PDPA: New Section 30 Access Rules Put Data Subject Access Request Operations on a Compliance Clock

The Personal Data Protection Committee (PDPC) has issued a binding notification setting out detailed rules for data subjects exercising the right of access under section 30 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA).

Published in the Royal Gazette on 16 July 2026, the Notification will take effect after the expiration of 60 days from publication. It should therefore be treated as an immediate implementation project rather than simply a regulatory development to monitor.

The importance of the Notification lies in its operational detail. Section 30 already gives data subjects the right to access and obtain copies of personal data concerning them that is under a controller’s responsibility, as well as to request disclosure of the source from which personal data was obtained without their consent. The new rules now specify how requests must be received, verified, assessed, fulfilled, refused, charged for, and recorded.

For controllers, this moves data subject access requests (DSARs) firmly from privacy-notice language into operational compliance.

Controllers Must Make Relevant Information Accessible:

The Notification requires controllers to make available information that enables data subjects to exercise the section 30 right. This includes personal data collected directly from the data subject, personal data collected from other sources, and information concerning the source or acquisition of personal data obtained without the data subject’s consent.

The controller must also make accessible relevant information that it is required to provide under section 23 of the PDPA and relevant items contained in the controller’s records of processing under section 39 that the data subject is entitled to access.

This requirement makes data inventory and data mapping particularly important. A controller cannot respond effectively to an access request if it does not know where an individual’s data is stored, how it was obtained, and which systems or service providers hold it.

Mandatory Request Channels:

The Notification does not leave request channels entirely to the controller’s discretion.

At a minimum, controllers must permit requests to be submitted:

  • in person at the controller’s place of business or another contact location notified to data subjects under section 23; and
  • by registered mail sent to that location.

Controllers may provide additional electronic or other channels. A data subject may exercise the right personally or through an authorized representative.

This is a significant implementation point. An organization that currently accepts DSARs only by email or through an online privacy portal should review whether its procedure accommodates the channels expressly required by the Notification.

Controllers should also determine how requests received at reception desks, branch offices, HR functions, customer-service centers, or by post will be recognized as section 30 requests and routed immediately to the responsible team.

Requests Must Contain Prescribed Information:

A request must be made in writing or electronically and must contain specified information and supporting evidence.

Among other things, the request must identify the data subject, specify the requested access or copy and, where relevant, disclosure of the source of personal data obtained without consent, provide sufficient details of the data requested, and carry the signature or electronic signature of the data subject or authorized representative.

The Notification also sets out identity-verification requirements.

Where a data subject submits a request in person, official identification may be required. Where a request is made by registered mail, certified copies of relevant identification documents may be required. The controller may use alternative verification methods, but those methods must not create an unreasonable obstacle to the exercise of the right. Controllers may also request additional information where necessary to establish identity, verify the request, or communicate with the data subject, including identifiers and contact information already known to the data subject.

The practical challenge is to strike the correct balance. Insufficient authentication can result in disclosure of personal data to the wrong person, while excessive authentication requirements may improperly obstruct the exercise of the right.

Representatives Require Proper Authority:

The Notification expressly addresses requests submitted through representatives. An authorized representative must provide a power of attorney identifying the matter for which authority has been given, with the required stamp duty and signatures, together with appropriate identification documentation for the relevant parties. Alternative verification methods may again be used, provided they do not create an unreasonable obstacle.

Controllers should therefore review their procedures for requests submitted by lawyers, family members, guardians, employee representatives, and other authorized persons. A generic assumption that an email from a representative is sufficient may no longer be appropriate.

A 15-Day Initial Review Stage:

One of the most important procedural features of the Notification is an initial review stage.

After receiving a request, the controller must examine the request details, supporting documents, and whether the requester is the data subject or a genuinely authorized representative. This review must be completed without delay and no later than 15 days from receipt of the request. If the request or supporting documents are incorrect or incomplete, or if the controller cannot verify the requester, the controller must notify the requester to correct the request or provide additional documents.

The controller must provide a period of not less than 10 days for the requester to correct the deficiency. For purposes of the subsequent process, the request is treated as received when the corrected request or complete supporting documentation has been received. If the requester does not correct the deficiency within the specified period, the request is treated as abandoned. The controller must notify the requester accordingly, although the data subject remains entitled to submit a new request.

This makes DSAR intake more than a logging exercise. Controllers should be able to distinguish between receipt of an initial request, completion of the verification process, requests for additional information, and the point from which the substantive response period runs.

The Substantive Response Period Is 30 Days:

Where the request is complete, the requester has been verified, and no ground for refusal applies, the controller must fulfill the request without delay and no later than 30 days from receipt of the request. The Notification allows an extension where the request concerns a large volume of information or where another necessity prevents the controller from completing the request within the ordinary period.

Importantly, the permitted extension is no more than an additional 30 days. The controller must inform the data subject or authorized representative of the necessity for the extension and the relevant details. This corrects an important point appearing in some descriptions of the new regime: the official Notification does not provide for a further 60-day extension. For implementation purposes, organizations should therefore build their DSAR workflow around a 30-day substantive response period, with only a limited additional 30-day period where the conditions for extension are satisfied.

How Access Can Be Provided:

The Notification permits several methods of fulfilling a request.

A controller may:

  • allow the data subject to inspect relevant personal data;
  • prepare and provide copies of documents containing the relevant personal data; or
  • provide access, copies, or source information electronically or in another format agreed between the controller and the data subject.

Where the data subject submits the request electronically and does not request another format, the controller must provide the response electronically where this can reasonably be done. Controllers should therefore consider not only whether data can be found, but also whether it can be extracted into a format that can safely and intelligibly be provided to the requester.

Refusal Grounds Are Now More Operationally Defined:

The Notification provides greater detail concerning circumstances in which a controller may refuse to comply with a request.

A request may be refused where compliance would be contrary to law or a court order. Refusal may also be permitted where compliance would adversely affect the legally protected rights and freedoms of another person. The Notification expressly refers to matters including another person’s personal data, official secrets, trade secrets, copyright, and other intellectual property rights.

A controller may also refuse a request that is manifestly unfounded or that would impose an unreasonable burden on the controller. However, third-party information does not automatically justify refusing the entire request.

Where disclosure would affect another person’s rights and freedoms, the controller must comply with the request to the extent reasonably possible after balancing the relevant rights and interests. The Notification expressly contemplates deletion, redaction, or other measures that prevent disclosure of information that would adversely affect the third party. This makes document review and redaction a core part of DSAR compliance.

Employee DSARs May Become Particularly Significant:

For HR functions, the new rules could have substantial practical consequences.

Employee personal data is rarely located in a single personnel file. It may be distributed across HR information systems, payroll platforms, performance evaluations, email, internal messaging systems, access-control records, CCTV, workplace monitoring tools, expense systems, disciplinary records, and documents held by external service providers.

A section 30 request may therefore require coordination between HR, legal, IT, information security, facilities, and other business functions. The 30-day substantive response period means that organizations should establish internal search and escalation procedures before requests are received, rather than attempting to construct the process after the clock has started.

AI Systems Should Be Included in DSAR Readiness Testing:

Organizations deploying AI should also consider whether personal data contained in or processed through AI systems can actually be identified and retrieved when a section 30 request is received.

Depending on the architecture, relevant personal data may exist in prompts, uploaded documents, user profiles, interaction histories, logs, retrieved contextual information, generated outputs linked to identifiable individuals, or data stores supporting an AI application.

The Notification does not create separate rules for AI. The practical point is that the same access obligation applies where relevant personal data is held within an AI-enabled environment. Accordingly, it is not sufficient for a privacy notice simply to state that data-subject rights are available. The technical architecture must allow the organization to operationalize those rights within the applicable timetable.

Processor and Vendor Cooperation Should Be Tested:

The Notification places the legal obligation to respond on the controller, but much of the relevant personal data may be held by processors or other service providers.

Controllers should therefore review processor and vendor agreements to determine whether they contain adequate obligations concerning:

  • assistance with data-subject requests;
  • data searches and retrieval;
  • response times;
  • provision of copies in usable formats;
  • identification of relevant systems and repositories;
  • preservation of data during the request process; and
  • assistance with deletion, redaction, or other measures needed to protect third-party information.

A processor that is contractually permitted to take several weeks simply to begin searching for data may make it difficult for the controller to comply with its own regulatory timetable.

Fees Are Permitted Only in Defined Circumstances

The Notification also contains detailed rules on fees.

Where access is provided electronically and the controller does not need to prepare data in a special medium or incur direct delivery costs, the controller must not charge a fee. Fees may be charged in other cases, but they must be reasonable and must not exceed actual costs. Certain copying charges are also subject to maximum rates specified in the annex to the Notification.

Where requests are repetitive, involve large volumes of information, or impose a greater-than-normal burden, the controller may charge a reasonable fee having regard to its costs. The controller may also limit the scope or method of compliance to the extent necessary, taking into account both the data subject’s rights and the burden involved.

The Notification further permits controllers to waive or reduce fees for low-income data subjects or in other appropriate circumstances. If a fee will be charged, the controller must notify the data subject before or when exercising the right to charge it. Controllers should therefore avoid adopting a standard DSAR fee without first determining whether charging is permitted in the particular circumstances.

Record-keeping Is Mandatory:

Controllers must maintain records of requests, supporting documentation, and the action taken or refusal to act on each request for at least two years for verification and evidentiary purposes. Those records may be kept electronically.

Where a request is refused, the controller must notify the data subject or representative of the refusal and the reasons, and the refusal and its basis must also be recorded in the controller’s records maintained under section 39 of the PDPA.

This makes a DSAR register or case-management system increasingly important. The record should allow the controller to reconstruct the lifecycle of the request, including receipt, identity verification, deficiencies, internal searches, processor involvement, redactions, extensions, fees, disclosure, refusal, and final closure.

What Controllers Should Do Before the Notification Takes Effect:

Controllers should use the remaining implementation period to test whether their existing DSAR procedure can comply with the new rules in practice.

Priority areas include:

  • request channels — ensuring that in-person and registered-mail requests can be received, recognized, and logged, in addition to any electronic channels;
  • identity verification — establishing proportionate procedures for verifying data subjects and representatives;
  • initial review — implementing the 15-day assessment process and procedures for curing incomplete requests;
  • internal routing — identifying responsible contacts in HR, IT, marketing, customer service, security, legal, and other relevant functions;
  • data discovery — determining how personal data can be located across email, HR, CRM, cloud services, CCTV, monitoring systems, archives, and other repositories;
  • processor cooperation — testing whether processors and vendors can retrieve relevant information quickly enough;
  • third-party information — establishing review and redaction procedures;
  • deadline controls — monitoring the 30-day response period and any justified additional 30-day extension;
  • response formats — determining how inspection, copies, and electronic access will be provided;
  • fees — ensuring that charges are imposed only where permitted and within the applicable limits;
  • refusals — developing a documented process for assessing refusal grounds and issuing required explanations; and
  • records — maintaining evidence of requests and their handling for at least two years.

A practical way to test readiness is to run a mock DSAR involving an employee or customer whose information is spread across several systems and at least one external processor. That exercise is likely to identify operational weaknesses more effectively than simply reviewing the wording of the organization’s privacy notice.

Key Takeaways:

The new Notification materially changes the operational expectations surrounding section 30 access requests.

Controllers will need more than a general statement in their privacy notices that data subjects have a right of access. They need an end-to-end process capable of receiving requests through the required channels, verifying identity and authority, identifying deficiencies within the initial review period, locating data across internal and external systems, protecting third-party rights, producing the requested information, managing statutory deadlines, documenting refusals, applying fee rules correctly, and preserving evidence of compliance.

Two timing points deserve particular attention: the controller must conduct the initial review without delay and within 15 days, while a valid request that proceeds to fulfillment must generally be completed within 30 days, subject to a justified extension of no more than an additional 30 days.

For organizations with mature DSAR procedures, the immediate task should be a gap analysis against the Notification. For organizations that have treated access rights primarily as privacy-notice language, a more substantial operational implementation project is required. The key compliance question is now straightforward: if a real section 30 request arrived today, could the organization authenticate the requester, find the relevant personal data across all relevant systems and processors, review it for third-party information, provide it in the required manner, and demonstrate that every step was completed within the prescribed timetable?

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

Big Data: Thailand Approves National Strategy to Accelerate AI and Data-Driven Economy

Thailand’s Cabinet has acknowledged the draft National Big Data Strategy, establishing the country’s first comprehensive policy framework for the development and use of big data as a foundation for digital government, artificial intelligence (AI), and a data-driven economy.

The strategy is intended to provide a unified direction for government agencies to improve data management, strengthen digital infrastructure, and promote the practical use of data in both the public and private sectors.

Why the strategy matters:

Although the strategy is not legislation and does not itself impose new legal obligations, it signals the Government’s long-term policy direction. Businesses operating in Thailand—particularly technology companies, cloud service providers, AI developers, healthcare providers, financial institutions, and organizations handling government-related data—should expect increased public investment and regulatory attention in data governance and AI.

The strategy also reinforces the Government’s objective of using data as a strategic national asset to improve public administration, support economic growth, and enhance Thailand’s digital competitiveness.

Key objectives:

According to the announcement, the strategy seeks to:

  • establish an integrated national big data ecosystem;
  • improve evidence-based policy making through better use of government data;
  • support AI adoption across government and industry;
  • enhance Thailand’s digital competitiveness; and
  • promote responsible and systematic use of data.

The Government has also set measurable goals, including increasing the economic value generated from big data and positioning Thailand among the world’s leading countries in big data capability.

Four strategic pillars:

The strategy consists of four principal initiatives.

1. Building national data infrastructure

The Government plans to strengthen core digital infrastructure through initiatives such as:

  • Government Cloud;
  • Government Data Catalog; and
  • National Big Data Platform.

These projects are intended to improve interoperability and enable more effective data sharing among government agencies.

2. Expanding practical use of data

The strategy encourages wider use of data analytics to address national priorities, including:

  • healthcare;
  • tourism;
  • environmental management;
  • agriculture; and
  • trade and economic development.

This reflects the Government’s intention to move beyond data collection toward data-driven decision-making.

3. Accelerating AI adoption

A significant component of the strategy is the promotion of AI across the public and private sectors.

The Government intends to:

  • expand AI applications in government services and industry;
  • support development of Thai-language AI models; and
  • establish datasets suitable for AI development.

These initiatives may create opportunities for AI developers, cloud providers, data platform operators, and businesses offering AI-enabled solutions.

4. Developing human capital

Recognizing that technology alone is insufficient, the strategy also emphasizes workforce development by increasing the number of professionals with expertise in big data and AI.

The Government aims to significantly expand the pool of skilled personnel capable of supporting Thailand’s digital transformation.

Legal and regulatory implications:

The strategy itself does not amend Thailand’s existing legal framework, including laws governing personal data protection, cybersecurity, or digital government.

Nevertheless, it indicates that future regulatory and policy initiatives are likely to focus on:

  • enhanced government data governance;
  • improved standards for data interoperability;
  • greater integration of public-sector datasets;
  • expanded use of AI in government services; and
  • stronger digital infrastructure supporting government cloud and data-sharing initiatives.

Organizations participating in government projects or processing government-related data should therefore continue monitoring future implementing measures, technical standards, procurement requirements, and sector-specific regulations that may follow.

Looking ahead:

The National Big Data Strategy represents an important policy milestone in Thailand’s digital transformation agenda. While much of its implementation will depend on future projects, funding, and regulatory measures, the strategy demonstrates the Government’s commitment to treating data and AI as key drivers of economic development and public-sector modernization.

For businesses, the announcement suggests increasing opportunities in AI, cloud computing, digital infrastructure, and government technology, while reinforcing the importance of robust data governance and regulatory compliance.

Key takeaways:

  • Businesses involved in AI, cloud services, digital infrastructure, and government technology should monitor future implementing regulations, technical standards, and procurement initiatives arising from the strategy.
  • Thailand has adopted its first comprehensive national strategy for big data development.
  • The strategy serves as a policy framework rather than creating immediate legal obligations.
  • Four priorities include national data infrastructure, wider use of data analytics, AI adoption, and workforce development.
  • Government investment is expected to accelerate in cloud infrastructure, data platforms, and AI ecosystems.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand’s Response to the 12.5% U.S. Section 301 and the request for Further Exemptions

Introduction

On July 23, 2026, the Office of the United States Trade Representative (“USTR”) issued its final action under Section 301 of the Trade Act of 1974 in the Forced Labor Investigation, covering approximately 60 trading partners. Thailand was placed in the higher 12.5% tariff band, effective July 24, 2026, alongside Vietnam, the Philippines, and Singapore. Thailand received this rate because the United States found it had not adopted, committed to, or partially implemented a prohibition on the import of goods produced with forced labor, unlike a smaller group of trading partners assigned a 10% rate.

A separate and still-ongoing USTR proceeding, the Excess Capacity Investigation, covers 16 trading partners, including Thailand, and examines alleged structural excess capacity in manufacturing sectors. This investigation has not concluded and no tariff has yet been imposed under it. If the United States ultimately takes action on this second track as well, Thai exporters could face a further tariff, with some commentators estimating a combined exposure of up to 25% across both proceedings.

Domestically, Prime Minister Anutin Charnvirakul has directed six ministries and the Royal Thai Police to address both issues. Externally, the Ministry of Commerce (“MOC”) continues to negotiate an Agreement on Reciprocal Trade (“ART”) with the United States and has requested exemptions for a further 78 tariff lines, while stating that its negotiating position will not compromise the interests of farmers, the public, or businesses.

Key Concerns and Thailand’s Response

Following the Cabinet meeting of July 27, 2026, the Cabinet Secretariat issued an urgent instruction to the Ministries of Finance, Foreign Affairs, Agriculture and Cooperatives, Commerce, Labor, and Industry, and to the Commissioner-General of the Royal Thai Police. Each agency has been directed to prepare supporting data and response measures, identify the units responsible for each task, and set clear implementation timeframes.

1. Forced Labor

The United States has emphasized the need for stronger measures against goods produced with forced labor, including enhanced Human Rights Due Diligence (“HRDD”) and supply-chain traceability. The Ministry of Labor leads this response, together with the Ministries of Commerce and Industry. Their tasks are to accelerate enforcement of existing laws and regulations, compile lists of at-risk products and industries, and develop origin-certification and traceability systems covering the full production chain, so that Thailand can substantiate its position in discussions with the United States and other trading partners.

Thailand does not yet have directly enforceable legislation on this point. Thailand’s Ministry of Justice has been developing a draft Act on the Promotion of Responsible Business Conduct (also referred to as the mandatory Human Rights and Environmental Due Diligence, or “HRDD/mHREDD,” bill) since 2025, intended to align with the UN Guiding Principles on Business and Human Rights. The bill remains under development, and its legislative timeline, including submission to Parliament, has not been firmly fixed as of this update. Businesses should not wait for enactment before building supply-chain records.

2. Structural Excess Capacity

This issue is the subject of the separate, ongoing USTR Excess Capacity Investigation described above. It did not itself determine Thailand’s placement in the 12.5% forced-labor tariff band, though it could result in additional measures. The MOC leads Thailand’s response, with the Ministries of Industry, Agriculture and Cooperatives, and Finance. The agencies must compile risk lists at the product and industry level, integrating data on production capacity, inventory levels, government subsidies, price structures, export volumes, and country of origin. They must also investigate false origin claims and the use of Thailand as a trans-shipment point to evade trade measures imposed by importing countries.

Government support policy is also shifting direction. Future assistance is intended to target productivity, cost reduction, technology adoption, value addition, and greater use of local content. Subsidies that expand production capacity or increase supply beyond market demand are to be avoided, as they could themselves be cited as evidence of excess capacity. In discussions with USTR, Thailand has represented that domestic capacity utilization in the targeted industries generally runs between 70% and 90%, with no industry operating below 60%.

Exposure and Exemptions Secured

Thailand has obtained exemptions for 2,120 tariff lines under Annex II, Part A, representing approximately 61.6% of tariff lines and US$56.2 billion in exports, or roughly half the value of Thai goods exported to the United States. This is a substantial increase from the 471 items exempted under an earlier, preliminary list. Goods already subject to duties under Section 232 of the Trade Expansion Act of 1962 (for example, automobiles, steel, aluminum, and copper) are not subject to duplicate Section 301 duties. This overlap covers roughly US$7 billion of the remaining non-exempt goods.

Taking both the exemption list and the Section 232 overlap into account, the MOC estimates that approximately 28% of Thai exports to the United States remain exposed to the additional 12.5% tariff. Leading non-exempt industrial products include car and truck tires, machinery, cameras, air conditioners, and vehicle wheels and rims. Products such as jewelry, milled rice, pet food, canned tuna, and processed shrimp likewise remain outside the current exemption list and are among the items for which Thailand is now seeking relief (see below).

Solar cells and modules face particularly high cumulative exposure. In addition to the Section 301 tariff, U.S. antidumping duties on Thai-origin solar cells have been assessed at rates of up to approximately 203%, and countervailing duties at rates of up to approximately 800%, reflecting separate U.S. Commerce Department determinations on dumping and subsidization. Combined with the Section 301 tariff, total cumulative duties on affected solar shipments can substantially exceed 800%, and in the highest cases run well over 1,000%.

The Request for 78 Additional Tariff Lines

The MOC has submitted a proposal covering seven product groups and 78 tariff lines, which are agriculture and food security, consumer and household goods, medical and public-health products, electronics and semiconductors, vehicles and parts, machinery components and industrial equipment, and handicrafts and value-added products. Illustrative items include rice and Thai hom mali (jasmine) rice, maize, coconuts, orchids, cassava and cassava starch products, and fishery products, alongside jewelry, dog and cat food, milled rice, medical rubber gloves, tuna, processed bonito, fresh and cooked shrimp, and sauces and seasonings. The Commerce Ministry has separately referenced a further proposal covering 13 additional items, though it has not clarified whether these form part of the 78-line request or a distinct submission.

Thailand’s negotiating position is subject to three limits. It will not cross the interests of farmers, the interests of the public, or the rights of businesses. Thailand has indicated it is prepared for technical-level ART talks and is awaiting a determination from USTR, after which the MOC has suggested negotiations could conclude within a matter of weeks.

Key Takeaways

  • Solar cells are a particular outlier, combined Section 301, antidumping, and countervailing duties can push cumulative exposure well above 800%, in some cases exceeding 1,000%.
  • The 12.5% tariff under Section 301 currently in effect stems from the Forced Labor Investigation only. The separate Excess Capacity Investigation remains open and could result in an additional tariff if concluded against Thailand.
  • After accounting for the Annex II exemption list and the Section 232 overlap, approximately 28% of Thai exports to the United States remain exposed to the 12.5% tariff.
  • Six ministries and the Royal Thai Police have been directed to address forced labor and excess capacity concerns, with traceability and origin certification central to the response.
  • A mandatory human rights and environmental due diligence bill is under development by the Ministry of Justice, and its legislative timeline is not yet fixed. Businesses should not wait for enactment before building supply-chain records.
  • A request for 78 further exemption lines across seven product groups remains pending, and technical-level ART talks await a USTR determination.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Tightens Registration Requirements for Partnerships and Limited Companies with Foreign Participation

Nominees: A Threat to Thailand’s Economy

Nominee arrangements — in which Thai nationals hold shares or capital contributions on behalf of foreign investors — have remained a longstanding compliance concern under the Foreign Business Act B.E. 2542 (1999) (the “FBA”). The Department of Business Development (the “DBD”) has now shifted a significant part of that scrutiny to the registration stage itself.

The use of nominees is a major national concern that undermines Thailand’s economic and business security by distorting market competition, reducing tax revenue, and eroding investor confidence. Foreign operators who rely on nominees unfairly bypass statutory business restrictions, undercutting law-abiding foreign investors and overwhelming Thai small and medium-sized enterprises (SMEs) that cannot compete against superior capital and resources — ultimately contributing to job losses and business closures. Nominee structures also facilitate tax evasion, money laundering, and other illicit financial activity, which compromises state revenue collection and damages Thailand’s international reputation by exposing gaps in regulatory and legal enforcement.

For these reasons, the rigorous inspection of, and crackdown on, nominee arrangements is a critical measure to protect the country’s economic interests, ensure fair competition, and safeguard the long-term stability of the Thai economy.

Background

Initial screening at the company incorporation stage previously offered partial protection against nominee risk by verifying Thai investment capital. However, bad actors circumvented these controls through subsequent corporate amendments — transferring shares or directorships to foreign nationals only after the company had already secured initial approval.

Legal Basis

To close this loophole, the DBD issued the “Central Partnership and Company Registrar Order No. 2/2569, Prescribing the Criteria and Supporting Documents for Applications for the Registration of the Incorporation and Amendment of Partnerships and Limited Companies Where Foreign Nationals Participate in the Investment or Hold Signing Authority in Partnerships and Limited Companies” (the “Order”). The Order took effect on 1 August 2026.

The Order extends DBD oversight across the full business lifecycle — from incorporation through post-registration amendments — to prevent unauthorized structural changes, while imposing stricter documentation requirements on all relevant registration applications.

It consolidates existing requirements by repealing two earlier orders:

  1. Order No. 2/2568, dated 1 December 2025 (B.E. 2568), concerning the registration of incorporation involving foreign investment, foreign directors, or foreign authorized signatories in a legal entity; and
  2. Order No. 1/2569, dated 16 March 2026 (B.E. 2569), concerning amendment registrations admitting foreign nationals as partners or as authorized signatory directors.

According to its preamble, the Order is intended to enhance the credibility of the commercial register, to prevent the concealment or disguise of funds derived from unlawful conduct through nominee arrangements, and to deter Thai nationals from providing assistance or support to, or jointly operating a business with, foreign nationals in the nature of a nominee.

New Legal Requirements

1. Registration of Incorporation

The additional documentary requirements apply to an application for the registration of incorporation in either of the following cases:

  • a partnership or limited company in which a foreign partner or shareholder contributes, or holds, less than 50% of the capital contribution or registered capital; or
  • a limited company with no foreign shareholder, where a foreign national serves as a director authorized to sign — whether solely or jointly — so as to bind the company.

Supporting documents required at incorporation

Applicants falling within the above categories must submit a Letter of Clarification on Investment, in the form annexed to the Order, together with the following bank statements:

  • a statement of the account from which each Thai partner or shareholder made payment, covering the three months prior to the date of payment and evidencing a withdrawal or transfer consistent with the amount and date of payment;
  • a statement of the account of the managing partner or director who received the funds, evidencing receipts consistent with the amount and date of payment from each partner and shareholder; and
  • where the receiving account is also the account relied upon to evidence payment under the first item above, an additional statement covering the three months prior to the date of receipt.

The third requirement addresses situations in which the managing partner or director settles their own contribution from funds already held in the receiving account, rather than by a traceable transfer. In such cases, the source of those funds must be explained separately in the Letter of Clarification.

2. Amendment Registrations Involving Foreign Nationals

A Letter of Confirmation of Investment, also in the form annexed to the Order, must be submitted with an application to register an amendment admitting a foreign national as a partner, or appointing a foreign national as an authorized signatory director, in either of the following cases:

  • a partnership in which all partners were previously Thai nationals, or in which foreign partners held 50% or more of the capital contribution, where the amendment results in foreign partners holding less than 50% and no foreign national serving as managing partner; or
  • a limited company in which all directors authorized to bind the company were previously Thai nationals, where an amendment to the directors — or to the number or names of the directors signing to bind the company — results in a foreign national holding sole or joint signing authority.

3. Additional Requirements for Recently Incorporated Entities

Where a partnership or limited company incorporated on or after 1 August 2026 submits an amendment application of the type described above within one year of its registration as a juristic person, it must additionally submit the amendment version of the Letter of Clarification on Investment, together with a bank statement evidencing that the entity — or the managing partner or director on its behalf — received the full amount of the capital contributions or share payments called up at incorporation.

This requirement addresses the sequencing of transactions whereby an entity is incorporated with Thai partners or directors and a foreign national is introduced shortly thereafter.

Legal Significance

The Order does not introduce a new prohibition; nominee arrangements already constitute an offence under Section 36 of the FBA. Its significance instead lies in shifting the evidentiary burden to the point of registration, and in the personal declaration now required of the signatory.

Under the Letter of Confirmation of Investment, the managing partner or authorized director confirms that all partners have genuinely made and paid their capital contributions, that all shareholders have genuinely paid for their shares, and that no Thai national has provided assistance or support to, or jointly operated a business with, a foreign national in the nature of a nominee. The signatory further acknowledges the following penalties:

  • Section 36 of the FBA: imprisonment not exceeding 3 years, a fine of THB 100,000 to 1,000,000, or both;
  • Section 137 of the Criminal Code (false statements to an official): imprisonment not exceeding 6 months, a fine not exceeding THB 10,000, or both; and
  • Section 267 of the Criminal Code (causing a false entry in a public document): imprisonment not exceeding 3 years, a fine not exceeding THB 60,000, or both.

Key Takeaways

  • Existing entities are unaffected until they register a qualifying amendment, at which point the Order applies in full.
  • The Order took effect on 1 August 2026 and applies to partnerships and limited companies in which foreign participation is below 50%, and to limited companies in which a foreign national holds signing authority.
  • Documentary requirements now extend to bank statements evidencing both the payment and receipt of capital contributions and share payments, supported by a prescribed clarification letter.
  • Amendment registrations introducing a foreign partner or foreign signatory require a signed Letter of Confirmation of Investment, which carries personal criminal exposure for the signatory.
  • Entities incorporated on or after the effective date are subject to additional requirements if a qualifying amendment is registered within their first year.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Class-Action Signal Raises the Stakes for Online Consumer Complaints

Background:

Thailand’s Office of the Consumer Protection Board (OCPB) has announced that it is developing a national action plan to strengthen consumer protection for products sold through online channels. The initiative is intended to improve coordination among government agencies responsible for digital commerce, online marketplaces, direct-selling businesses, and consumer protection, while establishing clearer responsibilities and performance indicators.

Although the proposed action plan itself does not introduce new legal obligations, one aspect deserves particular attention from businesses. The OCPB has been directed to study the broader use of class-action proceedings where large numbers of consumers suffer substantially similar losses.

Thailand already recognizes class actions under the Civil Procedure Code, but they have historically been used relatively infrequently. The latest policy initiative indicates that consumer regulators are considering greater reliance on collective litigation as an enforcement mechanism where systemic consumer harm is identified, particularly in the rapidly expanding digital marketplace.

Why this matters:

The announcement does not create a new statutory cause of action or impose additional regulatory requirements on online platforms. However, it signals a possible shift in enforcement priorities.

Traditionally, consumer complaints have often been addressed individually through customer service channels or administrative dispute resolution. A greater emphasis on class actions would instead encourage regulators and claimants to examine recurring patterns of similar complaints across multiple consumers.

This approach could significantly increase litigation exposure where businesses fail to identify or address systemic issues affecting multiple customers.

Practical implications for businesses:

Online marketplaces, e-commerce operators, social-commerce platforms, direct-marketing businesses, manufacturers, importers, brand owners, payment providers, logistics companies, and merchants should consider strengthening internal governance before any formal policy changes occur.

Particular attention should be given to:

  • identifying recurring complaints involving the same product, seller, advertisement, or defect;
  • maintaining reliable seller identification and beneficial ownership information;
  • preserving documentation relating to product origin, regulatory approvals, and compliance certifications;
  • implementing effective notice-and-takedown procedures for unlawful or unsafe products;
  • escalating recurring safety or quality issues through documented internal processes;
  • reviewing refund, replacement, recall, and remediation procedures;
  • preserving evidence, including listings, livestreams, advertisements, customer communications, payment records, and delivery information; and
  • reviewing merchant agreements to ensure appropriate cooperation, indemnification, and information-sharing obligations.

Repeated complaints that appear insignificant when viewed individually may later be relied upon collectively to establish knowledge of defects, inadequate remediation, misleading advertising, or broader compliance failures.

Intellectual property considerations:

The proposed enforcement direction is also relevant for intellectual property owners.

Counterfeit and unauthorized products frequently give rise to overlapping legal issues extending beyond trademark or copyright infringement. A single product listing may simultaneously involve misleading advertising, product safety concerns, inaccurate labeling, warranty issues, and consumer protection violations.

Accordingly, brand owners should avoid treating online enforcement as solely an intellectual property exercise. Internal coordination between IP, consumer protection, product compliance, marketplace enforcement, and litigation teams will become increasingly important where multiple consumer complaints concern the same products or sellers.

Data privacy considerations:

Any increase in collective consumer litigation is likely to require broader preservation and analysis of personal data.

Businesses may need to process information relating to customers, merchants, payment transactions, logistics providers, communications, complaint histories, and digital evidence. Such processing should continue to comply with Thailand’s Personal Data Protection Act.

Organizations should therefore review:

  • legal bases supporting evidence preservation and regulatory disclosures;
  • access controls for complaint and investigation datasets;
  • secure information-sharing procedures with regulators and external advisers;
  • contractual obligations imposed on processors, including marketplaces, call centers, logistics providers, and cloud service providers;
  • document retention policies and litigation-hold procedures; and
  • incident response plans addressing potential personal data breaches involving consolidated claimant information.

Importantly, the prospect of consumer enforcement should not be interpreted as permitting unrestricted disclosure of customer or merchant data. Any disclosure should remain subject to applicable legal authority, proportionality, security safeguards, and appropriate documentation.

Looking ahead:

The OCPB’s announcement remains a policy initiative rather than a binding regulatory change. Nevertheless, it provides an early indication that consumer enforcement may increasingly focus on systemic patterns of misconduct affecting multiple consumers rather than isolated disputes.

Businesses that rely on digital sales channels should therefore begin assessing whether existing compliance, complaint-handling, and evidence-preservation processes would adequately support regulatory investigations or collective litigation involving large groups of consumers.

Key takeaways:

  • Organizations should ensure that complaint investigations and evidence preservation continue to comply with Thailand’s Personal Data Protection Act, particularly where large volumes of personal data are involved.
  • The OCPB is considering greater use of class-action proceedings for widespread consumer harm arising from online commerce.
  • No new legal obligations have been introduced, but the initiative signals a potentially significant shift in enforcement priorities.
  • Businesses should strengthen systems for identifying recurring complaints and preserving evidence relating to products, sellers, and customer interactions.
  • Online platforms and brand owners should integrate consumer protection, product compliance, and intellectual property enforcement rather than treating them as separate functions.

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

Breaking Down Government Data Silos: New Rules on Inter-Agency Sharing of Personal Information

A new Royal Decree has established a legal framework requiring government agencies to share personal information under their control with other government agencies for specified electronic data-linkage purposes.

The Royal Decree on Disclosure of Personal Information Controlled by Government Agencies to Other Government Agencies B.E. 2569 (2026) (the “Royal Decree”) represents an important development in the government’s efforts to move away from fragmented, agency-specific databases toward greater interoperability of public-sector information.

The measure is intended to enable government agencies to use more complete and accurate information in policymaking, public services and targeted welfare programs, while reducing the burden on individuals of repeatedly submitting information already held by the government. The framework is also intended to contribute to greater transparency and more effective law enforcement.

Legal basis for inter-agency disclosure:

The Royal Decree is issued pursuant to Section 24(9) of the Official Information Act B.E. 2540 (1997).

Section 24 of the Official Information Act establishes, as a general rule, that a government agency may not disclose personal information under its control to another government agency or another person without the prior or contemporaneous written consent of the person concerned, subject to specified statutory exceptions.

Section 24(9) permits disclosure in other cases prescribed by Royal Decree.

The new Royal Decree uses this statutory mechanism to provide a specific legal basis for government-to-government disclosure of personal information falling within its scope. As a result, qualifying disclosure under the Royal Decree does not depend on obtaining the individual’s written consent on each occasion.

This is important because large-scale government data interoperability would be difficult to implement if each transfer of information between government agencies required separate consent from every affected individual.

From isolated databases to connected government:

The policy underlying the Royal Decree is broader than simply permitting one government agency to send information to another.

Government agencies hold significant amounts of information about individuals, but that information has traditionally been maintained within separate administrative systems. Where relevant information is distributed among different agencies, the government may not have ready access to the complete information required for policymaking, public services or welfare administration.

The Royal Decree is intended to address this fragmentation by enabling electronic linkage of personal information held across government agencies.

The stated objectives include allowing government policies and measures, government services and targeted welfare programs to be based on accurate and complete information. Greater data linkage is also intended to improve the efficiency of government services, reduce administrative burdens on the public, promote transparency and enhance the effectiveness of law enforcement.

In practical terms, the framework supports a move toward the principle that individuals should not continually be required to provide one government agency with information that is already held by another government agency where the conditions for lawful data linkage are satisfied.

Government agencies may be required to disclose information:

A significant feature of the Royal Decree is that it does not merely provide government agencies with a general permission to share personal information.

It establishes a framework under which a government agency controlling personal information must disclose that information to another government agency where the information is requested for purposes falling within the Royal Decree.

The relevant data linkage is intended to support the preparation and provision of government services and the provision of targeted welfare through electronic means.

This gives the Royal Decree practical significance beyond an ordinary exception to a confidentiality rule. It provides the legal infrastructure for systematic government data interoperability.

The receiving agency also assumes obligations:

Greater availability of government-held information is accompanied by safeguards.

A government agency requesting and receiving personal information must safeguard that information. Importantly, it may not further disclose the information to an outside person.

This restriction is an important limitation on the scope of the new regime. The Royal Decree should therefore not be understood as making personal information freely transferable simply because it has entered an interconnected government information system.

The legal authorization concerns disclosure within the framework established by the Royal Decree. Once information has been received, the recipient agency remains responsible for protecting it and complying with the restrictions applicable to its subsequent disclosure.

The required safeguards are also linked to criteria and conditions prescribed by the competent authority and cybersecurity requirements. Consequently, implementation of the Royal Decree is as much an information-governance issue as a data-access issue.

Targeted welfare and government services:

One of the clearest practical applications of government data linkage is the provision of targeted welfare.

Eligibility for government assistance may depend on information maintained by several different authorities. Without data linkage, individuals may have to obtain documents from one agency and submit them to another, while the agency administering the benefit may have difficulty independently establishing a complete picture of the applicant’s circumstances.

Electronic linkage can potentially change this process.

Where legally permitted, the administering agency may obtain relevant information directly from government data already available elsewhere. This can make eligibility assessment more accurate, reduce duplicate documentation and enable welfare programs to be directed more effectively toward intended recipients.

The same principle can apply more broadly to government services. Greater interoperability can reduce repeated requests for information and allow government agencies to make administrative decisions using more complete information.

Transparency and law enforcement:

The Royal Decree also has implications beyond welfare and administrative services.

The stated rationale includes increasing transparency within government and improving the effectiveness of law enforcement. Information that appears unremarkable when held in a single agency’s database may have greater significance when lawfully linked with information held by other agencies.

Inter-agency data linkage can therefore provide government authorities with a more complete information base for identifying inconsistencies, verifying information and carrying out their statutory functions.

This capability may be particularly relevant where investigations or enforcement activities require information held by several government bodies.

However, the Royal Decree should not be characterized as creating a general law-enforcement database or an unrestricted investigative power. Its significance lies in providing a statutory mechanism for disclosure and electronic data linkage within the scope established by the Royal Decree.

Data sharing does not mean unrestricted data use:

An important compliance point is the distinction between access to information and freedom to use or disclose that information.

The fact that one government agency is legally entitled to obtain information from another does not mean that information becomes unrestricted once transferred.

Government agencies implementing data-linkage arrangements should therefore consider controls covering at least:

  • the authority and purpose for requesting information;
  • identification of the information required;
  • authentication of requesting agencies and authorized personnel;
  • access controls within the receiving agency;
  • secure electronic transmission;
  • logging and traceability of access and transfers;
  • cybersecurity safeguards;
  • retention and management of linked information; and
  • controls preventing unauthorized onward disclosure.

These controls are particularly important because increased interoperability can increase the consequences of inadequate security. A weakness in one interconnected system may potentially expose information originating from several agencies.

Relationship with personal data protection requirements:

The Royal Decree should also be understood within the broader legal framework governing personal information.

Its immediate statutory basis is the Official Information Act, and it establishes a specific mechanism permitting inter-agency disclosure that would otherwise be subject to the restrictions in Section 24 of that Act.

However, the existence of a statutory basis for disclosure should not automatically be equated with unlimited authority to process the information for any subsequent purpose.

Government agencies participating in data-linkage arrangements should therefore identify the legal authority supporting each stage of the information lifecycle—including collection, disclosure, receipt, use, retention, security and any subsequent disclosure—and consider other applicable personal data protection and cybersecurity requirements.

The distinction is particularly important as government systems become increasingly interconnected. Legal authority to receive information is only one component of lawful and responsible data governance.

A significant step toward data-driven government:

The Royal Decree represents a structural change in the management of government-held personal information.

The traditional model in which each government agency maintains its own information and individuals repeatedly provide substantially the same information to different authorities is increasingly being replaced by a model based on controlled interoperability.

If implemented effectively, the new framework should enable government agencies to make greater use of information already available within the public sector, improve the accuracy of public services and welfare programs, and reduce unnecessary administrative burdens on individuals.

The corresponding challenge is governance.

The more effectively government information systems are connected, the more important it becomes to ensure that access is authorized, purposes are properly defined, information is adequately protected and subsequent disclosure remains controlled.

The Royal Decree therefore represents not simply an expansion of government access to data, but a move toward a more integrated model of public-sector data governance.

Key Takeaways:

  • The Royal Decree marks an important shift from government data held in separate institutional silos toward controlled, interoperable public-sector data infrastructure.
  • The Royal Decree establishes a statutory mechanism for the disclosure of personal information between government agencies for qualifying electronic data-linkage purposes.
  • Its legal basis is Section 24(9) of the Official Information Act, which allows exceptions to the general restriction on disclosure of government-controlled personal information without written consent.
  • The framework goes beyond merely permitting voluntary data sharing and supports systematic interoperability between government information systems.
  • A government agency receiving information under the framework must safeguard the information and is restricted from further disclosure to an outside person.
  • The framework is intended to support more accurate policymaking, more efficient government services and targeted welfare, reduced administrative burdens on the public, greater transparency and more effective law enforcement.
  • Government agencies should not treat authorization to receive information as unrestricted authority to use or further disclose it. Purpose limitation, access controls, cybersecurity and information governance remain central to implementation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

From Voluntary Guidance to Legal Accountability: The Changing Rules for Digital Platforms

Digital platform regulation is entering a new phase. Recent developments indicate a shift from a framework centered largely on registration, disclosure, and risk management toward a more substantive model addressing platform conduct, seller accountability, fee transparency, and potentially the allocation of liability between platforms and businesses operating through them.

Two developments illustrate this direction particularly well. The first is the proposed Digital Platform Economy Act, which is being developed as a broader statutory framework for the platform economy. The second is the Electronic Transactions Development Agency (ETDA) Guideline on Transparency and Fairness in Digital Platform Service Fees, which establishes voluntary best practices for the disclosure and adjustment of platform fees. Although the guideline is not mandatory and the proposed Act has not yet been enacted, considered together they provide a useful indication of the regulatory principles increasingly shaping oversight of digital platforms: transparency, fairness, accountability, and greater protection for users and consumers.

A New Regulatory Framework for Digital Platforms:

Digital platform services are currently regulated under the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification. The existing regime establishes notification requirements and imposes various obligations depending on the nature, size, and risk profile of a platform. The proposed Digital Platform Economy Act would represent a significant further development. The government has accelerated work on the legislation, with the current policy timetable contemplating submission to the Cabinet before the draft proceeds to Parliament. As the legislation remains under development, however, both its provisions and legislative timetable remain subject to change.

The emerging framework indicates several areas that platform operators should monitor closely. These include registration and disclosure of information concerning platform operations and revenue, as well as measures intended to give regulators greater visibility over businesses participating in the platform economy. Territorial scope will be particularly important for multinational businesses, since a platform providing services into the local market may potentially become subject to regulatory requirements even where the operator does not have a conventional physical presence in the jurisdiction.

Another important area concerns businesses and individuals offering goods or services through platforms. The regulatory direction increasingly places platforms in the position of gatekeepers rather than merely passive intermediaries. Existing regulatory measures already require certain platforms to obtain and verify seller information and implement risk-management measures concerning goods and services offered through their systems. The proposed legislation appears likely to develop this approach further, making seller onboarding, identity verification, record keeping, monitoring, and enforcement increasingly important compliance functions rather than merely commercial processes.

The Emerging Question of Platform Liability:

Perhaps the most significant issue to monitor is the extent to which a platform may bear responsibility for harm arising from transactions conducted through its service. Platform operators have traditionally characterized themselves as intermediaries connecting independent sellers with customers, and their terms and conditions commonly distinguish the platform from the seller responsible for the underlying goods or services.

The proposed regulatory approach may reduce the practical significance of that distinction. Discussions surrounding the Digital Platform Economy Act contemplate circumstances in which platforms could bear joint responsibility for consumer harm, particularly where the platform fails to perform duties imposed on it. The precise scope of any liability will depend on the final statutory language, including the conduct that triggers liability, available defenses, and the relationship between the new regime and existing consumer protection laws.

If enacted broadly, such liability could materially alter the allocation of risk in the platform economy. Seller verification and monitoring would no longer be viewed simply as regulatory procedures; they could become directly relevant to a platform’s financial exposure when consumers suffer loss. Contractual provisions placing responsibility on sellers, including indemnities, may remain important but would not necessarily protect a platform from independent statutory liability. Platform operators should therefore monitor the liability provisions particularly closely as the draft progresses.

Fee Transparency and Fairness:

While the proposed Act represents the potential development of mandatory statutory obligations, ETDA has adopted a softer regulatory approach to another significant platform issue: fees. Its Guideline on Transparency and Fairness in Digital Platform Service Fees is intended as voluntary best practice rather than direct price regulation. The guideline does not prescribe maximum commissions or other charges. Instead, it focuses on whether users can understand what they are being charged, what services they receive in return, and how changes to those charges are made.

Platforms are encouraged to present fee information clearly and in an accessible manner, including an explanation of individual fee items, the services or benefits associated with them, and the basis or method used to calculate the charges. This is particularly relevant where the actual cost of participating on a platform extends beyond a headline commission and may include advertising, promotional, affiliate, payment-related, or other service fees. The regulatory concern is therefore not simply whether a particular commission is high or low, but whether users can reasonably determine and evaluate the overall economic cost of using the platform.

The guideline also addresses changes to platform fees. It recommends that users receive at least 15 days’ advance notice of fee changes, together with information concerning the reason for the change, its scope and potential impact, and channels for inquiries or feedback. The guideline also contemplates a consultation process in connection with fee changes. Platforms should therefore distinguish between merely notifying users that a fee will change and maintaining a process that reflects the broader principles of transparency, consultation, and fairness contemplated by the guideline.

Fairness extends beyond disclosure. Platforms are encouraged to avoid unnecessary duplication of charges and to distinguish clearly between compulsory fees and charges for additional services. Optional services should correspond to genuine additional benefits rather than becoming effectively mandatory through the design or operation of the platform. The objective is not direct government control of platform pricing, but a framework in which platforms can explain how fees are determined and users can understand the true costs of participating in the platform ecosystem.

From Voluntary Guidance to Legal Accountability:

Considered separately, the proposed Digital Platform Economy Act and the fee guideline address different regulatory issues. Considered together, however, they reveal a broader trajectory. The fee guideline represents soft regulation, under which regulators articulate expectations concerning fair market conduct and encourage platforms voluntarily to incorporate those principles into their business practices. The proposed legislation points toward harder regulatory intervention, potentially involving registration, disclosure, seller verification, statutory duties, enforcement mechanisms, and greater responsibility for consumer harm.

This distinction is important for businesses. Voluntary guidance should not necessarily be treated as irrelevant simply because it does not create directly enforceable obligations. Such guidance may establish regulatory expectations concerning reasonable industry conduct, identify practices receiving regulatory scrutiny, and indicate areas in which more formal intervention could eventually follow if voluntary measures prove insufficient.

The broader development is therefore not simply an increase in the number of rules applicable to digital platforms. It reflects a gradual change in the regulatory conception of the platform itself. As platforms exercise greater control over seller admission, product visibility, payment mechanisms, fees, and transactions, regulators increasingly expect them to accept corresponding responsibilities for how those ecosystems operate.

Preparing for the Next Stage of Platform Regulation:

Platform operators need not wait for the proposed legislation to be enacted before reviewing their compliance architecture. Seller onboarding and verification procedures should be assessed to determine what information is collected, how identities and business credentials are verified, how information is updated, and what happens when inaccurate information or unlawful activity is detected. Systems should also retain sufficient records to demonstrate that verification, monitoring, complaints, and enforcement procedures have actually been followed.

Fee structures warrant similar attention. Platforms should consider whether users can readily identify the overall economic cost of using their services and whether compulsory fees, optional services, promotional charges, advertising costs, and other charges are adequately explained. Procedures for changing fees should also be reviewed against the transparency, advance-notice, and consultation principles reflected in ETDA’s guideline.

Finally, contractual arrangements with sellers should be considered together with operational compliance. If the new legislation imposes independent statutory duties on platforms, contractual provisions allocating responsibility entirely to sellers may have limited effect against claims brought directly against the platform. Indemnities, suspension rights, seller information obligations, insurance arrangements, record keeping, and mechanisms for recovering losses should therefore form part of a broader risk-management framework rather than being treated as substitutes for regulatory compliance.

Key Takeaways:

  • Digital platform regulation is moving beyond registration and disclosure toward greater operational accountability.
  • The proposed Digital Platform Economy Act may expand requirements concerning platform registration, business information, seller verification, platform conduct, and consumer protection. Its final provisions should be monitored as the legislative process progresses.
  • Potential joint liability for consumer harm may be one of the most significant developments because it could alter the traditional allocation of responsibility between platforms and independent sellers.
  • ETDA’s fee guideline remains voluntary and does not constitute direct price regulation, but it establishes regulatory expectations concerning fee transparency, fairness, advance notice, and consultation.
  • Platform operators should consider reviewing seller verification, monitoring, fee disclosures, change-management procedures, contractual risk allocation, and record-keeping systems before the new statutory framework is finalized.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand-Australia Strategic Partnership 2026–2029: Advancing Cybersecurity, Economic Resilience, Cross-Border Crime Cooperation, and Support for SMEs and Startups

Earlier, Thailand’s Cabinet approved the Joint Plan of Action to Implement the Thailand-Australia Strategic Partnership for 2026–2029. The four-year framework succeeds the 2022–2025 Plan and will be signed during the Thai Prime Minister’s official visit to Australia on 17–20 August 2026. It reaffirms the Strategic Partnership elevated in 2020 and provides a practical roadmap for cooperation across five pillars: political and security affairs; economic and trade relations; sectoral collaboration; people-to-people links; and regional and sub-regional engagement (including ASEAN, the Mekong, and the Indo-Pacific).

Two accompanying Joint Statements—one on combating transnational crime and one on strengthening economic cooperation—were approved in parallel. Together they signal a pragmatic, results-oriented deepening of ties with direct relevance for businesses, technology firms, and innovation ecosystems in both countries.

Cybersecurity and Digital Cooperation within the Security Pillar:

The political and security pillar explicitly covers defense cooperation, non-traditional security challenges (including cyber), good governance, and critical technologies. This builds on the existing Memorandum of Understanding on Cyber and Digital Cooperation between Thailand’s Ministry of Digital Economy and Society and Australia’s Department of Foreign Affairs and Trade. That MoU promotes information exchange, best-practice sharing on cybersecurity strategies and laws, protection of critical infrastructure, and a secure, open internet that supports digital trade and innovation.

The new Plan is expected to operationalize these commitments further, creating opportunities for Australian cybersecurity providers, Thai digital-security firms, and joint public-private initiatives focused on threat intelligence, capacity building, and resilience of critical infrastructure. In a region facing rising cyber risks, closer bilateral alignment also strengthens Thailand’s position within ASEAN and Indo-Pacific cyber frameworks.

Joint Statement on Transnational Crime: Targeting Online Scams and Related Threats

The dedicated Joint Statement on combating transnational crime prioritizes online scams/fraud, narcotics trafficking, human trafficking, and money laundering. Cooperation will proceed through bilateral channels and ASEAN mechanisms. This reflects the reality that sophisticated cyber-enabled crime—particularly large-scale online investment and romance scams operating from the region—has become a shared security and economic threat.

Existing operational links between the Royal Thai Police and the Australian Federal Police, including intelligence sharing and joint operations against cybercrime and financial crime networks, provide a foundation. The new Statement is likely to expand structured coordination, capacity building, and disruption of illicit financial flows. For the private sector this translates into stronger expectations around know-your-customer and anti-money-laundering compliance, potential public-private partnerships on fraud detection, and reduced exposure of legitimate businesses and consumers to scam ecosystems.

Economic and Trade Pillar: Resilience, Clean Energy, and Multilateral Trade:

The economic pillar emphasizes growth, resilient supply chains capable of withstanding global volatility, the clean-energy transition, and a robust multilateral trading system. It sits alongside long-standing instruments—the Thailand-Australia Free Trade Agreement (TAFTA), the Regional Comprehensive Economic Partnership (RCEP), and the Strategic Economic Cooperation Arrangement (SECA), which was renewed in late 2025 through 2028.

Two-way goods and services trade reached approximately A$32.4 billion in 2025, underscoring the commercial weight of the relationship. The Plan and the parallel Joint Statement on economic cooperation are expected to facilitate further trade facilitation, agricultural collaboration, and digital-economy linkages while supporting diversification of supply chains.

Opportunities for SMEs and Startups:

Although the full Plan has not yet been published in detail, official summaries highlight support for startups and SMEs, particularly through science, technology, innovation, and digital cooperation. This continues themes already present in the original Strategic Partnership Declaration, which called for extensive digital-economy collaboration to accelerate business growth, including for startups and SMEs, and to develop a digital-ready workforce.

Sectoral cooperation under the Plan spans agriculture, education, climate action, energy, infrastructure, science and innovation, public health, environment, disaster management, and gender equality/social welfare. For technology-oriented SMEs and startups these areas open concrete avenues:

•  Digital and cyber solutions for agriculture, supply-chain resilience, and clean-energy systems.

•  Innovation partnerships, research collaboration, and technology transfer with Australian counterparts.

•  Access to capacity-building, skills development, and potential co-investment or market-entry support under SECA and related mechanisms.

•  Participation in people-to-people exchanges that build networks and talent pipelines.

Australian firms offering cybersecurity tools, digital platforms, agritech, cleantech, or fintech solutions, and Thai startups seeking capital, technology, or export pathways to Australia and the broader Indo-Pacific, stand to benefit from the clearer policy framework and high-level political endorsement.

Looking Ahead

The Joint Plan of Action is a political framework rather than a legally binding treaty. Its value will be realized through concrete projects, dialogues, and private-sector engagement after the formal signing in mid-August 2026. Businesses and legal practitioners should monitor implementing arrangements under the cyber MoU, SECA work programs, and any new working groups on digital economy, innovation, or transnational crime.

For companies operating at the intersection of technology, trade, and compliance, the 2026–2029 Plan reinforces Thailand-Australia cooperation as a practical platform for managing cyber risk, building resilient commercial relationships, and accessing opportunities in a strategically important bilateral partnership.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

OCPB Introduces FastTrack Complaint Handling for Online Purchases: Practical Implications for Digital Businesses

The Office of the Consumer Protection Board (OCPB) has announced the introduction of OCPB FastTrack, an expedited complaint-handling process designed to assist consumers experiencing problems with online purchases. While the initiative does not introduce new legal obligations or amend existing consumer protection laws, it signals a more proactive enforcement approach and an expectation that online businesses will respond promptly to consumer complaints.

Overview of the FastTrack Process:

According to the OCPB, consumers may use the FastTrack process for common online shopping disputes, including:

  • products that differ from their advertisements;
  • non-delivery of purchased goods; and
  • sellers who fail to respond after payment.

The OCPB has indicated that the process aims to streamline complaint handling through digital coordination with online platforms and businesses, with a target of resolving complaints within 14 days.

To support their complaints, consumers are encouraged to submit evidence such as:

  • the original product advertisement;
  • proof of payment;
  • communications with the seller; and
  • photographs of the goods received.

Although the 14-day target is an administrative objective rather than a legally prescribed response period, it provides insight into the OCPB’s enforcement expectations and its intended speed of intervention.

Practical Implications for Online Businesses:

The FastTrack initiative is likely to increase the pace at which marketplaces, platforms, and merchants receive requests from the OCPB. Businesses should therefore evaluate whether their internal complaint-handling processes can support rapid investigation and response.

In particular, businesses should consider whether they can:

  • promptly identify the relevant seller and transaction;
  • preserve historical versions of product listings and advertisements as they appeared when the purchase was made;
  • retrieve payment, delivery, communications, refund, and complaint records efficiently;
  • identify and investigate repeat-offender sellers;
  • authorize appropriate refunds or other remedies without unnecessary escalation;
  • distinguish disputes involving misleading advertising from those involving counterfeit, defective, or unsafe products; and
  • coordinate responses across the platform, merchant, logistics provider, payment service provider, and customer-service functions.

Businesses should avoid relying solely on current versions of online listings. Product descriptions, images, pricing, and promotional claims may have been modified after a transaction occurred. Maintaining reliable version histories, timestamps, and archived advertising records will be increasingly important when responding to regulatory inquiries or consumer complaints.

Intellectual Property Considerations:

Consumer complaints alleging that products are “not as advertised” may also expose intellectual property issues. These complaints may involve:

  • counterfeit goods;
  • unauthorized use of trademarks;
  • unauthorized use of copyrighted product photographs or marketing materials;
  • substitution of genuine products with non-genuine products;
  • misleading claims regarding authorized distributor or dealer status; or
  • imitation packaging or branding intended to confuse consumers.

For businesses operating brand-protection programs, the FastTrack process highlights the value of integrating consumer complaints with existing intellectual property enforcement mechanisms. Information obtained through customer complaints may assist in identifying repeat infringers, counterfeit supply chains, or fraudulent marketplace accounts that would otherwise remain undetected.

Rather than treating consumer complaints and intellectual property enforcement as separate functions, businesses should consider adopting a coordinated approach involving legal, compliance, trust and safety, and customer-support teams.

Data Privacy Considerations:

Responding to FastTrack complaints may require businesses to collect, review, and disclose information relating to customers, sellers, payment transactions, deliveries, device information, and communications.

Businesses should ensure that their complaint-handling procedures incorporate appropriate data governance measures, including:

  • clearly designated authority to respond to OCPB requests;
  • data minimization practices when preparing evidence packages;
  • secure channels for transmitting information;
  • appropriate access controls for complaint files;
  • contractual safeguards with processors such as call centers, logistics providers, and cloud service providers; and
  • incident-response procedures where complaint files contain personal data.

As complaint investigations become increasingly digital and involve multiple service providers, maintaining a structured and documented approach to personal data handling will help reduce compliance risks while supporting efficient regulatory cooperation.

Looking Ahead:

Although OCPB FastTrack does not create new statutory obligations, it reflects an evolving enforcement environment in which regulators expect faster cooperation from digital businesses. Organizations that rely on online sales channels should view the initiative as an opportunity to review their complaint-handling, record-retention, advertising preservation, brand-protection, and data-governance processes.

Businesses that can quickly reconstruct transactions, preserve historical evidence, coordinate responses across multiple stakeholders, and implement appropriate remedies will be better positioned to manage both regulatory scrutiny and consumer expectations as online commerce enforcement continues to evolve.

Key Takeaways:

  • Strong record-keeping and coordinated internal response processes will help businesses manage regulatory inquiries and consumer disputes more effectively.
  • OCPB FastTrack is an administrative initiative designed to expedite online-purchase complaint handling rather than a new law or regulation.
  • The initiative signals an expectation that platforms and sellers will respond promptly when contacted by the OCPB.
  • Businesses should ensure they can preserve historical product listings, advertisements, communications, payment records, and delivery information.
  • Consumer complaints may reveal broader issues involving counterfeit goods, trademark infringement, misleading advertising, or unauthorized use of copyrighted materials.
  • Complaint management, brand protection, and product-safety functions should be integrated rather than operating independently.
  • Organizations should review data governance procedures to ensure that complaint investigations involving personal data are handled securely and consistently.

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

Thailand Moves Toward a Dedicated Regulatory Framework for Data Centers

Thailand may soon take a significant step toward regulating its rapidly expanding data center industry. According to recent reports, the government is preparing a Prime Minister’s Office Regulation that would establish a dedicated framework for overseeing data center operations, with particular emphasis on resource management, environmental impacts, and centralized regulatory oversight. While the proposed regulation has not yet been issued, it signals a potential shift from Thailand’s current investment-driven approach toward a more comprehensive regulatory model for the sector.

Background:

Thailand has become an increasingly attractive destination for data center investment due to strong government incentives, growing cloud adoption, and its strategic location in Southeast Asia. However, the rapid expansion of large-scale facilities has also raised concerns regarding infrastructure capacity, particularly electricity and water consumption.

According to the reported proposal, the government intends to introduce a dedicated regulatory mechanism to better coordinate oversight of the industry and manage its broader impacts on national resources.

Proposed regulatory framework:

The reported proposal indicates that the Prime Minister’s Office Regulation would establish a new committee responsible for supervising data center activities. Its responsibilities would reportedly include:

  • overseeing the overall development of the data center industry;
  • assessing the impacts of data center investments;
  • monitoring resource consumption, particularly electricity and water usage;
  • coordinating regulatory oversight among relevant government agencies; and
  • supervising approvals, permits, and compliance monitoring.

Although further details have not yet been published, the proposal suggests that the government intends to create a more centralized oversight structure than currently exists.

Addressing fragmented regulation:

At present, data center projects typically interact with multiple government agencies depending on the nature of the project. Investors may require approvals or incentives from different authorities, while utility arrangements are often negotiated separately.

The reported proposal appears intended to address this fragmented regulatory landscape by introducing a dedicated governance mechanism specifically focused on data centers.

Greater focus on infrastructure and resource management:

A notable feature of the proposal is its emphasis on resource planning.

According to the reports, the government has identified several concerns, including:

  • increasing electricity demand from large-scale data centers;
  • substantial water consumption required for cooling systems;
  • challenges in forecasting future resource demand; and
  • overlapping arrangements for water supply that may complicate national infrastructure planning.

The proposal therefore appears to reflect a policy objective of integrating data center development with broader infrastructure and environmental planning rather than regulating the industry solely from an investment perspective.

Different treatment for existing and future projects:

The reported framework would distinguish among three categories of data centers:

Existing operating facilities

Existing operators may become subject to audits or assessments focusing on matters such as resource consumption, temperature management, and noise impacts.

Approved projects under development

Projects that have already received approvals but are not yet operational may be required to comply with additional regulatory conditions before commencing operations.

Future applicants

New projects may become subject to a comprehensive regulatory regime addressing matters such as:

  • sustainable water management;
  • reserve water sources;
  • environmental impacts; and
  • measures designed to reduce adverse impacts on surrounding communities.

This tiered approach suggests that the government is seeking to avoid disrupting ongoing investments while progressively strengthening regulatory requirements for future developments.

Potential changes to location planning:

The reports also indicate that the government is considering a more strategic approach to determining where future data centers should be located.

Rather than concentrating additional facilities in existing investment hubs, policymakers are reportedly evaluating locations with stronger electricity and water infrastructure, including areas near major power generation facilities. The government has also indicated that supporting digital infrastructure, such as fiber-optic networks, could be expanded if new data center clusters are developed.

What investors should watch:

Although the proposal remains at the policy stage, investors and operators should monitor several issues as the framework develops:

  • the legal authority under which the new committee will operate;
  • whether additional licensing or approval requirements will be introduced;
  • technical standards relating to electricity, water use, and environmental impacts;
  • transitional requirements applicable to existing operators; and
  • the interaction between the new framework and existing approvals issued by sector-specific regulators.

The final regulatory approach will determine whether the proposed framework primarily serves as a coordination mechanism or introduces substantive compliance obligations for the industry.

Key takeaways:

  • Thailand is reportedly preparing a dedicated regulatory framework for data centers through a proposed Prime Minister’s Office Regulation.
  • The proposal reflects increasing government attention to electricity consumption, water usage, and environmental impacts associated with large-scale data center investments.
  • A new committee may be established to coordinate oversight of approvals, compliance, and resource management.
  • Existing facilities, projects under development, and future investments could become subject to different regulatory requirements.
  • Although the proposal has not yet been formally issued, investors planning data center projects in Thailand should closely monitor further regulatory developments, as they may significantly affect project planning, compliance obligations, and site selection.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles