NCSA Tackles Cloud Security with New Measures

The National Cyber Security Agency (NCSA) has recognized the growing reliance on cloud services by both government agencies and private sectors, along with the increasing number of cyberattacks targeting users. In response, the agency has drafted the Notification on Cloud System Cyber Security Standard (“Notification“), aiming to establish a robust standard of security measures for cloud systems.

Applicable Entities and Scope: The draft Notification is applicable to government agencies, supervising or regulating organizations, and organizations of critical information infrastructure (as defined under the Cybersecurity Act B.E. 2562 (2019)) that utilize cloud services and have official contracts with Cloud Service Providers (CSPs). These entities are collectively referred to as Cloud Service Customers (CSCs).

Risk Assessment and Categorization: According to the draft Notification, the risks associated with cloud system usage can originate from either the CSC or the CSP. Despite the fact that the draft Notification’s applicability is extended to only the CSCs, the CSPs are to be bound by its service agreement with CSCs to comply with the requirements of the draft Notification as well. CSCs and CSPs are mandated to assess the level of risk in accordance with the security objectives prescribed by another NCSA’s notification. The risk levels are categorized as low, moderate, and high, each with different minimum requirements for security standards, CSC and CSP assessments, and certifications.

green and white line illustration

Minimum Requirements: The minimum requirements for cloud security depend on the assessed risk level and the related security objectives. These requirements may encompass various aspects, including:

  1. Cloud security governance, encompassing information security policies, organization of information security, supplier relationships, and compliance with rules and regulations.
  2. Cloud infrastructure security and operations, covering human resources security, asset management, access control, cryptography, physical and environmental security, operations security, communication security, system acquisition, development and maintenance, supplier relationships, and information security incident management.

Assessment and Certification: Depending on the risk level and the related security objectives, CSCs or CSPs may be required to conduct compliance assessments as follows:

  1. Self-assessment, conducted in accordance with NCSA’s prescribed requirements.
  2. Assessment by a regulator or regulatory agency (attestation).
  3. Assessment by an advanced certified body.

The frequency of assessments and certifications will also depend on the assessed risk level.

The draft Notification provides greater details, and CSPs and CSCs subject to its provisions are required to carefully assess their associated risks and obligations.

Conclusion: The NCSA’s draft Notification aims to establish a comprehensive framework for ensuring the security of cloud systems used by government agencies, regulatory bodies, and critical infrastructure organizations. By introducing risk-based minimum requirements, assessments, and certifications, the agency seeks to address the growing cybersecurity threats and enhance the overall resilience of cloud services within the country.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

The Digital Leap for Ease of Doing Business in Thailand

In a significant move to enhance the ease of doing business in Thailand, a joint collaboration between government agencies and private sector organizations was unveiled. The Thai Chamber of Commerce, the Board of Trade of Thailand, the Office of the Public Sector Development Commission (OPDC), and the Department of Business Development (DBD) took the stage to announce the “Joint Corporate Data Linkage” initiative.

This groundbreaking project aims to revolutionize the way businesses interact with government entities by eliminating the need for physical document submissions, such as copies of national ID cards, house registration documents, and company affidavits. Through an online system, legal entity information will be seamlessly linked and shared among participating agencies, reducing redundancies and streamlining processes.

The Chairman of the Thai Chamber of Commerce and the Board of Trade of Thailand emphasized the importance of efficient government services in enhancing the country’s competitiveness. “For too long, entrepreneurs have been burdened with the task of submitting countless documents for various proceedings,” the Chairman stated. “This initiative marks a significant step forward in leveraging digital technology to alleviate those burdens and foster a more business-friendly environment.”

gray concrete buildings

The Joint Corporate Data Linkage is the culmination of years of legal and technological advancements, including the Licensing Facilitation Act B.E. 2558 (2015), the Digitalization of Public Administration and Services Delivery Act B.E. 2562 (2019), and the Act on Management of State Affairs by Electronic Means B.E. 2565 (2022). These legislative efforts have paved the way for a seamless integration of government services into the digital age.

Initially, ten government agencies have pledged their commitment to this initiative, including the Food and Drug Administration (FDA), the Department of Lands (DOL), the Treasury Department, the Board of Investment of Thailand (BOI), the Department of Industrial Works (DIW), the Excise Department, the Bank of Thailand (BOT), the Thai Customs Department, the Comptroller General’s Department, and the Revenue Department (RD).

The Secretary-General of the OPDC highlighted the significance of this collaboration, stating, “The OPDC recognizes the importance of harnessing digital technologies to enhance the efficiency of government services. By fostering cooperation between public and private entities, we aim to provide convenient, cost-effective, and inclusive services to businesses and citizens alike.”

The benefits of the Joint Corporate Data Linkage are multifaceted. According to projections, the initiative is expected to reduce up to 392 document retrieval procedures, resulting in substantial cost savings of approximately 800 Thai Baht per transaction. This translates into an estimated annual saving of around 7 billion Baht, factoring in time, document usage, accounting costs, and opportunity costs.

group of people photo
Photo by Helena Lopes on Pexels.com

The Director-General of the DBD underscored the technological advancements underpinning this endeavor. “We have developed a robust system that enables real-time, accurate, and secure data exchange between agencies,” the Director-General explained. “By leveraging the Central Data Exchange system (GDX), we can ensure efficient and seamless information flow, further enhancing the overall experience for businesses.”

The Joint Corporate Data Linkage is not only a testament to Thailand’s commitment to digital transformation but also a beacon of opportunity for investors. As the system matures and expands, investors may find lucrative opportunities in public-private partnerships, collaborating with government agencies to further develop and enhance the platform, potentially yielding long-term returns on investment.

With the formal commencement of the Joint Corporate Data Linkage on May 1st, 2024, Thailand takes a significant stride towards a future where doing business is streamlined, efficient, and aligned with the digital era. This initiative sets the stage for continued innovation and collaboration between the public and private sectors, positioning Thailand as a frontrunner in the global race for competitiveness and business-friendly practices.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thai Perspectives on AI Governance: Navigating Unique Realities Amidst Global Trends

With the recent successful approval of the AI Act in the European Parliament, policymakers worldwide are gearing up to develop comprehensive governance frameworks to support AI development and protect its users. Thailand, with its overarching national AI roadmap, is also developing a legal framework similar to the EU AI Act. However, it is crucial to note that Thailand’s unique context may not align perfectly with the EU’s approach. Diligently monitoring the effects and consequences of EU AI Act implementation, adapting to Thailand’s unique context, and leveraging Thailand’s capabilities to shape the country’s AI governance framework is of paramount importance.

On 9 February 2024, the AI Governance Clinic (AIGC) by the Electronic Transaction Development Agency (ETDA) conducted a webinar whereby Thai experts on AI gathered to discuss the direction of AI governance in Thailand. The AIGC, a leading authority in AI governance, plays a pivotal role in shaping the future of AI in Thailand. Unarguably, the experts point out that AI markets in Thailand are growing at an exponential rate; the adoption of AI in day-to-day business operations, as well as the number of AI developer startups, require effective governance to ensure the promotion of Thai AI to the international level and protection of users in the local level. Nonetheless, Thailand now lacks a clear governance direction, whether strong comprehensive AI regulations or self-regulation would be required and sufficient in Thailand’s context. 

In the interview on Policymakers set to prepare more AI rules with Bangkok Post given by the executive director of the ETDA, he mentioned that “Thai regulators view that Thailand is not in a rush to issue and impose strong and comprehensive AI regulations”. He also mentioned that “ETDA has prepared a draft law on the application of AI with good governance; such draft law will also govern the standardization of contracts between service providers and users of AI products or services and that the standardization of contracts would prevent problems arising from the users not knowing or not understanding the complex systems of AI”.  

clear mannequin on dark blue background

Without a solid and specific regulation, the ETDA prioritizes AI literacy, underscoring the importance of empowering users with the knowledge to discern and mitigate the risks associated with AI technologies, particularly concerning the proliferation of AI Deepfakes. The threat of AI Deepfakes, a type of Generative AI that can create synthetic media, whether still or moving images, voices, and sounds, creating an indistinguishable virtual identity of an individual, is a pressing concern. AI Deepfakes are often used in disinformation and hallucinating facts; the victims falling for AI Deepfakes, whether monetary damaged or not, are said to have been “AI Hallucinated.” While generative AI brings as much creation into modern society as possible, limits should be imposed. With this intricacy of balancing between the right amount of regulations, and the freedom to foster and promote new AI innovation, regulating AI requires the regulator to be very delicate in regulation drafting.

As Thailand charts its course forward in AI governance, it has a unique opportunity to not just follow global trends, but to lead. By leveraging its unique strengths and capabilities, Thailand can co-create a governance framework that not only addresses emerging challenges but also fosters innovation and inclusivity. By fostering collaboration between stakeholders, monitoring the impact of regulatory interventions, and embracing adaptability, Thailand can carve a distinctive path toward AI governance that reflects its values, aspirations, and economical and societal needs.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Modernizing Business: The DBD’s Digital Registration System

The Thai Department of Business Development (“DBD”), Ministry of Commerce aims to promote a brand new business registration system for partnership and company registration in order to facilitate entrepreneurs in starting and operating businesses by launching the DBD Biz Regist system, which provides online services of partnership and company registration for ease of operating businesses in Thailand.

Recently, a draft Rule of Office of the Central Company and Partnership Registration on the Partnership and Company Registration via the Digital Juristic Person Registration System (DBD Biz Regist) B.E. …. (“Draft Rule”) has been proposed to revoke the Rule of Office of the Central Company and Partnership Registration on the Partnership and Company Registration via the Digital Juristic Person Registration System (e-registration) B.E. 2564 (2021) and B.E. 2566 (2023) in order to support the new digital juristic person registration system which will replace the current electronic juristic person registration system.

man wearing gray blazer
\

The DBD Biz Regist would reduce difficulties and expenses for entrepreneurs and agents that may occur for corporate transactions. However, after submitting the documents via DBD Biz Regist, it will take approximately 3-5 days for the DBD’s officer to review and approve such application whereas registering in person at the DBD’s office will be completed on the submission’s date unless the application contains complex issues.

The Draft Rule is under public hearing until 15 April 2024. Once the Draft Rule is approved by the Director-General of DBD and becomes enforced, it could attract investors to invest and operate businesses in Thailand, enhance Thailand’s ranking on the World Bank’s Ease of Doing Business, and boosting the local economy.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Brief Notification for the Digital Platform Services

The Notification of the Electronic Transactions Commission regarding the Nature of the Digital Platform Services Requiring a Notification of the Brief List (“Notification”) was published in the Royal Gazette on 18 August 2023 by virtue of Section 8 of the Royal Decree on the Operation of Digital Platform Service Business that are Subject to Prior Notification B.E. 2565 (2022) (“Royal Decree”) and it will be enforced on 21 August 2023 onwards.

This Notification is aimed to prescribe details of the qualification of the digital platform service providers under Section 8 of the Royal Decree  which is  (1) earning a yearly gross income in Thailand of not more than 1,800,000 Baht as a natural person, or not more than50,000,000 Baht as a juristic person, and (2) Digital platform service providers with no more than 5,000 monthly average users (“Digital Platform Service Providers”) to notify information listed below (a brief list) to ETDA prior to operating their platforms:

  • Platform operator’s information, i.e., natural person’s name-surname or juristic person’s name, national identification number or juristic person registration number, address, juristic person’s accounting period, and contact channel which can be URL or application.
  • Digital Platform Service Providers’ information, i.e., name, type, and channel of the Digital Platform Service Providers.
  • Digital Platform Service Providers’ point of contact in Thailand.

In the Notification, we noticed that there are additional qualifications of the Digital Platform Service Providers specified therein which we view that those are in conflict with the principle of definition of the term “digital platform services” and Section 8 of the Royal Decree as it shall not include a digital platform service that is intended for offering goods or services of a single digital platform service operator or an affiliated company which is an agent of such operator, irrespective of whether the goods or services are offered to third persons or to affiliated companies.

Furthermore, the aforementioned Digital Platform Service Providers must notify the ETDA of the following information on an annual basis, i.e., (1) within 60 days of the end of the calendar year in the case of a natural person’s platform operator or (2) at the end of the fiscal year in the case of a juristic person platform operator:

  • Value of transactions incurred on the service platforms (if any)
  • Gross income from providing the service platform in Thailand (if any)

This Notification is only applicable to smaller size Digital Platform Service Providers. However, Digital Platform Service Providers in general are still obligated to comply with. The sanction for failure to notify the required information would be subject to the competent official issuing of an order prohibiting the Digital Platform Service Providers from providing the digital platform services.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Details of Terms and Conditions for the Digital Platform Service Businesses

On 21 August 2023, the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification B.E. 2565 (2022) (“Royal Decree”) has come into force. In this regard, Section 17 of the Royal Degree requires the digital platform service and the search engine Providers that meet certain requirements to prepare and publish the terms and conditions with minimum information as prescribed in the Royal Decree (“Terms and Conditions”). The Royal Decree itself, however, did not provide details or clarifications in regard to such minimum requirements. As such, the Electronic Transaction Development Agency (“ETDA”) has issued a Notification of ETDA number Thor.Por.Dor. 4/2566 on the Details on the Publication of Terms and Conditions of Services for Users’ Knowledge (“Notification”).

person marking check on opened book
Photo by Pixabay on Pexels.com

The Notification consisted of various details important for the digital platform service providers to comply with. The key provisions can be categorized as provisions that further clarify Section 17 of the Royal Decree and provisions that assign additional obligations to the digital platform service providers. Some of the key provisions are summarized as follows:

  1. The Terms and Conditions must be in Thai, easily understandable by the platform’s users, made easy in terms of accessibility, and composed of enough details for the user to make an informed decision whether to use the platform or not. The digital platform service providers must also notify the ETDA and provide evidence showing that they have published the Terms and Conditions for the users’ knowledge.
  2. Where the digital platform service providers treat each of the products, services, or contents of the business users differently, the digital platform service providers must clearly specify the differences in the Terms and Conditions.
  3. In addition to the prescribed minimum requirement in Section 17 of the Royal Decree, the digital platform service providers that meet the requirement of Section 16 (1) of the Royal Decree must also prescribe an additional item, such as an additional distribution channel, the ownership or entitlement in intellectual property after entering into the Terms and Conditions, ancillary or complementary goods and services that is offered to the users before the transaction is concluded, conditions for suspending or terminating the provision of services, etc.
  4. The Notification further provides an example, easing the digital platform service providers to comply with Section 17 of the Royal Decree, that is, the example of algorithms required to be included in the Terms and Conditions are given, for example, price, keywords, user demographic, quality of products, quality of seller, users’ review towards the goods or services.  
  5. Where Section 17 (8) of the Royal Decree requires the digital platform service providers to include in the Terms and Conditions, “an actions to be taken to illegal goods, services, or contents”, the Royal Decree further clarifies that the digital platform service providers must specify if the processes, measures, or mechanism used by the digital platform service providers in determining if a good, service, or contents are illegal or not, are done by an algorithm decision-making, or by human review. The Notification further requires the digital platform service providers to have in place a notice-and-takedown mechanism and details thereof.
man in black suit sitting on chair beside buildings

Please be reminded that the aforementioned information is only a brief detail prescribed under the Notification. Terms and Conditions to be prepared in accordance with the Notification are said to be of complex structures and details. Digital platform service providers must pay attention to the details to avoid any incompliance with the law.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

ETDA’s Recommendation for an Online Merchant Management System with Cash on Delivery Service

The Electronic Development Transactions Agency (ETDA) has recently proposed a draft of ICT Standards for Electronic Transactions, specifically recommending guidelines for an online merchant management system that offers cash-on-delivery (COD) services. The purpose of this recommendation is to establish consistent practices for service providers in this field, addressing emerging challenges and mitigating potential risks associated with COD transactions. Ultimately, the goal is to enhance customer confidence and trust in the process of buying and selling products through COD.

The recommendation is structured into four main sections: scope, definition, introduction of COD, and conditions for online merchant delivery management services. Key points from each section are summarized as follows:

  • Authentication of COD online merchant service providers are required to authenticate online merchants before allowing them to activate their services on the platform. This includes notifying the merchants about the authentication criteria and the information that needs to be collected, such as their names, identification numbers, and bank account numbers, to be in compliance with relevant laws.
  • Online merchant delivery information must be maintained. Such information includes tracking numbers and recipient details. Additionally, any unusual behavior exhibited by online merchant service providers must be monitored.
laptop technology ipad tablet
  • Provisions of recipient information on parcel cover sheets
    • Information on parcel cover sheets: service providers are obligated to include clear and visible information on the parcel cover sheets. This includes the service provider’s names, contact information, websites or communication channels, and details related to recipients’ support.
    • Information for assisting recipients: service providers must provide information on how the system assists recipients. This includes details on scenarios where the system can assist, channels for reporting problems, and any evidence that recipients may need to submit for investigation.
  • Monitoring and addressing online merchant delivery behavior to prevent scams related to COD transactions: service providers must continuously monitor and track incidents involving online merchants. They should establish procedures for addressing suspicious behavior, which include the following steps:
    • Suspected scammers: if more than 10% of recipients report unexpected deliveries or parcels, they did not purchase from a specific merchant. In this case, the service providers must permanently terminate that merchant’s account.
    • Non-compliant items: if the items received by recipients do not meet the specifications as specified, service providers should notify the online merchants and request information to investigate and resolve the issue for both the merchants and the recipients.
    • Incident recording for future analysis: service providers are required to maintain records of incidents involving online merchant behaviors, which can be analyzed in the future for further insights.
    • Gathering evidence and reporting wrongdoings: if evidence related to scams or other wrongdoings is gathered, service providers should report the findings to the relevant authorities.

It is important to note that the above conditions and procedures are recommendations with no legal enforcement. They serve as guidance for service providers in the industry to establish best practices and maintain a high level of service quality and protection to the customers.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand – defamation and insult can be considered as cyberbullying  

Previously, we discussed the difference between laws regulating cyberbullying in other countries and in Thailand. Some countries enact a law that enforces direct harm caused by one to another through electronic means either privately or publicly, such as the Cyber Protection Act 2017 in Canada, whereas Thailand uses the law on defamation, which requires a third party and intention to impute the others as components of offense.  

Therefore, in this article, we will now address cyberbullying legislation with an emphasis on children since bullying is more common among young people and children and it can now be engaged in social media. In accordance with the statistics of cyberbullying, the range between ages 14-18, the high school age, where reported bullying happened the most. Since the school is the place where the bullying happened physically and digitally. As a result, some countries have implemented legislation to protect minors against cyberbullying such as the United States and the Philippines which are Massachusetts Anti-Bullying Law and Anti-Bullying Act of 2013, respectively.  

two men about to kiss

In Massachusetts, following the incident involving Phoebe Prince, a student at the age of 15 at South Hadley School, the state adopted such Massachusetts Anti-Bullying Law governing in regard to cyberbullying. It includes district policy requirements such as the need for Massachusetts school districts to prevent and respond to bullying conducted by one or more students developing a bullying prevention and intervention plan, which districts must review and keep up to date at least biennially.  

The Philippines also enacted Republic Act No.10627, or the Anti-Bullying Act of 2013, which defines cyberbullying as an act of bullying and requires all elementary and secondary schools to adopt policies addressing the existence of bullying by specific acts such as prohibiting bullies, identifying the measures to take against perpetrators, and the Department of Education (DepEd) to provide training programs for school administrators and staffs to improve knowledge and skills in bullying. The aforementioned rules also encompass cyberbullying that happens outside of school premises or on non-school devices, since these criteria demonstrate the serious concerns and obligations for minors who engage in cyberbullying.  

In Thailand, there is no specific law governing cyberbullying act or protecting minors against cyberbullying at all. The case of cyberbullying will be governed by either the Penal Code (PC) regarding defamation and insult or the Computer-Related Crime Act B.E. 2560 (2017) (CRC Act).

The difference between defamation and insult is whether it involves a third party or not. For example, if the bully intends to impair the bullied’s reputation by spreading the message with a third party which can cause hate or scorn, it can be considered as defamation offense under Section 326 of the PC. However, if the bully decides to spread the intention to impair the bullied’s reputation through the publication on the social media platforms, i.e. posting on Facebook or Twitter, it can be considered as defamation offense under Section 328 of the PC.  

Moreover, the case could be applied to Section 14 (1) of the CRC Act since cyberbullying must distort the computer data into a computer system such as a social media platforms. In the case of insult, if the bully insults the bullied in a private forum without the third party’s involvement, it could be applied to Section 393 of the PC. Whether it could be applied to Section 392 of the PC if the bully threatens the bullied causing fear or fright even though it is from the social network service platforms.  

Let’s be honest. Even though the Thai law has several ways to take the bully as guilty, it is just the offenses of defamation or insult. The Thai law should be more specified to cover the action of cyberbullying especially in minors since the high school age, between 14-18, were reported bullying happened the most. This can also reduce the increase of bullying behaviors and the depression or anxiety in the children since being bullied is the major cause.  

Author: Panisa Suwanmatajarn, Managing Partner.

Related Article(s)

Cyberbullying VS Defamation – The Legal Co., Ltd.

Other Articles

Types of Business and Agency in which Certain Parts of the PDPA Shall not Be Applicable

Previously, on June 1st, 2022, the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) came into force, imposing obligations on any person who collects, uses, or discloses personal data.  

A data controller is defined as a person or juristic person having the power and duties to make decisions regarding the collection, use, or disclosure of personal data. Under the PDPA, the data controller shall be imposed with various obligations, for example, notifying of personal data collection, obtaining consent (if applicable), and having in place security measures, etc.

On July 11th, 2023, the cabinet approved the Draft Royal Decree Prescribing Types of Business and Agency in which certain parts of the PDPA shall not be applicable B.E. …. (the “Draft Royal Decree”). The Draft Royal Decree is intended to exempt certain obligations of the certain types of data controller, in order to ease their usual objectives or operations. Essentially, the key provisions of this Draft Royal Decree are, (1) certain obligations under the PDPA may be exempted where the collection of personal data is for the public interest, and such government agency is authorized by law; (2) consent for disclosure of personal data may not be required where the government agency is authorized to do so according to the law; and (3) the Draft Royal Decree reaffirm the data subject’s right to file a request to the Personal Data Protection Committee (“PDPC”) for interpretation of various matters.  

white caution cone on keyboard

According to the summary of the cabinet’s minutes by the government’s spokesperson, the certain government agencies may be exempted from the obligations under Part 2 ‘Personal Data Collection’ and Part 3 ‘Use or Disclosure of Personal Data’ of the PDPA to the extent that their processing of personal data is in accordance with the exemption’s conditions and purposes of personal data processing (prescribed under the Draft Royal Decree).  

That being said, we also noted that the summary of the Draft Royal Decree by the government spokesperson signifies that there has been a significant amendment from the previously published version (the Ministry of Digital Economy and Society’s Results of Public Hearing Group 2). In the previous version, it was also specified the cases where other types of data controllers (i.e., not government agencies) may be exempted from certain obligations. For example, where the data controller’s purposes for processing of personal data would be tampered by complying with the personal data collection notification requirements, then such data controller may be exempted from the said obligations.  

businesspeople talking

At this stage, the approved Draft Royal Decree shall soon be published in the Royal Gazette. Monitoring of this publication and enforcement of this Draft Royal Decree may be of the essence to all data controllers and/or data processors who are subjected to the PDPA’s obligations. As the exemption may be applicable to their cases as well.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles