increasingly important compliance functions rather than merely commercial processes.

The Emerging Question of Platform Liability:

Perhaps the most significant issue to monitor is the extent to which a platform may bear responsibility for harm arising from transactions conducted through its service. Platform operators have traditionally characterized themselves as intermediaries connecting independent sellers with customers, and their terms and conditions commonly distinguish the platform from the seller responsible for the underlying goods or services.

The proposed regulatory approach may reduce the practical significance of that distinction. Discussions surrounding the Digital Platform Economy Act contemplate circumstances in which platforms could bear joint responsibility for consumer harm, particularly where the platform fails to perform duties imposed on it. The precise scope of any liability will depend on the final statutory language, including the conduct that triggers liability, available defenses, and the relationship between the new regime and existing consumer protection laws.

If enacted broadly, such liability could materially alter the allocation of risk in the platform economy. Seller verification and monitoring would no longer be viewed simply as regulatory procedures; they could become directly relevant to a platform’s financial exposure when consumers suffer loss. Contractual provisions placing responsibility on sellers, including indemnities, may remain important but would not necessarily protect a platform from independent statutory liability. Platform operators should therefore monitor the liability provisions particularly closely as the draft progresses.

Fee Transparency and Fairness:

While the proposed Act represents the potential development of mandatory statutory obligations, ETDA has adopted a softer regulatory approach to another significant platform issue: fees. Its Guideline on Transparency and Fairness in Digital Platform Service Fees is intended as voluntary best practice rather than direct price regulation. The guideline does not prescribe maximum commissions or other charges. Instead, it focuses on whether users can understand what they are being charged, what services they receive in return, and how changes to those charges are made.

Platforms are encouraged to present fee information clearly and in an accessible manner, including an explanation of individual fee items, the services or benefits associated with them, and the basis or method used to calculate the charges. This is particularly relevant where the actual cost of participating on a platform extends beyond a headline commission and may include advertising, promotional, affiliate, payment-related, or other service fees. The regulatory concern is therefore not simply whether a particular commission is high or low, but whether users can reasonably determine and evaluate the overall economic cost of using the platform.

The guideline also addresses changes to platform fees. It recommends that users receive at least 15 days’ advance notice of fee changes, together with information concerning the reason for the change, its scope and potential impact, and channels for inquiries or feedback. The guideline also contemplates a consultation process in connection with fee changes. Platforms should therefore distinguish between merely notifying users that a fee will change and maintaining a process that reflects the broader principles of transparency, consultation, and fairness contemplated by the guideline.

Fairness extends beyond disclosure. Platforms are encouraged to avoid unnecessary duplication of charges and to distinguish clearly between compulsory fees and charges for additional services. Optional services should correspond to genuine additional benefits rather than becoming effectively mandatory through the design or operation of the platform. The objective is not direct government control of platform pricing, but a framework in which platforms can explain how fees are determined and users can understand the true costs of participating in the platform ecosystem.

From Voluntary Guidance to Legal Accountability:

Considered separately, the proposed Digital Platform Economy Act and the fee guideline address different regulatory issues. Considered together, however, they reveal a broader trajectory. The fee guideline represents soft regulation, under which regulators articulate expectations concerning fair market conduct and encourage platforms voluntarily to incorporate those principles into their business practices. The proposed legislation points toward harder regulatory intervention, potentially involving registration, disclosure, seller verification, statutory duties, enforcement mechanisms, and greater responsibility for consumer harm.

This distinction is important for businesses. Voluntary guidance should not necessarily be treated as irrelevant simply because it does not create directly enforceable obligations. Such guidance may establish regulatory expectations concerning reasonable industry conduct, identify practices receiving regulatory scrutiny, and indicate areas in which more formal intervention could eventually follow if voluntary measures prove insufficient.

The broader development is therefore not simply an increase in the number of rules applicable to digital platforms. It reflects a gradual change in the regulatory conception of the platform itself. As platforms exercise greater control over seller admission, product visibility, payment mechanisms, fees, and transactions, regulators increasingly expect them to accept corresponding responsibilities for how those ecosystems operate.

Preparing for the Next Stage of Platform Regulation:

Platform operators need not wait for the proposed legislation to be enacted before reviewing their compliance architecture. Seller onboarding and verification procedures should be assessed to determine what information is collected, how identities and business credentials are verified, how information is updated, and what happens when inaccurate information or unlawful activity is detected. Systems should also retain sufficient records to demonstrate that verification, monitoring, complaints, and enforcement procedures have actually been followed.

Fee structures warrant similar attention. Platforms should consider whether users can readily identify the overall economic cost of using their services and whether compulsory fees, optional services, promotional charges, advertising costs, and other charges are adequately explained. Procedures for changing fees should also be reviewed against the transparency, advance-notice, and consultation principles reflected in ETDA’s guideline.

Finally, contractual arrangements with sellers should be considered together with operational compliance. If the new legislation imposes independent statutory duties on platforms, contractual provisions allocating responsibility entirely to sellers may have limited effect against claims brought directly against the platform. Indemnities, suspension rights, seller information obligations, insurance arrangements, record keeping, and mechanisms for recovering losses should therefore form part of a broader risk-management framework rather than being treated as substitutes for regulatory compliance.

Key Takeaways:

  • Digital platform regulation is moving beyond registration and disclosure toward greater operational accountability.
  • The proposed Digital Platform Economy Act may expand requirements concerning platform registration, business information, seller verification, platform conduct, and consumer protection. Its final provisions should be monitored as the legislative process progresses.
  • Potential joint liability for consumer harm may be one of the most significant developments because it could alter the traditional allocation of responsibility between platforms and independent sellers.
  • ETDA’s fee guideline remains voluntary and does not constitute direct price regulation, but it establishes regulatory expectations concerning fee transparency, fairness, advance notice, and consultation.
  • Platform operators should consider reviewing seller verification, monitoring, fee disclosures, change-management procedures, contractual risk allocation, and record-keeping systems before the new statutory framework is finalized.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Moves Toward a Dedicated Regulatory Framework for Data Centers

Thailand may soon take a significant step toward regulating its rapidly expanding data center industry. According to recent reports, the government is preparing a Prime Minister’s Office Regulation that would establish a dedicated framework for overseeing data center operations, with particular emphasis on resource management, environmental impacts, and centralized regulatory oversight. While the proposed regulation has not yet been issued, it signals a potential shift from Thailand’s current investment-driven approach toward a more comprehensive regulatory model for the sector.

Background:

Thailand has become an increasingly attractive destination for data center investment due to strong government incentives, growing cloud adoption, and its strategic location in Southeast Asia. However, the rapid expansion of large-scale facilities has also raised concerns regarding infrastructure capacity, particularly electricity and water consumption.

According to the reported proposal, the government intends to introduce a dedicated regulatory mechanism to better coordinate oversight of the industry and manage its broader impacts on national resources.

Proposed regulatory framework:

The reported proposal indicates that the Prime Minister’s Office Regulation would establish a new committee responsible for supervising data center activities. Its responsibilities would reportedly include:

  • overseeing the overall development of the data center industry;
  • assessing the impacts of data center investments;
  • monitoring resource consumption, particularly electricity and water usage;
  • coordinating regulatory oversight among relevant government agencies; and
  • supervising approvals, permits, and compliance monitoring.

Although further details have not yet been published, the proposal suggests that the government intends to create a more centralized oversight structure than currently exists.

Addressing fragmented regulation:

At present, data center projects typically interact with multiple government agencies depending on the nature of the project. Investors may require approvals or incentives from different authorities, while utility arrangements are often negotiated separately.

The reported proposal appears intended to address this fragmented regulatory landscape by introducing a dedicated governance mechanism specifically focused on data centers.

Greater focus on infrastructure and resource management:

A notable feature of the proposal is its emphasis on resource planning.

According to the reports, the government has identified several concerns, including:

  • increasing electricity demand from large-scale data centers;
  • substantial water consumption required for cooling systems;
  • challenges in forecasting future resource demand; and
  • overlapping arrangements for water supply that may complicate national infrastructure planning.

The proposal therefore appears to reflect a policy objective of integrating data center development with broader infrastructure and environmental planning rather than regulating the industry solely from an investment perspective.

Different treatment for existing and future projects:

The reported framework would distinguish among three categories of data centers:

Existing operating facilities

Existing operators may become subject to audits or assessments focusing on matters such as resource consumption, temperature management, and noise impacts.

Approved projects under development

Projects that have already received approvals but are not yet operational may be required to comply with additional regulatory conditions before commencing operations.

Future applicants

New projects may become subject to a comprehensive regulatory regime addressing matters such as:

  • sustainable water management;
  • reserve water sources;
  • environmental impacts; and
  • measures designed to reduce adverse impacts on surrounding communities.

This tiered approach suggests that the government is seeking to avoid disrupting ongoing investments while progressively strengthening regulatory requirements for future developments.

Potential changes to location planning:

The reports also indicate that the government is considering a more strategic approach to determining where future data centers should be located.

Rather than concentrating additional facilities in existing investment hubs, policymakers are reportedly evaluating locations with stronger electricity and water infrastructure, including areas near major power generation facilities. The government has also indicated that supporting digital infrastructure, such as fiber-optic networks, could be expanded if new data center clusters are developed.

What investors should watch:

Although the proposal remains at the policy stage, investors and operators should monitor several issues as the framework develops:

  • the legal authority under which the new committee will operate;
  • whether additional licensing or approval requirements will be introduced;
  • technical standards relating to electricity, water use, and environmental impacts;
  • transitional requirements applicable to existing operators; and
  • the interaction between the new framework and existing approvals issued by sector-specific regulators.

The final regulatory approach will determine whether the proposed framework primarily serves as a coordination mechanism or introduces substantive compliance obligations for the industry.

Key takeaways:

  • Thailand is reportedly preparing a dedicated regulatory framework for data centers through a proposed Prime Minister’s Office Regulation.
  • The proposal reflects increasing government attention to electricity consumption, water usage, and environmental impacts associated with large-scale data center investments.
  • A new committee may be established to coordinate oversight of approvals, compliance, and resource management.
  • Existing facilities, projects under development, and future investments could become subject to different regulatory requirements.
  • Although the proposal has not yet been formally issued, investors planning data center projects in Thailand should closely monitor further regulatory developments, as they may significantly affect project planning, compliance obligations, and site selection.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Managing Regulatory Due Diligence for Cross-Border Investors in Financial and Digital Asset Businesses

Introduction:

Cross-border investments in financial services and digital asset businesses present unique regulatory challenges that extend well beyond traditional legal or financial due diligence. Whether an investor is acquiring a licensed payment service provider, a securities business, a digital asset exchange, or a fintech company operating under sector-specific regulation, the value of the transaction can depend as much on the target’s regulatory standing as on its commercial performance.

Unlike ordinary commercial businesses, regulated entities operate under continuing supervision. Their ability to conduct business depends not only on maintaining the necessary licenses but also on demonstrating ongoing compliance with governance requirements, prudential standards, anti-money laundering obligations, cybersecurity controls, and consumer protection rules. A company with strong financial performance may nevertheless represent a significant acquisition risk if its regulatory compliance has deteriorated or if it is subject to undisclosed supervisory concerns.

For cross-border investors unfamiliar with the Thai regulatory landscape, regulatory due diligence is therefore not merely a legal exercise. It is an essential component of transaction risk assessment and should begin early in the acquisition process.

Looking Beyond the License:

One of the most common misconceptions among foreign investors is that verifying the existence of a regulatory license is sufficient. In reality, the existence of a license represents only the starting point of the analysis.

Many regulated businesses have evolved over time, expanding their products and services beyond the scope originally contemplated when their licenses were granted. A fintech company may initially have operated as an electronic payment platform before introducing digital lending, cross-border remittance services, or digital asset-related products. Each new business activity may require separate regulatory approval or may be subject to different supervisory requirements.

Regulatory due diligence should therefore examine whether every revenue-generating activity falls within the scope of the target’s existing licenses and whether any exemptions relied upon remain available. It is equally important to determine whether any license conditions have been imposed by regulators and whether the company has complied with those conditions throughout its operations.

Regulatory Approval May Determine Whether the Transaction Can Close:

Unlike acquisitions involving ordinary commercial companies, transactions involving regulated financial businesses frequently require regulatory approval before completion. In some sectors, a change in significant shareholding or control may not become legally effective until the relevant regulator has approved the transaction. Other regulatory regimes may require post-closing notifications or impose “fit and proper” assessments on incoming shareholders, directors, or senior management.

Consequently, regulatory due diligence should identify not only the approvals required for the target’s day-to-day operations but also those triggered by the proposed acquisition itself. Failure to identify these requirements early can delay completion, affect financing arrangements, or require restructuring of the transaction.

Cross-border investors should also consider whether foreign ownership restrictions, residency requirements, or limitations on board composition may influence the post-closing governance structure.

Compliance Culture Often Matters More Than Written Policies:

Modern financial regulators increasingly assess how compliance operates in practice rather than whether a company simply maintains a complete set of written policies.

Accordingly, regulatory due diligence should extend beyond reviewing compliance manuals and internal procedures. Investors should seek evidence that compliance functions are adequately resourced, that internal reporting mechanisms operate effectively, and that senior management actively oversees regulatory risk.

The company’s interactions with regulators may provide particularly valuable insight. Inspection reports, supervisory correspondence, warning letters, remediation plans, and historical enforcement actions often reveal recurring compliance weaknesses that are not apparent from corporate documentation alone. Even where no formal penalties have been imposed, repeated supervisory findings may indicate weaknesses in governance or internal controls that require significant remediation after closing.

Technology Risk Has Become a Core Regulatory Issue:

Technology is now central to regulatory supervision of financial institutions and digital asset businesses. Cybersecurity failures, operational disruptions, and weaknesses in technology governance increasingly attract regulatory attention regardless of whether they result in customer losses.

For investors, this means regulatory due diligence should include an assessment of cybersecurity governance, incident response procedures, disaster recovery planning, outsourcing arrangements, cloud service management, and operational resilience frameworks. Businesses operating digital asset platforms should also be assessed for wallet security, custody arrangements, transaction monitoring systems, and market surveillance capabilities.

Technology deficiencies may not immediately affect valuation but can require substantial investment after completion to satisfy regulatory expectations.

AML and Financial Crime Controls Remain High-Risk Areas:

Anti-money laundering and counter-terrorism financing compliance continues to be among the highest enforcement priorities for financial regulators. Deficiencies in customer due diligence, transaction monitoring, sanctions screening, or suspicious transaction reporting can expose regulated businesses to substantial regulatory sanctions and reputational damage.

Investors should therefore evaluate not only the target’s written AML policies but also the effectiveness of their implementation. Questions such as how high-risk customers are identified, how beneficial ownership is verified, and how suspicious transactions are escalated can provide a clearer picture of the target’s compliance maturity than policy documents alone.

Where previous regulatory inspections have identified AML deficiencies, investors should assess whether remediation has been completed and whether regulators remain satisfied with the company’s corrective measures.

Data Protection and Outsourcing Should Not Be Overlooked:

Financial institutions increasingly rely on external service providers for cloud infrastructure, customer verification, payment processing, and cybersecurity services. While outsourcing may improve operational efficiency, regulators continue to emphasize that responsibility for regulatory compliance ultimately remains with the licensed entity.

Accordingly, regulatory due diligence should review the contractual framework governing outsourced services, the company’s oversight of critical vendors, and its contingency planning should key service providers become unavailable.

Similarly, businesses handling significant volumes of customer information should be assessed for compliance with personal data protection requirements, particularly where customer information is transferred across borders or processed by third-party vendors.

Due Diligence Findings Should Shape Transaction Documents:

Regulatory due diligence should not end with the preparation of a report. Its findings should directly influence transaction structuring and the allocation of risk between buyer and seller.

Where significant compliance concerns are identified, investors may seek enhanced representations and warranties regarding licensing, regulatory compliance, anti-money laundering controls, cybersecurity, and data protection. Specific indemnities may be appropriate for known regulatory investigations or historical compliance failures. In some cases, buyers may also require identified deficiencies to be remediated as conditions precedent before closing.

Integrating regulatory due diligence into transaction documentation helps ensure that regulatory risks are appropriately allocated and reduces the likelihood of post-completion disputes.

Conclusion:

As financial regulation becomes increasingly complex and technology-driven, regulatory due diligence has evolved from a narrow licensing review into a comprehensive assessment of an institution’s regulatory health. For cross-border investors, understanding how a target interacts with regulators, manages compliance risks, and maintains operational resilience is often as important as evaluating its financial performance.

A well-executed regulatory due diligence exercise enables investors to identify hidden regulatory exposures, anticipate approval requirements, negotiate more effective contractual protections, and develop realistic post-acquisition integration plans. In regulated financial and digital asset sectors, it is often the quality of regulatory compliance—not simply the quality of the business—that ultimately determines whether an investment achieves its intended value.

Key Takeaways:

  • In acquisitions involving financial and digital asset businesses, robust regulatory due diligence is essential to preserving investment value and minimizing post-closing regulatory exposure.
  • Regulatory due diligence should evaluate the target’s overall regulatory health rather than simply confirming the existence of licenses.
  • Investors should assess governance, supervisory history, AML/CTF controls, cybersecurity, data protection, outsourcing arrangements, and change-of-control requirements alongside licensing compliance.
  • Early identification of regulatory risks helps facilitate transaction planning, regulatory approvals, and appropriate contractual risk allocation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

BOT: Bank of Thailand Introduces Stricter Rules on Large Cash Transactions to Combat Illicit Flows

The Bank of Thailand (BOT) is set to implement enhanced oversight on significant cash movements as part of efforts to address gray-area financial activities, reduce risks of money laundering, and promote greater transparency in the financial system.

Under the upcoming regulations, financial institutions will soon be required to perform detailed customer due diligence for any cash withdrawal exceeding 5 million baht in a single transaction. Customers must clearly explain the source of the funds and the intended purpose of the cash. If the explanation is unsatisfactory or unverifiable, banks may restrict or decline to process the transaction.

This measure primarily targets unusual or high-risk cash usage that could be linked to informal, unregulated, or illicit activities. In a later phase, similar requirements will apply to cash deposits of 5 million baht or more, where the origin of the funds must also be justified.

The BOT has indicated that legitimate needs—such as those of small and medium-sized enterprises (SMEs), individuals conducting regular business operations, or other verifiable purposes—will continue to be accommodated, provided appropriate documentation and explanations are provided. However, the rules aim to make large-scale cash handling more accountable and discourage reliance on physical currency for questionable purposes.

Looking ahead, after an initial implementation period and evaluation of impacts (including any effects on ordinary users), the threshold may be lowered to 3 million baht for both withdrawals and deposits to further strengthen controls.

These changes form part of broader initiatives to tackle structural economic vulnerabilities, encourage electronic payments where practical, and limit opportunities for crime or opaque transactions.

Impact on the Public:

Most everyday individuals and small businesses will remain largely unaffected, as transactions below the 5 million baht threshold face no new requirements, and legitimate large needs can proceed with proper justification.

People or entities accustomed to handling large cash amounts (e.g., for property deals, business purchases, or other high-value activities) will need to prepare explanations and supporting evidence in advance, potentially adding time and documentation steps at the bank.

Those involved in informal or gray-area dealings may find it significantly harder to move large sums in cash without scrutiny, increasing the risk of restrictions or reporting to authorities.

Overall, the shift promotes safer, more traceable financial habits while aiming to reduce crime risks associated with large cash volumes and ease burdens through related reviews of common banking fees.

Key Takeaways:

Implementation is expected in the near future (early to mid-March timeframe), giving the public time to adjust to more accountable cash handling practices.

Cash withdrawals over 5 million baht will require clear justification of purpose and source; unsatisfactory explanations may lead to restrictions.

The rules will later extend to large cash deposits and could lower the threshold to 3 million baht after review.

Legitimate users (e.g., SMEs and individuals with valid reasons) can continue transactions by providing details—no outright ban is intended.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

BOI: Incentive Reforms Target Aviation, AI and Sustainable Industries as Investment Applications Surge

Thailand’s Board of Investment (BOI) has continued to refine its investment promotion framework in 2026 through amendments to promoted activities and targeted incentive measures aimed at attracting high-value investment, strengthening industrial competitiveness and supporting the country’s transition towards a digital and sustainable economy.

The latest policy developments coincide with a substantial increase in investment activity. Investment promotion applications during the first quarter of 2026 exceeded THB 1 trillion, continuing the strong momentum seen in 2025 when applications reached a record level. The figures reflect increasing investor confidence in Thailand as a regional manufacturing, technology and innovation hub, particularly amid ongoing supply chain diversification and shifts in global production strategies.

Aviation and Air Transport Sector:

Among the recent initiatives, the BOI has expanded support for aviation and air transport-related activities as part of Thailand’s strategy to strengthen its position as a regional aviation and logistics hub. The revised promotion framework is expected to encourage investment in air transport services, aircraft maintenance, aviation support services and related infrastructure.

The measures complement broader efforts to improve transportation connectivity, facilitate cross-border trade and investment, and enhance Thailand’s competitiveness within the ASEAN region.

Smart and Sustainable Industries:

The BOI has also continued to enhance its policies supporting smart and sustainable industries, encouraging businesses to adopt advanced technologies, automation systems, energy-efficient machinery and environmentally sustainable production processes.

The policy direction reflects the government’s commitment to industrial upgrading, productivity enhancement and sustainability-driven growth. For investors, the reforms signal continued support for projects involving digital transformation, energy efficiency, carbon reduction and resource optimization. Such initiatives are increasingly aligned with the environmental, social and governance (ESG) expectations of global investors and multinational supply chains.

Digital and Artificial Intelligence Investments:

Digital technologies and artificial intelligence (AI) remain key priorities under Thailand’s investment promotion strategy. Recent investment trends indicate growing demand for projects involving data centers, cloud services, software development, AI applications and related digital infrastructure.

The continued emphasis on AI and digital transformation aligns with broader government objectives aimed at accelerating technological innovation, strengthening digital capabilities and attracting high-value industries. These developments further reinforce Thailand’s ambition to position itself as a regional technology and digital services hub.

Enhancements to the Long-Term Resident (LTR) Visa Program:

In parallel with investment promotion measures, the government has introduced adjustments to the Long-Term Resident (LTR) Visa program to facilitate the entry of foreign investors, executives and highly skilled professionals.

The revisions are intended to improve accessibility for qualified applicants and strengthen Thailand’s ability to attract global talent in strategic sectors. The combination of BOI incentives and LTR Visa benefits continues to form an important component of Thailand’s investment promotion strategy, particularly for multinational enterprises considering the establishment of regional headquarters, research and development centres or technology-focused operations in the country.

Continued Foreign Investment Momentum:

The strong investment figures recorded in early 2026 indicate that Thailand continues to benefit from global trends such as supply chain diversification, regionalization of manufacturing and increasing demand for digital infrastructure.

Investment activity has been concentrated in sectors including advanced electronics, AI-related businesses, digital infrastructure, clean energy, logistics and advanced manufacturing. The growth demonstrates continued investor confidence in Thailand’s investment ecosystem and the competitiveness of its incentive regime.

Key Takeaways:

  • The BOI continues to refine its investment promotion framework to attract high-value investments in strategic sectors, particularly aviation, digital technologies, artificial intelligence and sustainable industries.
  • Recent reforms demonstrate Thailand’s continued focus on industrial upgrading, technological innovation and environmentally sustainable growth.
  • Enhancements to the Long-Term Resident (LTR) Visa programme complement investment incentives by facilitating the attraction of foreign investors, executives and highly skilled professionals.
  • Record investment promotion applications in early 2026 indicate sustained investor confidence and Thailand’s growing role as a regional investment and manufacturing hub.

Businesses considering expansion into Thailand should review the availability of BOI incentives and assess how evolving promotion policies may support investment projects, regional headquarters, technology operations and sustainability initiatives.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand’s Foreign Business Regulatory Reform: Cabinet Approves Easing of Foreign Business Restrictions in Selected Service Sectors

Background of the Current Foreign Business Law (FBL):

Thailand’s Foreign Business Act B.E. 2542 (1999), commonly referred to as the FBA, regulates foreign participation in various economic activities to protect national interests and ensure Thai nationals remain competitive in key sectors. The law categorizes restricted businesses into three lists:

•  List 1 – activities strictly prohibited to foreigners for special reasons, such as media, rice farming, forestry, and land trading.

•  List 2 – businesses related to national security, culture, and natural resources, requiring the Cabinet’s approval.

•  List 3 – encompasses a wide range of service-oriented businesses where Thai nationals are deemed not yet ready to compete fully with foreigners. These typically require obtaining a Foreign Business License (FBL) from the Department of Business Development, Ministry of Commerce.

This framework has historically required foreign investors to obtain the FBL for many service activities.

Recent Cabinet Approval for Reforms:

On May 12, 2026, the Thai Cabinet approved in principle two draft subordinate regulations under the FBL. These aim to modernize the regulatory environment by easing restrictions on certain activities where Thai businesses are now competitive or where strong sectoral oversight already exists.

Next Steps Following the Cabinet’s Approval:

The approval in principle marks an important initial step, but the reforms are not yet in effect. The following legislative key processes are required:

1.  Review and Revision — The drafts will be undergone detailed scrutiny by relevant agencies, including potential incorporation of stakeholders’ feedback.

2.  Council of State Examination — The drafts will be proceeded to the Council of State for legal review to ensure consistency with existing laws and constitutional requirements.

3.  Second Cabinet’s Approval — Following revisions by the relevant agencies, stakeholders, and the Council of State, the drafts will return to the Cabinet for final endorsement.

4.  Publication in the Royal Gazette — Once approved by the Cabinet, the drafts will be published in the Royal Gazette to become legally enforceable.

All in all, these processes are expected to take several months, if not longer, depending on the complexity of reviews and any additional consultations required. Investors should monitor official announcements for updates on the effective date.

The Eight Exempted Service Businesses:

Foreign investors can operate the following without applying for an FBL (subject to compliance with relevant sector-specific laws), once the drafts take effect:

•  Telecommunication services without their own network infrastructure.

•  Financial management or treasury center businesses.

•  Internal network administration services.

•  Domestic debt guarantee businesses.

•  Petroleum drilling services.

•  Various lending activities secured by collateral under securities and futures laws.

•  Acting as agents, brokers, advisors, or fund managers for futures contracts not covered under the Futures Exchange Act.

•  Services for leasing space to install electronic equipment and automatic vending machines.

These activities remain subject to rigorous oversight by specialized regulators, such as the National Broadcasting and Telecommunications Commission (NBTC), Bank of Thailand, Securities and Exchange Commission (SEC), and energy authorities.

Strategic Objectives and Safeguards:

The government has emphasized that these changes do not represent full liberalization. Instead, they aim to reduce unnecessary administrative burdens, eliminate overlapping regulations, attract advanced technology and expertise, and position Thailand as a regional business and services hub.

Implications for Foreign Investors:

These amendments signal a more investor-friendly stance in targeted modern sectors while maintaining the core protective framework of the FBL. Foreign businesses in exempted categories can anticipate streamlined market entry once effective, though they must still adhere to sector-specific regulations.

Key Takeaways:

•  Thailand’s FBA continues to prohibit or restrict foreign ownership in sensitive sectors via its three lists, but recent reforms ease burdens in competitive or well-regulated areas.

•  The Cabinet has approved in principle exemptions for eight service businesses and adjustments for agricultural futures trading, subject to a multi-step approval process.

•  Implementation will require several months or longer, involving Council of State review and final publication in the Royal Gazette.

•  The changes prioritize efficiency, technology transfer, and competitiveness without compromising national safeguards.

•  Foreign investors should consult legal experts to monitor developments and ensure compliance with both the updated FBL rules and industry-specific laws.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Revised Digital Government Standard Updates Public Sector Data Governance Framework

The Digital Government Development Agency (DGA) continues to advance digital transformation across the public sector by releasing an updated framework for data governance. This revision strengthens structured, ethical, secure, and interoperable data management practices, serving as a vital foundation for efficient public services, evidence-based policymaking, and trusted collaboration between government and the private sector.

The Announcement of the Digital Government Development Committee on Digital Government Standards Regarding the Public Sector Data Governance Framework (Revised Edition: Practical Guidelines) (Mor Dor. 6 : 2566), commonly referred to as DGF V.2.0, replaces the earlier version and introduces significantly more actionable implementation support for government agencies.

Background and Purpose of the Revision:

The update is grounded in the Digital Government Administration and Services Act B.E. 2562 (2019), which requires public agencies to adopt sound data governance practices. While the original framework (V.1.0) focused primarily on establishing theoretical foundations, the 2023 revision (Mor Dor. 6 : 2566) retains core principles while substantially expanding practical guidance based on implementation experience and agency feedback.

The revised standard is designed for a wide audience — ranging from non-IT personnel and field operators to policymakers, data analysts, and senior executives. Its main objectives include:

  • Improving data quality, security, accessibility, and usability
  • Facilitating seamless data integration and sharing across agencies
  • Advancing open government data initiatives
  • Enabling advanced analytics and data-driven decision making
  • Building public confidence through transparent, accountable, and privacy-respecting data practices

Notable enhancements include clearer definitions of key terms (such as “government agency,” “public sector data governance,” “data strategy,” “data owner,” and “data agent”), refined data classification categories (public, internal, personal, official secret, and national security data), and the addition of practical implementation tools, readiness assessments, maturity models, and real-world case studies.

Core Components of the Revised Framework:

The standard takes a comprehensive lifecycle approach to data management — from collection, processing, and storage to sharing, archiving, and disposal. It is structured in two main sections:

  1. Theoretical Foundations — Core principles of lawfulness, transparency, accountability, data quality, security, privacy protection (fully aligned with the Personal Data Protection Act — PDPA), interoperability, ethical use, and stewardship. These principles have been clarified and made more accessible.
  2. Practical Guidelines — Newly expanded content offering step-by-step implementation support, including:
    • Establishing effective data governance structures and committees
    • Defining clear roles and responsibilities (data owners, custodians, stewards, and processors)
    • Developing agency-specific data strategies, policies, and procedures
    • Metadata management, data cataloguing, and data quality control
    • Readiness assessment and progressive maturity evaluation
    • Auditing, monitoring, compliance mechanisms, and risk management
    • Practical case studies and solutions to common implementation challenges

The framework promotes integration with national platforms such as the Government Data Exchange (GDX) and the Government Data Catalog (GD Catalog), enhancing discoverability and secure data sharing.

Alignment with National Digital Infrastructure and Investment Goals:

This data governance update supports the government’s broader strategy to upgrade critical infrastructure and attract high-value investments in future-oriented industries. Recent policy announcements emphasize strengthening digital foundations alongside clean energy development to support sectors such as data centers, semiconductors, electric vehicles, artificial intelligence, smart cities, and other high-technology industries.

Robust public sector data governance provides the essential trust layer required for secure public-private partnerships, large-scale digital projects, and the responsible use of data in analytics and AI applications.

Key Takeaways for Businesses and Investors:

  • Elevated Compliance Standards: Government agencies are expected to enforce stricter requirements on data security, privacy, quality, and interoperability in all interactions, procurement processes, and partnerships.
  • New Business Opportunities: Rising demand for data governance platforms, training services, metadata tools, analytics solutions, compliance consulting, and implementation support services.
  • Smoother Collaboration: Enhanced interoperability reduces friction in government procurement, licensing, reporting, data-sharing agreements, and joint digital projects.
  • Risk Reduction: Companies that align with the new public sector benchmarks can better manage compliance risks, especially in regulated industries such as financial services, healthcare, telecommunications, and energy.
  • Innovation Enablement: Improved availability and governance of public data open new avenues for developing value-added services, open data applications, and AI-driven solutions.
  • Strategic Positioning: Early alignment with these standards strengthens competitiveness when bidding for government contracts and participating in Thailand’s expanding digital economy ecosystem.

Outlook and Recommendations:

The public sector data governance landscape continues to evolve rapidly. The DGA is expected to roll out additional supporting tools, training programs, and related standards on open data and data cataloguing.

Businesses should consider the following actions:

Explore partnership opportunities in supporting digital government transformation projects.

Benchmark internal data governance practices against the revised public sector framework, particularly when handling government data or participating in public-private initiatives.

Monitor the publication of agency-level data strategies and any forthcoming implementation guidelines.

Engage with DGA resources, workshops, and capability-building programs.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand’s DBD Launches Public Hearing to Evaluate the Effectiveness of the Foreign Business Act B.E. 2542 (1999)

The Department of Business Development (“DBD”), under the Ministry of Commerce of Thailand, is currently conducting a nationwide public hearing from 30 March to 30 April 2026 (the “Public Hearing”) to evaluate the effectiveness and practical implications of the Foreign Business Act B.E. 2542 (1999) (the “FBA”) in the current economic context. The FBA, which serves as the cornerstone of Thailand’s legal framework governing foreign participation in business activities, seeks to balance the protection of Thai business operators with the promotion of foreign investment. It not only regulates market access but also ensures that foreign participation contributes to the Thai economy through job creation, technology and knowledge transfer, and an expanded range of goods and services.

The Public Hearing aims to assess whether key aspects of the current legal framework — including the definition of “foreigner,” business classifications, licensing requirements, and enforcement mechanisms — remain appropriate in today’s evolving economic environment. It also reflects the government’s commitment to keeping the law aligned with changing business practices and international obligations. Feedback gathered through this process will inform targeted amendments intended to improve legal clarity, close existing loopholes, strengthen enforcement, and streamline regulatory procedures, ultimately establishing a more balanced and effective framework that protects Thai interests while remaining conducive to foreign investment.

Scope of the Public Hearing to Assess and Revise the FBA

The Public Hearing conducted by the DBD is designed to gather stakeholder feedback on key provisions of the FBA in order to assess their effectiveness and practical suitability. The feedback collected will assist the DBD in determining whether the FBA and its subsidiary regulations function as intended, and in identifying areas where adjustments may be required to enhance clarity, compliance, and enforcement. The matters under consideration include the following:

1. Definition of “Foreigner” (Section 4): Whether the current definition provides sufficient clarity and consistency, particularly in the context of complex shareholding structures.

2. Business Classification (Section 8): The continued categorisation of business activities into three lists:

  • List 1: Business activities strictly prohibited to foreigners, covering sensitive sectors that affect Thai livelihoods.
  • List 2: Business activities affecting national security, cultural heritage, or natural resources, which require Cabinet approval.
  • List 3: Business activities in sectors where Thai operators are not yet sufficiently competitive, which require DBD approval.

3. Regulatory Framework for the Foreign Business Certificate (“FBC”) (Sections 10–12): Whether the procedures for obtaining an FBC are practical and consistent with Thai law, international treaties, and special circumstances such as those applicable to foreign-born individuals residing in Thailand.

4. Approval Criteria: Whether the requirements imposed on applicants — including legal status, absence of prohibitions, and financial standing — effectively serve the objectives of national security, economic development, and public order.

5. Compliance Requirements: Whether obligations relating to the display of licenses, reporting of material changes, and applications for replacement licenses are clear and operationally feasible for businesses.

6. Minimum Capital and Capital Injection: Whether current thresholds and timelines for capital investment remain appropriate for business operations across the different classification categories.

7. Enforcement and Penalties: The effectiveness of administrative fines and court-based penalties, including measures to address unauthorized operations and nominee arrangements.

Authorizations under the Current FBA

According to DBD data updated as of March 2026, the majority of approvals under the FBA are concentrated in Foreign Business Licenses (“FBL”) for service businesses classified under List 3. This category accounts for the highest number of approved FBLs, with figures approximately double those of the next most common category — representative offices, which was also used to classified under List 3 of the FBA (currently the representative offices category is exempted from obtaining the FBL).

By contrast, the highest number of Foreign Business Certificates (FBCs) are issued to legal and accounting service firms. These certificates are primarily obtained under the Treaty of Amity between Thailand and the United States, which grants American companies national treatment in Thailand and exempts them from many of the restrictions otherwise imposed by the FBA.

Summary and Outlook

The ongoing Public Hearing presents an important opportunity for Thailand to review and modernize the FBA. Through this process, the DBD has identified several key areas for reform, including clarifying the definition of “foreigner,” updating enforcement and penalty provisions, standardizing licensing, and registration procedures, and addressing mechanisms to prevent legal circumvention. These reforms are aimed at closing existing legal gaps and improving regulatory clarity, thereby creating a framework that effectively protects Thai business interests while remaining supportive of foreign investment.

Under the FBA, violations may result in imprisonment, fines, or both, depending on the severity of the offence and judicial discretion. To reduce the burden on the courts, Section 42 of the FBA empowers the DBD’s Director-General to impose settlement fines for certain categories of offences, enabling cases to be resolved administratively upon payment of the applicable penalties under the Criminal Code. This approach underscores the need to strengthen enforcement mechanisms while maintaining the efficiency of administrative processes.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles