Breaking Down Government Data Silos: New Rules on Inter-Agency Sharing of Personal Information

A new Royal Decree has established a legal framework requiring government agencies to share personal information under their control with other government agencies for specified electronic data-linkage purposes.

The Royal Decree on Disclosure of Personal Information Controlled by Government Agencies to Other Government Agencies B.E. 2569 (2026) (the “Royal Decree”) represents an important development in the government’s efforts to move away from fragmented, agency-specific databases toward greater interoperability of public-sector information.

The measure is intended to enable government agencies to use more complete and accurate information in policymaking, public services and targeted welfare programs, while reducing the burden on individuals of repeatedly submitting information already held by the government. The framework is also intended to contribute to greater transparency and more effective law enforcement.

Legal basis for inter-agency disclosure:

The Royal Decree is issued pursuant to Section 24(9) of the Official Information Act B.E. 2540 (1997).

Section 24 of the Official Information Act establishes, as a general rule, that a government agency may not disclose personal information under its control to another government agency or another person without the prior or contemporaneous written consent of the person concerned, subject to specified statutory exceptions.

Section 24(9) permits disclosure in other cases prescribed by Royal Decree.

The new Royal Decree uses this statutory mechanism to provide a specific legal basis for government-to-government disclosure of personal information falling within its scope. As a result, qualifying disclosure under the Royal Decree does not depend on obtaining the individual’s written consent on each occasion.

This is important because large-scale government data interoperability would be difficult to implement if each transfer of information between government agencies required separate consent from every affected individual.

From isolated databases to connected government:

The policy underlying the Royal Decree is broader than simply permitting one government agency to send information to another.

Government agencies hold significant amounts of information about individuals, but that information has traditionally been maintained within separate administrative systems. Where relevant information is distributed among different agencies, the government may not have ready access to the complete information required for policymaking, public services or welfare administration.

The Royal Decree is intended to address this fragmentation by enabling electronic linkage of personal information held across government agencies.

The stated objectives include allowing government policies and measures, government services and targeted welfare programs to be based on accurate and complete information. Greater data linkage is also intended to improve the efficiency of government services, reduce administrative burdens on the public, promote transparency and enhance the effectiveness of law enforcement.

In practical terms, the framework supports a move toward the principle that individuals should not continually be required to provide one government agency with information that is already held by another government agency where the conditions for lawful data linkage are satisfied.

Government agencies may be required to disclose information:

A significant feature of the Royal Decree is that it does not merely provide government agencies with a general permission to share personal information.

It establishes a framework under which a government agency controlling personal information must disclose that information to another government agency where the information is requested for purposes falling within the Royal Decree.

The relevant data linkage is intended to support the preparation and provision of government services and the provision of targeted welfare through electronic means.

This gives the Royal Decree practical significance beyond an ordinary exception to a confidentiality rule. It provides the legal infrastructure for systematic government data interoperability.

The receiving agency also assumes obligations:

Greater availability of government-held information is accompanied by safeguards.

A government agency requesting and receiving personal information must safeguard that information. Importantly, it may not further disclose the information to an outside person.

This restriction is an important limitation on the scope of the new regime. The Royal Decree should therefore not be understood as making personal information freely transferable simply because it has entered an interconnected government information system.

The legal authorization concerns disclosure within the framework established by the Royal Decree. Once information has been received, the recipient agency remains responsible for protecting it and complying with the restrictions applicable to its subsequent disclosure.

The required safeguards are also linked to criteria and conditions prescribed by the competent authority and cybersecurity requirements. Consequently, implementation of the Royal Decree is as much an information-governance issue as a data-access issue.

Targeted welfare and government services:

One of the clearest practical applications of government data linkage is the provision of targeted welfare.

Eligibility for government assistance may depend on information maintained by several different authorities. Without data linkage, individuals may have to obtain documents from one agency and submit them to another, while the agency administering the benefit may have difficulty independently establishing a complete picture of the applicant’s circumstances.

Electronic linkage can potentially change this process.

Where legally permitted, the administering agency may obtain relevant information directly from government data already available elsewhere. This can make eligibility assessment more accurate, reduce duplicate documentation and enable welfare programs to be directed more effectively toward intended recipients.

The same principle can apply more broadly to government services. Greater interoperability can reduce repeated requests for information and allow government agencies to make administrative decisions using more complete information.

Transparency and law enforcement:

The Royal Decree also has implications beyond welfare and administrative services.

The stated rationale includes increasing transparency within government and improving the effectiveness of law enforcement. Information that appears unremarkable when held in a single agency’s database may have greater significance when lawfully linked with information held by other agencies.

Inter-agency data linkage can therefore provide government authorities with a more complete information base for identifying inconsistencies, verifying information and carrying out their statutory functions.

This capability may be particularly relevant where investigations or enforcement activities require information held by several government bodies.

However, the Royal Decree should not be characterized as creating a general law-enforcement database or an unrestricted investigative power. Its significance lies in providing a statutory mechanism for disclosure and electronic data linkage within the scope established by the Royal Decree.

Data sharing does not mean unrestricted data use:

An important compliance point is the distinction between access to information and freedom to use or disclose that information.

The fact that one government agency is legally entitled to obtain information from another does not mean that information becomes unrestricted once transferred.

Government agencies implementing data-linkage arrangements should therefore consider controls covering at least:

  • the authority and purpose for requesting information;
  • identification of the information required;
  • authentication of requesting agencies and authorized personnel;
  • access controls within the receiving agency;
  • secure electronic transmission;
  • logging and traceability of access and transfers;
  • cybersecurity safeguards;
  • retention and management of linked information; and
  • controls preventing unauthorized onward disclosure.

These controls are particularly important because increased interoperability can increase the consequences of inadequate security. A weakness in one interconnected system may potentially expose information originating from several agencies.

Relationship with personal data protection requirements:

The Royal Decree should also be understood within the broader legal framework governing personal information.

Its immediate statutory basis is the Official Information Act, and it establishes a specific mechanism permitting inter-agency disclosure that would otherwise be subject to the restrictions in Section 24 of that Act.

However, the existence of a statutory basis for disclosure should not automatically be equated with unlimited authority to process the information for any subsequent purpose.

Government agencies participating in data-linkage arrangements should therefore identify the legal authority supporting each stage of the information lifecycle—including collection, disclosure, receipt, use, retention, security and any subsequent disclosure—and consider other applicable personal data protection and cybersecurity requirements.

The distinction is particularly important as government systems become increasingly interconnected. Legal authority to receive information is only one component of lawful and responsible data governance.

A significant step toward data-driven government:

The Royal Decree represents a structural change in the management of government-held personal information.

The traditional model in which each government agency maintains its own information and individuals repeatedly provide substantially the same information to different authorities is increasingly being replaced by a model based on controlled interoperability.

If implemented effectively, the new framework should enable government agencies to make greater use of information already available within the public sector, improve the accuracy of public services and welfare programs, and reduce unnecessary administrative burdens on individuals.

The corresponding challenge is governance.

The more effectively government information systems are connected, the more important it becomes to ensure that access is authorized, purposes are properly defined, information is adequately protected and subsequent disclosure remains controlled.

The Royal Decree therefore represents not simply an expansion of government access to data, but a move toward a more integrated model of public-sector data governance.

Key Takeaways:

  • The Royal Decree marks an important shift from government data held in separate institutional silos toward controlled, interoperable public-sector data infrastructure.
  • The Royal Decree establishes a statutory mechanism for the disclosure of personal information between government agencies for qualifying electronic data-linkage purposes.
  • Its legal basis is Section 24(9) of the Official Information Act, which allows exceptions to the general restriction on disclosure of government-controlled personal information without written consent.
  • The framework goes beyond merely permitting voluntary data sharing and supports systematic interoperability between government information systems.
  • A government agency receiving information under the framework must safeguard the information and is restricted from further disclosure to an outside person.
  • The framework is intended to support more accurate policymaking, more efficient government services and targeted welfare, reduced administrative burdens on the public, greater transparency and more effective law enforcement.
  • Government agencies should not treat authorization to receive information as unrestricted authority to use or further disclose it. Purpose limitation, access controls, cybersecurity and information governance remain central to implementation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

From Voluntary Guidance to Legal Accountability: The Changing Rules for Digital Platforms

Digital platform regulation is entering a new phase. Recent developments indicate a shift from a framework centered largely on registration, disclosure, and risk management toward a more substantive model addressing platform conduct, seller accountability, fee transparency, and potentially the allocation of liability between platforms and businesses operating through them.

Two developments illustrate this direction particularly well. The first is the proposed Digital Platform Economy Act, which is being developed as a broader statutory framework for the platform economy. The second is the Electronic Transactions Development Agency (ETDA) Guideline on Transparency and Fairness in Digital Platform Service Fees, which establishes voluntary best practices for the disclosure and adjustment of platform fees. Although the guideline is not mandatory and the proposed Act has not yet been enacted, considered together they provide a useful indication of the regulatory principles increasingly shaping oversight of digital platforms: transparency, fairness, accountability, and greater protection for users and consumers.

A New Regulatory Framework for Digital Platforms:

Digital platform services are currently regulated under the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification. The existing regime establishes notification requirements and imposes various obligations depending on the nature, size, and risk profile of a platform. The proposed Digital Platform Economy Act would represent a significant further development. The government has accelerated work on the legislation, with the current policy timetable contemplating submission to the Cabinet before the draft proceeds to Parliament. As the legislation remains under development, however, both its provisions and legislative timetable remain subject to change.

The emerging framework indicates several areas that platform operators should monitor closely. These include registration and disclosure of information concerning platform operations and revenue, as well as measures intended to give regulators greater visibility over businesses participating in the platform economy. Territorial scope will be particularly important for multinational businesses, since a platform providing services into the local market may potentially become subject to regulatory requirements even where the operator does not have a conventional physical presence in the jurisdiction.

Another important area concerns businesses and individuals offering goods or services through platforms. The regulatory direction increasingly places platforms in the position of gatekeepers rather than merely passive intermediaries. Existing regulatory measures already require certain platforms to obtain and verify seller information and implement risk-management measures concerning goods and services offered through their systems. The proposed legislation appears likely to develop this approach further, making seller onboarding, identity verification, record keeping, monitoring, and enforcement increasingly important compliance functions rather than merely commercial processes.

The Emerging Question of Platform Liability:

Perhaps the most significant issue to monitor is the extent to which a platform may bear responsibility for harm arising from transactions conducted through its service. Platform operators have traditionally characterized themselves as intermediaries connecting independent sellers with customers, and their terms and conditions commonly distinguish the platform from the seller responsible for the underlying goods or services.

The proposed regulatory approach may reduce the practical significance of that distinction. Discussions surrounding the Digital Platform Economy Act contemplate circumstances in which platforms could bear joint responsibility for consumer harm, particularly where the platform fails to perform duties imposed on it. The precise scope of any liability will depend on the final statutory language, including the conduct that triggers liability, available defenses, and the relationship between the new regime and existing consumer protection laws.

If enacted broadly, such liability could materially alter the allocation of risk in the platform economy. Seller verification and monitoring would no longer be viewed simply as regulatory procedures; they could become directly relevant to a platform’s financial exposure when consumers suffer loss. Contractual provisions placing responsibility on sellers, including indemnities, may remain important but would not necessarily protect a platform from independent statutory liability. Platform operators should therefore monitor the liability provisions particularly closely as the draft progresses.

Fee Transparency and Fairness:

While the proposed Act represents the potential development of mandatory statutory obligations, ETDA has adopted a softer regulatory approach to another significant platform issue: fees. Its Guideline on Transparency and Fairness in Digital Platform Service Fees is intended as voluntary best practice rather than direct price regulation. The guideline does not prescribe maximum commissions or other charges. Instead, it focuses on whether users can understand what they are being charged, what services they receive in return, and how changes to those charges are made.

Platforms are encouraged to present fee information clearly and in an accessible manner, including an explanation of individual fee items, the services or benefits associated with them, and the basis or method used to calculate the charges. This is particularly relevant where the actual cost of participating on a platform extends beyond a headline commission and may include advertising, promotional, affiliate, payment-related, or other service fees. The regulatory concern is therefore not simply whether a particular commission is high or low, but whether users can reasonably determine and evaluate the overall economic cost of using the platform.

The guideline also addresses changes to platform fees. It recommends that users receive at least 15 days’ advance notice of fee changes, together with information concerning the reason for the change, its scope and potential impact, and channels for inquiries or feedback. The guideline also contemplates a consultation process in connection with fee changes. Platforms should therefore distinguish between merely notifying users that a fee will change and maintaining a process that reflects the broader principles of transparency, consultation, and fairness contemplated by the guideline.

Fairness extends beyond disclosure. Platforms are encouraged to avoid unnecessary duplication of charges and to distinguish clearly between compulsory fees and charges for additional services. Optional services should correspond to genuine additional benefits rather than becoming effectively mandatory through the design or operation of the platform. The objective is not direct government control of platform pricing, but a framework in which platforms can explain how fees are determined and users can understand the true costs of participating in the platform ecosystem.

From Voluntary Guidance to Legal Accountability:

Considered separately, the proposed Digital Platform Economy Act and the fee guideline address different regulatory issues. Considered together, however, they reveal a broader trajectory. The fee guideline represents soft regulation, under which regulators articulate expectations concerning fair market conduct and encourage platforms voluntarily to incorporate those principles into their business practices. The proposed legislation points toward harder regulatory intervention, potentially involving registration, disclosure, seller verification, statutory duties, enforcement mechanisms, and greater responsibility for consumer harm.

This distinction is important for businesses. Voluntary guidance should not necessarily be treated as irrelevant simply because it does not create directly enforceable obligations. Such guidance may establish regulatory expectations concerning reasonable industry conduct, identify practices receiving regulatory scrutiny, and indicate areas in which more formal intervention could eventually follow if voluntary measures prove insufficient.

The broader development is therefore not simply an increase in the number of rules applicable to digital platforms. It reflects a gradual change in the regulatory conception of the platform itself. As platforms exercise greater control over seller admission, product visibility, payment mechanisms, fees, and transactions, regulators increasingly expect them to accept corresponding responsibilities for how those ecosystems operate.

Preparing for the Next Stage of Platform Regulation:

Platform operators need not wait for the proposed legislation to be enacted before reviewing their compliance architecture. Seller onboarding and verification procedures should be assessed to determine what information is collected, how identities and business credentials are verified, how information is updated, and what happens when inaccurate information or unlawful activity is detected. Systems should also retain sufficient records to demonstrate that verification, monitoring, complaints, and enforcement procedures have actually been followed.

Fee structures warrant similar attention. Platforms should consider whether users can readily identify the overall economic cost of using their services and whether compulsory fees, optional services, promotional charges, advertising costs, and other charges are adequately explained. Procedures for changing fees should also be reviewed against the transparency, advance-notice, and consultation principles reflected in ETDA’s guideline.

Finally, contractual arrangements with sellers should be considered together with operational compliance. If the new legislation imposes independent statutory duties on platforms, contractual provisions allocating responsibility entirely to sellers may have limited effect against claims brought directly against the platform. Indemnities, suspension rights, seller information obligations, insurance arrangements, record keeping, and mechanisms for recovering losses should therefore form part of a broader risk-management framework rather than being treated as substitutes for regulatory compliance.

Key Takeaways:

  • Digital platform regulation is moving beyond registration and disclosure toward greater operational accountability.
  • The proposed Digital Platform Economy Act may expand requirements concerning platform registration, business information, seller verification, platform conduct, and consumer protection. Its final provisions should be monitored as the legislative process progresses.
  • Potential joint liability for consumer harm may be one of the most significant developments because it could alter the traditional allocation of responsibility between platforms and independent sellers.
  • ETDA’s fee guideline remains voluntary and does not constitute direct price regulation, but it establishes regulatory expectations concerning fee transparency, fairness, advance notice, and consultation.
  • Platform operators should consider reviewing seller verification, monitoring, fee disclosures, change-management procedures, contractual risk allocation, and record-keeping systems before the new statutory framework is finalized.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Moves Toward a Dedicated Regulatory Framework for Data Centers

Thailand may soon take a significant step toward regulating its rapidly expanding data center industry. According to recent reports, the government is preparing a Prime Minister’s Office Regulation that would establish a dedicated framework for overseeing data center operations, with particular emphasis on resource management, environmental impacts, and centralized regulatory oversight. While the proposed regulation has not yet been issued, it signals a potential shift from Thailand’s current investment-driven approach toward a more comprehensive regulatory model for the sector.

Background:

Thailand has become an increasingly attractive destination for data center investment due to strong government incentives, growing cloud adoption, and its strategic location in Southeast Asia. However, the rapid expansion of large-scale facilities has also raised concerns regarding infrastructure capacity, particularly electricity and water consumption.

According to the reported proposal, the government intends to introduce a dedicated regulatory mechanism to better coordinate oversight of the industry and manage its broader impacts on national resources.

Proposed regulatory framework:

The reported proposal indicates that the Prime Minister’s Office Regulation would establish a new committee responsible for supervising data center activities. Its responsibilities would reportedly include:

  • overseeing the overall development of the data center industry;
  • assessing the impacts of data center investments;
  • monitoring resource consumption, particularly electricity and water usage;
  • coordinating regulatory oversight among relevant government agencies; and
  • supervising approvals, permits, and compliance monitoring.

Although further details have not yet been published, the proposal suggests that the government intends to create a more centralized oversight structure than currently exists.

Addressing fragmented regulation:

At present, data center projects typically interact with multiple government agencies depending on the nature of the project. Investors may require approvals or incentives from different authorities, while utility arrangements are often negotiated separately.

The reported proposal appears intended to address this fragmented regulatory landscape by introducing a dedicated governance mechanism specifically focused on data centers.

Greater focus on infrastructure and resource management:

A notable feature of the proposal is its emphasis on resource planning.

According to the reports, the government has identified several concerns, including:

  • increasing electricity demand from large-scale data centers;
  • substantial water consumption required for cooling systems;
  • challenges in forecasting future resource demand; and
  • overlapping arrangements for water supply that may complicate national infrastructure planning.

The proposal therefore appears to reflect a policy objective of integrating data center development with broader infrastructure and environmental planning rather than regulating the industry solely from an investment perspective.

Different treatment for existing and future projects:

The reported framework would distinguish among three categories of data centers:

Existing operating facilities

Existing operators may become subject to audits or assessments focusing on matters such as resource consumption, temperature management, and noise impacts.

Approved projects under development

Projects that have already received approvals but are not yet operational may be required to comply with additional regulatory conditions before commencing operations.

Future applicants

New projects may become subject to a comprehensive regulatory regime addressing matters such as:

  • sustainable water management;
  • reserve water sources;
  • environmental impacts; and
  • measures designed to reduce adverse impacts on surrounding communities.

This tiered approach suggests that the government is seeking to avoid disrupting ongoing investments while progressively strengthening regulatory requirements for future developments.

Potential changes to location planning:

The reports also indicate that the government is considering a more strategic approach to determining where future data centers should be located.

Rather than concentrating additional facilities in existing investment hubs, policymakers are reportedly evaluating locations with stronger electricity and water infrastructure, including areas near major power generation facilities. The government has also indicated that supporting digital infrastructure, such as fiber-optic networks, could be expanded if new data center clusters are developed.

What investors should watch:

Although the proposal remains at the policy stage, investors and operators should monitor several issues as the framework develops:

  • the legal authority under which the new committee will operate;
  • whether additional licensing or approval requirements will be introduced;
  • technical standards relating to electricity, water use, and environmental impacts;
  • transitional requirements applicable to existing operators; and
  • the interaction between the new framework and existing approvals issued by sector-specific regulators.

The final regulatory approach will determine whether the proposed framework primarily serves as a coordination mechanism or introduces substantive compliance obligations for the industry.

Key takeaways:

  • Thailand is reportedly preparing a dedicated regulatory framework for data centers through a proposed Prime Minister’s Office Regulation.
  • The proposal reflects increasing government attention to electricity consumption, water usage, and environmental impacts associated with large-scale data center investments.
  • A new committee may be established to coordinate oversight of approvals, compliance, and resource management.
  • Existing facilities, projects under development, and future investments could become subject to different regulatory requirements.
  • Although the proposal has not yet been formally issued, investors planning data center projects in Thailand should closely monitor further regulatory developments, as they may significantly affect project planning, compliance obligations, and site selection.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

NBTC Issues AI Governance Guidelines for Telecom Licensees

Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has issued new guidelines setting out its expectations for the responsible use of artificial intelligence (AI) by telecommunications licensees. Although the guidelines are not legally binding, they establish a comprehensive risk-based framework for AI governance and provide a clear indication of the regulatory standards that the NBTC expects telecom operators to adopt when deploying AI in the provision of telecommunications services.

The guidelines reflect the increasing regulatory focus on AI governance and complement existing legal obligations relating to cybersecurity, personal data protection, and telecommunications. They also align with broader national efforts to develop a comprehensive AI regulatory framework.

Scope of the Guidelines:

The guidelines apply to holders of telecommunications business licenses under Thailand’s telecommunications licensing regime, but only in relation to AI systems used to provide licensed telecommunications services.

Organizations that are not telecommunications licensees are not directly subject to the guidelines. Nevertheless, AI developers, technology vendors, cloud service providers, and outsourced service providers may be indirectly affected because telecommunications licensees are expected to exercise oversight over third-party AI solutions used in their operations. As a result, contractual obligations and vendor due diligence are likely to become increasingly important for suppliers serving the telecommunications sector.

The guidelines should be considered alongside existing legal requirements, including the Personal Data Protection Act, the Cybersecurity Act, the Computer Crime Act, and the NBTC Notification on the Protection of Telecommunications Service Users’ Rights in relation to personal data, privacy, and the freedom of telecommunications. They also complement the broader AI legislation currently under development by the Electronic Transactions Development Agency (ETDA).

Strengthening AI Governance:

A central feature of the guidelines is the expectation that AI governance should extend beyond technical implementation and become an organizational responsibility.

Telecommunications licensees are encouraged to establish governance structures at both the policy and operational levels, such as AI committees, working groups, or designated responsible officers. These governance bodies should oversee AI strategy, establish internal policies, supervise risk management, and define accountability throughout the AI lifecycle.

The guidelines also emphasize that responsibilities should be clearly assigned not only to internal personnel but also to third-party AI solution providers and outsourced service providers. Licensees are expected to ensure that contractual arrangements clearly define each party’s obligations regarding AI governance, risk management, and regulatory compliance.

A Principles-Based Approach to Responsible AI:

Rather than prescribing detailed technical requirements, the guidelines adopt a principles-based approach centered on six core expectations.

First, AI systems should comply with applicable laws, ethical principles, and internationally recognized standards. AI should respect privacy, human dignity, and fundamental rights, and organizations should consider implementing appropriate safeguards, including content filtering, to reduce the risk of generating harmful or unlawful outputs.

Second, AI systems should operate fairly. This includes using representative and reliable training data, assessing potential bias, and taking appropriate measures to mitigate discriminatory outcomes.

Third, cybersecurity and privacy protections should be integrated into AI systems. The guidelines encourage the adoption of internationally recognized security standards and recommend technical safeguards such as encryption, anonymization, and access controls to protect personal data and system integrity.

Fourth, organizations should promote transparency by maintaining documentation regarding AI design, development, and operation, while providing consumers with appropriate information about how AI systems influence decisions or recommendations.

Fifth, accountability should be clearly established throughout the organization. Internal policies should define responsibility for AI outcomes, while consumers should have accessible channels to submit inquiries or complaints regarding AI-enabled services.

Finally, AI systems should be reliable and robust. The guidelines recommend testing AI models to ensure that they produce accurate and consistent results, including under unexpected operating conditions.

Governance Throughout the AI Lifecycle:

The guidelines emphasize that AI governance should be integrated throughout the entire AI lifecycle rather than focusing solely on deployment.

Licensees are expected to conduct risk assessments before development begins, evaluate the capabilities and reliability of third-party AI providers, and maintain appropriate standards for data quality and traceability. Before deployment, AI systems should undergo testing for reliability, fairness, and operational performance.

Once AI systems are operational, organizations should continuously monitor performance, maintain appropriate human oversight, and periodically evaluate whether AI systems continue to operate as intended. The guidelines also address the retirement of AI systems, encouraging secure decommissioning processes that protect data and maintain appropriate records throughout the system’s lifecycle.

This lifecycle-based approach reflects the growing international trend toward continuous AI governance rather than one-time compliance assessments.

Consumer Transparency and Organizational Readiness:

Consumer protection is another significant feature of the guidelines.

Telecommunications licensees are encouraged to notify consumers when they are interacting with AI systems, such as chatbots or voicebots. Where AI-generated recommendations may influence consumer decisions, organizations should provide appropriate disclosures and allow consumers to request assistance from a human representative where appropriate. Effective feedback and complaint mechanisms should also be maintained.

Internally, the guidelines recognize that responsible AI governance requires organization-wide awareness. Licensees are therefore encouraged to provide AI-related training across all levels of the organization. Employees who use AI systems should understand the associated legal and operational risks, while technical personnel and external developers should receive training on organizational AI policies, ethical principles, and applicable regulatory requirements.

Practical Implications:

Although the guidelines do not create new legal obligations, they provide valuable insight into the NBTC’s regulatory expectations and are likely to influence future regulatory supervision and industry best practices.

Telecommunications licensees should consider reviewing their existing AI governance frameworks to determine whether governance responsibilities are clearly assigned and appropriately documented. Organizations should also evaluate AI risk management procedures, update contracts with AI vendors and outsourced service providers, assess consumer disclosure mechanisms, and ensure that staff receive appropriate AI governance training.

The guidelines may also have implications for corporate transactions involving telecommunications businesses. As AI becomes increasingly integrated into telecommunications operations, AI governance maturity, data governance practices, and vendor oversight may become important considerations during legal and regulatory due diligence.

Key Takeaways:

  • Telecommunications licensees should review their governance frameworks, contractual arrangements, AI risk management processes, consumer disclosure practices, and staff training programs to align with the NBTC’s expectations.
  • The NBTC’s AI guidelines establish a comprehensive risk-based governance framework for telecommunications licensees and provide a clear indication of the regulator’s expectations for responsible AI deployment.
  • Although nonbinding, the guidelines are likely to influence regulatory supervision and industry best practices within Thailand’s telecommunications sector.
  • AI governance is expected to extend throughout the entire AI lifecycle, encompassing organizational governance, risk management, vendor oversight, cybersecurity, consumer protection, and ongoing monitoring.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Managing Regulatory Due Diligence for Cross-Border Investors in Financial and Digital Asset Businesses

Introduction:

Cross-border investments in financial services and digital asset businesses present unique regulatory challenges that extend well beyond traditional legal or financial due diligence. Whether an investor is acquiring a licensed payment service provider, a securities business, a digital asset exchange, or a fintech company operating under sector-specific regulation, the value of the transaction can depend as much on the target’s regulatory standing as on its commercial performance.

Unlike ordinary commercial businesses, regulated entities operate under continuing supervision. Their ability to conduct business depends not only on maintaining the necessary licenses but also on demonstrating ongoing compliance with governance requirements, prudential standards, anti-money laundering obligations, cybersecurity controls, and consumer protection rules. A company with strong financial performance may nevertheless represent a significant acquisition risk if its regulatory compliance has deteriorated or if it is subject to undisclosed supervisory concerns.

For cross-border investors unfamiliar with the Thai regulatory landscape, regulatory due diligence is therefore not merely a legal exercise. It is an essential component of transaction risk assessment and should begin early in the acquisition process.

Looking Beyond the License:

One of the most common misconceptions among foreign investors is that verifying the existence of a regulatory license is sufficient. In reality, the existence of a license represents only the starting point of the analysis.

Many regulated businesses have evolved over time, expanding their products and services beyond the scope originally contemplated when their licenses were granted. A fintech company may initially have operated as an electronic payment platform before introducing digital lending, cross-border remittance services, or digital asset-related products. Each new business activity may require separate regulatory approval or may be subject to different supervisory requirements.

Regulatory due diligence should therefore examine whether every revenue-generating activity falls within the scope of the target’s existing licenses and whether any exemptions relied upon remain available. It is equally important to determine whether any license conditions have been imposed by regulators and whether the company has complied with those conditions throughout its operations.

Regulatory Approval May Determine Whether the Transaction Can Close:

Unlike acquisitions involving ordinary commercial companies, transactions involving regulated financial businesses frequently require regulatory approval before completion. In some sectors, a change in significant shareholding or control may not become legally effective until the relevant regulator has approved the transaction. Other regulatory regimes may require post-closing notifications or impose “fit and proper” assessments on incoming shareholders, directors, or senior management.

Consequently, regulatory due diligence should identify not only the approvals required for the target’s day-to-day operations but also those triggered by the proposed acquisition itself. Failure to identify these requirements early can delay completion, affect financing arrangements, or require restructuring of the transaction.

Cross-border investors should also consider whether foreign ownership restrictions, residency requirements, or limitations on board composition may influence the post-closing governance structure.

Compliance Culture Often Matters More Than Written Policies:

Modern financial regulators increasingly assess how compliance operates in practice rather than whether a company simply maintains a complete set of written policies.

Accordingly, regulatory due diligence should extend beyond reviewing compliance manuals and internal procedures. Investors should seek evidence that compliance functions are adequately resourced, that internal reporting mechanisms operate effectively, and that senior management actively oversees regulatory risk.

The company’s interactions with regulators may provide particularly valuable insight. Inspection reports, supervisory correspondence, warning letters, remediation plans, and historical enforcement actions often reveal recurring compliance weaknesses that are not apparent from corporate documentation alone. Even where no formal penalties have been imposed, repeated supervisory findings may indicate weaknesses in governance or internal controls that require significant remediation after closing.

Technology Risk Has Become a Core Regulatory Issue:

Technology is now central to regulatory supervision of financial institutions and digital asset businesses. Cybersecurity failures, operational disruptions, and weaknesses in technology governance increasingly attract regulatory attention regardless of whether they result in customer losses.

For investors, this means regulatory due diligence should include an assessment of cybersecurity governance, incident response procedures, disaster recovery planning, outsourcing arrangements, cloud service management, and operational resilience frameworks. Businesses operating digital asset platforms should also be assessed for wallet security, custody arrangements, transaction monitoring systems, and market surveillance capabilities.

Technology deficiencies may not immediately affect valuation but can require substantial investment after completion to satisfy regulatory expectations.

AML and Financial Crime Controls Remain High-Risk Areas:

Anti-money laundering and counter-terrorism financing compliance continues to be among the highest enforcement priorities for financial regulators. Deficiencies in customer due diligence, transaction monitoring, sanctions screening, or suspicious transaction reporting can expose regulated businesses to substantial regulatory sanctions and reputational damage.

Investors should therefore evaluate not only the target’s written AML policies but also the effectiveness of their implementation. Questions such as how high-risk customers are identified, how beneficial ownership is verified, and how suspicious transactions are escalated can provide a clearer picture of the target’s compliance maturity than policy documents alone.

Where previous regulatory inspections have identified AML deficiencies, investors should assess whether remediation has been completed and whether regulators remain satisfied with the company’s corrective measures.

Data Protection and Outsourcing Should Not Be Overlooked:

Financial institutions increasingly rely on external service providers for cloud infrastructure, customer verification, payment processing, and cybersecurity services. While outsourcing may improve operational efficiency, regulators continue to emphasize that responsibility for regulatory compliance ultimately remains with the licensed entity.

Accordingly, regulatory due diligence should review the contractual framework governing outsourced services, the company’s oversight of critical vendors, and its contingency planning should key service providers become unavailable.

Similarly, businesses handling significant volumes of customer information should be assessed for compliance with personal data protection requirements, particularly where customer information is transferred across borders or processed by third-party vendors.

Due Diligence Findings Should Shape Transaction Documents:

Regulatory due diligence should not end with the preparation of a report. Its findings should directly influence transaction structuring and the allocation of risk between buyer and seller.

Where significant compliance concerns are identified, investors may seek enhanced representations and warranties regarding licensing, regulatory compliance, anti-money laundering controls, cybersecurity, and data protection. Specific indemnities may be appropriate for known regulatory investigations or historical compliance failures. In some cases, buyers may also require identified deficiencies to be remediated as conditions precedent before closing.

Integrating regulatory due diligence into transaction documentation helps ensure that regulatory risks are appropriately allocated and reduces the likelihood of post-completion disputes.

Conclusion:

As financial regulation becomes increasingly complex and technology-driven, regulatory due diligence has evolved from a narrow licensing review into a comprehensive assessment of an institution’s regulatory health. For cross-border investors, understanding how a target interacts with regulators, manages compliance risks, and maintains operational resilience is often as important as evaluating its financial performance.

A well-executed regulatory due diligence exercise enables investors to identify hidden regulatory exposures, anticipate approval requirements, negotiate more effective contractual protections, and develop realistic post-acquisition integration plans. In regulated financial and digital asset sectors, it is often the quality of regulatory compliance—not simply the quality of the business—that ultimately determines whether an investment achieves its intended value.

Key Takeaways:

  • In acquisitions involving financial and digital asset businesses, robust regulatory due diligence is essential to preserving investment value and minimizing post-closing regulatory exposure.
  • Regulatory due diligence should evaluate the target’s overall regulatory health rather than simply confirming the existence of licenses.
  • Investors should assess governance, supervisory history, AML/CTF controls, cybersecurity, data protection, outsourcing arrangements, and change-of-control requirements alongside licensing compliance.
  • Early identification of regulatory risks helps facilitate transaction planning, regulatory approvals, and appropriate contractual risk allocation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

BOT: Bank of Thailand Introduces Stricter Rules on Large Cash Transactions to Combat Illicit Flows

The Bank of Thailand (BOT) is set to implement enhanced oversight on significant cash movements as part of efforts to address gray-area financial activities, reduce risks of money laundering, and promote greater transparency in the financial system.

Under the upcoming regulations, financial institutions will soon be required to perform detailed customer due diligence for any cash withdrawal exceeding 5 million baht in a single transaction. Customers must clearly explain the source of the funds and the intended purpose of the cash. If the explanation is unsatisfactory or unverifiable, banks may restrict or decline to process the transaction.

This measure primarily targets unusual or high-risk cash usage that could be linked to informal, unregulated, or illicit activities. In a later phase, similar requirements will apply to cash deposits of 5 million baht or more, where the origin of the funds must also be justified.

The BOT has indicated that legitimate needs—such as those of small and medium-sized enterprises (SMEs), individuals conducting regular business operations, or other verifiable purposes—will continue to be accommodated, provided appropriate documentation and explanations are provided. However, the rules aim to make large-scale cash handling more accountable and discourage reliance on physical currency for questionable purposes.

Looking ahead, after an initial implementation period and evaluation of impacts (including any effects on ordinary users), the threshold may be lowered to 3 million baht for both withdrawals and deposits to further strengthen controls.

These changes form part of broader initiatives to tackle structural economic vulnerabilities, encourage electronic payments where practical, and limit opportunities for crime or opaque transactions.

Impact on the Public:

Most everyday individuals and small businesses will remain largely unaffected, as transactions below the 5 million baht threshold face no new requirements, and legitimate large needs can proceed with proper justification.

People or entities accustomed to handling large cash amounts (e.g., for property deals, business purchases, or other high-value activities) will need to prepare explanations and supporting evidence in advance, potentially adding time and documentation steps at the bank.

Those involved in informal or gray-area dealings may find it significantly harder to move large sums in cash without scrutiny, increasing the risk of restrictions or reporting to authorities.

Overall, the shift promotes safer, more traceable financial habits while aiming to reduce crime risks associated with large cash volumes and ease burdens through related reviews of common banking fees.

Key Takeaways:

Implementation is expected in the near future (early to mid-March timeframe), giving the public time to adjust to more accountable cash handling practices.

Cash withdrawals over 5 million baht will require clear justification of purpose and source; unsatisfactory explanations may lead to restrictions.

The rules will later extend to large cash deposits and could lower the threshold to 3 million baht after review.

Legitimate users (e.g., SMEs and individuals with valid reasons) can continue transactions by providing details—no outright ban is intended.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Launches “Economic Cabinet Plus” Plan to Drive High-Growth and High-Income Status

The Thai government has launched a major initiative to work more closely with the private sector on economic policy. Through a new fast-track mechanism and a Joint Public-Private Consultative Committee, the government aims to process private-sector proposals more efficiently and convert business ideas into concrete projects.

What the Government Has Agreed To Do

The initiative’s central aim is to cut red tape and streamline slow-moving bureaucratic processes. The government has established a special fast-track channel that allows economic proposals from business leaders to be reviewed and approved without the delays typical of the traditional system. A newly formed joint public-private committee is then tasked with translating these ideas into implemented projects.

To carry out this plan, the government is driving the economy through four main engines, designed to work in tandem to deliver both short-term and long-term results:

  1. Attracting new investment through a future investment hub and a fast-track approvals initiative aimed at resolving bottlenecks and accelerating project sign-off. The focus is on positioning Thailand as a regional hub for AI, digital technology, and financial services, while advancing the green economy and next-generation automotive industries.
  2. Shifting tourism strategy away from visitor volume and toward high-value, quality tourism — including wellness tourism and medical tourism — while pursuing Free Trade Agreements with major markets such as the EU, the US, and the UK.
  3. Upgrading the national skills base by prioritizing STEM and AI education, and building a stronger ecosystem for startups and private-sector research.
  4. Reforming internal government processes by reducing bureaucratic red tape, expanding digital government and e-licensing services to curb corruption, and updating regulations so that government budgets flow into the economy more quickly.

Under these four engines, the government has identified seven target industries for long-term growth:

  1. High-quality agriculture and food
  2. Future automotive
  3. Smart electronics and digital technology
  4. Medicine and healthcare
  5. High-quality tourism
  6. Global and regional trade
  7. The creative economy

The Government’s Goals

Working in close coordination with the private sector, the government has set measurable targets. First, it aims to raise Thailand’s economic growth potential above 3% annually — a marked improvement on recent performance. Second, it wants to place Thailand among the world’s top 20 most competitive economies, positioning the country as a regional investment hub. The overarching goal of this 12-year plan is to elevate Thailand to “high-income country” status, raising average annual per-capita income to roughly $15,000, up from the current $8,000–$9,000.

What This Means for Investors

For both Thai and foreign investors, the plan offers meaningful advantages. The fast-track system is designed to reduce red tape and shorten approval timelines for licenses and permits. Investors in AI, green energy, digital technology, and financial services — along with the seven target industries — can expect additional support and a more favorable regulatory environment. The government’s 12-year roadmap is also intended to give investors greater confidence in Thailand’s long-term policy stability.

What This Means for Thai Citizens

For Thai citizens, the plan is intended to translate into tangible benefits. Growth in high-tech, financial, and advanced manufacturing industries is expected to create higher-skilled, better-paying jobs. Investment in STEM and AI training aims to build a more competitive workforce, while faster budget disbursement and integration into new investment supply chains should benefit small and medium-sized enterprises (SMEs). As the economy expands, the government intends to reinvest additional revenue into public transport, healthcare, and education.

Key Takeaways

  • A new fast-track mechanism is intended to accelerate the transition from private-sector proposals to government action, organized around four core economic engines.
  • Official targets include lifting the country’s economic growth potential above 3%, placing Thailand in the global top 20 for competitiveness by 2030, and raising average per-capita income to roughly $15,000 within 12 years.
  • Investors can expect reduced red tape, faster licensing through e-government initiatives, and targeted support across seven priority industries.

Thai citizens stand to benefit from STEM/AI training programs, stronger SME support, higher-paying jobs, and improved public infrastructure.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Consumer and Platform Accountability: Increasing Scrutiny of Digital Intermediaries in Scam-Related Advertising

Recent litigation involving a major online platform in connection with alleged scam-related advertising has drawn renewed attention to the role of digital intermediaries in protecting consumers from online fraud. While the dispute itself remains subject to judicial determination, it highlights broader policy and regulatory questions regarding the responsibilities of digital platforms that facilitate advertising and online commercial activities.

Although Thailand has not yet adopted a comprehensive platform accountability framework specifically addressing scam-related advertisements, the issue aligns with wider regulatory efforts to combat technology-enabled fraud, strengthen consumer protection, and enhance trust in the digital economy. As online scams continue to generate substantial consumer losses, digital platforms may face increasing expectations from regulators, policymakers, and the public to take a more proactive role in preventing harm.

Existing Legal Framework:

Consumer Protection Law

The Consumer Protection Act B.E. 2522 (1979) serves as Thailand’s principal legislation governing unfair and misleading advertising practices. The Act prohibits advertisements that are false, exaggerated, misleading, or otherwise likely to cause consumer misunderstanding.

Traditionally, enforcement efforts have focused on advertisers themselves. However, as digital advertising ecosystems become increasingly complex, questions have emerged regarding whether platform operators that facilitate the dissemination of advertisements should assume greater responsibility for preventing fraudulent or deceptive content from reaching consumers.

While the Act does not currently establish explicit platform liability for scam-related advertisements, its consumer protection objectives may influence future regulatory approaches to digital platform governance.

Technology Crime Prevention Framework

Thailand has significantly expanded its legal framework for combating online fraud through the Emergency Decree on Measures for the Prevention and Suppression of Technology Crimes B.E. 2566 (2023), as amended.

The Emergency Decree reflects a broader policy shift toward preventive measures and imposes obligations on various stakeholders within the digital ecosystem to cooperate in addressing technology-related crimes. Although the current framework primarily focuses on financial institutions, telecommunications providers, and other relevant service providers, it demonstrates an increasing willingness by policymakers to require private-sector participants to implement measures aimed at reducing fraud risks.

This regulatory approach may provide insight into how future obligations for digital platforms could evolve.

Computer Crime Law

The Computer Crime Act B.E. 2550 (2007), as amended, establishes legal mechanisms for addressing unlawful online activities and removing illegal content from computer systems.

Although the Act was not specifically designed to regulate online advertising, it forms part of the broader legal framework governing intermediary conduct and online content management. The Act illustrates Thailand’s recognition that service providers play an important role in preventing and addressing harmful online activities.

As digital risks continue to evolve, policymakers may look to existing intermediary-related principles when considering future platform governance measures.

Emerging Platform Accountability Trends:

Recent developments suggest that regulators are increasingly focused not only on the perpetrators of online scams but also on the systems and mechanisms that enable fraudulent advertisements to reach consumers.

Several themes are likely to influence future policy discussions.

Enhanced Advertiser Verification

One potential area of reform involves stronger verification requirements for advertisers.

Regulators may increasingly expect platforms to implement robust due diligence procedures before allowing advertisements to be published, particularly in high-risk sectors such as financial services, investments, health products, and online commerce.

Possible measures may include:

  • Verification of advertiser identity;
  • Verification of business registration status;
  • Confirmation of regulatory licenses where applicable; and
  • Risk-based screening of advertising accounts.

Such requirements could reduce opportunities for anonymous or fraudulent actors to exploit digital advertising systems.

Proactive Monitoring and Detection

Another emerging trend involves the expectation that platforms implement systems capable of identifying potentially fraudulent activities before consumer harm occurs.

This may include:

  • Automated monitoring of advertising content;
  • Detection of suspicious advertising patterns;
  • Escalation procedures for high-risk advertisements; and
  • Internal fraud-prevention mechanisms supported by technology and human review.

Although such obligations may increase compliance costs, regulators may increasingly view proactive monitoring as a necessary component of responsible platform governance.

Notice-and-Takedown Mechanisms

Future regulatory initiatives may place greater emphasis on the speed and effectiveness of platform responses to scam-related content.

Platforms may be expected to maintain clear procedures for:

  • Receiving consumer complaints;
  • Reviewing reports of fraudulent advertisements;
  • Removing harmful content within reasonable timeframes; and
  • Preserving evidence for law enforcement and regulatory investigations.

Effective notice-and-takedown systems are increasingly regarded as a key safeguard in digital marketplaces.

Transparency and Accountability Measures

Policymakers may also consider imposing enhanced transparency requirements on digital platforms.

Potential measures could include:

  • Disclosure of advertiser information;
  • Publication of platform enforcement policies;
  • Transparency reporting regarding fraudulent advertisements; and
  • Cooperation and reporting obligations involving regulatory authorities.

Such measures seek to improve accountability while strengthening consumer confidence in online transactions.

Potential Regulatory Developments:

At present, Thailand has not enacted legislation imposing comprehensive liability on digital platforms for scam-related advertisements. Nevertheless, several factors suggest that further regulatory developments remain possible.

First, technology-enabled fraud continues to be a significant public policy concern. Second, regulators increasingly favor preventive approaches that require cooperation from private-sector participants. Third, digital platforms occupy a central role in the dissemination of commercial information and consumer engagement.

As a result, future initiatives could emerge through:

  • Amendments to consumer protection legislations;
  • Sector-specific digital platform regulations;
  • Additional anti-fraud compliance requirements;
  • Regulatory guidelines issued by relevant authorities; or
  • Multi-agency cooperation frameworks addressing online fraud.

Businesses operating digital platforms should therefore closely monitor regulatory developments and assess whether existing governance frameworks remain sufficient in light of evolving expectations.

Implications for Platform Operators:

Even in the absence of immediate legislative reform, platform operators may benefit from reviewing their existing compliance and risk-management practices.

Areas for consideration include:

  • Advertiser onboarding procedures;
  • Fraud detection and monitoring capabilities;
  • Internal complaint management systems;
  • Content moderation policies;
  • Record retention practices; and
  • Cooperation protocols with regulators and law enforcement authorities.

Organizations that adopt robust governance measures at an early stage may be better positioned to manage regulatory risk and maintain consumer trust as expectations continue to evolve.

Key Takeaways:

  • Recent litigation involving a major online platform has intensified discussion regarding the role of digital intermediaries in preventing scam-related advertising.
  • Thailand currently does not impose comprehensive statutory liability on digital platforms for fraudulent advertisements, but regulatory expectations are evolving.
  • Existing laws, including the Consumer Protection Act, the Emergency Decree on Measures for the Prevention and Suppression of Technology Crimes, and the Computer Crime Act, demonstrate increasing policy emphasis on consumer protection and fraud prevention.
  • Future regulatory initiatives may focus on advertiser verification, proactive monitoring, notice-and-takedown procedures, and transparency obligations.

Digital platform operators should proactively assess their governance and compliance frameworks in anticipation of increasing regulatory scrutiny and consumer protection expectations.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

BOI: Incentive Reforms Target Aviation, AI and Sustainable Industries as Investment Applications Surge

Thailand’s Board of Investment (BOI) has continued to refine its investment promotion framework in 2026 through amendments to promoted activities and targeted incentive measures aimed at attracting high-value investment, strengthening industrial competitiveness and supporting the country’s transition towards a digital and sustainable economy.

The latest policy developments coincide with a substantial increase in investment activity. Investment promotion applications during the first quarter of 2026 exceeded THB 1 trillion, continuing the strong momentum seen in 2025 when applications reached a record level. The figures reflect increasing investor confidence in Thailand as a regional manufacturing, technology and innovation hub, particularly amid ongoing supply chain diversification and shifts in global production strategies.

Aviation and Air Transport Sector:

Among the recent initiatives, the BOI has expanded support for aviation and air transport-related activities as part of Thailand’s strategy to strengthen its position as a regional aviation and logistics hub. The revised promotion framework is expected to encourage investment in air transport services, aircraft maintenance, aviation support services and related infrastructure.

The measures complement broader efforts to improve transportation connectivity, facilitate cross-border trade and investment, and enhance Thailand’s competitiveness within the ASEAN region.

Smart and Sustainable Industries:

The BOI has also continued to enhance its policies supporting smart and sustainable industries, encouraging businesses to adopt advanced technologies, automation systems, energy-efficient machinery and environmentally sustainable production processes.

The policy direction reflects the government’s commitment to industrial upgrading, productivity enhancement and sustainability-driven growth. For investors, the reforms signal continued support for projects involving digital transformation, energy efficiency, carbon reduction and resource optimization. Such initiatives are increasingly aligned with the environmental, social and governance (ESG) expectations of global investors and multinational supply chains.

Digital and Artificial Intelligence Investments:

Digital technologies and artificial intelligence (AI) remain key priorities under Thailand’s investment promotion strategy. Recent investment trends indicate growing demand for projects involving data centers, cloud services, software development, AI applications and related digital infrastructure.

The continued emphasis on AI and digital transformation aligns with broader government objectives aimed at accelerating technological innovation, strengthening digital capabilities and attracting high-value industries. These developments further reinforce Thailand’s ambition to position itself as a regional technology and digital services hub.

Enhancements to the Long-Term Resident (LTR) Visa Program:

In parallel with investment promotion measures, the government has introduced adjustments to the Long-Term Resident (LTR) Visa program to facilitate the entry of foreign investors, executives and highly skilled professionals.

The revisions are intended to improve accessibility for qualified applicants and strengthen Thailand’s ability to attract global talent in strategic sectors. The combination of BOI incentives and LTR Visa benefits continues to form an important component of Thailand’s investment promotion strategy, particularly for multinational enterprises considering the establishment of regional headquarters, research and development centres or technology-focused operations in the country.

Continued Foreign Investment Momentum:

The strong investment figures recorded in early 2026 indicate that Thailand continues to benefit from global trends such as supply chain diversification, regionalization of manufacturing and increasing demand for digital infrastructure.

Investment activity has been concentrated in sectors including advanced electronics, AI-related businesses, digital infrastructure, clean energy, logistics and advanced manufacturing. The growth demonstrates continued investor confidence in Thailand’s investment ecosystem and the competitiveness of its incentive regime.

Key Takeaways:

  • The BOI continues to refine its investment promotion framework to attract high-value investments in strategic sectors, particularly aviation, digital technologies, artificial intelligence and sustainable industries.
  • Recent reforms demonstrate Thailand’s continued focus on industrial upgrading, technological innovation and environmentally sustainable growth.
  • Enhancements to the Long-Term Resident (LTR) Visa programme complement investment incentives by facilitating the attraction of foreign investors, executives and highly skilled professionals.
  • Record investment promotion applications in early 2026 indicate sustained investor confidence and Thailand’s growing role as a regional investment and manufacturing hub.

Businesses considering expansion into Thailand should review the availability of BOI incentives and assess how evolving promotion policies may support investment projects, regional headquarters, technology operations and sustainability initiatives.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

NBTC’s Third Broadcasting and Television Master Plan (2026–2030): Expanded Oversight of OTT Platforms and the Future of Digital Broadcasting

Introduction:

Thailand’s National Broadcasting and Telecommunications Commission (NBTC) is currently conducting public consultations on the Draft Third Broadcasting and Television Master Plan (2026–2030), which is intended to serve as the principal policy framework for the broadcasting sector over the next five years.

The draft plan reflects the NBTC’s recognition that the media landscape has undergone significant transformation as audiences increasingly consume content through online platforms and streaming services rather than traditional broadcasting channels. In response, the NBTC is proposing a broader regulatory approach that extends beyond conventional television and radio operators to encompass digital content ecosystems, online media platforms, and emerging forms of content distribution.

The proposed framework also addresses growing concerns regarding misinformation, the competitiveness of domestic digital platforms, and the future of the digital television sector as existing licenses approach expiry.

Greater Focus on OTT and Online Media Platforms:

A key feature of the draft plan is the NBTC’s intention to strengthen oversight of over-the-top (OTT) services and online media platforms.

The traditional broadcasting regulatory framework was designed primarily for licensed television and radio operators. However, the rapid growth of streaming platforms, social media services, and other online content providers has significantly altered viewing behavior and challenged the effectiveness of existing regulatory models.

The draft plan therefore contemplates the development of regulatory mechanisms appropriate for the digital environment, including measures aimed at enhancing accountability and governance of online content distribution platforms. While the specific regulatory tools remain under consideration, the proposal signals the NBTC’s intention to play a more active role in overseeing digital media services that reach Thai audiences.

This policy direction reflects a broader recognition that online platforms have become an integral part of the communications ecosystem and increasingly influence public discourse, information consumption, and media competition.

Measures to Combat Fake News and Harmful Content:

The draft plan identifies misinformation, disinformation, and content that may create social division or public disorder as important regulatory concerns.

The NBTC proposes closer cooperation with relevant government agencies, media organizations, and digital platform operators to strengthen mechanisms for monitoring and addressing false or misleading information disseminated through broadcasting and online channels.

Particular attention is expected to be given to content that may affect public safety, national security, social harmony, or public confidence in state institutions. The draft plan also contemplates the development of systems that promote responsible media practices and improve public awareness regarding information verification.

Although detailed implementation measures have not yet been announced, platform operators and content providers should anticipate increased regulatory attention to content governance and compliance frameworks in the coming years.

Promotion of Domestic Digital Platforms and Local Content:

Another important objective of the draft plan is the promotion of domestic digital platforms and the strengthening of Thailand’s content industry.

The NBTC has expressed support for initiatives that enhance the competitiveness of local media operators and encourage the development of platforms capable of serving Thai audiences while promoting domestic content creation.

The draft plan also seeks to encourage innovation in broadcasting technologies and digital content distribution. Such initiatives are intended to support sustainable growth within the media sector and reduce structural disadvantages faced by local operators in competing with large international digital platforms.

This policy direction aligns with broader national objectives relating to digital economy development and technological self-reliance.

Preparing for the Post-2029 Digital Television Landscape:

The draft plan also addresses the future of the digital television industry as existing digital television licenses are expected to expire around 2029.

Since the transition to digital broadcasting, television operators have faced substantial economic pressures arising from changing consumer behavior, fragmentation of audiences, and increasing competition from online media services. These developments have raised questions regarding the long-term sustainability of the current broadcasting model.

In response, the NBTC intends to develop a roadmap for the future of digital television. The roadmap is expected to examine the role of terrestrial broadcasting in an increasingly digital environment, potential adjustments to licensing frameworks, spectrum management strategies, and measures to support industry sustainability.

The outcome of these discussions is likely to influence the structure of Thailand’s broadcasting sector for years to come and may have significant implications for broadcasters, investors, content producers, and telecommunications operators.

Implications for Businesses:

The draft master plan demonstrates a regulatory shift towards a more integrated approach to media governance, where distinctions between traditional broadcasting services and online content platforms are becoming less pronounced.

Businesses that may be affected by future policy developments include:

  • OTT and streaming service providers;
  • social media and content-sharing platforms;
  • broadcasters and television operators;
  • telecommunications service providers;
  • digital advertising businesses; and
  • content creators and media companies.

Although the draft plan does not itself create immediate legal obligations, it provides a clear indication of the NBTC’s regulatory priorities and may serve as the foundation for future regulations, licensing requirements, and policy initiatives affecting the digital media sector.

Stakeholders should therefore monitor the consultation process and forthcoming regulatory developments closely.

Outlook:

The Draft Third Broadcasting and Television Master Plan (2026–2030) reflects the NBTC’s effort to modernize the regulatory framework governing Thailand’s broadcasting and media sectors in response to technological change and evolving consumer behavior.

By focusing on OTT regulation, combating misinformation, promoting domestic digital platforms, and preparing for the expiry of digital television licenses, the NBTC is signaling a broader and more proactive approach to media regulation in the digital era.

While many of the proposed measures remain at the policy stage, the draft plan provides important insight into the direction of future regulatory developments and the issues that are likely to shape Thailand’s communications and media landscape over the coming years.

Key Takeaways:

  • The NBTC is consulting on the Draft Third Broadcasting and Television Master Plan (2026–2030), which will guide broadcasting policy over the next five years.
  • Regulatory attention is increasingly shifting towards OTT services and online media platforms as digital content consumption continues to grow.
  • The draft plan proposes stronger measures to address fake news, disinformation, and other forms of harmful online content.
  • The NBTC seeks to promote domestic digital platforms and strengthen the competitiveness of Thailand’s content industry.
  • A roadmap is being developed to address the future of digital television ahead of the expected expiry of digital TV licenses around 2029.

Although no immediate legal obligations arise from the draft plan, businesses should monitor future regulatory initiatives that may affect platform governance, content regulation, and broadcasting operations.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles