Telemedicine Practices and Data Protection Compliance in Thailand: Legal Brief

I. Introduction to Telemedicine in Thailand:

Telemedicine has emerged as one of the most transformative innovations in healthcare. By leveraging modern communication technologies, telemedicine enables the delivery of medical services regardless of geographic barriers. As the global demand for accessible, efficient, and cost-effective healthcare increases, many countries have embraced telemedicine to overcome traditional challenges such as distance, cost, and limited access to medical expertise.

Thailand, with its rapidly developing digital infrastructure and progressive approach to healthcare, is becoming a prominent destination for telemedicine providers. However, alongside its tremendous growth potential, Thailand presents unique challenges, particularly in the realm of data protection and privacy. For both local and international telemedicine platforms, understanding and complying with the local legal environment is critical. The country’s evolving legal landscape, especially concerning data protection, patient privacy, and healthcare standards, requires providers to implement robust compliance measures. Doing so not only safeguards sensitive patient information but also builds trust with users, ensuring sustainable business growth in a competitive market.

In this guide, we delve into the key considerations for data compliance, discuss the relevant regulatory frameworks under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), and outline practical steps for telemedicine platforms to navigate these regulations. By doing so, telemedicine providers can effectively mitigate risks, secure patient data, and maintain a competitive edge in the Thai market.


II. Health Information Protection Before the Enforcement of the Personal Data Protection Law:

  1. The National Health Act and Ministerial Regulation:

Thailand’s regulatory framework for data protection has undergone significant evolution over recent years. Prior to the enactment of the PDPA in 2019, Thailand relied on a combination of the Thai Constitution, the Thai Civil and Commercial Code, and sector-specific regulations like the National Health Act B.E. 2550 (2007) (“National Health Act”). The National Health Act mandated that personal health information be kept confidential. Specifically, Section 7 of the National Health Act required that such information not be disclosed in a manner that could harm the data subject, except when authorized by the individual or required by law.

The Ministerial Regulation on the Protection and Management of Personal Health Information B.E. 2561 (2018) (“MR”) provided further details on the scope and nature of personal health information. Clause 4 of the MR defined personal health information as encompassing a variety of documents, case files, reports, and other materials capable of identifying an individual’s health status. Clause 11 offered an exhaustive list of items considered personal health information, such as:

  1. Health History: Such as height, weight, blood type, and body shape.
    1. Medical Records: Such as nursing records, laboratory examinations, and x-ray films.
    1. Related Documents: Any documents or objects that relate to the above data.
    1. Photographic Evidence: Images of medical personnel or actions during treatment.
    1. Additional Information: Any further information as specified by the Personal Health Data Protection and Management Committee.
  2. Penalties for Non-Compliance:

Before the PDPA’s enactment, violations regarding the unlawful or unauthorized disclosure of personal health information were met with penalties prescribed under the NHA. Under Section 49 of the National Health Act, such violations could result in imprisonment of up to six months, fines of up to 10,000 THB, or both. Moreover, wrongful use of personal data was addressed under Section 420 of the Civil and Commercial Code, which provided for civil liability in cases where data misuse resulted in harm to the data subject.

  • Transition to the PDPA:

In 2019, the PDPA was published in the Royal Gazette, marking a significant shift in Thailand’s data protection landscape. With its comprehensive framework, the PDPA rendered the earlier MR obsolete. The Medical Council of Thailand subsequently issued a new Ministerial Regulation on the Revocation of the MR B.E. 2565 (2022). This evolution represents Thailand’s commitment to aligning its data protection standards with international best practices.


III. What Is Health Information?

As a result of the MR revocation, Thailand no longer has a statutory definition of health information, which is crucial in terms of personal data protection and compliance with obligations under the PDPA. Telemedicine platforms need to understand the personal data in their possession and handle such data according to the PDPA.

In the absence of subordinate regulations, directives, or guidelines to clarify the extent and scope of health information under the PDPA, it is worth exploring the definition given under the European Union General Data Protection Regulations (2016/679) (“EU GDPR”), which was a core foundation of the Thai PDPA, containing many similar provisions tailored to Thailand’s contexts.

Article 4 (15) of the EU GDPR defines ‘data concerning health’ as personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status. Additionally, the European Parliament and the Council of the European Union opined that ‘personal data concerning health’ should include all data pertaining to the health status of a data subject, including information collected during registration or provision of health care services, testing results, disease history, clinical treatments, or physiological states.

By this principle, personal data that may not obviously qualify as health information could still be considered health information depending on the context of personal data processing activities.


IV. Overview of PDPA Compliance for Telemedicine Platforms:

The PDPA extends its reach not only to local businesses but also to international data controllers who process the personal data of Thai residents. This extraterritorial effect means that even telemedicine platforms headquartered outside Thailand must comply with the PDPA if they process the personal data of individuals located in the country.

  1. Extraterritorial Applicability:

According to Section 5, Paragraph 2 of the PDPA, foreign data controllers are subject to the PDPA if any of the following criteria are met:

  1. The offering of goods or services to the data subjects who are in the Kingdom of Thailand, irrespective of whether the payment is made by the data subject, or
    1. The monitoring of the data subject’s behavior, where the behavior takes place in the Kingdom of Thailand.
  • Obligations for Telemedicine Providers:

Once the PDPA applies, telemedicine providers (whether local or international) must adhere to various obligations under the PDPA, some of which include:

  1. Data Collection and Processing: Ensure that personal data is collected, used, and disclosed with legal bases supporting each processing activity.
    1. Privacy Notices: Clearly communicate to data subjects how their personal data will be used.
    1. Security Measures: Implement appropriate technical and organizational measures to safeguard personal data.
    1. Data Subject Rights: Provide mechanisms for data subjects to exercise their rights (e.g., access, correction, deletion).
    1. Breach Notification: Establish procedures to notify both the regulatory authority and affected data subjects in the event of a data breach.
    1. Record-Keeping: Maintain a Record of Processing Activities (ROPA) to document data processing practices.

V. Privacy Notice / Privacy Policy Under the PDPA:

One of the foundational requirements under the PDPA is the preparation and dissemination of a comprehensive privacy notice or privacy policy. This document serves to inform data subjects about how their personal data is collected, processed, stored, and shared.

  1. Content of Privacy Policy:

Under Section 23 of the PDPA, data controllers must notify data subjects of the purposes of data collection prior to or at the time of collection. Common practices include written notices, electronic pop-ups on websites or applications, or verbal communications as applicable.

  • Best Practices for Drafting a Privacy Policy:

For telemedicine platforms, drafting a privacy policy involves a deep understanding of the personal data flows within the organization. Understanding the customer journey is vital for telemedicine platforms in preparing the privacy policy, as each touchpoint involves the collection and processing of personal data.

  1. Sign-Up / Registration:

During the initial sign-up process, users are generally required to provide basic personal data such as their name, age, contact details, and, in some cases, initial health information, such as their height, weight, medical history, passport or national identification card, contact information, and information relating to personal allergies. This stage sets the foundation for subsequent interactions and must be handled with the highest level of security and clarity regarding data usage.

  • Know Your Customer (KYC) and Confirming the Identity of the Data Subject: To ensure compliance with Thailand’s PDPA and safeguard sensitive personal data, telemedicine platforms must implement robust KYC procedures during the sign-up phase. These procedures are designed to verify the identity of the data subject and establish trust between the platform and its users.
  • Verification of Identity: Platforms should require users to provide a valid
    • identification documents, such as a national ID card, passport, or other government-issued IDs, to confirm their identity.
    • The verification process may involve uploading scanned copies of these documents or using digital identity verification tools that comply with Thai legal standards.
  • Biometric Verification (Optional):

For enhanced security, telemedicine platforms may opt to incorporate biometric verification methods, such as facial recognition or fingerprint scanning, where applicable and permitted by law.

  • Data Matching:

Once the user submits their identification details, the platform should cross-check this information against official databases (e.g., government records) to ensure accuracy and prevent fraud.

  • Explicit Consent:

During the registration process, explicit consent must be obtained from the user for the collection, use, and disclosure of both general personal data and sensitive personal data. This includes clear explanations of how their data will be processed, stored, and shared.

If the user is under 20 years of age, additional consent from their legal representative, guardian, or curator may be required under Section 20 of the PDPA.

  • Booking / Appointment Scheduling:

Once registered, users schedule appointments with healthcare providers. The booking process may involve selecting a healthcare professional based on specialty, availability, or patient reviews. Additional forms might be used to capture medical history or current health conditions.

  • Consultation:

Consultations are the core of telemedicine services. Whether conducted via video calls, chat sessions, or telephone, these interactions involve real-time exchange of sensitive health information. Data from these sessions may include verbal communications, visual data, and records of diagnosis and treatment.

  1. Post-Consultation Services:

After the consultation, several processes may occur:

  • Payments: Patients make payments through integrated or third-party payment gateways. This process generally involves third-party service providers.
  • Insurance Claims: In some cases, patients may file insurance claims. Telemedicine platforms might assist in this process by forwarding relevant health information to insurers.
  • Medicine Delivery: If medication is prescribed, delivery logistics come into play. This may involve sharing personal data (such as address and contact information) with third-party courier services.
  • Follow-up Appointments: Follow-up consultations or treatment plans may be scheduled, requiring further data collection.
  • Feedback and Reviews: Post-consultation feedback is often solicited to improve service quality. While this may involve general data, any health-related feedback is treated with heightened sensitivity

n)


VI. Legal Bases for Each Activity:

Different stages of the customer journey require distinct legal bases under the PDPA. For example:

ActivityGeneral Personal DataSensitive Personal Data
Sign-up / RegistrationNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Booking / AppointmentNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
ConsultationNecessary to enter into / Performance of a contract
(Section 24 (3))
Necessary for compliance with a law with respect to the provision of health or social care / Explicit Consent (Section 26 (5)(a) / Section 26)
Payment and BillingNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Insurance ClaimsLegitimate interest
(Section 24 (5))
Explicit Consent
(Section 26)
Medicine DeliveryNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Feedback / ReviewsLegitimate interest
(Section 24 (5))
Explicit Consent
(Section 26)

Important Remark: Please note that the table above shall only be used as a reference. The actual legal basis for each activity may differ based on the specific facts and circumstances.


VII. Processing Personal Data of Minors, Quasi-Incompetent Persons, or Incompetent Persons:

Where a patient is under 20 years of age or is a quasi-incompetent person or incompetent person, Section 20 of the PDPA requires their consent to be accompanied by consent from their respective legal representatives, guardians, or curators. However, if the patient is under 10 years of age, sole consent from the legal representative is sufficient.

Section 24 of the Thai Civil and Commercial Code provides an exemption for acts deemed suitable for a minor’s reasonable needs. Therefore, a minor (between 10 and 20 years of age) may give sole consent for telemedicine consultation purposes, as it deems suitable and actually required for their reasonable needs.


VIII. Data Subject Rights and Request Compliance Under the PDPA:

The PDPA enshrines several rights for data subjects. Telemedicine platforms must have robust processes to facilitate these rights.

A. Overview of Data Subject Rights:

The PDPA grants data subjects the following rights:

  1. Right to Access: Data subjects may request copies of their personal data.
  2. Right to Data Portability: Individuals can obtain their personal data in a structured, commonly used format.
  3. Right to Object: Data subjects may object to certain personal data processing activities.
  4. Right to Delete: Also known as the “right to be forgotten,” this allows data subjects to request deletion or anonymization of their personal data.
  5. Right to Restrict Processing: In certain circumstances, processing may be limited or suspended.
  6. Right to Rectification: Data subjects can have inaccurate or incomplete personal data corrected.
  7. Right to Lodge a Complaint: Data subjects can lodge complaints with regulatory authorities.
  8. Right to Withdraw Consent: Where processing is based on consent, data subjects may withdraw that consent at any time.

B. Procedures for Data Subject Rights Requests (DSRR):

Upon receiving a data subject request, telemedicine platforms should follow a set of protocols:

  1. Verification: Confirm the identity of the data subject or their representative.
  • Clarification: Request additional information if the request is ambiguous.
  • Documentation: Record all details of the request.
  • Data Retrieval: Locate and compile the relevant data.
  • Review for Exemptions: Determine if any exemptions apply.
  • Response: Communicate a clear response—either fulfilling the request, rejecting it, or outlining why an exception applies.
  • Record-Keeping: Maintain records of the requests and responses for regulatory audits.

IX. Record of Processing Activities (ROPA):

Maintaining a detailed ROPA is a regulatory requirement under Section 39 of the PDPA.

A comprehensive ROPA should include,

  1. the collected personal data;
    1. the purpose of the collection of personal data in each category;
    1. details of the data controller;
    1. the retention period of personal data;
    1. rights and methods for accessing personal data, including conditions for exercising these rights;
    1. the use or disclosure of personal data;
    1. rejection or objection to the data subject’s rights request; and
    1. explanation of the appropriate security measures.

However, SMEs may be exempt from maintaining a full ROPA if they employ fewer than 100 people and have an annual revenue of no more than 300,000,000 THB. Nevertheless, telemedicine platforms handling sensitive personal data must maintain a full ROPA due to the risks involved.


X. Appropriate Security Measures for Telemedicine Platforms:

Prescribed under Section 37 (1) of the PDPA, where a data controller is required to provide appropriate security measures to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data. In this regard, the appropriate security measures for the telemedicine platforms shall focus on the maintenance of personal data’s confidentiality, integrity, and availability.

According to the PDPC’s Announcement on Security Measures for Personal Data,  the security measures should contain at least the following mechanism: (1) access controls, allowing access to personal data only on a need-to-know basis provided that there shall also be an identity proofing, authentication, and authorization procedure; (2) user access management including registration and de-registration of access provision; (3) user responsibilities shall be prescribed; (4) implement an audit trail to enable the reviewing of access, change, alteration, or deletion of personal data.

The duty to implement appropriate security measures shall be extended to the imposition of obligations on the data processor of the telemedicine platforms (such as medicine delivery service providers), to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data.


XI. Personal Data Breach and Breach Notification Procedures:

Despite security measures, data breaches can occur. The PDPA requires prompt action in response to breaches.

A. Definition:

A personal data breach is defined as a breach of security measures resulting in the loss, access, use, alteration, modification, or disclosure of personal data without authorization or unlawfully.

B. Procedures:

Assess the reliability of the breach report and investigate the facts.

Notify the PDPC within 72 hours if the breach affects the rights and freedoms of data subjects.

Notify affected data subjects without delay if the breach poses a high risk.

Mitigate the situation and review security measures to prevent future breaches.


XII. Processing of Sensitive Personal Data by Data Processors:

Throughout the customer journey, a data processor may be involved in processes such as medicine delivery. A data controller must prepare a Data Processing Agreement (DPA) to control the activities of the data processor. Key provisions of a DPA include:

Restriction on use or disclosure of personal data.

Implementation of appropriate security measures.

Recording of personal data processing activities.

Notification of personal data breaches.


XIII. Designating a Representative and a Data Protection Officer (DPO) in Thailand:

A. Designating a Representative for Foreign Providers:

Foreign telemedicine providers offering services to Thai residents must designate a representative in Thailand under Section 5, Paragraph 2 of the PDPA.

B. Appointment of a Data Protection Officer (DPO):

Telemedicine platforms are obligated to designate a DPO if their core activities involve processing sensitive personal data. External or outsourced DPOs may be appointed for SMEs.


XIV. Use of Sensitive Personal Data (Health Information) for Telemarketing Purposes:

Sensitive personal data cannot be used for marketing purposes without explicit consent. Instead, telemedicine platforms may rely on general personal data (e.g., email addresses) for mass communications, provided an opt-out mechanism is available.


XV. Frequently Asked Questions (FAQs)

Q1: Does Weight and Height Qualify as Health Information?

Weight and height information may qualify as either general personal data or sensitive personal data, depending on the context. For example, in telemedicine services, weight and height may play a vital role in medical analysis and thus could be considered sensitive personal data.

Q2: Can a Patient Request Deletion of Their Health Information?

Patients have the right to request deletion of their personal data under certain conditions. However, telemedicine platforms are required to retain medical records for at least 5 years in accordance with the National Health Act.


XVI. Conclusion

As telemedicine continues to revolutionize the healthcare industry, ensuring robust compliance with data protection laws like the PDPA is critical. Health information, being sensitive personal data, demands the highest level of security and compliance to protect patient privacy and maintain trust in digital healthcare services.

For telemedicine platforms operating in Thailand, navigating the interplay between local regulations and international frameworks necessitates a meticulous approach to data processing. Failure to comply can lead to reputational damage, regulatory penalties, and legal liabilities. By adopting best practices such as transparent privacy policies, strong security measures, and compliance with data subject rights, telemedicine providers can create a safe and legally compliant environment.

In conclusion, the landscape of health information regulation is complex and continuously evolving. Telemedicine platform providers must proactively update their policies and compliance strategies to align with changing regulations, ensuring that patient rights remain protected while fostering innovation in digital healthcare solutions. By doing so, they can contribute to a more secure, efficient, and globally compliant telemedicine ecosystem.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Billing Software Requirements vs. Electronic Invoicing Requirements

Executive Summary:

As governments continue to digitalize tax administration, businesses are increasingly expected to adopt electronic invoicing solutions that comply with evolving regulatory requirements. Although the terms billing software and electronic invoicing are often used interchangeably, they represent distinct concepts that serve different commercial and legal functions.

In Thailand, billing software is not subject to a dedicated statutory or regulatory framework. Businesses are generally free to select accounting, billing, or enterprise resource planning (ERP) systems that best support their commercial operations, provided they comply with the Revenue Code and other applicable laws. Electronic invoicing, by contrast, is governed by the Revenue Department’s e-Tax Invoice & e-Receipt framework, which establishes the legal and technical requirements for issuing electronic tax invoices recognized for VAT purposes.

Understanding the distinction between these concepts is important for businesses implementing digital invoicing solutions. A billing system that efficiently generates commercial invoices does not necessarily satisfy the legal requirements for issuing electronic tax invoices. Businesses should therefore evaluate their invoicing systems not only from an operational perspective but also from a tax compliance standpoint.

Introduction:

Digital transformation has fundamentally changed the way businesses prepare invoices, maintain accounting records, and comply with tax obligations. Around the world, tax authorities have introduced electronic invoicing regimes to improve tax compliance, enhance transparency, and reduce administrative burdens for both taxpayers and regulators.

Although electronic invoicing has become an increasingly common feature of modern tax systems, countries have adopted different regulatory approaches. Some jurisdictions regulate the software used to generate invoices, while others focus on the legal validity and technical characteristics of the electronic tax documents themselves.

Thailand follows the latter approach. Rather than regulating billing software as a separate category of software, Thai law establishes a framework governing the issuance of electronic tax invoices through the Revenue Department’s e-Tax Invoice & e-Receipt system. Consequently, businesses remain free to use their preferred accounting or ERP software, provided that the electronic tax documents generated by those systems comply with the applicable legal and technical requirements.

For businesses operating in Thailand, particularly multinational enterprises implementing global ERP platforms, understanding the distinction between billing software and electronic invoicing is essential. While both are integral components of modern financial management, they perform different functions and are subject to different legal considerations.

Billing Software:

Billing software generally refers to applications used by businesses to prepare invoices, calculate taxes, record payments, manage customer accounts, and maintain accounting records. These functions support day-to-day commercial operations and are commonly integrated into accounting software or ERP systems.

Unlike some jurisdictions that regulate invoicing software, Thailand does not currently impose a dedicated legal or regulatory regime governing billing software itself. There is no statutory requirement for billing software to be licensed, certified, or approved by the Revenue Department before it can be used by businesses. Instead, Thai law focuses on the legal sufficiency of the invoices and accounting records generated by the software.

This does not mean that businesses have complete discretion in how billing systems are used. Regardless of the software selected, businesses remain responsible for ensuring that invoices comply with the Revenue Code, VAT is correctly calculated where applicable, accounting records are properly maintained, and supporting documentation is available for inspection by the tax authorities.

Accordingly, compliance under Thai law depends not on the software itself, but on whether the business uses that software in a manner that satisfies its statutory obligations. A business may therefore choose from a wide range of commercial accounting platforms, cloud-based invoicing applications, or ERP systems without obtaining prior approval from the Revenue Department.

Electronic Invoicing:

Electronic invoicing serves a different purpose. Rather than facilitating internal billing processes, it establishes the legal framework under which electronic tax invoices are recognized for VAT purposes.

Thailand’s electronic invoicing regime is principally governed by the Revenue Code, supplemented by the Electronic Transactions Act, Ministerial Regulation No. 384, and Revenue Department notifications prescribing the technical standards for electronic tax documents. Collectively, these instruments enable tax invoices and receipts to be created, transmitted, and retained electronically while ensuring their authenticity, integrity, and reliability.

Businesses wishing to issue electronic tax invoices under the Revenue Department’s e-Tax Invoice & e-Receipt framework must comply with prescribed legal and technical requirements. These include registration with the Revenue Department, generation of electronic tax documents in the prescribed format, use of appropriate electronic authentication mechanisms, transmission through approved channels where applicable, and maintenance of electronic records in accordance with the Revenue Department’s requirements.

An important characteristic of the Thai framework is that it regulates the electronic tax document rather than the accounting software used to produce it. Consequently, businesses may continue using their existing accounting or ERP systems, provided those systems are capable of generating electronic tax invoices that comply with the Revenue Department’s technical specifications. In practice, many businesses achieve this through system localization or integration with specialized e-Tax solutions or authorized service providers.

Thailand currently provides two principal electronic invoicing models. The e-Tax Invoice & e-Receipt system is designed for businesses requiring full electronic integration, while the e-Tax Invoice by Email system provides a simplified alternative for eligible businesses. Although both systems enable businesses to issue legally recognized electronic tax invoices, they differ in their technical implementation and authentication methods.

Key Takeaways:

  • Thailand does not regulate billing software as a separate legal category or require billing software to be certified or approved by the Revenue Department.
  • The Revenue Department’s e-Tax Invoice & e-Receipt framework governs the issuance of legally recognized electronic tax invoices and establishes the applicable technical and procedural requirements.
  • A commercial invoice generated by billing software does not automatically constitute an electronic tax invoice for VAT purposes.
  • Businesses implementing accounting or ERP systems should evaluate both operational functionality and compliance with Thailand’s e-Tax requirements.
  • Early coordination among finance, tax, legal, and information technology functions can help ensure a successful implementation of electronic invoicing while supporting long-term digital tax compliance.

Source: International Comparison July 2026: Global Legal Market Analysis

Read Full Article

Thailand signals a shift toward expenditure-based management of universal healthcare

Thailand’s universal healthcare system has long been regarded as one of the country’s most successful public policy achievements. However, increasing healthcare utilization, an aging population, rising treatment costs, and fiscal constraints are prompting policymakers to reconsider how the system should be financed over the long term.

Recent policy discussions within the Ministry of Public Health indicate that the focus is no longer solely on expanding healthcare benefits. Instead, the government appears to be moving toward a framework that emphasizes expenditure management, efficiency, and value-based healthcare while maintaining universal access to essential medical services.

Shift from expanding benefits to managing sustainability:

Thailand’s public healthcare system is primarily delivered through three government-funded schemes:

  • the Universal Coverage Scheme (UCS);
  • the Social Security Scheme (SSS); and
  • the Civil Servant Medical Benefit Scheme (CSMBS).

Although annual government appropriations for these schemes have continued to increase, healthcare expenditure has grown at an even faster pace due to demographic changes, increasing prevalence of chronic diseases, advances in medical technology, and greater public expectations regarding access to treatment. Policymakers have therefore expressed concern that healthcare expenditure may outpace long-term fiscal capacity unless structural reforms are implemented.

Proposed expenditure management measures:

Current policy discussions suggest that future reforms may include greater reliance on expenditure controls rather than across-the-board budget increases.

Measures under consideration reportedly include:

  • expenditure ceilings for public hospitals;
  • tighter monitoring of hospital operating costs, pharmaceuticals, and medical supplies;
  • wider use of digital technologies and data analytics to improve financial oversight;
  • periodic review of healthcare benefit packages to prioritize clinically effective and cost-effective services; and
  • broader adoption of value-based healthcare models that reward providers based on patient outcomes rather than service volume.

These initiatives reflect an effort to improve efficiency without fundamentally changing the principle of universal healthcare coverage.

Potential implications for healthcare providers:

Public hospitals may face increasing pressure to operate within fixed budgetary allocations while maintaining service quality. More sophisticated financial management, procurement practices, and clinical governance are therefore likely to become increasingly important.

Healthcare providers may also experience:

  • greater scrutiny of prescribing practices;
  • stronger emphasis on evidence-based treatment pathways;
  • expanded use of health technology assessment in reimbursement decisions; and
  • increased reporting and compliance obligations relating to cost management.

Private healthcare providers participating in government reimbursement programs may likewise experience closer oversight of reimbursement methodologies and service delivery standards.

Regulatory considerations:

While no legislative amendments have fundamentally altered Thailand’s universal healthcare framework, any future implementation of expenditure caps or revised reimbursement mechanisms will require careful alignment with existing legislation governing public health financing and healthcare entitlements.

Future regulatory developments may include:

  • revised payment methodologies;
  • updated reimbursement criteria;
  • enhanced procurement controls;
  • expanded digital monitoring of healthcare expenditure; and
  • revised administrative guidelines governing public healthcare providers.

Businesses operating in the healthcare, pharmaceutical, medical device, and digital health sectors should therefore continue to monitor policy developments, as changes in reimbursement and procurement practices may influence market access and commercial strategies.

Key takeaways:

  • Thailand is shifting its healthcare policy emphasis from expanding benefits toward improving financial sustainability.
  • Expenditure management and value-based healthcare are emerging as central policy themes.
  • Public hospitals are likely to face tighter budgetary controls and enhanced financial oversight.
  • Healthcare suppliers should anticipate increasing scrutiny of reimbursement, procurement, and cost-effectiveness.
  • Although universal healthcare remains intact, future reforms are expected to focus on preserving the system through more disciplined allocation of healthcare resources rather than unlimited expenditure growth.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

ETDA’s Proposed AI Sandbox Signals a New Phase of AI Governance

The Electronic Transactions Development Agency (ETDA) has opened a public consultation on a draft notification establishing an Artificial Intelligence (AI) Sandbox. Although the notification has not yet been adopted, it represents one of the clearest regulatory signals that Thailand is moving toward a structured governance framework for AI systems through a controlled testing environment.

For businesses developing or deploying AI solutions, the proposed AI Sandbox is more than a pilot initiative. It is likely to establish regulatory expectations that may influence future AI compliance standards across multiple sectors.

Why the AI Sandbox matters                                              

Regulatory sandboxes have long been used in the financial sector to facilitate innovation while allowing regulators to observe risks under controlled conditions. The proposed AI Sandbox extends this concept to AI technologies by providing an environment where AI systems can be tested before wider deployment.

Unlike traditional compliance regimes that focus primarily on post-deployment enforcement, an AI Sandbox emphasizes governance during the development and testing stages. This reflects an international regulatory trend toward proactive AI risk management.

Although participation in the Sandbox may initially be voluntary, organizations should not view it merely as an experimental program. Regulatory sandboxes frequently become the foundation for future best practices and may ultimately shape industry standards and supervisory expectations.

A shift toward risk-based AI governance

While the draft notification remains subject to consultation, it suggests that AI governance in Thailand is moving toward a risk-based model.

Businesses should expect greater emphasis on governance measures such as:

  • AI risk identification and assessment;
  • testing and validation before deployment;
  • documentation of AI models, datasets, and development processes;
  • human oversight over significant AI-assisted decisions;
  • ongoing monitoring throughout the AI lifecycle; and
  • governance mechanisms for accountability and incident management.

These principles are broadly consistent with international AI governance developments and demonstrate a growing expectation that organizations should be able to explain not only what an AI system does, but also how risks have been identified and managed.

Implications for businesses

The proposed framework has implications across numerous industries, particularly where AI systems influence commercial or operational decision-making.

  • Technology companies and SaaS providers
  • Software developers offering AI-enabled products may need to implement more formal governance processes throughout the product lifecycle. Technical documentation, testing records, model validation, and change management procedures could become increasingly important in demonstrating responsible AI practices.
  • Organizations that currently rely on informal development processes may eventually need governance structures comparable to those already used for cybersecurity and information security compliance.
  • Financial services and fintech
  • Financial institutions already operate within a highly regulated environment. AI governance requirements may become an additional layer of compliance where AI is used for credit scoring, fraud detection, investment services, customer onboarding, or automated decision-making.
  • Existing risk management frameworks may therefore need to expand to include AI-specific controls.
  • Healthcare and health technology
  • Healthcare providers and health technology companies using AI for diagnostics, treatment recommendations, clinical decision support, or patient management are likely to face heightened expectations regarding accuracy, validation, human supervision, and patient safety.
  • Testing within a controlled environment could become an important mechanism for demonstrating reliability before deployment.
  • HR technology
  • Organizations using AI in recruitment, employee evaluation, workforce management, or performance assessment should anticipate closer scrutiny of automated decision-making processes.
  • Transparent governance, human review, and measures to reduce discriminatory outcomes are likely to become increasingly significant compliance considerations.
  • Digital platforms
  • Platform operators deploying generative AI, recommendation algorithms, content moderation systems, or AI-powered customer services may also need stronger governance over system performance, monitoring, and accountability.
  • The ability to document how AI systems operate and respond to identified risks may become an important aspect of regulatory compliance.

Interaction with existing legal frameworks

Although the AI Sandbox is intended to facilitate innovation, participation is unlikely to exempt organizations from existing legal obligations.

Organizations testing AI systems would still be expected to comply with applicable laws, including those governing:

  • personal data protection under the Personal Data Protection Act;
  • electronic transactions;
  • cybersecurity obligations;
  • consumer protection;
  • intellectual property rights; and
  • sector-specific regulatory requirements.

For example, organizations using personal data for AI model training or testing should ensure that appropriate legal bases, transparency obligations, data security measures, and data subject rights continue to be observed.

Similarly, businesses developing generative AI applications should continue to assess potential intellectual property risks relating to training data, generated outputs, and ownership of AI-assisted content.

Preparing for future regulatory expectations

Although the draft notification has not yet entered into force, organizations should consider using the consultation period to evaluate their existing AI governance practices.

Practical steps may include:

  • identifying AI systems currently in operation;
  • classifying AI use cases according to potential risk;
  • documenting AI development and deployment processes;
  • establishing internal AI governance policies;
  • implementing human oversight for significant AI-assisted decisions;
  • reviewing contractual allocation of AI-related responsibilities with vendors and customers; and
  • ensuring that AI governance aligns with existing data protection and cybersecurity compliance programs.

Organizations that begin implementing these governance measures now are likely to be better positioned if the AI Sandbox becomes operational and if similar requirements are incorporated into future regulatory frameworks.

Looking ahead

The draft AI Sandbox notification demonstrates that Thai regulators are moving beyond high-level discussions about artificial intelligence and toward practical governance mechanisms.

Even if participation remains voluntary during its initial stages, the Sandbox is likely to influence regulatory expectations regarding responsible AI development and deployment. Businesses should therefore view the proposal not simply as a testing initiative, but as an indication of the governance standards that may shape future AI regulation.

Key takeaways

Businesses that prepare early are likely to be better positioned as AI governance requirements continue to evolve.

The proposed AI Sandbox represents a significant step toward a structured AI governance framework.

The initiative reflects a broader shift toward risk-based regulation and responsible AI development.

Organizations developing or deploying AI should begin strengthening governance, documentation, testing, and oversight processes.

Existing obligations under data protection, cybersecurity, consumer protection, and intellectual property laws will continue to apply during AI development and testing.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Super License Reform Moves to Final Stage Before Becoming Law

In our previous article, “Super License: The Draft Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public,” we discussed the proposed overhaul of the administrative licensing regime and its potential to fundamentally modernize public services and regulatory approvals.

Super License: The Draft Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public – The Legal Co., Ltd.

The legislative process has now reached a significant milestone. The Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public B.E. 2569 has been approved by Parliament and is currently awaiting publication in the Government Gazette before coming into force. Once effective, the new legislation will repeal the Facilitation of Licensing by Government Agencies Act B.E. 2558 (2015) and introduce a substantially broader and more integrated framework for government licensing and public services.

A Shift from Licensing Control to Public Service Facilitation:

The new legislation reflects a significant policy shift in the administration of regulatory approvals. Rather than focusing solely on licensing procedures, it establishes a broader framework designed to improve the overall delivery of government services by emphasizing efficiency, transparency, digital integration, and reduced administrative burdens.

The scope of the law extends beyond traditional licensing procedures to cover registrations, notifications, approvals, and various public services provided by government agencies. This broader application aims to establish consistent administrative standards across the public sector while making interactions with government agencies more predictable and user-friendly.

Greater Transparency Through Mandatory Public Handbooks:

One of the most significant reforms is the enhanced requirement for government agencies to prepare comprehensive public handbooks.

These handbooks must clearly specify:

  • application procedures;
  • required documents;
  • statutory processing periods;
  • applicable fees;
  • approval criteria;
  • conditions imposed on applicants; and
  • written guidelines governing the exercise of official discretion.

Requiring agencies to disclose how discretion will be exercised represents an important development. It is intended to reduce inconsistent decision-making, improve legal certainty, and minimize opportunities for arbitrary administrative actions.

Digital Government and “Once-Only” Documentation:

The legislation further advances the government’s digital transformation policy by requiring agencies to utilize electronic information already available within government systems.

Where government agencies already possess information through interconnected databases, applicants generally should not be required to submit the same documents repeatedly. This “once-only” principle is expected to reduce paperwork significantly and improve the overall efficiency of administrative procedures.

The legislation also supports greater use of electronic application systems and centralized digital service platforms.

The Super License Mechanism:

Perhaps the most anticipated feature is the introduction of the Super License mechanism.

For business activities designated by the Cabinet, applicants will be able to obtain a principal license that automatically covers related subsidiary approvals normally issued by multiple government agencies. Instead of pursuing numerous sequential approvals, businesses will be able to complete much of the licensing process through a single application.

Although the categories of businesses eligible for the Super License mechanism will be determined through subsequent implementing measures, the reform is expected to benefit sectors that traditionally require multiple regulatory approvals, including manufacturing, hospitality, energy, and certain service industries.

The practical effectiveness of this mechanism will ultimately depend upon the implementing regulations and the level of coordination among participating agencies.

Faster Licensing Procedures:

The legislation introduces several measures intended to shorten administrative timelines.

Government agencies will be required to review applications promptly upon receipt, notify applicants immediately if documents are incomplete, and adhere to published processing periods. Where delays become unavoidable, agencies must notify applicants and explain the reasons for any extension.

In addition, the legislation provides for:

  • centralized application centers;
  • electronic submission and tracking systems;
  • expedited processing channels for eligible matters;
  • simplified renewal procedures for certain licenses; and
  • multilingual services where appropriate.

Collectively, these measures are designed to reduce procedural uncertainty while improving the overall applicant experience.

Deemed Approval for Certain Applications:

One of the most closely watched reforms is the introduction of a form of deemed approval.

For specified categories of lower-risk activities, where the responsible agency fails to complete consideration within the prescribed timeframe and does not properly extend the review period, the application may be treated as approved by operation of law.

This mechanism is intended to encourage administrative efficiency while providing greater certainty for businesses. However, it is not expected to apply universally, particularly where public safety, environmental protection, national security, or other significant public interests require substantive regulatory review.

Provisional Operations for Low-Risk Activities:

The legislation also introduces mechanisms allowing certain low-risk businesses to commence operations through notification or registration before obtaining full approval.

This represents a notable departure from the traditional approach, under which businesses generally must wait until all approvals have been formally issued before commencing operations. The reform seeks to facilitate earlier economic activity while maintaining appropriate regulatory oversight.

Increased Accountability for Government Agencies:

The legislation imposes stronger obligations on public officials responsible for licensing and service delivery.

Failure to comply with statutory procedures—such as requesting unnecessary documents, failing to meet prescribed timelines without justification, or otherwise violating procedural requirements—may constitute disciplinary misconduct.

These accountability measures reinforce the legislation’s broader objective of improving public confidence in administrative decision-making.

What Businesses Should Do Next:

Although the legislation has completed the parliamentary process, businesses should recognize that it will not become effective until publication in the Government Gazette.

In the meantime, companies that regularly interact with licensing authorities should begin assessing how the new framework may affect their operations. Particular attention should be paid to businesses that currently require approvals from multiple agencies, as they may eventually benefit from the Super License mechanism once implementing regulations identify eligible sectors.

Businesses should also monitor forthcoming subordinate legislation, ministerial regulations, and administrative guidelines, which will determine many of the practical details governing implementation.

Key Takeaways:

  • Businesses should begin reviewing their regulatory compliance strategies and monitor the issuance of subordinate legislation that will govern implementation of the new regime.
  • Parliament has approved the new Act, which is now awaiting publication in the Government Gazette before becoming effective.
  • The legislation replaces the existing licensing facilitation framework with a broader law covering licensing, registrations, notifications, approvals, and public services.
  • The new framework emphasizes transparency, digital government, reduced administrative burdens, and standardized procedures.
  • The Super License mechanism has the potential to significantly simplify regulatory approvals for businesses requiring multiple licenses, although further implementing regulations will determine its practical scope.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles: Super License: The Draft Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public – The Legal Co., Ltd.

Other Articles

Thailand Launches THIM App to Streamline Arrivals for Foreign Travelers

Thailand’s Immigration Bureau is rolling out a new mobile application — THIM (Thailand Immigration Mobile Application) — that allows foreign nationals to register their arrival details prior to boarding their flight, with the aim of facilitating immigration procedures for entering and staying in Thailand.

Key Features

THIM offers a faster, more user-friendly alternative for travelers to submit arrival information. The registration process can typically be completed in under three minutes. The platform also supports group submissions, enabling information for up to 10 travelers to be entered and processed simultaneously — a feature that significantly reduces administrative burden for tour groups and families. Compared to the existing web-based system, which is often slower and less intuitive, THIM provides a considerably more convenient experience for inbound travelers.

What’s Next: THIM as a Super Application

Looking ahead, THIM is expected to evolve into a comprehensive “Super Application” serving all categories of foreign nationals in Thailand — including short-term visitors, long-term residents, and permanent residents. The platform will function as a one-stop service for immigration-related matters, enabling users to request official immigration documents, submit applications along with supporting materials, and communicate directly with immigration officers online. This digital-first approach is intended to reduce the need for in-person visits to Immigration Bureau offices.

Additional planned features include an appointment scheduling system to help minimize travel time and waiting periods, as well as an emergency assistance function that will allow registered users to contact the Tourist Police through the application around the clock, 24 hours a day, seven days a week.

Language Support

During the initial launch phase, THIM supports four languages: English, Russian, Japanese, and Chinese, reflecting Thailand’s largest inbound visitor demographics. Future updates are expected to extend language support to at least 15 additional languages to better accommodate travelers from a broader range of countries.

Availability and Current Status

THIM is currently available for download on both iOS and Android devices. At present, users can access the Thailand Digital Arrival Card (TDAC) registration system through the application. Additional features and services will be introduced in subsequent updates, with a full platform launch anticipated in August 2026.

Key Takeaways

THIM is available now on iOS and Android in a trial phase, with a full launch expected in August 2026.

Thailand’s Immigration Bureau is introducing THIM, a mobile application enabling foreign nationals to register arrival details before their flight.

Registration takes under three minutes, with support for group submissions of up to 10 travelers simultaneously.

Future plans include expanding THIM into a Super Application, incorporating document requests, visa applications, officer appointments, and 24/7 Tourist Police access.

The application currently supports four languages: English, Russian, Japanese, and Chinese.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Government Agencies Accelerate Work-from-Home Policies Through e-Office and Digital Government Initiatives

Introduction:

The public sector is continuing its digital transformation through expanded adoption of work-from-home (WFH) arrangements supported by electronic office systems and digital government infrastructure. In 2026, the government intensified these efforts as part of broader energy conservation measures while simultaneously advancing long-term public sector digitalization objectives.

Recent government directives signal a significant policy shift toward greater reliance on electronic document management, digital signatures, online collaboration tools, and cloud-based administrative platforms. Government agencies are therefore increasingly required to review and update internal regulations, operational procedures, and workforce management policies to support remote working arrangements without compromising public services, information security, or administrative accountability.

Cabinet Resolution Promoting Work-from-Home Arrangements:

On 10 March 2026, the Cabinet resolved that government agencies and state enterprises should immediately implement work-from-home measures for functions that do not directly involve public-facing services. The policy was introduced primarily as a response to energy concerns and rising fuel consumption, while also supporting broader governmental objectives relating to digital government development.

The Ministry of Digital Economy and Society (MDES) subsequently announced support for the policy through expanded utilization of the government’s e-Office platform and related digital systems. The initiative reflects the government’s continuing commitment to reducing paper-based administrative processes and promoting flexible work arrangements across the public sector.

e-Office as the Foundation for Remote Government Operations:

The e-Office platform serves as a centralized electronic office management system designed to enable government officials to perform their duties remotely while maintaining official administrative processes.

Core functionalities include:

  • Electronic document management (e-Document);
  • Digital workflow and document routing;
  • Electronic correspondence and records management;
  • Digital signature capabilities;
  • Online meeting and collaboration tools;
  • Task monitoring and reporting systems; and
  • Time attendance and work tracking functions through integrated Timesheet applications.

The system allows government personnel to access official documents, approve transactions, monitor workflow progress, and collaborate with colleagues from remote locations while preserving audit trails and administrative transparency.

According to government reports, more than 160 government agencies and local administrative organizations have already adopted the platform. Agencies may also utilize the Government Data Center and Cloud Service (GDCC) infrastructure to deploy e-Office solutions without incurring additional licensing costs.

Regulatory and Governance Considerations:

While technology enables remote work, successful implementation requires corresponding adjustments to internal regulations and administrative procedures.

Government agencies adopting WFH arrangements should review and update internal rules governing:

Performance Management and Supervision

Traditional attendance-based supervision may no longer be suitable in a remote work environment. Agencies should establish clear frameworks for:

  • Work assignment and delegation;
  • Deliverable-based performance measurement;
  • Reporting obligations;
  • Monitoring mechanisms; and
  • Accountability requirements for remote personnel.

The emphasis should shift from physical presence toward measurable outputs and documented performance indicators.

Working Hours and Attendance Controls

Although work may be performed remotely, agencies remain responsible for ensuring compliance with official working-hour requirements.

Appropriate measures may include:

  • Electronic attendance recording;
  • Timesheet systems;
  • Activity reporting requirements;
  • System log monitoring; and
  • Supervisor approval procedures.

Clear policies should be established regarding availability, response times, and communication expectations during official working hours.

Information Security and Data Protection

Remote access to government systems introduces cybersecurity and information security risks.

Agencies should establish policies addressing:

  • Secure remote access protocols;
  • Authentication requirements;
  • Use of government-issued devices;
  • Confidentiality obligations;
  • Storage and transmission of official information; and
  • Incident reporting procedures.

Particular attention should be given to sensitive government information and compliance with applicable cybersecurity and data governance requirements.

Continuity of Public Services

A fundamental principle of the government’s WFH policy is that public services must not be adversely affected.

Accordingly, agencies should identify:

  • Functions suitable for remote work;
  • Essential on-site operations;
  • Minimum staffing requirements;
  • Public service continuity plans; and
  • Escalation procedures for urgent matters.

Several agencies have adopted rotational work arrangements to balance operational efficiency with service delivery obligations.

Sector-Specific Implementation

Certain government sectors have already introduced tailored WFH frameworks.

For example, the Ministry of Public Health has implemented rotational remote-working arrangements designed to maintain uninterrupted healthcare services while reducing on-site staffing levels where operationally feasible.

Such approaches demonstrate that WFH implementation is not intended as a uniform solution across all agencies but rather as a flexible framework that must be adapted according to each organization’s operational requirements and public service responsibilities.

Implications for Government Agencies:

The 2026 policy initiative reflects a broader transition from temporary remote working measures toward institutionalized digital government operations.

Government agencies should therefore consider:

  • Updating internal regulations to formally recognize remote work arrangements;
  • Expanding deployment of e-Office and digital workflow systems;
  • Establishing objective performance evaluation frameworks;
  • Enhancing cybersecurity and data governance controls;
  • Developing clear WFH eligibility criteria; and
  • Ensuring uninterrupted public service delivery.

As digital government infrastructure continues to mature, WFH arrangements are likely to become a permanent component of public sector administration rather than merely an emergency or temporary measure.

Key Takeaways:

  • The Cabinet has directed government agencies and state enterprises to implement WFH arrangements for non-public-facing functions as part of energy conservation and digital transformation initiatives.
  • The government’s e-Office platform serves as a key technological enabler, providing electronic document management, digital signatures, workflow automation, online collaboration, and work tracking capabilities.
  • Agencies should revise internal regulations governing performance management, attendance monitoring, information security, and service continuity to accommodate remote work environments.
  • Cybersecurity, data protection, and accountability remain critical compliance considerations when implementing WFH policies.

The 2026 initiative represents a significant step toward long-term digital government operations and greater institutional adoption of flexible working arrangements within the public sector.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

ETDA: Proposed Overhaul of Thailand’s Electronic Transactions Act – Modernizing for the Digital Economy

Thailand’s existing Electronic Transactions Act B.E. 2544 (2001, as amended) has served as the foundational legal framework for electronic transactions for over two decades. Enacted in an earlier era of digital adoption, it primarily addressed basic electronic signatures, data messages, and recognition of electronic records. However, it increasingly struggles to accommodate rapid technological advancements, including automated contracting systems, electronic transferable instruments (such as e-bills of lading), cloud-based data storage, digital identity solutions, and complex cross-border digital platforms.

Limitations in the current law—such as uncertainty around the reliability and evidentiary weight of electronic data, rigid requirements that do not flexibly support emerging technologies without additional regulations, and enforcement gaps—hinder full digital transformation. This creates friction for businesses adopting paperless processes, e-commerce, fintech, logistics, and other innovative models central to Thailand 4.0 and the broader digital economy.

Many jurisdictions have proactively updated their frameworks to address these challenges. The United Nations Commission on International Trade Law (UNCITRAL) Model Laws on Electronic Commerce, Electronic Signatures, and Electronic Transferable Records have influenced reforms worldwide. Countries like Singapore, the EU (with eIDAS and related directives), and others have introduced technology-neutral rules, enhanced trust services, liability frameworks for service providers, and specific provisions for electronic equivalents of negotiable instruments. These updates boost legal certainty, reduce compliance burdens, facilitate international trade, and stimulate innovation while maintaining consumer and business protections.

Key Changes in the Draft Act and UNCITRAL Alignment:

The Electronic Transactions Development Agency (ETDA) has proposed a comprehensive Draft Electronic Transactions Act for public hearing (comments due by June 15, 2026). The draft represents a substantial rewrite rather than a simple amendment. It shifts Thailand toward a more technology-neutral, principles-based, and trust-oriented framework, building on the original law’s foundations while incorporating newer UNCITRAL instruments.

Major Changes from the Current Law:

Broader Legal Recognition of Electronic Data and Transactions: Electronic records that are accessible, reusable, and retain integrity will satisfy requirements for “writing,” originals, retention, and evidence across civil, criminal, and procedural contexts. Electronic transactions become the default/preferred mode. This significantly expands functional equivalence beyond the 2001 Act’s more limited scope.

Electronic Signatures, Seals, Timestamps, and Notices: Reliable electronic methods (or ETDA-prescribed ones) fulfill signature, seal, timestamp, and registered mail requirements. Public announcements can shift to verified online platforms. New emphasis on electronic seals and reliable timestamps strengthens evidentiary value.

Reliable Methods, Certification, and Burden of Proof: Introduction of “reliable electronic methods” with ETDA recognition/certification. When approved systems are used, the burden and cost of disproving reliability shift to the challenger. This provides stronger legal certainty and incentivizes certified solutions.

Automated and Electronic Contracting: Explicit validation of contracts formed by automated systems (with or without human intervention), plus detailed rules on attribution, receipt acknowledgment, timing/place of dispatch, input error correction, and verification methods.

New Regime for Electronic Transferable Instruments: A dedicated framework for e-bills of lading, warehouse receipts, promissory notes, etc., including exclusive control (equivalent to possession), transfer, endorsement, amendment, integrity, and paper-electronic conversion. This is a major addition.

Regulation of Service Providers: Broader coverage of identity proofing, e-signatures, timestamping, data storage, and related services. Replaces rigid licensing with a voluntary certification (“trust mark”) scheme, risk management, cybersecurity, and complaint-handling obligations. Liability protections for compliant providers, with transitional recognition for existing licensees.

Strong UNCITRAL Alignment:

Builds on the original Act’s foundation in the Model Law on Electronic Commerce (1996) and Electronic Signatures (2001).

Incorporates the Electronic Communications Convention (ECC, 2005) — Thailand acceded in 2025 — for automated contracting and international rules.

Adopts principles from the Model Law on Electronic Transferable Records (MLETR, 2017) for e-transferable instruments.

Aligns with the Model Law on Electronic Identity and Trust Services (MLIT, 2022) through trust services, certification, and technology-neutral identity frameworks.

Supports overall technology neutrality and functional equivalence, enhancing interoperability under initiatives like the Framework Agreement on Cross-border Paperless Trade (CPTA).

Business Impacts and Preparation Steps:

The Draft Act would lower barriers to digital operations, reduce paper dependency, streamline contracting and record-keeping, and improve cross-border compatibility. Sectors like trade finance, logistics, e-commerce, fintech, cloud services, and digital identity providers stand to benefit significantly.

New compliance expectations include system reliability, risk management, cybersecurity, audits, and vendor due diligence. Businesses may need to update processes, contracts, policies, and user interfaces.

Businesses should prepare by:

Reviewing current electronic systems against emerging “reliable method” standards.

Assessing exposure as service providers or users.

Monitoring ETDA subordinate regulations, certifications, and guidance.

Updating contracts, terms, privacy notices, and record-retention policies.

Enhancing cyber security and complaint-handling mechanisms.

Current Status and Next Steps:

The Draft Act is currently in the public hearing phase (comments due by June 15, 2026). Following consultation, it will undergo refinement, Cabinet approval, parliamentary review, and publication in the Government Gazette.

Implementation is not immediate: The law would generally take effect 180 days after Gazette publication, with ETDA issuing subordinate rules, standards, and certification procedures (targeted within 180 days post-publication, though effective timelines may extend). Full industry adaptation and technical rollout could span months to years. Existing providers receive transitional support.

Key Takeaways:

The Draft Act modernizes Thailand’s electronic transactions framework through broader recognition, new instruments for digital trade, and a flexible certification model — strongly aligned with evolving UNCITRAL standards.

It addresses longstanding limitations while promoting trust, innovation, and paperless processes across private and public sectors.

Businesses should proactively assess impacts, strengthen systems, and participate in the ongoing public consultation.

Successful implementation will enhance Thailand’s digital economy competitiveness, though it requires coordinated regulatory and industry efforts over the coming years.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

AI-Powered Assistant “Nok Krasip” Launched to Empower SME Retailers Through Digital Tools

The government has introduced “Nok Krasip” (Whispering Bird), an AI chatbot assistant integrated into the “Thung Ngern” mobile application. This forms part of the “Thai Help Thai Plus 60/40” program, designed to support small retailers and community businesses with practical digital solutions.

Program Context:

This initiative underscores efforts to strengthen the grassroots economy by equipping micro, small, and medium-sized enterprises (MSMEs) — particularly traditional shops — with accessible technology. The Thung Ngern application serves as a central platform for financial and business management, with the AI feature representing a key advancement in providing real-time insights.

Core Features of the AI Assistant:

Nok Krasip delivers user-friendly tools tailored for retailers with limited technical expertise:

•  Sales Analysis: Automatic summaries of daily sales performance, transaction trends, peak periods, and inventory suggestions.

•  Raw Material Price Monitoring: Real-time market price data for essential commodities such as meats and other inputs, drawn from official sources.

•  Cost and Profit Analysis: Simple calculations that compare input costs with selling prices to support better pricing and margin decisions.

•  Intelligent Chatbot: Instant answers to questions about the program and application functions, featuring preset options for quick navigation.

The assistant is available in Thung Ngern version 5.50.0 and higher for eligible registered users.

Legal and Regulatory Considerations:

The introduction of this AI tool carries several implications for businesses operating in the digital economy:

•  Data Privacy Compliance: Processing of sales, inventory, and transaction data requires adherence to the Personal Data Protection Act B.E. 2562 (PDPA). Platform operators should maintain clear consent mechanisms and transparent data handling practices, especially when information is shared with government entities.

•  Digital Transaction Governance: The tool supports broader goals of fair digital commerce and MSME empowerment, aligning with regulations on electronic transactions, consumer protection, and platform responsibilities.

•  Cybersecurity and Procurement Standards: Government-backed digital services typically involve cybersecurity requirements and public technology procurement rules.

•  Intellectual Property Aspects: Issues may emerge concerning ownership of AI-generated insights, underlying datasets, and developed algorithms.

Practical Guidance for Stakeholders:

•  Retailers and MSMEs: Participants should review the application’s terms of service and data policies prior to extensive use. While the AI can enhance operational efficiency, it should supplement — not substitute — professional financial advice.

•  Platform Operators and Partners: Entities involved in such ecosystems should monitor evolving rules on data governance and electronic transactions.

•  Risk Management: Businesses adopting AI tools are advised to implement robust cybersecurity protocols and include appropriate contractual safeguards regarding accuracy and liability.

Key Takeaways:

•  The AI assistant Nok Krasip provides accessible, practical tools that help small retailers analyze sales, control costs, and make informed decisions.

•  Integration into the Thung Ngern application advances digital inclusion for MSMEs participating in government support programs.

•  Stakeholders should prioritize PDPA compliance, data security, and clear policies when leveraging such government-supported AI platforms.

•  This development signals continued focus on technology-driven support for the traditional retail sector, potentially improving competitiveness and access to future financing opportunities.

This article provides general information only and does not constitute legal advice. Readers should seek qualified professional counsel for matters specific to their situation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Super License: The Draft Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public

The Draft Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public, widely known as the “Super License” law, constitutes a major reform to Thailand’s administrative licensing and public service framework. It revises and expands upon the Facilitation of Licensing by Government Agencies Act B.E. 2558 (2015), aiming to reduce bureaucratic obstacles, enhance transparency, integrate digital processes,  foster a more efficient and applicant-centered administration.

1. Background:

The initiative traces its origins to evaluations of the 2015 Act, which demonstrated effectiveness in facilitating public interactions with government agencies but revealed opportunities for improvement amid evolving economic, social, and technological conditions. The Office of the Public Sector Development Commission (OPDC) proposed revisions to minimize unnecessary procedures, discretionary decisions, and compliance burdens while aligning with digital government objectives under the Electronic Government Operations Act B.E. 2565 (2022).

The draft was approved in principle by the Cabinet on April 2, 2024, and underwent public hearings (including a third round from September 20 to October 11, 2024) before review by the Office of the Council of State. It advanced through parliamentary consideration in 2025, passing reviews in both the House of Representatives and the Senate. Progress paused due to parliamentary dissolution prior to final enactment.

2. Key Provisions:

The draft organizes reforms across general principles, procedural enhancements, licensing mechanisms, service delivery improvements, periodic evaluations, centralized systems, and accountability measures. Core provisions include:

•  Expanded Scope: Application extends beyond licenses to registrations, notifications, approvals, and broader public services provided by state agencies, ensuring uniform standards.

•  Mandatory Public Handbooks: Authorities must publish detailed, standardized handbooks specifying criteria, procedures, documents, fees, timelines, conditions, and electronic options, with prohibitions on redundant requests and immediate deficiency notifications.

•  Streamlined Processing: Immediate verification of completeness upon receipt; strict timeline adherence with delay notifications (every 15 days) and explanations for extensions beyond 30 days; oversight by the Commission on Public Sector Development for persistent issues.

•  Automatic Renewal via Fee Payment: Renewal deemed effective upon fee payment for designated licenses (per ministerial regulations), reducing formal re-applications while maintaining compliance monitoring.

•  Super License (Principal License) Mechanism: The Cabinet may designate a principal license for activities requiring multiple approvals; issuance automatically grants subsidiary permissions, enabling single-point completion for sectors like factory construction, hotels, spas, and energy projects.

•  Extended or Permanent Validity: Licenses to have indefinite duration or a minimum five-year term where appropriate, replacing frequent short-term renewals.

•  Provisional/Trial Operations: Low-risk activities permitted temporarily via notification or registration pending full approval, with refinements toward notification systems recommended.

•  Centralized One-Stop and Electronic Centers: Joint physical/digital centers for submissions, inquiries, payments, and tracking; a national electronic central reception center (potentially with private involvement under data protection) forwards applications within one working day and monitors progress.

•  Fast-Track and Multilingual Support: Accelerated channels for urgent cases; forms and information available in English and other languages upon request.

•  Accountability Measures: Procedural violations (e.g., untimely processing, redundant demands) constitute disciplinary offenses for officials.

These elements collectively promote efficiency, digital integration, and reduced discretion while safeguarding public interests.

3. Impact to the Public:

The reforms promise tangible benefits for citizens, entrepreneurs, and investors:

•  Simplified access to services through consolidated processes and single-point submissions, reducing time, costs, and repeated interactions.

•  Greater transparency via mandatory handbooks, clear timelines, and limited discretion, minimizing opportunities for arbitrary decisions or corruption.

•  Faster business commencement, particularly for low-risk activities via provisional operations and automatic mechanisms, supporting economic activities in manufacturing, tourism, hospitality, and emerging sectors.

•  Enhanced competitiveness by improving Thailand’s ease of doing business rankings, attracting domestic and foreign investment, especially in high-value industries such as data centers, semiconductors, and modern agriculture.

•  Improved accessibility for non-Thai speakers and international applicants through multilingual support and digital channels.

Overall, the legislation prioritizes user convenience and national economic growth without compromising regulatory integrity.

4. Current Status:

As of mid-March 2026, the draft has secured prior approval from both the House and Senate but requires reaffirmation following parliamentary dissolution. Public discussions and media coverage in early March 2026 highlight cross-party recognition of its value, positioning it as a continuation of established reform efforts. No enactment has occurred, but momentum suggests active preparation for legislative progression.

5. Key Takeaways:

•  The Super License initiative modernizes governance by emphasizing efficiency, digital tools, and centralized services over fragmented approvals.

•  It exhibits policy continuity across administrations, demonstrating that beneficial reforms transcend political boundaries for national advantage.

•  Successful enactment could substantially alleviate bureaucratic burdens, boost investment attractiveness, and elevate public service quality.

•  Effective rollout will hinge on robust inter-agency coordination, digital infrastructure development, and periodic reviews (every five years) to adapt to future needs.

This proposed legislation underscores Thailand’s commitment to administrative modernization and enhanced competitiveness.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles