DIP e-Exchange: A New Framework for Accessing and Using IP Data

The Department of Intellectual Property (DIP) has launched DIP e-Exchange, a new platform designed to enable government agencies and private-sector organizations to connect with and exchange intellectual property (IP) information held by the DIP. The initiative goes beyond providing another online search facility. It establishes an application programming interface (API)-based infrastructure through which eligible organizations can potentially integrate official IP information into their own systems and workflows.

The DIP describes the platform as part of its development of an IP data infrastructure that allows information to be exchanged between organizations in a standardized and secure manner. The new system replaces the DIP’s previous API channel for existing participating organizations and is provided without charge. The DIP also emphasizes compliance with government data governance and information security requirements.

From IP Records to Usable Business Data:

The DIP e-Exchange currently provides APIs covering six categories of IP information: copyright, geographical indications, petty patents, design patents, invention patents, and trademarks. The DIP’s announcement indicates that the information available through the system includes, for example, granted or published patent information, trademark and rights-holder information, and information concerning copyright works and persons who have notified copyright information to the DIP.

This is significant because IP registry information has traditionally been approached primarily as information to be searched when a particular legal or commercial need arises. An API-based infrastructure offers a different model. Instead of requiring a user to conduct an individual search and manually incorporate the results into another process, an authorized organization’s system can potentially retrieve relevant information directly from the DIP and use that information within its own digital workflow.

The DIP has identified a broad range of potential applications. These include verifying the existence of IP rights in public- and private-sector transactions, supporting the development of higher-value products and services through IP, assisting IP valuation for SME financing, facilitating research and analysis, and enabling enforcement authorities to verify IP rights more efficiently.

Implications for IP Transactions and Financing:

The new infrastructure could be particularly relevant to transactions in which the existence, ownership, or status of IP rights needs to be verified. IP information is routinely relevant to mergers and acquisitions, investments, licensing, technology transfers, financing arrangements, enforcement actions, and IP due diligence. Where organizations regularly undertake these activities, direct access to official data may allow some verification processes to be incorporated into existing compliance, transaction, or portfolio-management systems.

The potential application to financing is particularly noteworthy. One practical challenge in IP-based financing is obtaining reliable information concerning the underlying asset. The DIP specifically identifies the use of IP information for IP valuation in connection with financial institutions’ lending to SMEs as one potential application of the platform.  Easier access to authoritative registry information could therefore contribute to the information infrastructure necessary for financial institutions and other stakeholders to assess IP assets.

However, data obtained from the DIP should not be regarded as a substitute for legal due diligence. Registry information is only one component of determining the legal and commercial position of an IP asset. Depending on the transaction, separate investigation may still be required regarding matters such as chain of title, licenses, assignments, security interests, contractual restrictions, pending disputes, actual use of trademarks, unregistered rights, and the validity or enforceability of particular rights. The legal significance of information retrieved through the system must therefore be distinguished from the efficiency with which that information can be obtained.

Information Security and Data Governance:

DIP e-Exchange is intended for legal entities in both the public and private sectors whose activities relate to IP and that maintain appropriate information security arrangements. Organizations seeking access are required to register and submit supporting documentation to the DIP.

The supporting documentation identified by the DIP includes a request for data connectivity, an MOU where applicable, the relevant service application form, and either evidence of ISO/IEC 27001 certification or the organization’s information security policies and practices.  The platform’s technical documentation also indicates that API access operates through an authorization token, illustrating that access is controlled rather than being an unrestricted bulk-data facility.

These requirements highlight an important distinction between making IP information available for individual public searches and permitting systematic access to government data through APIs. Once information can be retrieved and processed at scale, issues of cybersecurity, access control, permitted use, data retention, system integrity, and internal accountability become increasingly important.

Organizations considering connection to DIP e-Exchange should therefore approach implementation as both an IP-data project and a data-governance project. Appropriate internal controls may need to address who is authorized to access the system, the purposes for which information may be retrieved, how retrieved information is stored and incorporated into other databases, and how access and use are monitored.

Toward Interoperable IP Infrastructure:

The broader significance of DIP e-Exchange is the movement from digitization toward interoperability in IP administration.

Digitization allows applicants, rights holders, professionals, and members of the public to interact electronically with the DIP. Interoperability goes a step further: it enables official IP information to become part of the digital processes of other organizations. Instead of government data remaining within a standalone database that must be consulted separately, standardized APIs can potentially allow that data to interact with other systems.

This may create opportunities well beyond conventional IP searches. Businesses and service providers could potentially incorporate official IP information into portfolio-management and transaction systems; financial institutions could use relevant data as part of IP valuation and financing processes; researchers could conduct more systematic analysis; and enforcement agencies could verify rights more efficiently. The DIP itself has characterized IP information as capable of supporting public services, policy analysis, and the development of future digital services.

The practical value of DIP e-Exchange will ultimately depend on matters such as the scope and quality of the available data, the frequency with which it is updated, the conditions governing access and use, and the extent to which organizations integrate the APIs into their operational systems. Nevertheless, the platform represents an important change in how official IP information can be accessed and potentially used.

For businesses, financial institutions, technology companies, research organizations, IP professionals, and other organizations that regularly process IP information, the relevant question may increasingly shift from whether official IP information is available online to how authoritative IP data can be securely incorporated into the systems through which legal and commercial decisions are made.

Key Takeaways:

DIP e-Exchange introduces API-based access to official IP information, covering copyright, geographical indications, petty patents, design patents, invention patents, and trademarks.

The potential uses extend beyond conventional registry searches. The DIP identifies transaction verification, IP valuation and financing, research, enforcement, and development of digital services among the intended applications.

API access may facilitate the integration of IP information into organizational workflows, including due diligence, portfolio management, financing, and compliance processes.

Registry data does not replace legal due diligence. Ownership, contractual rights, chain of title, disputes, unregistered rights, and validity or enforceability issues may still require separate investigation.

Information security is a central feature of the framework. Organizations seeking access are expected to demonstrate appropriate information security standards, policies, or practices.

The initiative represents a broader transition toward interoperable IP infrastructure, in which government-held IP information can potentially become part of the digital systems used to make legal, financial, and commercial decisions.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Employee Welfare Fund Contributions: What Employers Need to Know

Employers falling within the scope of the Labor Protection Act are required to make contributions to the Employee Welfare Fund, creating an additional payroll and compliance obligation alongside social security contributions. The regime is particularly relevant to employers with at least 10 employees that have not established a provident fund or other employee welfare arrangement satisfying the statutory exemption. The Ministry of Labor estimates that approximately 105,416 establishments and 5.57 million employees will be covered.

Who Is Required to Contribute?:

Employees of businesses employing at least 10 employees are generally required to participate in the Employee Welfare Fund. An exemption applies where an employer has established a provident fund under the Provident Fund Act or provides qualifying welfare arrangements for employees upon termination of employment or death. Employers should therefore review their existing benefit arrangements carefully rather than assume that merely having a provident fund automatically exempts their entire workforce.

Contribution Rates and Employer Responsibilities:

From 1 October 2026 through 30 September 2031, employees must contribute 0.25% of wages, with employers contributing an additional 0.25%. From 1 October 2031 onward, the contribution rate increases to 0.50% for each side. The employer is responsible for deducting the employee contribution from wages, adding its own contribution, and remitting both amounts to the Fund. For example, for monthly wages of THB 30,000, the employee and employer would initially contribute THB 75 each, resulting in a total monthly contribution of THB 150.

Employers should review payroll settings, employee classifications, provident fund coverage, and contribution procedures. Failure to remit contributions in full may result in an additional payment of 5% per month on outstanding contributions. Failure to submit required information or the submission of false information may also expose an employer to imprisonment for up to six months, a fine of up to THB 10,000, or both.

Other Tax and Payroll Compliance Points:

Individuals subject to the half-year personal income tax return (PND 94), principally those deriving income under Sections 40(5)–(8) of the Revenue Code, generally have a 30 September filing deadline, extended to 8 October for electronic filing. The reduced 7% VAT rate remains in effect, while the Social Security Fund wage ceiling for employees insured under Section 33 is THB 17,500 per month, resulting in a maximum monthly contribution of THB 875 each for the employee and employer.

The Social Security Fund and Employee Welfare Fund are separate regimes. Employers falling within the scope of both must therefore account for both contribution obligations when configuring payroll and calculating employment costs.

Key Takeaways:

Employers with at least 10 employees should determine which employees are subject to the Employee Welfare Fund and whether existing provident fund or welfare arrangements satisfy the statutory exemption. Payroll systems should be configured for the applicable employee deduction and corresponding employer contribution, with particular attention to the potentially significant 5% monthly additional payment for late or incomplete remittances.

Employers should also consider the Employee Welfare Fund together with their broader payroll compliance obligations, including social security contributions and applicable tax requirements. A coordinated review of payroll systems, employee coverage, and existing benefit arrangements can help identify compliance gaps before they result in additional payments or penalties.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

Amendments to TCCT Notifications: Modernizing Thailand’s Market Dominance and Merger Control Frameworks

Driven by the rapid transformation of modern trade alongside increasingly complex business operations, concerns regarding unfair market practices and anti-competitive conduct in Thailand have escalated substantially. To address these concerns, the Trade Competition Commission of Thailand (“TCCT”) has drafted three notifications to modernize market oversight and ensure clear, robust legal standards. These Drafts update market dominance criteria and refine merger control concepts by establishing clearer monetary thresholds, including explicit rules on affiliate sales aggregation.

Accordingly, the TCCT has released the following draft notifications (“Drafts”):

1.     Draft Notification on Rules for Determining Business Operators with Market Dominance (“Draft Market Dominance Notification”)

2.     Draft Notification on Rules, Procedures, and Conditions for Seeking Permission and Granting Approval for Business Combinations (No. ..) B.E. …. (“Draft Merger Approval Notification”)

3.     Draft Notification on Rules, Procedures, and Conditions for Reporting the Results of Business Combinations (No. ..) B.E. …. (“Draft Merger Reporting Notification”)

These Drafts, presently open for public feedback between September 22 and October 21, 2026, represent a significant update to Thailand’s trade competition and merger control framework. By revising market dominance criteria, refining the definition of a monopoly, and updating thresholds for mergers that may significantly reduce competition, these changes aim to eliminate regulatory ambiguity, close corporate loopholes regarding sales aggregation across affiliated entities, adapt to modern business models, and foster fair market competition.

Key Objectives

1. Draft Market Dominance Notification

·        Repeal of the Previous Notification

This Draft explicitly repeals the Notification of the TCCT regarding Criteria for Determining Business Operators with Market Dominance, dated November 10, B.E. 2568 (2025).

·        Revised Quantitative Thresholds for Market Dominance

The Draft mandates that a business operator shall be regarded as holding market dominance if it meets either of the following quantitative conditions:

o   Single Entity: A single operator in any product or service market that commanded a market share of 33% or higher and generated sales revenue of 500 million THB or more in the preceding year.

o   Two Entities Combined: Any two operators in a given market that held a combined market share of 75% or higher in the preceding year. However, this rule exempts any operator within the pair whose individual annual sales were below 500 million THB or whose market share was less than 10%.

·        Aggregation of Market Share for Corporate Affiliates

The proposed provision directs the authority to aggregate the market shares and sales revenues of business entities sharing policy-level management or controlling power, explicitly declaring all affiliated entities within such a group as dominant operators.

·        Qualitative Assessment Criteria for Dynamic and Digital Platform Markets

The proposed amendments exempt dynamic markets—such as rapidly evolving industries, short-term supply/demand fluctuating markets, and digital platforms—from the quantitative thresholds outlined above. Instead, regulators are instructed to determine dominance using qualitative metrics, including barriers to market entry, buyer power, and relevant regulatory frameworks.

2. Draft Merger Approval Notification

·             Redefining “Monopoly”

The TCCT has revised the definition of “Monopoly” under the Notification of the TCCT on Rules, Procedures, and Conditions for Seeking Permission and Granting Approval for Business Combinations B.E. 2561 (2018). The new provision combines an annual sales threshold of 500 million THB or more with the existing qualitative criteria of single-operator price and output control.

3. Draft Merger Reporting Notification

·          Redefining “Mergers that May Significantly Reduce Competition”

The Draft Notification updates the definition of mergers that significantly reduce competition under the Notification of the TCCT on Rules, Procedures, and Conditions for Reporting the Results of Business Combinations B.E. 2561 (2018). The revised rule establishes a combined annual sales threshold of 500 million THB or more for transactions that do not create a monopoly or dominance. Furthermore, it explicitly directs the authority to aggregate sales revenues from all policy-linked or common-control affiliates.

Implementation and Public Participation

These proposed amendments mark an important milestone for competition regulation in Thailand. It is crucial that all stakeholders—including businesses, industry associations, and consumer advocates—thoroughly examine the text and submit insightful feedback while the consultation window remains open. Direct involvement from all sectors will play a pivotal role in shaping a balanced regulatory environment that aligns rigorous oversight with commercial realities.

Conclusion

The proposed amendments to the TCCT notifications mark a pivotal shift toward a more transparent, predictable, and modern trade competition framework in Thailand. By establishing clear monetary thresholds of 500 million THB, mandating sales aggregation across corporate affiliates, and introducing qualitative evaluations for dynamic digital markets, these Drafts effectively close long-standing regulatory loopholes. Ultimately, this comprehensive reform balances rigorous antitrust oversight with practical commercial realities, fostering a fair competitive landscape while strengthening long-term consumer welfare.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

When Health Data Moves Beyond Its Original Purpose

Large-scale health screening programs can generate datasets of exceptional value. Information initially collected to assess an individual’s health may later be useful for population-health planning, epidemiological studies, academic research, development of healthcare technologies, or collaboration among public authorities, hospitals and research institutions. At the same time, such projects illustrate one of the more difficult questions under the Personal Data Protection Act (PDPA): when may health data collected for one purpose subsequently be used or disclosed for another?

A recent consultation submitted to the data protection regulator in connection with health information collected through a large-scale screening program brings several of these issues into focus. Rather than discussing the regulator’s conclusions in that particular matter, this article examines the compliance questions the scenario raises for organizations handling health and data collection.

Health information requires a two-layer legal analysis:

The starting point is that health information is expressly classified as sensitive personal data under Section 26 of the PDPA. As a general rule, collecting such information without the data subject’s explicit consent is prohibited unless one of the statutory exceptions applies.

This is important because organizations sometimes begin their analysis with Section 24, particularly Section 24(1), which permits the collection of personal data without consent for historical or archival purposes in the public interest, or for research or statistical purposes, provided appropriate safeguards are implemented.  For ordinary personal data that may be the principal legal-basis analysis. For health data, however, satisfying Section 24 does not by itself resolve the issue. The processing must also be capable of being justified under the special rules applicable to sensitive personal data in Section 26.

Section 26 contains several potentially relevant exceptions, including processing necessary for certain health-related purposes where the statutory requirements are satisfied. The applicable exception will depend on the nature of the project, the statutory functions of the organizations concerned, who performs the processing, and the purpose for which the health information is being used.  Consequently, describing a project simply as “research” or “public health” should not be treated as a substitute for identifying the precise statutory basis supporting each processing operation.

Secondary use is a separate question:

A second issue is purpose limitation. Section 21 requires a controller to collect, use or disclose personal data in accordance with the purpose communicated to the data subject. Using the information for a different purpose generally requires notification of the new purpose and consent, unless the PDPA or another law permits the new processing.

This distinction becomes particularly important where information was originally collected to provide an individual health screening service but is later proposed to be used for research, analytics, public-health planning or development of new systems. The question is not merely whether research can, in the abstract, be conducted without consent. The organization should identify what the original purpose was, what the subsequent purpose is, and what provision of law permits the transition from one to the other.

The PDPA recognizes research and statistical activities in a number of places and also contemplates situations in which providing an individual notice may be impossible or seriously obstruct the achievement of scientific, historical or statistical research. In such circumstances, however, appropriate safeguards for the rights, freedoms and interests of data subjects remain important.  This makes research governance more than an exercise in selecting a lawful basis: data minimization, access restrictions, security controls, retention limits and the manner in which research results are disclosed all become part of the compliance analysis.

Removing names may not end the PDPA analysis:

Another recurring issue is whether health data can simply be “de-identified” before being transferred or used for research.

The distinction between genuinely anonymous information and information from which direct identifiers have merely been removed is critical. Removing a person’s name, identification number or telephone number does not necessarily mean that the person can no longer be identified. Health datasets frequently contain combinations of age, location, diagnosis, treatment history, dates and other variables that may permit identification when combined with other information.

The PDPA itself distinguishes between personal data and information that has been made incapable of identifying the data subject. For example, it expressly recognizes anonymization as one possible means of dealing with data in connection with a deletion request.  Organizations should therefore avoid treating “de-identification”, “pseudonymization” and “anonymization” as interchangeable concepts.

As a practical matter, data linked to a code while a corresponding key remains available should normally be treated cautiously as personal data. Whether a dataset has become genuinely anonymous should be assessed against the realistic possibility of re-identification, including identification through combination with information held separately. For valuable health datasets, this may require both technical controls and organizational restrictions rather than simply deleting direct identifiers.

Who is the controller when several organizations participate?

Large-scale health projects commonly involve several participants: a government agency may establish the program, hospitals may collect samples and examination results, a university may analyze the information, an IT provider may host the database and separate researchers may later obtain datasets.

The labels used in the collaboration agreement are not necessarily decisive. The relevant question is who determines the purposes and essential means of each particular processing activity. A participant acting solely on documented instructions may have a processor role, whereas an institution that determines its own research question and decides how information will be analyzed may itself exercise controller functions.

The same institution may therefore occupy different roles at different stages of a project. That distinction matters because the PDPA imposes different obligations on controllers and processors, and because disclosure from one independent controller to another requires its own legal justification rather than merely a data processing agreement.

Organizations managing collaborative health projects should consequently map the data flow and the decision-making structure, rather than assigning a single PDPA label to each institution for the project as a whole.

Data sharing is itself a processing activity:

Where health information is disclosed to another organization, it is not enough that the recipient intends to conduct worthwhile research. Section 27 restricts the use and disclosure of personal data unless consent has been obtained or the information was collected under an applicable statutory exception. It also restricts a recipient from subsequently using the information for purposes beyond those communicated when obtaining the data.

This means that data-sharing arrangements should identify, among other matters, the purpose of disclosure, categories of information involved, respective legal bases, permitted uses, security measures, retention and deletion arrangements, onward disclosure restrictions, handling of data-subject rights, breach responsibilities and the respective controller or processor status of the parties.

The existence of a data-sharing agreement is valuable evidence of governance, but the agreement does not itself create a lawful basis that does not otherwise exist under the PDPA.

International research creates an additional layer:

Where research collaborators, cloud providers or analytical systems are located outside Thailand, the international-transfer provisions must also be considered independently of the lawful basis for the underlying research.

Section 28 establishes the principle that transfers should be made to destinations having an adequate standard of personal data protection, subject to specified statutory exceptions.  Section 29 provides mechanisms concerning transfers within groups and permits other safeguards in circumstances prescribed under the statutory framework.

Accordingly, an organization may have a valid domestic basis to process health information for a particular purpose but still need to address a separate transfer question before making the information accessible overseas. This is especially relevant where data is stored on international cloud infrastructure or foreign researchers are given remote access to a Thai database; an organization should not assume that the absence of a physical file transfer necessarily removes the cross-border issue.

Why these issues extend beyond healthcare:

Although health screening provides a particularly clear example because Section 26 applies, the underlying questions are much broader. Businesses increasingly seek to reuse datasets originally collected for operational purposes to train algorithms, develop AI systems, perform behavioral analytics or create new products. The same sequence of questions frequently arises: What was the original purpose? What is the proposed secondary purpose? Does the new processing have an independent legal basis? Are sensitive data involved? Can the information genuinely be anonymized? Who determines the new purpose? Will another organization receive the data? Will it become accessible outside Thailand?

The regulatory risk often arises not because the organization lacks a legitimate business or public-interest objective, but because these questions are addressed only after a valuable dataset has already been created. Building secondary-use governance into the data lifecycle from the beginning is therefore considerably safer than attempting to reconstruct the legal basis when a research or AI opportunity later emerges.

Key Takeaways:

  • Health data requires special treatment: An organization relying on a research basis under Section 24 must still address the sensitive-data requirements of Section 26.
  • Secondary use should be analyzed separately from original collection: A lawful basis for collecting health information does not automatically authorize every later research, analytics or development purpose.
  • Removing names is not necessarily anonymization: The ability to identify an individual through remaining data or other available information remains relevant.
  • Roles should be determined activity by activity: A university, hospital, government agency or technology provider may have different controller or processor roles at different stages of the same project.
  • A contract does not replace a lawful basis: Data-sharing agreements and processing agreements are governance tools; they do not themselves legalize a disclosure.
  • Cross-border access adds another compliance layer: International transfer requirements must be considered separately from the legal basis for the underlying research.
  • Research and AI projects benefit from governance by design. Organizations should determine secondary-use rules, access controls, anonymization standards and data-sharing procedures before datasets are repurposed.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Criteria and Conditions for Allowing Foreign Nationals to Use Automated Passport Control Channels

Background

The Immigration Bureau introduced Automated Passport Control Channels under the Order No. 322/2566 (the “Previous Order”), effective 15 December 2023, to support tourism and improve immigration processing efficiency.

However, the original framework was relatively narrow in scope, covering only a limited group of foreign nationals and restricting outbound automated processing to Suvarnabhumi Airport. To enhance accessibility and accommodate a wider range of travelers, the Immigration Bureau subsequently issued the Order No. 196/2569 (the “Current Order”), which substantially expands the scope of the Automated Passport Control System.

Immigration Bureau Order No. 196/2569

To further facilitate immigration clearance for foreign travelers, the Immigration Bureau issued the Current Order, effective on 24 August 2026. The Current Order significantly expands access to Automated Passport Control Channels by broadening eligible nationalities, visa categories, and airport checkpoints. Here is what has been changed compared to the previous order.

  1. Expanded Eligible Nationalities

The most significant change is the expansion of eligible nationalities from only Singapore and Hong Kong under the Previous Order to 33 countries and territories under the Current Order.

The expanded list now includes major business and tourism markets such as the United Kingdom, Japan, South Korea, Australia, New Zealand, Germany, France, Switzerland, Italy, the Netherlands, Sweden, Norway, Denmark, Finland, Belgium, Austria, Canada, and Singapore.

As a result, a substantially larger number of foreign travelers are now eligible to use Automated Passport Control Channels when entering and departing Thailand.

  • Expanded Visa Eligibility

The Previous Order primarily limited access to permanent residents, diplomats, government representatives, and certain designated individuals.

Under the Current Order, eligibility has been extended to holders of specified Non-Immigrant Visas as listed in its Appendix, covering a wider range of foreign nationals residing, working, studying, investing, or living with family members in Thailand.

  • Expanded Airport Access

Under the Previous Order:

  • Inbound automated channels were available only to a limited group of foreign nationals and specific type of passport holders.
  • Outbound automated channels were available only at Suvarnabhumi Airport.

Under the Current Order:

  • Eligible foreign nationals as listed in its Appendix can use automated channels for both inbound and outbound travel.
  • Access is available at any international airport equipped with the Automated Passport Control System.
  • Operational Improvements

The Current Order also introduces procedures enabling immigration officers to promptly correct minor system errors, including issues related to visa classification, period-of-stay records, and automated overstay alerts, thereby helping to reduce delays and unnecessary processing.

  • Broader Coverage of Eligible Travelers

The Current Order also broadens eligibility to include:

  • Business: employees, executives, assignees, and investors;
  • Education: teachers, researchers, and students;
  • Family: spouses, parents, children, and other qualifying family members of Thai nationals, permanent residents, and eligible foreign residents.  

It is crucial to note that each criterion is evaluated independently. Therefore, if a foreigner fits into one of the eligible groups (such as holding a qualifying visa or belonging to an eligible nationality), they will be allowed to use the automated channels

Practical Examples

  1. Long-Term Business Professionals and Expatriates Holding Non-Immigrant “B” Visas

Under the Previous Order:

  • Inbound: No access to the Automated Passport Control System was allowed; even senior executives of multinational companies and citizens of major economies such as the United States, the United Kingdom, Japan, and China. They  were required to use manual immigration counters.
  • Outbound: The Automated Passport Control System is available only at Suvarnabhumi Airport.

Under the Current Order:

  • Inbound and Outbound: It is accessible at any international airport equipped with the Automated Passport Control Channels, provided the traveler qualifies under the Appendix of the Current Order and holds a valid re-entry permit where required.
  • Short-Term Business Travelers and Tourists

Under the Previous Order:

  • Inbound: No access to the Automated Passport Control System was allowed, except for Singaporean and Hong Kong passport holders.
  • Outbound: The Automated Passport Control System is available only at Suvarnabhumi Airport.

Under the Current Order:

  • Inbound and Outbound: Eligible travelers from countries listed in the Appendix to the Current Order, including the United States, Japan, China, and the United Kingdom, can use Automated Passport Control Channels at any international airport equipped with the Automated Passport Control System.

Key Takeaways

  • Significant Expansion: Eligibility has increased from only two nationalities to 33 countries and territories under the Current Order.
  • Broader Access: Business travelers, expatriates, investors, academics, students, and family-based visa holders can now benefit from automated immigration processing.
  • Nationwide Availability: Automated outbound processing is no longer limited to Suvarnabhumi Airport, and it is now being used at any international airport equipped with the system.
  • Improved Efficiency: Immigration officers are now authorized to resolve minor system errors immediately, helping to reduce delays and unnecessary procedures.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Social Commerce Overhaul: From Seller Verification to Influencer Accountability

The regulatory gap created by social commerce:

Social commerce has blurred many of the distinctions on which traditional e-commerce regulation was built. A consumer may discover a product through an influencer, encounter promotional content on a social-media platform, communicate directly with a seller through the same platform, and complete the purchase without ever visiting a conventional online marketplace. The seller, the person promoting the product, the person paying for the advertisement, and the platform carrying the content may all be different parties. This structure creates a regulatory challenge because consumer protection laws have traditionally focused on businesses supplying goods or services and unlawful advertising, while digital-platform regulation has focused principally on platform operators. Social commerce sits between these regimes. Recent regulatory initiatives indicate that this gap is gradually being addressed—not through a single “social commerce” law, but through complementary regulatory work-streams involving the Electronic Transactions Development Agency (ETDA) and the Office of the Consumer Protection Board (OCPB).

ETDA: From online marketplaces to identifying sellers and advertisers

The regulatory framework for digital commerce has already moved beyond conventional marketplace websites. Under the Digital Platform Services (DPS) framework, ETDA regulates qualifying digital platform services and has progressively developed requirements and guidance concerning online marketplaces, product and seller information, advertising, notice-and-takedown mechanisms, and other aspects of platform governance. Social media is increasingly relevant to this framework because commercial activity can take place within services that were not originally designed as conventional marketplaces. ETDA has also identified social commerce as an area requiring further regulatory attention.

A particularly important development is the increasing emphasis on the identity and traceability of sellers and advertisers. ETDA’s existing advertising guidance recommends that platforms establish procedures for checking advertiser information and verifying identity, maintain relevant advertiser records, and use mechanisms such as watchlists, blacklists, and whitelists. It also addresses screening advertisements before publication and monitoring them afterward through reporting and flagging mechanisms. ETDA’s developing measures for social-media platforms build on this approach by contemplating risk-based identification and verification of users, sellers, and persons placing advertisements. The underlying regulatory objective is increasingly clear: commercial activity conducted through social media should not permit the persons behind a seller account or paid advertisement to remain effectively unidentifiable. For social-commerce businesses, advertiser and seller identification may therefore become an increasingly important part of the platform compliance infrastructure.

OCPB: Bringing influencers into the consumer-protection framework

A parallel development is occurring under consumer protection law. The OCPB has proposed a substantial amendment to the Consumer Protection Act aimed at modernizing the framework for digital commerce and contemporary advertising practices. One of its significant features is the proposed expansion of responsibility within the advertising ecosystem, including persons hired to advertise goods or services. If enacted in its proposed form, this could bring influencers, content creators, and other persons engaged to promote products more directly within the statutory consumer-protection framework. This is particularly important for influencer marketing, where the traditional distinction between an advertiser and the medium carrying an advertisement can be difficult to maintain. Influencers may create promotional content themselves, demonstrate products, repeat claims supplied by brands, integrate commercial messages into personal recommendations or entertainment, provide purchasing links, and participate in affiliate arrangements. The person communicating the advertising message can therefore play a much more active role in influencing the consumer’s decision than a conventional advertising medium.

The OCPB initiative addresses a different part of the social-commerce problem from ETDA’s platform regulation. ETDA’s developing framework focuses substantially on the platform and the identification and traceability of persons using it for commercial activity, while the OCPB proposal strengthens responsibility for the consumer-facing commercial message and the persons participating in communicating that message. The proposed Consumer Protection Act amendment remains draft legislation, so its final scope may change during the legislative process. Nevertheless, its direction is important for brands, agencies, influencers, and content creators because compliance may increasingly extend beyond the business that ultimately supplies the product.

Two regulatory layers across one transaction:

The interaction between these initiatives is perhaps the most significant feature of the emerging framework. Consider a typical social-commerce transaction: a brand engages an influencer to promote a product; promotional content appears on a social-media service; the content directs consumers to a seller operating through that platform or another online channel; and a consumer purchases the product after relying on representations contained in the promotional content. Different regulatory obligations can potentially attach at several points along that chain. The platform may increasingly be expected to identify sellers and advertisers, retain information permitting them to be traced, screen certain advertisements, monitor problematic content, and provide mechanisms for responding to complaints or unlawful activity. The seller or brand remains subject to applicable consumer-protection and product-specific requirements. At the same time, the OCPB amendment could place influencers and other persons hired to advertise more directly within the consumer-protection regime.

The emerging division can therefore be summarized as follows: ETDA is developing the infrastructure of accountability, while OCPB is extending accountability through the advertising chain. The distinction is not absolute. ETDA’s role extends beyond identity verification into advertising screening and monitoring, while OCPB already exercises broad authority over consumer-facing advertising. The regulatory regimes should therefore be understood as overlapping layers rather than completely separate jurisdictions. Together, however, they address a central weakness of social commerce: the difficulty of identifying and allocating responsibility among the multiple parties involved between the creation of an advertisement and the eventual consumer transaction.

From regulating the seller to regulating the commercial chain:

These developments point toward a broader change in the regulation of digital commerce. Traditional e-commerce could largely be conceptualized around the consumer, the online seller, and the marketplace facilitating the transaction. Social commerce introduces additional actors: platforms distribute commercial content, advertisers may be different from sellers, influencers and content creators communicate product claims, and transactions can move from public social-media content into private messaging or other channels. The emerging regulatory framework increasingly follows this entire chain. Instead of asking only who sold the product, regulators are developing mechanisms that can also address who promoted it, who paid for or arranged the advertisement, who communicated the claims, and which platform facilitated the commercial interaction.

For businesses, social-commerce compliance should therefore no longer be treated solely as an issue for the legal entity making the final sale. Brands will need to consider how influencers and advertisers are selected, instructed, and supervised; whether advertising and product claims can be substantiated; what information must be supplied to platforms; and how responsibility is allocated contractually among brands, agencies, influencers, and other participants. Influencer and advertising agreements may require greater attention to regulatory compliance, disclosure and approval procedures, substantiation of claims, record-keeping, corrective measures, content removal, and cooperation with platforms or regulators. Platforms face a different compliance trajectory, with increasing expectations around identification, verification, screening, monitoring, traceability, and intervention where commercial activity creates risks for consumers.

An emerging social-commerce framework:

There is not yet a single comprehensive regulatory instrument governing social commerce. Instead, a network of complementary rules is emerging to regulate different stages of the same commercial activity. ETDA’s DPS framework and related initiatives provide the platform-governance layer; developing seller and advertiser verification requirements strengthen identification and traceability; and the proposed Consumer Protection Act amendment would strengthen the consumer-facing advertising layer by potentially extending responsibility more directly to influencers and other participants in the advertising process. Viewed together, these developments suggest that social commerce is moving toward end-to-end accountability—from the identity behind an advertisement to the person delivering the commercial message and ultimately to the transaction with the consumer.

Key Takeaways:

The social-commerce regulatory framework is developing through several complementary initiatives rather than one dedicated law. ETDA is strengthening the platform side of the equation, particularly the identification and traceability of sellers and advertisers, while OCPB is seeking to strengthen responsibility on the consumer-facing side, including the role of influencers and other persons engaged in advertising. Businesses operating through social commerce should therefore look beyond seller compliance alone. Brands, sellers, advertising agencies, influencers, content creators, and digital platforms increasingly form parts of the same regulated commercial chain, and the compliance focus is shifting from responsibility for the final sale toward accountability throughout the process by which a consumer encounters, evaluates, and purchases a product online.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Public Procurement Reform Would Shift Focus Beyond Price

The Cabinet has approved in principle a significant amendment to the Public Procurement and Supplies Administration Act that could materially change how government agencies evaluate bidders and manage contractor performance. The proposal forms part of a broader legislative reform package and is intended to move public procurement away from an approach perceived as placing excessive emphasis on the lowest price. Importantly, the amendment remains a draft Act. Cabinet approval does not itself amend the existing procurement rules, and the proposal must proceed through the legislative process before becoming binding.

Greater Emphasis on Value and Performance:

A central feature of the proposed reform is a shift in supplier selection toward the interests of the procuring government agency, the purpose for which the goods or services will be used, and the bidder’s ability to perform the contract. The Government has previously explained the policy objective as enabling government agencies to obtain supplies and services that offer appropriate value and quality rather than evaluating procurement predominantly by reference to the lowest price.

This could be particularly significant for procurements involving technology, cloud services, cybersecurity, healthcare products, infrastructure, consulting and other sophisticated services. Suppliers whose offerings involve higher initial prices but stronger technical capabilities, security, reliability, service levels or lifecycle value may have greater scope to differentiate their proposals if the final legislation and implementing rules translate the policy into broader evaluation criteria. Businesses should nevertheless distinguish between the Government’s stated policy direction and the criteria that will ultimately become legally applicable once the legislation and related rules are finalized.

Stronger Consequences for Poor Performance:

The draft would also strengthen the Government’s ability to deal with contractors that fail to perform satisfactorily. The proposed amendments expand the circumstances in which contracts may be terminated and contractors may be designated as defaulting contractors where performance is defective or involves serious errors that cause, or could cause, damage to government agencies, the public, property or the environment. The proposal would also give heads of contracting government agencies greater authority to designate bidders or contractors as defaulting contractors, with the relevant information subsequently circulated through the government procurement system.

These changes could substantially increase the consequences of contract-performance failures. Government contractors should therefore consider strengthening project governance, acceptance procedures, quality controls, subcontractor management and documentation of contractual performance. For technology and service contracts in particular, careful documentation of service levels, testing, acceptance criteria, incident management and responsibility for delays may become increasingly important where poor performance could potentially lead not only to contractual remedies but also to restrictions on participation in future government procurement.

Procurement Appeals May Become More Costly:

Another significant element is the proposed introduction of measures intended to discourage procurement appeals made without reasonable grounds. The Government has indicated that frequent appeals can delay procurement projects and that the amendment is intended to reduce inappropriate use of the appeal mechanism. The contemplated framework includes security requirements for certain procurement appeals.

The details will be important. An appropriately calibrated security mechanism could discourage tactical challenges intended primarily to delay contract awards. However, if the required security is substantial, it could also affect the practical ability of smaller bidders to challenge procurement decisions. Businesses participating regularly in government tenders should therefore monitor the final provisions governing the amount of security, circumstances in which it must be provided, and conditions for its return or forfeiture.

Particular Relevance to Technology Procurement:

The move away from predominantly price-based evaluation could be especially relevant to government technology procurement. Technology solutions are often difficult to compare meaningfully by acquisition price alone because cybersecurity, resilience, interoperability, data-management capability, service levels, scalability and lifecycle costs can materially affect the overall value and risk of a project.

The proposed reform could provide a stronger statutory foundation for procurement approaches that recognize these factors. However, the Cabinet materials do not themselves establish cybersecurity certification, data-management capability, SLA performance or interoperability as mandatory evaluation criteria. Whether and how such considerations become part of procurement evaluations will depend on the final legislation, implementing regulations, procurement specifications and practices adopted by individual government agencies.

What Businesses Should Do Now:

Because the proposal is not yet binding, suppliers do not need to change their tendering practices solely as a result of Cabinet approval. Businesses that regularly contract with government agencies should nevertheless follow the legislative process and begin considering how their procurement strategies may need to evolve. In particular, suppliers may wish to strengthen evidence demonstrating technical capability and value beyond price, review internal controls for government-contract performance, maintain detailed records supporting compliance with contractual obligations, and reassess procedures for deciding whether and when to challenge procurement decisions.

Key Takeaways:

The proposed amendment represents a potentially important change in public procurement policy: from an emphasis on price toward a broader assessment of value, suitability and contractor capability. At the same time, the reform would increase the potential consequences of defective performance and could make procurement appeals more disciplined through security requirements.

For businesses selling sophisticated products and services to government agencies, the reform could create opportunities to compete more effectively on quality, technical capability and long-term value rather than price alone. Those opportunities would come with increased performance and compliance risk. For now, however, the existing procurement regime remains applicable, and businesses should monitor the draft as it proceeds through the legislative process.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Substantive Agreement Reached on the Thailand–United States Agreement on Reciprocal Trade (ART)

Introduction

On 1 September 2026, Thailand and the United States reached agreement on the substance of an Agreement on Reciprocal Trade (the “ART”) in Washington, D.C. Technical details remain outstanding, and the ART has not been signed.

The tariff rate applicable to Thai goods is likewise unsettled. A Section 301 investigation into structural excess capacity remains before the United States Trade Representative (“USTR”), and the final rate will depend on its outcome.

The 12.5 percent rate now in force did not simply replace an earlier rate. It is the latest in a sequence of four measures, each resting on a different legal footing, and in each case the preceding measure ceased to apply because its statutory basis lapsed, was struck down, or was superseded by negotiation.

How One Measure Replaced Another

  • Reciprocal tariffs under IEEPA: Thailand was subject to a reciprocal tariff of 36 percent imposed under the International Emergency Economic Powers Act (“IEEPA”). Following a joint statement with the United States, that rate was reduced to 19 percent, announced on 1 August 2025, which in turn led to the announcement of the ART framework on 26 October 2025.
  • The Supreme Court ruling: On 20 February 2026, the United States Supreme Court held, by six votes to three, that IEEPA does not confer authority on the President to impose tariffs. The reciprocal tariff regime fell away, including the 19 percent rate applied to Thailand.
  • Section 122: The United States then imposed a temporary tariff of 10 percent on all countries under Section 122 of the Trade Act of 1974. That authority carries a statutory limit of 150 days, and the measure expired on 24 July 2026.
  • Section 301: On the same day, the USTR announced tariffs under Section 301 covering 60 trading partners. Thailand was placed in the 12.5 percent band under the forced labor case. Cambodia, Indonesia and Malaysia were placed at 10 percent, leaving Thai exporters with a cost disadvantage of approximately 2.5 percentage points against those regional competitors.

Each step rests on a different statute. A rate imposed under one authority is not comparable with a rate imposed under another, even where the percentage is identical.

Where the Rate Stands Now

Section 301 does not produce a single rate. It proceeds case by case, and the resulting rates accumulate.

  • Case 1 — Forced labor: Determined, producing the 12.5 percent rate now in force.
  • Case 2 — Structural excess capacity: Pending, no determination has been issued.

The Department of Foreign Trade (“DFT”) expects the two cases together to result in a combined rate of no more than 19 to 20 percent. With Case 1 at 12.5 percent, this implies approximately 6.5 percent from Case 2.

It is at this point that the two figures of 19 percent must be kept distinct. The 19 percent applied before February 2026 was a single reciprocal tariff imposed under IEEPA and no longer exists. A figure of 19 percent today refers to the two Section 301 cases taken together, under an entirely different statute. The same number denotes a different measure.

What Was Agreed on 1 September

The Deputy Prime Minister and Minister of Commerce met the USTR and the Deputy USTR in Washington, D.C. on 1 September 2026, following four days of technical negotiation conducted by Thailand’s representatives.

The parties agreed on the substance of the ART, and the negotiating teams on both sides were directed to finalize the remaining technical details. The ART addresses non-tariff barriers, digital trade, and commercial opportunities. The United States indicated that the rate arising from the pending Section 301 excess capacity investigation would be set at a fair and competitive level.

Why the ART Does Not Settle the Rate

The Ministry of Commerce (“MOC”) confirmed on 7 September 2026 that agreement on the substance of the ART does not fix the final tariff rate, because the Section 301 excess capacity investigation remains under consideration.

Two distinct instruments are involved:

  • The ART is a bilateral agreement between Thailand and the United States.
  • A Section 301 determination is a unilateral United States administrative process.

Concluding the former does not conclude the latter.

The two meet at a single point. The USTR set the Case 1 rate at 10 percent for economies that already prohibit imports of goods made with forced labor, that operate a partial regime having that effect, or that have committed through an ART to impose and enforce such a prohibition. Thailand satisfies none of these conditions and therefore remains at 12.5 percent.

What lowers the rate is the forced labor commitment that an ART carries, not the ART itself. An agreement without such a commitment would not qualify, and an agreement containing one would still leave Case 2 open.

What Remains Outstanding

Three matters remain unresolved.

  • The Case 2 determination has not been issued, and no date has been announced. Until it is, the rate applicable to Thai goods is not fixed.
  • The technical annexes to the ART have not been finalized, and the agreement has not been signed.
  • The commercial terms of the ART have not been published. Commitments on imports of United States goods will bear on Thailand’s trade and current account balances.

Key Takeaways

  • The tariff applicable to Thai goods has been replaced three times since 2025, moving from 36 percent and then 19 percent under IEEPA, to 10 percent under Section 122, to 12.5 percent under Section 301 to date.
  • Rates imposed under different statutes are not comparable, even where the percentage is identical.
  • Section 301 rates accumulate across cases. Case 1 (forced labor) produced the current 12.5 percent. Case 2 (excess capacity) is pending.
  • A combined figure of 19 to 20 percent refers to both Section 301 cases together, and not to the former IEEPA rate of 19 percent.
  • Agreement on the substance of the ART was reached on 1 September 2026. Technical details remain outstanding and the ART is not signed.
  • An ART containing a forced labor undertaking would move Case 1 from 12.5 percent to 10 percent, but would not determine Case 2. Thailand remains at 12.5 percent, and the MOC confirmed on 7 September 2026 that the final rate awaits that determination.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

BOT Framework for Safeguarding the Financial Sector from Illicit Activities: New Supervisory Expectations for Financial Institutions and Payment Providers

The Bank of Thailand (BOT), together with financial institutions and regulated financial service providers, has formally launched the Framework for Safeguarding the Financial Sector from Illicit Activities, a sector-wide initiative intended to prevent the financial system from being used to facilitate technology-enabled crime, corruption, money laundering, fraud, and other illicit activities. The Framework represents a significant supervisory development for banks, payment service providers, e-money operators, foreign exchange businesses, and non-bank lenders. While the Framework itself is principally a cooperation and policy framework rather than a standalone regulation imposing penalties, the BOT has expressly indicated that it will strengthen regulations, minimum standards, and supervisory oversight to promote consistent implementation across the financial sector. Accordingly, regulated entities should view the Framework not merely as a statement of policy, but as an indication of the direction in which future supervisory expectations and regulatory requirements are likely to develop.

Five Core Principles:

The Framework is built around five principles that participating institutions are expected to apply in a manner appropriate to their business models and risk profiles. First, preventing misuse of the financial sector should form part of leadership and corporate governance, with boards and senior management responsible for establishing policies, strategic direction, oversight arrangements, and adequate resources. Second, institutions should translate those commitments into effective standards and execution, including appropriate minimum standards for monitoring, detection, and risk response, with periodic review as risks evolve. Third, institutions are expected to develop expertise and data-driven capabilities, using data, technology, and specialized knowledge to improve monitoring and detection. Fourth, the Framework emphasizes collaboration and collective intelligence, including exchanges of information, intelligence, fraud typologies, risk indicators, and best practices among financial institutions, government authorities, private-sector organizations, and other relevant stakeholders, subject to applicable legal frameworks. Finally, preventive measures should pursue balanced objectives, taking into account financial inclusion, fair competition, innovation, customer convenience, and the need to avoid unnecessary burdens on legitimate users.

From Policy Framework to Operational Controls:

The significance of the Framework becomes clearer when the commitments of the BOT and participating industry groups are considered. The BOT intends to strengthen KYC, Customer Due Diligence (CDD), and Enhanced Due Diligence (EDD) standards, including end-to-end controls against mule accounts. It also plans to strengthen Know Your Merchant (KYM) requirements and oversight of high-risk merchants, particularly in payment acceptance services. Other areas identified for enhanced controls include high-value cash transactions, conversion of illicit proceeds into assets that are more difficult to trace, digital financial service security, and standards applicable to non-bank operators.

Financial institutions and industry associations have correspondingly committed to stronger customer identification and due diligence, greater scrutiny of high-risk accounts and cash transactions, and increased use of data and technology to identify unusual transactions and behavioral patterns. Banks are expected to integrate internal information with trusted external sources and use customer profiles, behavioral information, and transaction inflow/outflow patterns to identify links among accounts and suspicious activity. Payment service providers are expected to strengthen KYM throughout the merchant lifecycle, including enhanced merchant screening and behavioral monitoring, while non-bank lenders are expected to strengthen their assessment of customers, related parties, transactions, and sources of funds. The Framework also contemplates databases of high-risk persons and merchants, links with the Central Fraud Registry, and development of industry-wide AML/CFT operational guidelines.

Data Sharing Becomes a Central Compliance Issue:

One of the most consequential elements of the Framework is its emphasis on information sharing. The BOT intends to analyze linkages and share risk patterns, behavioral indicators, and information concerning individuals, legal entities, and merchants identified as high risk. It also envisages greater data exchange and collaborative analytics involving regulatory authorities, law enforcement agencies, and other government bodies. Financial institutions and payment providers will likewise be expected to contribute relevant information, including unusual transaction patterns, merchant information, fraud intelligence, and other indicators that may assist in identifying misuse of the financial system.

This creates an important intersection between financial-crime prevention and personal data protection. The Framework expressly recognizes that information exchange must occur within applicable legal frameworks. Consequently, an expectation or request to share information for fraud prevention purposes should not automatically be treated as removing the need for analysis under the Personal Data Protection Act (PDPA). Institutions should identify an appropriate lawful basis for each relevant processing and disclosure activity, determine whether the data collected and shared are necessary and proportionate to the stated purpose, establish appropriate retention periods, and implement access controls and security safeguards. Data accuracy will be particularly important where information is used to classify a person or merchant as high risk or to restrict access to financial services.

High-Risk and Blacklist Databases Require Particular Attention:

The contemplated development and sharing of high-risk-person and merchant information raises additional governance considerations. A risk indicator used merely to trigger additional review is materially different from a blacklist that automatically results in account restrictions, rejection of onboarding, termination of services, or other adverse consequences. Institutions should therefore consider establishing clear criteria for inclusion and removal, defining the evidentiary threshold required for a high-risk designation, controlling who may submit or amend records, periodically reviewing whether information remains accurate and relevant, and establishing escalation or review procedures where a designation may materially affect a customer.

These issues become more significant as databases are interconnected across institutions or with centralized fraud information systems. Incorrect, outdated, or insufficiently verified information could potentially propagate across the financial sector and affect an individual or business beyond the institution that originally generated the risk indicator. Governance of shared databases should therefore address not only cybersecurity and access management but also data provenance, accuracy, correction procedures, retention, accountability, and the distinction between intelligence suggesting risk and verified findings of unlawful conduct.

What Financial Institutions and Payment Providers Should Do Now

Although detailed minimum standards will continue to develop, regulated entities should consider conducting a readiness assessment against the Framework now rather than waiting for individual implementing measures. This should include reviewing whether board and senior-management oversight adequately covers financial-crime and fraud risks; mapping existing KYC/CDD/EDD and KYM controls against the emerging supervisory direction; assessing high-value cash and unusual-transaction monitoring; reviewing the use of AI, behavioral analytics, and external data sources; and identifying existing or planned information-sharing arrangements with other institutions, industry bodies, regulators, and law-enforcement agencies. Particular attention should be given to the interface between financial-crime controls and the institution’s PDPA, cybersecurity, data governance, outsourcing, and third-party risk frameworks.

Institutions should also document the legal and governance architecture supporting fraud-related data processing before broader industry sharing becomes operational. This may include reviewing privacy notices, records of processing activities, data-sharing agreements or protocols, retention schedules, access matrices, security controls, procedures for correcting inaccurate risk information, and the allocation of responsibilities among compliance, AML, fraud, privacy, cybersecurity, legal, and business teams. Where automated tools or risk-scoring systems are used to identify high-risk customers or transactions, institutions should also consider whether their governance arrangements provide sufficient human oversight and mechanisms to manage false positives and unintended customer impacts.

Key Takeaways:

The Framework marks a shift toward a more coordinated, intelligence-led approach to protecting the financial sector from illicit activities. Although it is not, by itself, a standalone penal regulation, the BOT has expressly signaled further development of regulations, minimum standards, and supervisory oversight, making the Framework an important indicator of future compliance expectations.

For financial institutions, payment providers, and other regulated non-banks, the immediate priorities are to assess existing KYC/CDD/EDD and KYM controls, strengthen technology-based detection and high-risk transaction monitoring, and prepare for substantially greater information sharing across the financial ecosystem. At the same time, fraud prevention and financial-crime objectives must be reconciled with PDPA requirements, cybersecurity controls, proportionality, data accuracy, retention, and appropriate governance of high-risk and blacklist databases.

The next major development to monitor will be the BOT’s issuance or enhancement of minimum standards, regulations, supervisory guidelines, or operational requirements implementing the Framework. Those measures are likely to determine when the Framework moves from a high-level sector commitment to more concrete and enforceable compliance expectations.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Bangkok Blueprint: A New Framework for Protecting the Financial Sector from Illicit Activities

The Bank of Thailand (BOT) is moving toward a broader and more coordinated approach to preventing the financial system from being used for fraud and other illicit activities. As part of this initiative, the BOT, together with relevant financial-sector stakeholders, is preparing the Framework on Safeguarding the Financial Sector from Illicit Activities, while the BOT, the International Monetary Fund (IMF), and the World Bank Group are also advancing the Bangkok Blueprint for Fraud-Resilient Financial Services.

Although the final text of the Framework has not yet been separately published in the official materials reviewed for this article, the initiatives signal an important development in financial-sector supervision: fraud prevention and the prevention of illicit financial flows are increasingly being treated as responsibilities extending across the financial ecosystem rather than as matters confined to individual institutions or conventional anti-money laundering controls.

The Bangkok Blueprint:

The Bangkok Blueprint is intended to strengthen the resilience of financial services against fraud and scams in the digital age. The BOT has described the initiative as being developed with the IMF and World Bank Group and as providing a practical reference for strengthening coordinated responses to digital financial fraud.

This direction reflects the changing nature of financial crime. Digitalization has made payments faster and financial services more accessible, but it has also allowed fraud proceeds to move rapidly between accounts, institutions, payment channels, and potentially other asset classes. An effective response therefore increasingly depends on coordination among financial institutions and other participants in the financial ecosystem.

The BOT has already taken measures addressing unauthorized payment fraud and, more recently, authorized push payment fraud. These measures have included controls relating to mule accounts, tracing of fund flows, use of customer behavioral information, risk-based transaction limits, and shared-responsibility principles. The Bangkok Blueprint appears to place these developments within a broader policy framework focused on making financial services more resilient against fraud.

Safeguarding the Financial Sector from Illicit Activities

Alongside the Bangkok Blueprint, the BOT is coordinating the Framework on Safeguarding the Financial Sector from Illicit Activities. According to the BOT’s official announcement, this is intended to be a sector-wide initiative aimed at preventing the financial system from being misused for illegal and fraudulent activities.

The significance of the Framework is its potentially broad institutional reach. The policy direction described publicly extends beyond commercial banks and reflects the need for controls across different points through which illicit funds may enter, move through, or leave the financial system.

Public statements surrounding the initiative indicate an emphasis on strengthening customer due diligence, identifying higher-risk transactions, improving information sharing, and reinforcing anti-money laundering controls. However, until the final Framework is officially published, these matters should not be treated as new binding regulatory requirements merely by reason of the Framework itself.

From Individual Compliance to Ecosystem Responsibility:

The more important development may be the shift in regulatory philosophy. Traditional compliance programs tend to focus on whether an individual institution has properly identified its customer, monitored transactions, reported suspicious activity, and complied with applicable restrictions. Digital fraud demonstrates the limitations of an institution-by-institution approach because funds can move through several accounts and service providers within a very short period.

The emerging approach therefore places greater importance on the ability of institutions to identify suspicious behavior rapidly, connect information from different sources, exchange relevant fraud intelligence, and intervene before illicit funds disappear from the regulated financial system.

For banks and other regulated financial businesses, this could eventually affect the design of onboarding controls, customer risk classification, transaction-monitoring systems, mule-account detection, escalation procedures, information-sharing arrangements, and internal governance. It may also increase expectations that management can demonstrate not merely formal compliance with existing rules, but the effectiveness of controls in preventing the institution’s products and infrastructure from facilitating illicit activity.

What Financial Institutions Should Watch:

The practical significance of the Framework will depend on the final text and any subsequent BOT rules, guidelines, supervisory expectations, or industry commitments implementing it. In particular, financial institutions should monitor whether the initiative results in more specific expectations concerning mule-account identification and management, customer and merchant onboarding, enhanced due diligence for higher-risk customers, transaction monitoring, cross-institution information sharing, rapid restriction or suspension of suspicious transactions, and governance responsibility for financial-crime controls.

Institutions should also consider the interaction between these measures and their existing obligations concerning anti-money laundering, cybersecurity, fraud prevention, consumer protection, and personal data protection. Greater information sharing can improve fraud detection, but institutions will need appropriate legal bases, governance, security measures, access controls, retention policies, and safeguards governing the use and disclosure of customer information.

Key Takeaways:

The Bangkok Blueprint and the Framework on Safeguarding the Financial Sector from Illicit Activities indicate a move toward a more integrated approach to financial crime, linking fraud prevention, illicit-fund detection, customer due diligence, transaction monitoring, and cooperation across the financial ecosystem.

For regulated financial businesses, the key issue will be whether the final Framework remains principally a statement of collective commitment or develops into concrete supervisory expectations. If detailed obligations or commitments are introduced, institutions may need to reassess their customer onboarding, mule-account controls, transaction-monitoring capabilities, information-sharing arrangements, escalation procedures, and governance structures.

Until the final Framework is officially available, however, institutions should distinguish between the BOT’s announced policy direction and legally or regulatory binding requirements. The publication of the final Framework—and any subsequent implementing measures—will therefore be important in determining the immediate compliance impact on banks, payment service providers, non-bank lenders, foreign exchange businesses, and other regulated financial-sector participants.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles