ETDA’s TTR Guidance: A New Framework for E-Marketplace Fee Transparency

The Electronic Transactions Development Agency (ETDA) has issued new guidance introducing the concept of the Total Take Rate (TTR) for e-marketplaces. The guidance is intended to give merchants a clearer and more comparable picture of the total fees and expenses associated with selling through an e-marketplace, particularly before they decide whether to participate in a campaign, promotional program, or additional service.

The initiative responds to an increasingly complex fee structure in the e-commerce ecosystem. A merchant’s cost of selling through an e-marketplace may extend well beyond the headline commission rate and include payment processing fees, infrastructure or system fees, campaign participation costs, merchant-funded discounts, advertising fees, affiliate fees, and charges for additional services. Because these charges may use different names, rates, and calculation bases, merchants may find it difficult to determine the actual economic cost of a transaction. The TTR framework is designed to address this information gap by presenting the aggregate financial impact in a standardized and understandable form. (ETDA⁠)

What is the Total Take Rate?

Under the guidance, TTR generally represents the total fees and expenses borne by a merchant in connection with the sale of a product, expressed as a percentage of the net product price. The net product price is essentially the initial selling price after deducting discounts for which the merchant is responsible. TTR should be presented both as a percentage and as an actual monetary amount so that merchants can see how platform charges affect the proceeds they expect to receive. (ETDA⁠)

The guidance divides TTR into three components:

Baseline TTR represents the aggregate fees ordinarily necessary for an order to take place and be completed. These may include commissions, payment processing fees, and infrastructure fees, without including costs attributable to campaigns or additional services.

Scenario TTR takes the Baseline TTR and adds the costs associated with a particular campaign or additional service that the merchant is considering. Depending on the arrangement, these may include additional discounts, campaign participation charges, advertising fees, affiliate fees, or fees for special programs.

Incremental TTR represents the difference between the Scenario TTR and Baseline TTR. It therefore gives the merchant a relatively straightforward indication of the additional economic burden associated with participating in the proposed campaign or additional service. (ETDA⁠)

This distinction is important because a platform’s headline commission rate may provide only a partial picture of the actual cost of a sale. By comparing the Baseline and Scenario TTR, a merchant can assess the financial position both with and without participation in a particular campaign.

Disclosure before the merchant commits:

A central feature of the guidance is the timing of disclosure. Relevant TTR information should be made available at the point at which the merchant is making the commercial decision, particularly before confirming participation in a campaign or additional service.

The platform should provide information that allows the merchant to understand the Baseline TTR, the Scenario TTR, the resulting Incremental TTR, and the estimated net proceeds. The objective is to enable the merchant to assess the economic consequences before committing, rather than discovering the full cost only after the transaction has taken place.

The guidance therefore encourages platforms to place TTR information at relevant decision points, such as product pricing pages, fee information pages, seller dashboards, and, importantly, the screen presented before a merchant confirms participation in a campaign or additional service. Information should be presented clearly and accessibly rather than being obscured in detailed terms and conditions or links that are difficult to locate. (ETDA⁠)

TTR calculation tools:

The guidance also encourages e-marketplaces to provide merchants with a TTR calculation tool that is easy to use and available without an additional charge.

Such a tool could allow a merchant to select a particular product or SKU and enter relevant variables, including the selling price, merchant-funded discounts, campaign participation, and applicable fees. The resulting calculation should enable the merchant to compare the cost of selling under the ordinary arrangement with the cost that would apply if the merchant participates in the proposed campaign or additional service.

The output should show relevant fees in both monetary and percentage terms and provide an estimate of the merchant’s net proceeds. Where sufficient information is available, the tool may also show gross profit and the break-even selling price. The guidance additionally contemplates merchants being able to save or download calculation results for subsequent verification. (ETDA⁠)

This aspect of the guidance may have practical implications beyond simply adding another disclosure to a platform’s terms of service. E-marketplace operators may need to consider whether their merchant interfaces, campaign enrollment processes, fee databases, and internal calculation systems are capable of generating sufficiently accurate TTR information at the point when a merchant makes its decision.

Changes to fees affecting TTR:

The guidance also addresses subsequent changes to the fee structure. Where a platform changes a fee rate, calculation base, collection method, or other condition affecting TTR, it should generally notify merchants at least 30 days in advance.

The information should allow merchants to compare the position before and after the change and understand how the change affects the Baseline TTR and Scenario TTR. This gives merchants an opportunity to assess the commercial consequences and adjust their pricing or participation strategy before the new fee structure applies. (ETDA⁠)

This approach reflects a broader transparency objective: merchants should not merely know that a particular fee has changed, but should also be able to understand how that change affects the overall cost of using the platform.

Transparency after the transaction:

The TTR framework does not end once the merchant has agreed to participate in a campaign. The guidance also encourages transparency after a transaction has been completed.

Merchants should be able to review the fees actually deducted and compare them against the TTR previously estimated. Where the amounts differ, the platform should provide sufficient information to explain the discrepancy. Possible reasons could include the actual use of coupons, product returns, refunds, or changes in the merchant’s status.

ETDA also recommends that calculation histories and actual fee information remain accessible through the platform for at least three months and that merchants be able to save or download relevant information. Annual summaries are also contemplated to assist merchants in evaluating the overall cost of selling through the platform. (ETDA⁠)

A transparency framework, not a fee cap:

An important point is what the TTR guidance does not do. It does not prescribe a maximum commission or impose a ceiling on the amount that an e-marketplace may charge. ETDA describes its purpose as improving the completeness, transparency, comparability, and verifiability of fee information so that merchants can make informed commercial decisions. (ETDA⁠)

The legal status of the instrument should therefore be understood accordingly. ETDA places the TTR guidance within its category of “Best-practice/Self-Regulation” measures rather than mandatory platform rules. (ETDA⁠) The guidance should therefore not be characterized as immediately imposing a statutory obligation on every e-marketplace to implement the TTR model exactly as described.

Nevertheless, the distinction between guidance and mandatory regulation should not obscure its practical importance. The TTR framework provides a detailed regulatory benchmark for how ETDA considers platform fee transparency should operate. E-marketplace operators should therefore consider the guidance when reviewing their fee structures, merchant-facing disclosures, campaign enrollment processes, and supporting IT systems.

Why TTR matters for merchants:

For merchants, the principal benefit of the TTR model is that it changes the focus from individual fee rates to the aggregate economic effect of selling through the platform.

Consider a product with an initial price of THB 1,000 where the merchant bears a THB 100 discount, producing a net product price of THB 900. ETDA illustrates how a Baseline TTR of 12.96% would correspond to approximately THB 116.63 in baseline charges and estimated net proceeds of THB 783.37. If participation in a campaign creates another THB 108 of costs, the Scenario TTR would rise to 24.96%, with the Incremental TTR showing an additional 12 percentage points and estimated net proceeds falling to THB 675.37. (ETDA⁠)

The example illustrates the commercial rationale behind the framework. A merchant considering a campaign should be able to assess not simply whether the campaign may increase sales, but also how much additional revenue or volume would be required to offset the additional platform costs.

Practical implications for e-marketplace operators:

For platform operators, implementation of the TTR framework is potentially a product, compliance, and systems issue rather than merely a matter of revising contractual terms.

Platforms may need to map the different charges imposed on merchants, identify the relevant calculation bases, distinguish baseline costs from campaign-specific or additional costs, and ensure that their systems can calculate and present the resulting TTR accurately. Merchant dashboards and campaign enrollment interfaces may also need to be designed so that relevant information is available before the merchant confirms participation.

Operators should also consider whether their post-transaction records allow merchants to reconcile estimated and actual charges and whether changes to fees can be communicated in a manner that explains their overall TTR impact rather than merely announcing a revised percentage for an individual fee.

For merchants, meanwhile, TTR could become a useful metric for comparing the economic effect of different campaigns and services. In particular, the Incremental TTR provides a relatively direct way of assessing the additional cost of a campaign against its expected contribution to sales.

Key takeaways:

  • ETDA has introduced TTR as a framework for improving transparency over the aggregate fees and expenses borne by merchants selling through e-marketplaces.
  • TTR is divided into Baseline TTR, Scenario TTR, and Incremental TTR, allowing merchants to distinguish ordinary transaction costs from the additional costs associated with campaigns or additional services.
  • The guidance emphasizes disclosure before a merchant commits to a campaign or additional service, rather than relying solely on general fee schedules or contractual terms.
  • E-marketplaces are encouraged to provide accessible TTR calculation tools showing fees, estimated net proceeds, and other relevant financial information in both monetary and percentage terms.
  • Changes affecting TTR should generally be notified to merchants at least 30 days in advance, together with information enabling them to understand the impact of the change.
  • Merchants should be able to compare estimated TTR with fees actually deducted after transactions and access historical fee information.
  • The TTR framework does not impose a cap on platform fees. It is currently presented by ETDA as a best-practice/self-regulatory measure aimed at transparency and informed decision-making rather than direct price regulation.
  • Although not framed as an immediately mandatory fee-control regime, the guidance provides e-marketplace operators with a detailed regulatory benchmark against which their fee disclosure practices and merchant-facing systems can be reviewed.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Criteria and Conditions for Allowing Foreign Nationals to Use Automated Passport Control Channels

Background

The Immigration Bureau introduced Automated Passport Control Channels under the Order No. 322/2566 (the “Previous Order”), effective 15 December 2023, to support tourism and improve immigration processing efficiency.

However, the original framework was relatively narrow in scope, covering only a limited group of foreign nationals and restricting outbound automated processing to Suvarnabhumi Airport. To enhance accessibility and accommodate a wider range of travelers, the Immigration Bureau subsequently issued the Order No. 196/2569 (the “Current Order”), which substantially expands the scope of the Automated Passport Control System.

Immigration Bureau Order No. 196/2569

To further facilitate immigration clearance for foreign travelers, the Immigration Bureau issued the Current Order, effective on 24 August 2026. The Current Order significantly expands access to Automated Passport Control Channels by broadening eligible nationalities, visa categories, and airport checkpoints. Here is what has been changed compared to the previous order.

  1. Expanded Eligible Nationalities

The most significant change is the expansion of eligible nationalities from only Singapore and Hong Kong under the Previous Order to 33 countries and territories under the Current Order.

The expanded list now includes major business and tourism markets such as the United Kingdom, Japan, South Korea, Australia, New Zealand, Germany, France, Switzerland, Italy, the Netherlands, Sweden, Norway, Denmark, Finland, Belgium, Austria, Canada, and Singapore.

As a result, a substantially larger number of foreign travelers are now eligible to use Automated Passport Control Channels when entering and departing Thailand.

  • Expanded Visa Eligibility

The Previous Order primarily limited access to permanent residents, diplomats, government representatives, and certain designated individuals.

Under the Current Order, eligibility has been extended to holders of specified Non-Immigrant Visas as listed in its Appendix, covering a wider range of foreign nationals residing, working, studying, investing, or living with family members in Thailand.

  • Expanded Airport Access

Under the Previous Order:

  • Inbound automated channels were available only to a limited group of foreign nationals and specific type of passport holders.
  • Outbound automated channels were available only at Suvarnabhumi Airport.

Under the Current Order:

  • Eligible foreign nationals as listed in its Appendix can use automated channels for both inbound and outbound travel.
  • Access is available at any international airport equipped with the Automated Passport Control System.
  • Operational Improvements

The Current Order also introduces procedures enabling immigration officers to promptly correct minor system errors, including issues related to visa classification, period-of-stay records, and automated overstay alerts, thereby helping to reduce delays and unnecessary processing.

  • Broader Coverage of Eligible Travelers

The Current Order also broadens eligibility to include:

  • Business: employees, executives, assignees, and investors;
  • Education: teachers, researchers, and students;
  • Family: spouses, parents, children, and other qualifying family members of Thai nationals, permanent residents, and eligible foreign residents.  

It is crucial to note that each criterion is evaluated independently. Therefore, if a foreigner fits into one of the eligible groups (such as holding a qualifying visa or belonging to an eligible nationality), they will be allowed to use the automated channels

Practical Examples

  1. Long-Term Business Professionals and Expatriates Holding Non-Immigrant “B” Visas

Under the Previous Order:

  • Inbound: No access to the Automated Passport Control System was allowed; even senior executives of multinational companies and citizens of major economies such as the United States, the United Kingdom, Japan, and China. They  were required to use manual immigration counters.
  • Outbound: The Automated Passport Control System is available only at Suvarnabhumi Airport.

Under the Current Order:

  • Inbound and Outbound: It is accessible at any international airport equipped with the Automated Passport Control Channels, provided the traveler qualifies under the Appendix of the Current Order and holds a valid re-entry permit where required.
  • Short-Term Business Travelers and Tourists

Under the Previous Order:

  • Inbound: No access to the Automated Passport Control System was allowed, except for Singaporean and Hong Kong passport holders.
  • Outbound: The Automated Passport Control System is available only at Suvarnabhumi Airport.

Under the Current Order:

  • Inbound and Outbound: Eligible travelers from countries listed in the Appendix to the Current Order, including the United States, Japan, China, and the United Kingdom, can use Automated Passport Control Channels at any international airport equipped with the Automated Passport Control System.

Key Takeaways

  • Significant Expansion: Eligibility has increased from only two nationalities to 33 countries and territories under the Current Order.
  • Broader Access: Business travelers, expatriates, investors, academics, students, and family-based visa holders can now benefit from automated immigration processing.
  • Nationwide Availability: Automated outbound processing is no longer limited to Suvarnabhumi Airport, and it is now being used at any international airport equipped with the system.
  • Improved Efficiency: Immigration officers are now authorized to resolve minor system errors immediately, helping to reduce delays and unnecessary procedures.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Revises Visa Exemption Scheme: 30-Day Stay and Revised List of Eligible Countries

1. Introduction

The Ministry of Interior has issued notification revising Thailand’s visa exemption arrangements for foreign nationals. The revised measures repeal the special 60-day visa exemption scheme introduced in July 2024 and establish an updated list of countries and territories whose passport or travel-document holders may enter the Kingdom without a visa for tourism purposes, for a period not exceeding 30 days.

The notifications were signed on 26 August 2026 and published in the Royal Gazette on 31 August 2026, and will take effect on 15 September 2026, being 15 days after publication.

2. Background: The Previous 60-Day Visa Exemption Scheme

Under the Ministry of Interior notification dated 15 July 2024, nationals of 93 countries and territories entering Thailand for tourism, work, or short-term business purposes were exempt from visa requirements and permitted to stay for up to 60 days.

3. The Revised 30-Day Visa Exemption Scheme

3.1 Scope

  • The revised notification sets out an updated list of countries and territories eligible for visa-free entry for tourism purposes with the permitted period of stay reduced from 60 days to 30 days.
  • The revised scheme covers 60 countries and territories in total: 59 retained from the previous list, plus the Kyrgyz Republic, which has been newly added.

3.2 Retained Countries and Territories (59)

  • Asia: Bahrain, Bhutan, Brunei Darussalam, Georgia, India, Indonesia, Israel, Japan, Jordan, Kuwait, Malaysia, Maldives, Oman, Philippines, Qatar, Saudi Arabia, Singapore, Taiwan, Türkiye, and the United Arab Emirates.
  • Europe: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland, Ukraine, and the United Kingdom.
  • Africa: South Africa.
  • North America: Canada and the United States.
  • Oceania: Australia, Fiji, and New Zealand.

3.3 Amended Countries and Territories Covered by the Revised 15-Day Scheme (2)

  • Africa: Seychelles and Mauritius 

Seychelles is not counted as retained Country and Territory as it never been in the Scheme while the Mauritius was in 30 – Day Scheme.

In addition, the Kyrgyz Republic has been newly added to the revised list as well as Seychelles on the Revised 15 – Day Scheme. 

3.4 Countries and Territories No Longer Covered by the Revised 30-Day Scheme (34)

  • Asia: Cambodia, China, Hong Kong, Kazakhstan, Korea (ROK), Laos, Macao, Mongolia, Sri Lanka, Uzbekistan, and Vietnam.
  • Europe: Albania, Andorra, Kosovo, Monaco, Russia, and San Marino.
  • Africa:  Mauritius and Morocco.
  • North, Central America and the Caribbean: Cuba, Dominica, the Dominican Republic, Guatemala, Jamaica, Mexico, Panama,Trinidad and Tobago.
  • South America: Brazil, Colombia, Ecuador, Peru, and Uruguay.
  • Oceania: Papua New Guinea and Tonga.

These countries and territories are no longer covered by the revised 30-day visa exemption scheme. Certain nationals among them are eligible for visa-free entry under separate arrangements.

4. Key Operational Requirements Under the Revised Scheme

4.1 Purpose of Entry

Whereas the previous notification permitted eligible nationals from a broader list of countries to enter Thailand for tourism purposes for up to 60 days, the revised notification limits the privilege to a reduced number of eligible countries and shortens the permitted stay to 30 days.

4.2 Land-Border Entry Limitations

  • Visa-exempt entry through land-border immigration checkpoints for the nationals listed in Item 3.2 is limited to no more than two entries per calendar year, except for nationals of Malaysia, Brunei Darussalam, Indonesia, and Singapore, and any other countries as may be further designated by the Ministry of Interior.

5. Effect on Nationals Removed From the Previous Scheme

Once the revised measures take effect, nationals of countries and territories removed from the previous list will no longer be entitled to the former 60-day exemption and also this 30-day exemption. However, some may nonetheless remain eligible for visa-free entry under separate bilateral arrangements. The applicable entry requirements and permitted period of stay therefore depend on the specific legal basis applicable to each foreign national.

  • Required to obtain a visa prior to entry (21 from 34 countries): Albania, Andorra, Colombia, Cuba, Dominica, the Dominican Republic, Ecuador, Guatemala, Jamaica, Kosovo, Mexico, Monaco, Morocco, Panama, Papua New Guinea, San Marino, Sri Lanka, Tonga, Trinidad and Tobago, Uruguay, and Uzbekistan.
  • Covered under separate bilateral arrangements (11 countries and territories): Cambodia, China, Hong Kong, Kazakhstan, Korea (ROK), Laos, Macao, Mongolia, Russia, Vietnam, and Mauritius continue to be governed by their respective bilateral frameworks. For example, Chinese nationals continue to be eligible for visa-exempt entry under the agreement between Thailand and the People’s Republic of China on mutual visa exemption, allowing a stay of up to 30 days per entry, subject to the terms and conditions of the agreement.

6. Key Takeaways

  • The permitted period of visa-exempt stay under the general scheme has been reduced from 60 days to 30 days.
  • The number of countries and territories eligible under the general visa exemption has decreased from 93 to 60.
  • Nationals of countries removed from the list will no longer benefit from the former 60-day exemption, however, subject to any separate bilateral or country-specific arrangements.
  • The revised measures take effect on 15 September 2026. Travellers admitted before that date retain the period of stay granted under the rules in force on their date of arrival.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Telemedicine Practices and Data Protection Compliance in Thailand: Legal Brief

I. Introduction to Telemedicine in Thailand:

Telemedicine has emerged as one of the most transformative innovations in healthcare. By leveraging modern communication technologies, telemedicine enables the delivery of medical services regardless of geographic barriers. As the global demand for accessible, efficient, and cost-effective healthcare increases, many countries have embraced telemedicine to overcome traditional challenges such as distance, cost, and limited access to medical expertise.

Thailand, with its rapidly developing digital infrastructure and progressive approach to healthcare, is becoming a prominent destination for telemedicine providers. However, alongside its tremendous growth potential, Thailand presents unique challenges, particularly in the realm of data protection and privacy. For both local and international telemedicine platforms, understanding and complying with the local legal environment is critical. The country’s evolving legal landscape, especially concerning data protection, patient privacy, and healthcare standards, requires providers to implement robust compliance measures. Doing so not only safeguards sensitive patient information but also builds trust with users, ensuring sustainable business growth in a competitive market.

In this guide, we delve into the key considerations for data compliance, discuss the relevant regulatory frameworks under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), and outline practical steps for telemedicine platforms to navigate these regulations. By doing so, telemedicine providers can effectively mitigate risks, secure patient data, and maintain a competitive edge in the Thai market.


II. Health Information Protection Before the Enforcement of the Personal Data Protection Law:

  1. The National Health Act and Ministerial Regulation:

Thailand’s regulatory framework for data protection has undergone significant evolution over recent years. Prior to the enactment of the PDPA in 2019, Thailand relied on a combination of the Thai Constitution, the Thai Civil and Commercial Code, and sector-specific regulations like the National Health Act B.E. 2550 (2007) (“National Health Act”). The National Health Act mandated that personal health information be kept confidential. Specifically, Section 7 of the National Health Act required that such information not be disclosed in a manner that could harm the data subject, except when authorized by the individual or required by law.

The Ministerial Regulation on the Protection and Management of Personal Health Information B.E. 2561 (2018) (“MR”) provided further details on the scope and nature of personal health information. Clause 4 of the MR defined personal health information as encompassing a variety of documents, case files, reports, and other materials capable of identifying an individual’s health status. Clause 11 offered an exhaustive list of items considered personal health information, such as:

  1. Health History: Such as height, weight, blood type, and body shape.
    1. Medical Records: Such as nursing records, laboratory examinations, and x-ray films.
    1. Related Documents: Any documents or objects that relate to the above data.
    1. Photographic Evidence: Images of medical personnel or actions during treatment.
    1. Additional Information: Any further information as specified by the Personal Health Data Protection and Management Committee.
  2. Penalties for Non-Compliance:

Before the PDPA’s enactment, violations regarding the unlawful or unauthorized disclosure of personal health information were met with penalties prescribed under the NHA. Under Section 49 of the National Health Act, such violations could result in imprisonment of up to six months, fines of up to 10,000 THB, or both. Moreover, wrongful use of personal data was addressed under Section 420 of the Civil and Commercial Code, which provided for civil liability in cases where data misuse resulted in harm to the data subject.

  • Transition to the PDPA:

In 2019, the PDPA was published in the Royal Gazette, marking a significant shift in Thailand’s data protection landscape. With its comprehensive framework, the PDPA rendered the earlier MR obsolete. The Medical Council of Thailand subsequently issued a new Ministerial Regulation on the Revocation of the MR B.E. 2565 (2022). This evolution represents Thailand’s commitment to aligning its data protection standards with international best practices.


III. What Is Health Information?

As a result of the MR revocation, Thailand no longer has a statutory definition of health information, which is crucial in terms of personal data protection and compliance with obligations under the PDPA. Telemedicine platforms need to understand the personal data in their possession and handle such data according to the PDPA.

In the absence of subordinate regulations, directives, or guidelines to clarify the extent and scope of health information under the PDPA, it is worth exploring the definition given under the European Union General Data Protection Regulations (2016/679) (“EU GDPR”), which was a core foundation of the Thai PDPA, containing many similar provisions tailored to Thailand’s contexts.

Article 4 (15) of the EU GDPR defines ‘data concerning health’ as personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status. Additionally, the European Parliament and the Council of the European Union opined that ‘personal data concerning health’ should include all data pertaining to the health status of a data subject, including information collected during registration or provision of health care services, testing results, disease history, clinical treatments, or physiological states.

By this principle, personal data that may not obviously qualify as health information could still be considered health information depending on the context of personal data processing activities.


IV. Overview of PDPA Compliance for Telemedicine Platforms:

The PDPA extends its reach not only to local businesses but also to international data controllers who process the personal data of Thai residents. This extraterritorial effect means that even telemedicine platforms headquartered outside Thailand must comply with the PDPA if they process the personal data of individuals located in the country.

  1. Extraterritorial Applicability:

According to Section 5, Paragraph 2 of the PDPA, foreign data controllers are subject to the PDPA if any of the following criteria are met:

  1. The offering of goods or services to the data subjects who are in the Kingdom of Thailand, irrespective of whether the payment is made by the data subject, or
    1. The monitoring of the data subject’s behavior, where the behavior takes place in the Kingdom of Thailand.
  • Obligations for Telemedicine Providers:

Once the PDPA applies, telemedicine providers (whether local or international) must adhere to various obligations under the PDPA, some of which include:

  1. Data Collection and Processing: Ensure that personal data is collected, used, and disclosed with legal bases supporting each processing activity.
    1. Privacy Notices: Clearly communicate to data subjects how their personal data will be used.
    1. Security Measures: Implement appropriate technical and organizational measures to safeguard personal data.
    1. Data Subject Rights: Provide mechanisms for data subjects to exercise their rights (e.g., access, correction, deletion).
    1. Breach Notification: Establish procedures to notify both the regulatory authority and affected data subjects in the event of a data breach.
    1. Record-Keeping: Maintain a Record of Processing Activities (ROPA) to document data processing practices.

V. Privacy Notice / Privacy Policy Under the PDPA:

One of the foundational requirements under the PDPA is the preparation and dissemination of a comprehensive privacy notice or privacy policy. This document serves to inform data subjects about how their personal data is collected, processed, stored, and shared.

  1. Content of Privacy Policy:

Under Section 23 of the PDPA, data controllers must notify data subjects of the purposes of data collection prior to or at the time of collection. Common practices include written notices, electronic pop-ups on websites or applications, or verbal communications as applicable.

  • Best Practices for Drafting a Privacy Policy:

For telemedicine platforms, drafting a privacy policy involves a deep understanding of the personal data flows within the organization. Understanding the customer journey is vital for telemedicine platforms in preparing the privacy policy, as each touchpoint involves the collection and processing of personal data.

  1. Sign-Up / Registration:

During the initial sign-up process, users are generally required to provide basic personal data such as their name, age, contact details, and, in some cases, initial health information, such as their height, weight, medical history, passport or national identification card, contact information, and information relating to personal allergies. This stage sets the foundation for subsequent interactions and must be handled with the highest level of security and clarity regarding data usage.

  • Know Your Customer (KYC) and Confirming the Identity of the Data Subject: To ensure compliance with Thailand’s PDPA and safeguard sensitive personal data, telemedicine platforms must implement robust KYC procedures during the sign-up phase. These procedures are designed to verify the identity of the data subject and establish trust between the platform and its users.
  • Verification of Identity: Platforms should require users to provide a valid
    • identification documents, such as a national ID card, passport, or other government-issued IDs, to confirm their identity.
    • The verification process may involve uploading scanned copies of these documents or using digital identity verification tools that comply with Thai legal standards.
  • Biometric Verification (Optional):

For enhanced security, telemedicine platforms may opt to incorporate biometric verification methods, such as facial recognition or fingerprint scanning, where applicable and permitted by law.

  • Data Matching:

Once the user submits their identification details, the platform should cross-check this information against official databases (e.g., government records) to ensure accuracy and prevent fraud.

  • Explicit Consent:

During the registration process, explicit consent must be obtained from the user for the collection, use, and disclosure of both general personal data and sensitive personal data. This includes clear explanations of how their data will be processed, stored, and shared.

If the user is under 20 years of age, additional consent from their legal representative, guardian, or curator may be required under Section 20 of the PDPA.

  • Booking / Appointment Scheduling:

Once registered, users schedule appointments with healthcare providers. The booking process may involve selecting a healthcare professional based on specialty, availability, or patient reviews. Additional forms might be used to capture medical history or current health conditions.

  • Consultation:

Consultations are the core of telemedicine services. Whether conducted via video calls, chat sessions, or telephone, these interactions involve real-time exchange of sensitive health information. Data from these sessions may include verbal communications, visual data, and records of diagnosis and treatment.

  1. Post-Consultation Services:

After the consultation, several processes may occur:

  • Payments: Patients make payments through integrated or third-party payment gateways. This process generally involves third-party service providers.
  • Insurance Claims: In some cases, patients may file insurance claims. Telemedicine platforms might assist in this process by forwarding relevant health information to insurers.
  • Medicine Delivery: If medication is prescribed, delivery logistics come into play. This may involve sharing personal data (such as address and contact information) with third-party courier services.
  • Follow-up Appointments: Follow-up consultations or treatment plans may be scheduled, requiring further data collection.
  • Feedback and Reviews: Post-consultation feedback is often solicited to improve service quality. While this may involve general data, any health-related feedback is treated with heightened sensitivity

n)


VI. Legal Bases for Each Activity:

Different stages of the customer journey require distinct legal bases under the PDPA. For example:

ActivityGeneral Personal DataSensitive Personal Data
Sign-up / RegistrationNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Booking / AppointmentNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
ConsultationNecessary to enter into / Performance of a contract
(Section 24 (3))
Necessary for compliance with a law with respect to the provision of health or social care / Explicit Consent (Section 26 (5)(a) / Section 26)
Payment and BillingNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Insurance ClaimsLegitimate interest
(Section 24 (5))
Explicit Consent
(Section 26)
Medicine DeliveryNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Feedback / ReviewsLegitimate interest
(Section 24 (5))
Explicit Consent
(Section 26)

Important Remark: Please note that the table above shall only be used as a reference. The actual legal basis for each activity may differ based on the specific facts and circumstances.


VII. Processing Personal Data of Minors, Quasi-Incompetent Persons, or Incompetent Persons:

Where a patient is under 20 years of age or is a quasi-incompetent person or incompetent person, Section 20 of the PDPA requires their consent to be accompanied by consent from their respective legal representatives, guardians, or curators. However, if the patient is under 10 years of age, sole consent from the legal representative is sufficient.

Section 24 of the Thai Civil and Commercial Code provides an exemption for acts deemed suitable for a minor’s reasonable needs. Therefore, a minor (between 10 and 20 years of age) may give sole consent for telemedicine consultation purposes, as it deems suitable and actually required for their reasonable needs.


VIII. Data Subject Rights and Request Compliance Under the PDPA:

The PDPA enshrines several rights for data subjects. Telemedicine platforms must have robust processes to facilitate these rights.

A. Overview of Data Subject Rights:

The PDPA grants data subjects the following rights:

  1. Right to Access: Data subjects may request copies of their personal data.
  2. Right to Data Portability: Individuals can obtain their personal data in a structured, commonly used format.
  3. Right to Object: Data subjects may object to certain personal data processing activities.
  4. Right to Delete: Also known as the “right to be forgotten,” this allows data subjects to request deletion or anonymization of their personal data.
  5. Right to Restrict Processing: In certain circumstances, processing may be limited or suspended.
  6. Right to Rectification: Data subjects can have inaccurate or incomplete personal data corrected.
  7. Right to Lodge a Complaint: Data subjects can lodge complaints with regulatory authorities.
  8. Right to Withdraw Consent: Where processing is based on consent, data subjects may withdraw that consent at any time.

B. Procedures for Data Subject Rights Requests (DSRR):

Upon receiving a data subject request, telemedicine platforms should follow a set of protocols:

  1. Verification: Confirm the identity of the data subject or their representative.
  • Clarification: Request additional information if the request is ambiguous.
  • Documentation: Record all details of the request.
  • Data Retrieval: Locate and compile the relevant data.
  • Review for Exemptions: Determine if any exemptions apply.
  • Response: Communicate a clear response—either fulfilling the request, rejecting it, or outlining why an exception applies.
  • Record-Keeping: Maintain records of the requests and responses for regulatory audits.

IX. Record of Processing Activities (ROPA):

Maintaining a detailed ROPA is a regulatory requirement under Section 39 of the PDPA.

A comprehensive ROPA should include,

  1. the collected personal data;
    1. the purpose of the collection of personal data in each category;
    1. details of the data controller;
    1. the retention period of personal data;
    1. rights and methods for accessing personal data, including conditions for exercising these rights;
    1. the use or disclosure of personal data;
    1. rejection or objection to the data subject’s rights request; and
    1. explanation of the appropriate security measures.

However, SMEs may be exempt from maintaining a full ROPA if they employ fewer than 100 people and have an annual revenue of no more than 300,000,000 THB. Nevertheless, telemedicine platforms handling sensitive personal data must maintain a full ROPA due to the risks involved.


X. Appropriate Security Measures for Telemedicine Platforms:

Prescribed under Section 37 (1) of the PDPA, where a data controller is required to provide appropriate security measures to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data. In this regard, the appropriate security measures for the telemedicine platforms shall focus on the maintenance of personal data’s confidentiality, integrity, and availability.

According to the PDPC’s Announcement on Security Measures for Personal Data,  the security measures should contain at least the following mechanism: (1) access controls, allowing access to personal data only on a need-to-know basis provided that there shall also be an identity proofing, authentication, and authorization procedure; (2) user access management including registration and de-registration of access provision; (3) user responsibilities shall be prescribed; (4) implement an audit trail to enable the reviewing of access, change, alteration, or deletion of personal data.

The duty to implement appropriate security measures shall be extended to the imposition of obligations on the data processor of the telemedicine platforms (such as medicine delivery service providers), to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data.


XI. Personal Data Breach and Breach Notification Procedures:

Despite security measures, data breaches can occur. The PDPA requires prompt action in response to breaches.

A. Definition:

A personal data breach is defined as a breach of security measures resulting in the loss, access, use, alteration, modification, or disclosure of personal data without authorization or unlawfully.

B. Procedures:

Assess the reliability of the breach report and investigate the facts.

Notify the PDPC within 72 hours if the breach affects the rights and freedoms of data subjects.

Notify affected data subjects without delay if the breach poses a high risk.

Mitigate the situation and review security measures to prevent future breaches.


XII. Processing of Sensitive Personal Data by Data Processors:

Throughout the customer journey, a data processor may be involved in processes such as medicine delivery. A data controller must prepare a Data Processing Agreement (DPA) to control the activities of the data processor. Key provisions of a DPA include:

Restriction on use or disclosure of personal data.

Implementation of appropriate security measures.

Recording of personal data processing activities.

Notification of personal data breaches.


XIII. Designating a Representative and a Data Protection Officer (DPO) in Thailand:

A. Designating a Representative for Foreign Providers:

Foreign telemedicine providers offering services to Thai residents must designate a representative in Thailand under Section 5, Paragraph 2 of the PDPA.

B. Appointment of a Data Protection Officer (DPO):

Telemedicine platforms are obligated to designate a DPO if their core activities involve processing sensitive personal data. External or outsourced DPOs may be appointed for SMEs.


XIV. Use of Sensitive Personal Data (Health Information) for Telemarketing Purposes:

Sensitive personal data cannot be used for marketing purposes without explicit consent. Instead, telemedicine platforms may rely on general personal data (e.g., email addresses) for mass communications, provided an opt-out mechanism is available.


XV. Frequently Asked Questions (FAQs)

Q1: Does Weight and Height Qualify as Health Information?

Weight and height information may qualify as either general personal data or sensitive personal data, depending on the context. For example, in telemedicine services, weight and height may play a vital role in medical analysis and thus could be considered sensitive personal data.

Q2: Can a Patient Request Deletion of Their Health Information?

Patients have the right to request deletion of their personal data under certain conditions. However, telemedicine platforms are required to retain medical records for at least 5 years in accordance with the National Health Act.


XVI. Conclusion

As telemedicine continues to revolutionize the healthcare industry, ensuring robust compliance with data protection laws like the PDPA is critical. Health information, being sensitive personal data, demands the highest level of security and compliance to protect patient privacy and maintain trust in digital healthcare services.

For telemedicine platforms operating in Thailand, navigating the interplay between local regulations and international frameworks necessitates a meticulous approach to data processing. Failure to comply can lead to reputational damage, regulatory penalties, and legal liabilities. By adopting best practices such as transparent privacy policies, strong security measures, and compliance with data subject rights, telemedicine providers can create a safe and legally compliant environment.

In conclusion, the landscape of health information regulation is complex and continuously evolving. Telemedicine platform providers must proactively update their policies and compliance strategies to align with changing regulations, ensuring that patient rights remain protected while fostering innovation in digital healthcare solutions. By doing so, they can contribute to a more secure, efficient, and globally compliant telemedicine ecosystem.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Integrating Cybersecurity, Fraud Response, and PDPA Compliance: Practical Implications of the Proposed Digital Channel Security Framework

The Bank of Thailand (BOT) has released a proposed Digital Channel Security framework that would strengthen expectations for authentication, fraud prevention, incident response, and the governance of digital financial services. While the proposal focuses primarily on enhancing the security and resilience of digital channels, financial institutions should not view these requirements in isolation.

In practice, a single cybersecurity incident frequently triggers multiple legal and regulatory obligations simultaneously. For example, an account takeover resulting from a phishing attack may require an institution to activate its cybersecurity incident response procedures, implement fraud mitigation measures, assess whether a personal data breach has occurred under the Personal Data Protection Act (PDPA), evaluate outsourcing or third-party service provider involvement, and make appropriate internal and regulatory notifications.

Although these obligations arise from different legal and regulatory sources, organizations may benefit from managing them through a coordinated incident response framework. This article examines the practical implications of the proposed BOT framework alongside existing obligations under the PDPA and broader operational governance practices.

From cybersecurity to operational resilience:

The proposed framework reflects an increasing regulatory emphasis on operational resilience rather than viewing cybersecurity solely as an information technology function. It places greater focus on preventing, detecting, responding to, and recovering from threats affecting digital financial services while maintaining the continuity and integrity of critical operations.

At the same time, financial institutions should recognize that cybersecurity incidents rarely occur in isolation. A single event may involve operational disruption, attempted fraud, compromise of customer credentials, unauthorized disclosure of personal data, and third-party service providers. As a practical matter, organizations may therefore benefit from adopting governance arrangements capable of addressing these interconnected risks through a unified response process.

Governance beyond information technology:

The proposed framework emphasizes that responsibility for digital channel security extends beyond information security teams.

Boards of directors and senior management are expected to establish appropriate governance, oversee digital risks, allocate adequate resources, monitor security performance, and ensure that significant incidents are escalated appropriately.

From a broader governance perspective, institutions should also consider ensuring that legal, compliance, privacy, operational risk, business continuity, and customer service functions are integrated into incident management processes. This cross-functional approach can help organizations address multiple regulatory obligations efficiently when significant incidents occur.

Fraud prevention as part of digital channel security:

The BOT proposal places significant emphasis on fraud prevention through enhanced digital channel security. Proposed measures include stronger customer authentication, monitoring of suspicious activities, behavioral analysis, device identification, protection against phishing and social engineering attacks, and mechanisms for responding to suspicious transactions.

These expectations primarily seek to reduce fraud risks affecting digital financial services. However, successful fraud attacks frequently have wider legal implications. Unauthorized access to customer accounts may also involve compromised personal data, contractual issues with service providers, customer remediation, and regulatory reporting obligations. Institutions should therefore consider integrating fraud response procedures into broader cybersecurity governance rather than treating fraud management as a separate operational function.

Incident response across multiple regulatory frameworks:

The proposed framework expects institutions to establish formal incident response procedures covering detection, escalation, containment, investigation, recovery, and post-incident review.

In practice, these procedures should also enable organizations to identify other legal and regulatory obligations that may arise from the same incident. Depending on the circumstances, an incident may require parallel consideration of fraud management, operational resilience measures, contractual obligations, outsourcing arrangements, and personal data protection requirements.

Developing coordinated response procedures may help reduce duplication of effort, improve decision-making, and ensure that regulatory obligations are addressed consistently across different functions.

Interaction with the Personal Data Protection Act:

The proposed BOT framework does not replace or modify existing obligations under the PDPA. Rather, the two regimes operate alongside one another.

Where a cybersecurity incident involves unauthorized access to, disclosure of, alteration of, or loss of personal data, organizations should assess their obligations under the PDPA independently of the BOT framework. This may include determining whether a personal data breach has occurred, evaluating notification obligations, preserving relevant evidence, documenting response measures, and implementing appropriate remediation.

Accordingly, organizations may wish to ensure that privacy officers, legal counsel, and cybersecurity teams participate jointly in incident response planning and tabletop exercises so that both operational and data protection considerations are addressed from the outset.

Third-party risk management:

Digital financial services increasingly depend on cloud service providers, payment processors, managed service providers, software vendors, and other external partners.

The proposed framework reinforces expectations regarding oversight of third-party service providers throughout the outsourcing lifecycle. Institutions should conduct appropriate due diligence, establish contractual security requirements, monitor vendor performance, and ensure that incident reporting and business continuity arrangements are clearly defined.

Because cybersecurity incidents involving third parties may also raise fraud and personal data protection issues, organizations should consider aligning vendor management processes with their broader incident response and compliance frameworks.

Documentation and evidence of compliance:

The proposed framework places considerable emphasis on governance, accountability, and demonstrating that appropriate controls are in place.

Organizations should maintain comprehensive records of cybersecurity governance, risk assessments, incident response activities, testing, training, vendor oversight, and business continuity exercises. From a broader compliance perspective, documentation should also support obligations arising under other applicable legal frameworks, including the PDPA and contractual commitments relating to outsourced services.

Maintaining complete records may facilitate regulatory engagement, internal investigations, and post-incident reviews while demonstrating that reasonable organizational and technical measures have been implemented.

Practical considerations:

As organizations prepare for the proposed framework, they may wish to assess not only technical cybersecurity controls but also how different compliance functions interact during a significant incident.

Areas for review may include:

  • governance and board oversight;
  • coordination among cybersecurity, legal, compliance, privacy, and operational teams;
  • fraud detection and response procedures;
  • customer authentication controls;
  • third-party risk management;
  • incident reporting and escalation processes;
  • documentation and recordkeeping; and
  • operational resilience testing and tabletop exercises.

An integrated approach may improve organizational readiness while reducing the risk that separate regulatory obligations are managed through disconnected processes.

Key takeaways:

  • The proposed BOT Digital Channel Security framework primarily addresses digital channel security, fraud prevention, governance, and operational resilience.
  • Existing obligations under the PDPA continue to apply independently where cybersecurity incidents involve personal data.
  • A single cyber incident may simultaneously trigger cybersecurity, fraud management, personal data protection, outsourcing, and operational governance obligations.
  • Although these obligations arise under different legal and regulatory frameworks, organizations may benefit from managing them through an integrated incident response framework.
  • Financial institutions should consider reviewing governance structures, cross-functional coordination, and documentation practices to improve operational resilience and regulatory compliance.

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

Billing Software Requirements vs. Electronic Invoicing Requirements

Executive Summary:

As governments continue to digitalize tax administration, businesses are increasingly expected to adopt electronic invoicing solutions that comply with evolving regulatory requirements. Although the terms billing software and electronic invoicing are often used interchangeably, they represent distinct concepts that serve different commercial and legal functions.

In Thailand, billing software is not subject to a dedicated statutory or regulatory framework. Businesses are generally free to select accounting, billing, or enterprise resource planning (ERP) systems that best support their commercial operations, provided they comply with the Revenue Code and other applicable laws. Electronic invoicing, by contrast, is governed by the Revenue Department’s e-Tax Invoice & e-Receipt framework, which establishes the legal and technical requirements for issuing electronic tax invoices recognized for VAT purposes.

Understanding the distinction between these concepts is important for businesses implementing digital invoicing solutions. A billing system that efficiently generates commercial invoices does not necessarily satisfy the legal requirements for issuing electronic tax invoices. Businesses should therefore evaluate their invoicing systems not only from an operational perspective but also from a tax compliance standpoint.

Introduction:

Digital transformation has fundamentally changed the way businesses prepare invoices, maintain accounting records, and comply with tax obligations. Around the world, tax authorities have introduced electronic invoicing regimes to improve tax compliance, enhance transparency, and reduce administrative burdens for both taxpayers and regulators.

Although electronic invoicing has become an increasingly common feature of modern tax systems, countries have adopted different regulatory approaches. Some jurisdictions regulate the software used to generate invoices, while others focus on the legal validity and technical characteristics of the electronic tax documents themselves.

Thailand follows the latter approach. Rather than regulating billing software as a separate category of software, Thai law establishes a framework governing the issuance of electronic tax invoices through the Revenue Department’s e-Tax Invoice & e-Receipt system. Consequently, businesses remain free to use their preferred accounting or ERP software, provided that the electronic tax documents generated by those systems comply with the applicable legal and technical requirements.

For businesses operating in Thailand, particularly multinational enterprises implementing global ERP platforms, understanding the distinction between billing software and electronic invoicing is essential. While both are integral components of modern financial management, they perform different functions and are subject to different legal considerations.

Billing Software:

Billing software generally refers to applications used by businesses to prepare invoices, calculate taxes, record payments, manage customer accounts, and maintain accounting records. These functions support day-to-day commercial operations and are commonly integrated into accounting software or ERP systems.

Unlike some jurisdictions that regulate invoicing software, Thailand does not currently impose a dedicated legal or regulatory regime governing billing software itself. There is no statutory requirement for billing software to be licensed, certified, or approved by the Revenue Department before it can be used by businesses. Instead, Thai law focuses on the legal sufficiency of the invoices and accounting records generated by the software.

This does not mean that businesses have complete discretion in how billing systems are used. Regardless of the software selected, businesses remain responsible for ensuring that invoices comply with the Revenue Code, VAT is correctly calculated where applicable, accounting records are properly maintained, and supporting documentation is available for inspection by the tax authorities.

Accordingly, compliance under Thai law depends not on the software itself, but on whether the business uses that software in a manner that satisfies its statutory obligations. A business may therefore choose from a wide range of commercial accounting platforms, cloud-based invoicing applications, or ERP systems without obtaining prior approval from the Revenue Department.

Electronic Invoicing:

Electronic invoicing serves a different purpose. Rather than facilitating internal billing processes, it establishes the legal framework under which electronic tax invoices are recognized for VAT purposes.

Thailand’s electronic invoicing regime is principally governed by the Revenue Code, supplemented by the Electronic Transactions Act, Ministerial Regulation No. 384, and Revenue Department notifications prescribing the technical standards for electronic tax documents. Collectively, these instruments enable tax invoices and receipts to be created, transmitted, and retained electronically while ensuring their authenticity, integrity, and reliability.

Businesses wishing to issue electronic tax invoices under the Revenue Department’s e-Tax Invoice & e-Receipt framework must comply with prescribed legal and technical requirements. These include registration with the Revenue Department, generation of electronic tax documents in the prescribed format, use of appropriate electronic authentication mechanisms, transmission through approved channels where applicable, and maintenance of electronic records in accordance with the Revenue Department’s requirements.

An important characteristic of the Thai framework is that it regulates the electronic tax document rather than the accounting software used to produce it. Consequently, businesses may continue using their existing accounting or ERP systems, provided those systems are capable of generating electronic tax invoices that comply with the Revenue Department’s technical specifications. In practice, many businesses achieve this through system localization or integration with specialized e-Tax solutions or authorized service providers.

Thailand currently provides two principal electronic invoicing models. The e-Tax Invoice & e-Receipt system is designed for businesses requiring full electronic integration, while the e-Tax Invoice by Email system provides a simplified alternative for eligible businesses. Although both systems enable businesses to issue legally recognized electronic tax invoices, they differ in their technical implementation and authentication methods.

Key Takeaways:

  • Thailand does not regulate billing software as a separate legal category or require billing software to be certified or approved by the Revenue Department.
  • The Revenue Department’s e-Tax Invoice & e-Receipt framework governs the issuance of legally recognized electronic tax invoices and establishes the applicable technical and procedural requirements.
  • A commercial invoice generated by billing software does not automatically constitute an electronic tax invoice for VAT purposes.
  • Businesses implementing accounting or ERP systems should evaluate both operational functionality and compliance with Thailand’s e-Tax requirements.
  • Early coordination among finance, tax, legal, and information technology functions can help ensure a successful implementation of electronic invoicing while supporting long-term digital tax compliance.

Source: International Comparison July 2026: Global Legal Market Analysis

Read Full Article

Consumer Enforcement Intensifies for EV Businesses as Complaint Cases Rise and Labeling Expectations Increase

Thailand’s consumer protection regulator has signaled a more assertive enforcement approach toward the electric vehicle (EV) sector through two related developments. First, it has indicated its readiness to initiate legal proceedings on behalf of consumers in appropriate EV dispute cases. Second, it has issued new guidance consolidating labeling requirements for automobiles, electric vehicles, and used cars.

Although neither development introduces new legislation, together they demonstrate heightened regulatory scrutiny of the automotive industry and provide valuable insight into the regulator’s current enforcement priorities. Manufacturers, importers, distributors, dealers, service centers, and online vehicle marketplaces should treat these developments as an opportunity to reassess their compliance and dispute management frameworks.

Increased Enforcement Risk from EV Consumer Complaints:

The Office of the Consumer Protection Board (OCPB) has reported a significant number of consumer complaints relating to electric vehicles, with a substantial portion already progressing through legal procedures. The agency has confirmed that it has begun issuing formal demand letters in cases supported by sufficient documentation and has reiterated its statutory authority to commence legal proceedings on behalf of consumers where the legal requirements are satisfied.

This represents an important enforcement signal. Rather than merely facilitating mediation between consumers and businesses, the regulator has indicated its willingness to escalate suitable cases into formal litigation.

The risk is particularly significant where multiple complaints arise from the same product model, manufacturing issue, software defect, battery performance concern, warranty practice, or recurring after-sales service problem. A pattern of similar complaints may increase regulatory attention and expose businesses to coordinated enforcement actions, representative litigation, or broader product liability claims.

Businesses operating within the EV supply chain should therefore review whether existing complaint-handling mechanisms are capable of identifying systemic issues before they evolve into regulatory investigations or court proceedings.

Strengthened Expectations for Vehicle Label Compliance:

Separately, the OCPB has published an electronic handbook consolidating labeling requirements applicable to automobiles, electric vehicles, and used vehicles.

The publication emphasizes information that consumers commonly rely upon when making purchasing decisions, including battery specifications, driving range, testing standards, pricing information, warranty coverage, and the disclosure of material vehicle history for used vehicles.

Although the handbook itself is not legally binding, it provides a clear indication of the regulator’s compliance expectations. It reinforces that automobiles and electric vehicles remain controlled labeling products under consumer protection law and that incomplete, inaccurate, or misleading information may expose businesses to regulatory enforcement.

The guidance also illustrates that compliance extends beyond physical labels. Regulators are increasingly likely to examine whether information presented across all customer-facing channels remains accurate and consistent.

Businesses should therefore review:

  • labels displayed at dealerships and points of sale;
  • information published on corporate websites and online marketplaces;
  • brochures and sales presentations used by sales personnel;
  • representations concerning driving range and the testing methodology used, such as WLTP or NEDC;
  • battery capacity, expected degradation, warranty scope, and warranty exclusions;
  • disclosures relating to collision history, flood damage, major repairs, and battery replacement for used vehicles; and
  • consistency between information published by manufacturers, importers, dealers, and affiliated sales channels.

Claims relating to vehicle performance, battery longevity, operating costs, sustainability, resale value, or environmental benefits should be supported by appropriate technical evidence and internal documentation before publication.

Litigation Readiness and Document Preservation:

These developments also highlight the importance of litigation preparedness.

Businesses should consider establishing a centralized process for collecting and analyzing customer complaints to determine whether recurring issues indicate broader product or service risks.

At the same time, organizations should preserve relevant evidence, including:

  • sales documentation;
  • warranty records;
  • repair histories;
  • technical diagnostic reports;
  • replacement part records;
  • communications with customers;
  • call center recordings;
  • email correspondence;
  • mobile application records; and
  • connected vehicle diagnostic data.

Where disputes may reasonably be anticipated, organizations should consider implementing litigation hold procedures to reduce the risk of inadvertent deletion of potentially relevant evidence.

Companies should also review contractual risk allocation among overseas manufacturers, importers, dealers, distributors, and service centers, including indemnity provisions and responsibilities for handling product defects, recalls, warranty claims, and consumer litigation.

Data Protection Considerations:

Responding to consumer complaints frequently requires the collection and sharing of customer information, vehicle service histories, location information, and connected vehicle diagnostic data. Much of this information may constitute personal data under the Personal Data Protection Act.

Organizations should ensure that internal investigations and litigation response procedures incorporate appropriate data governance measures, including clearly defined access controls, documented processing purposes, retention periods, and secure mechanisms for sharing information with external counsel, technical experts, and other authorized parties.

Integrating consumer protection compliance with data governance can reduce both regulatory and litigation risks while supporting more effective dispute management.

Key Takeaways:

  • Organizations should strengthen complaint management, evidence preservation, document retention, contractual risk allocation, and data governance processes to prepare for increased regulatory scrutiny and potential consumer litigation.
  • The OCPB’s indication that it is prepared to commence litigation on behalf of consumers represents a significant escalation in consumer protection enforcement affecting the EV industry.
  • Businesses should not view repeated consumer complaints as isolated customer service matters but as potential regulatory and litigation risks requiring centralized oversight.
  • The newly published vehicle labeling handbook, although not legally binding, demonstrates higher regulatory expectations regarding the accuracy, completeness, and consistency of vehicle-related information across all sales channels.
  • Automotive businesses should review advertising claims, warranty disclosures, battery-related representations, and used vehicle disclosures to ensure they are fully substantiated.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Revises Visa Exemption Scheme: Shorter Stay Periods and a New Country-Based Category System

Introduction

On 14 July 2026, the Thai Cabinet approved a revision of Thailand’s visa exemption scheme. Under the revised framework, the current uniform 60-day visa exemption will be abolished and replaced with a country-based system that classifies eligible countries according to Thailand’s diplomatic relations and immigration risk assessment. Depending on the category assigned, eligible foreign nationals will be permitted to enter Thailand visa-free for stays of up to 30 or 15 days, or will remain eligible for a Visa on Arrival.

Background

In 2024, Thailand introduced a 60-day visa exemption for nationals of 93 countries and territories to stimulate tourism and support the country’s economic recovery following the COVID-19 pandemic. Since implementation, however, the government has identified several concerns associated with the scheme, including visa runs, illegal employment, nominee business arrangements, transnational crime, and visa overstays. In response, the government resolved to review and revise the existing visa exemption policy.

Key Changes

1. Introduction of a Tiered Visa Exemption Framework

30-Day Visa Exemption (59 Countries and Territories)

Nationals of 59 countries and territories will be eligible for visa-free entry for tourism purposes for stays of up to 30 days. The revised scheme extends this 30-day entitlement to six countries that were not previously covered:

  • India
  • Croatia
  • Bulgaria
  • Cyprus
  • Malta
  • Maldives

With these additions, all 27 European Union Member States will receive the same 30-day visa exemption entitlement, promoting greater consistency across Thailand’s visa policy. The government expects this measure to strengthen diplomatic relations, support future discussions on Schengen visa exemptions for Thai nationals, and facilitate continued economic and trade cooperation with partner countries.

15-Day Visa Exemption (2 Countries)                                                                                                                                                                            

Nationals of Mauritius and Seychelles will be eligible for visa-free entry for stays of up to 15 days. The government intends to periodically review this entitlement based on tourism statistics and visitor spending patterns.

Visa on Arrival (3 Countries)

Nationals of the following three countries will remain eligible to obtain a Visa on Arrival at Thailand’s immigration checkpoints:

  • Azerbaijan
  • Belarus
  • Serbia

2. Implementation of the “One Country, One Entitlement” Policy

Under the revised framework, each country will be eligible for only one immigration privilege, and overlapping schemes will be eliminated. For example, India will no longer be eligible for a Visa on Arrival, as it has instead been granted 30-day visa exemption status.

3. Enhanced Border Screening

The government will strengthen the Thailand Digital Arrival Card (TDAC) system by integrating it with relevant government databases, improving immigration risk assessment, border screening, and monitoring of visa exemption usage.

The Cabinet resolution provides for a revised visa framework covering a reported total of 65 countries and territories across the categories described above. The complete list of eligible countries and territories in each category has not yet been officially published; further detail is expected in forthcoming Ministry of Interior notifications and related subordinate legislation.

Effective Date

The revised measures have not yet entered into force. They will take effect 15 days after the relevant Ministry of Interior notifications are published in the Royal Gazette. Until that time, the existing immigration rules remain in effect, and foreign nationals who enter Thailand before the change takes effect will be permitted to remain for the duration of their existing permitted stay.

Key Takeaways

  • The revised measures are pending implementation and will take effect 15 days after publication in the Royal Gazette.
  • Thailand will replace its uniform 60-day visa exemption scheme with a tiered, country-based system.
  • The revised scheme aims to balance tourism promotion and ease of international travel against the prevention of visa abuse and the strengthening of immigration control and national security.
  • Eligible countries will receive 30-day or 15-day visa-free entry, while three countries retain Visa on Arrival status; overlapping privileges are removed under the “one country, one entitlement” policy.
  • The TDAC system will be enhanced to strengthen immigration screening and monitoring.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand signals a shift toward expenditure-based management of universal healthcare

Thailand’s universal healthcare system has long been regarded as one of the country’s most successful public policy achievements. However, increasing healthcare utilization, an aging population, rising treatment costs, and fiscal constraints are prompting policymakers to reconsider how the system should be financed over the long term.

Recent policy discussions within the Ministry of Public Health indicate that the focus is no longer solely on expanding healthcare benefits. Instead, the government appears to be moving toward a framework that emphasizes expenditure management, efficiency, and value-based healthcare while maintaining universal access to essential medical services.

Shift from expanding benefits to managing sustainability:

Thailand’s public healthcare system is primarily delivered through three government-funded schemes:

  • the Universal Coverage Scheme (UCS);
  • the Social Security Scheme (SSS); and
  • the Civil Servant Medical Benefit Scheme (CSMBS).

Although annual government appropriations for these schemes have continued to increase, healthcare expenditure has grown at an even faster pace due to demographic changes, increasing prevalence of chronic diseases, advances in medical technology, and greater public expectations regarding access to treatment. Policymakers have therefore expressed concern that healthcare expenditure may outpace long-term fiscal capacity unless structural reforms are implemented.

Proposed expenditure management measures:

Current policy discussions suggest that future reforms may include greater reliance on expenditure controls rather than across-the-board budget increases.

Measures under consideration reportedly include:

  • expenditure ceilings for public hospitals;
  • tighter monitoring of hospital operating costs, pharmaceuticals, and medical supplies;
  • wider use of digital technologies and data analytics to improve financial oversight;
  • periodic review of healthcare benefit packages to prioritize clinically effective and cost-effective services; and
  • broader adoption of value-based healthcare models that reward providers based on patient outcomes rather than service volume.

These initiatives reflect an effort to improve efficiency without fundamentally changing the principle of universal healthcare coverage.

Potential implications for healthcare providers:

Public hospitals may face increasing pressure to operate within fixed budgetary allocations while maintaining service quality. More sophisticated financial management, procurement practices, and clinical governance are therefore likely to become increasingly important.

Healthcare providers may also experience:

  • greater scrutiny of prescribing practices;
  • stronger emphasis on evidence-based treatment pathways;
  • expanded use of health technology assessment in reimbursement decisions; and
  • increased reporting and compliance obligations relating to cost management.

Private healthcare providers participating in government reimbursement programs may likewise experience closer oversight of reimbursement methodologies and service delivery standards.

Regulatory considerations:

While no legislative amendments have fundamentally altered Thailand’s universal healthcare framework, any future implementation of expenditure caps or revised reimbursement mechanisms will require careful alignment with existing legislation governing public health financing and healthcare entitlements.

Future regulatory developments may include:

  • revised payment methodologies;
  • updated reimbursement criteria;
  • enhanced procurement controls;
  • expanded digital monitoring of healthcare expenditure; and
  • revised administrative guidelines governing public healthcare providers.

Businesses operating in the healthcare, pharmaceutical, medical device, and digital health sectors should therefore continue to monitor policy developments, as changes in reimbursement and procurement practices may influence market access and commercial strategies.

Key takeaways:

  • Thailand is shifting its healthcare policy emphasis from expanding benefits toward improving financial sustainability.
  • Expenditure management and value-based healthcare are emerging as central policy themes.
  • Public hospitals are likely to face tighter budgetary controls and enhanced financial oversight.
  • Healthcare suppliers should anticipate increasing scrutiny of reimbursement, procurement, and cost-effectiveness.
  • Although universal healthcare remains intact, future reforms are expected to focus on preserving the system through more disciplined allocation of healthcare resources rather than unlimited expenditure growth.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

New Apostille Rules Simplify Thailand Working and Retirement Visa Renewal Documents Requirement

The Immigration Bureau has issued Immigration Bureau Order No. 122/2026 (the “Order”), amending certain documentary requirements under Immigration Bureau Order No. 12/2025 for applications for renewal of visa. The Order came into effect on 28 May 2026.

Previously, where certain prescribed documents were unavailable, applicants were generally required to authenticate them through notarization by a notary public, legalization by a Royal Thai Embassy or Royal Thai Consulate-General, and super-legalization by Thailand’s Ministry of Foreign Affairs. The new Order introduces Apostille certification as an alternative method of authentication for specified documents.

Key Amendments

The amendments primarily benefit foreign nationals applying for the renewal of Non-Immigrant “B” (Business) and Non-Immigrant “O-A” (Retirement) categories. In particular, the changes are expected to benefit foreign nationals working for foreign companies operating in Thailand through their representative offices, regional offices, and branch offices set up in Thailand requiring renewal of their visa, for which the affidavits or certificates of incorporation relating to those offices are required to be submitted. The amendment also benefits foreign retirees required to submit health insurance documents or evidence of state welfare benefits issued or granted overseas.

Previously, such documents were generally required to be certified by the issuing authority and/or notarized, followed by legalization by a Royal Thai Embassy or Royal Thai Consulate-General and super-legalization by Thailand’s Ministry of Foreign Affairs. The amendment streamlines this process by reducing the number of authentication steps required for eligible documents.

The amendments also address practical difficulties faced by representative offices, regional offices, and branch offices of foreign companies in obtaining certain corporate registration documents. In practice, the Department of Business Development (DBD) may not issue particular certificates in certain circumstances The revised requirements therefore provide greater flexibility where equivalent DBD-issued documents are unavailable.

Conclusion

The Order represents a practical modernization of Thailand’s immigration procedures by introducing Apostille certification as an alternative method of authenticating documents for certain business and retirement-based applications.

Although the amendments do not alter the substantive eligibility requirements of renewal of visa, they simplify documentary compliance, reduce reliance on multiple layers of consular legalization, and offer practical solutions for foreign business entities that may encounter difficulties obtaining certain certifications in Thailand. Overall, the changes are expected to make the immigration process more efficient for both foreign businesses and foreign retirees.

Key Takeaways

The changes reflect Thailand’s continuing movement toward

Apostille certification is now recognized as an alternative to traditional embassy legalization for certain business and retirement-based extension of stay applications.

The amendments simplify document authentication and reduce administrative burdens for eligible applicants.

Foreign nationals working with representative offices, regional offices, and branch offices in Thailand may benefit from greater flexibility where equivalent DBD-issued certifications are unavailable.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles