A call center scam is a type of fraud that occurs when a caller, posing as a representative from a legitimate business or government agency, attempts to trick the person on the receiving end into giving away personal information and/or money. The scammer may claim to be providing a service such as a customer service, technical support, or debt collection. They may also offer products or services at a discounted rate in order to convince the person to provide payment information. The scammer may also request additional personal details such as social security numbers or bank account information by claiming that this is necessary for the transaction to be completed. In some cases, the scammer may even ask for money to be wired directly to a “Horse Account”. Once the person has provided the requested data or money, the scammer typically disappears without providing any of the promised services or products. The Horse Account is usually opened for the purpose of receiving money from the victim. The money will stay in the Horse Account only for a few seconds or so, then it will be transferred to another account of scammer.
Online threats that come in the form of call centers, deceiving them to click on various links to steal money from bank accounts are considered a cybercrime. Seriously, many people were affected and caused damage to the country’s economy. According to the statistics of scams online in the period of March 2022 – October 2020, deceiving the public online by transferring money costs around 22,000 billion baht which averages 800 cases a day.
Recently, the cabinet has approved in principle of draft Royal Decree on Measures for Prevention and Suppression of Technology Crime (“Draft Royal Decree”) which was proposed by the Ministry of Digital Economy and Society.
This draft Royal Decree serves the purpose to prevent and suppress the public from defrauding by transferring funds and also to penalize the offenders by having a “Crime Prevention and Suppression Technology Committee” mechanism in order to determine the prevention guideline, stipulating the authorized institution to access the exchange information, authorize the power to the financial institutions and entrepreneurs to exchange the information on accounts and transactions of clients including authorizing the power to telecommunication services to exchange the services information among the Royal Thai Police, Anti-Money Laundering Office and the authorized institutions. Moreover, this draft Royal Decree stipulates an exemption from Personal Data Protection Act B.E. 2562 (2019) regarding transferring data and accessing data in order that government institutions, financial institutions or entrepreneurs can order the National Broadcasting and Telecommunications Commission to establish a database system regarding registration information, messages and logfile from Mobile Network Operator for investigation. It is worthwhile to note that not only Thailand suffers from telephone scams but also other countries like the US. In 2019, President Trump signed the Telephone Robocall Abuse Criminal Enforcement and Deterrence (TRACED) Act to become enforced. Telephone companies will now be required to use a system called SHAKEN/STIR, which helps protect people from scam calls. If a call is potentially suspicious, it will be marked as “scam likely” or “spam likely”, enabling consumers to quickly recognize and ignore robocalls.
Thai people can now access government services with their digital ID. Thanks to Section 14 of the Digital Public Service Act B.E. 2565 (2022). To use this service, you are required to present a physical ID card to the registrar at any registration division of district office for verifying the information and then you need to download the application namely “D. DOPA”. The following is required to do:
Select “self-registration” and accept the terms and conditions of the service;
Submit a front and back of a physical ID card, verify the information and confirm;
Take a selfie of your full face and confirm;
Set the password; and
Consent to upload the information and fill out a consent form under Personal Data Protection Act B.E. 2562(2019.).
The digital ID card is a useful and innovative way to verify a person’s identity quickly and securely. It eliminates the need for physical identification cards, which can easily be lost or stolen and keeps personal information safe from unauthorized access. With the digital ID card, users can authenticate their identity with a simple scan of their phones or other devices using biometric authentication such as facial recognition or fingerprint scanning. The system is also secure and reliable with data stored in an encrypted format that prevents tampering or manipulation. With this technology, businesses can quickly and efficiently verify one’s identity and streamline their operations. Additionally, the digital ID card can be used to improve customer services by providing quick and seamless access to information.
Digital Platform Service Operation to Be Regulated
With the rise of modern technology and the spread of COVID-19, businesses are increasingly turning to online platforms as a way to operate without needing to travel. These platforms cover a wide range of services, such as online marketplaces, social commerce and food delivery. In general, terms of use imposed by service operators should be transparent with their users. They should provide clear information about their policies, pricing, data usage and other relevant information. They should also give users the opportunity to make decisions about how their data is used and how they are served by the service. This will ensure that users are aware of how their data is being used and that they are not being taken advantage of.
The regulation of digital platform services to be imposed by the government should be based on a set of fair and transparent rules that are applicable to all parties. These rules should ensure the safety of users, ensure data privacy and security, protect against anti-competitive practices and ensure that the user experience is not compromised. Additionally, government should take an active role in monitoring the digital platform services and enforcing these regulations, as well as providing a framework for dispute resolution between users, companies and government.
The regulation should also consider the innovative nature of digital platform services and allow room for experimentation and innovation. Additionally, the government should also provide incentives for companies to innovate and create new services. This will ensure that digital platform services remain competitive and continue to innovate in order to provide the best user experience possible.
As for Thailand, the Royal Decree on Supervision of Digital Platform Services Operation Requiring a Notification (“Royal Decree”) was announced on 23 December 2022 and will be effective 240 days after the announcement (i.e., 20 August 2023) in order to govern this matter.
Digital Platform Services shall refer to the provision of electronic platform services as a medium with data management that connects Digital Platform Service Operators (“Platform Operator”), consumers or users via a computer network in order to enable electronic transactions, whether or not a service charge is charged. Digital Platform Service under this Royal Decree excludes the Digital Platform Services that are intended to be used to offer such Platform Operator’s or its affiliates’ goods or services, regardless of whether such goods or services are offered to third parties or its affiliates.
The Platform Operator under the Royal Decree must report its operations to the Electronic Transactions Development Agency (“ETDA”) and examples of qualifications are as follows:
A natural person who operates digital platform service in Thailand and earns more than 1,800,000 THB per year or more than 50,000,000 THB if the Platform Operator is a legal entity; and
Digital platform service with average monthly users in Thailand over 5,000 users.
As the Royal Decree’s main objective is to protect consumers within Thailand, regardless of Platform Operators operating outside of Thailand, this Royal Decree determines that the digital platform services that operate outside Thailand and provide services with one of the following characteristics shall be deemed to provide services to users in Thailand, namely, (1) Thai language digital platforms, (2) digital platforms with the domain name “.th” or “.ไทย” (3) digital platforms that accept payment in Thai baht, (4) Digital platforms governed by laws of Thailand and subject to the exclusive jurisdiction of the courts of Thailand and others as specified in this Royal decree.
Platform Operators who will operate digital platform services must report the following information and evidence to ETDA:
Platform Operator’s information such as name, surname or legal entity’s name, identification number or company registration number, address, accounting period and contact channel;
Digital platform service information such as platform’s name, type of the platform, platform service channel (i.e., URL or application), value of transaction made on digital platform service (if any), etc.; and
Users’ information such as user type (i.e. person who offers goods or services to consumer through digital platform service, customers and etc.), the total number of user and the total amount for each type of user, service provider’s information (i.e. freight forwarder and warehouse service provider), the total number of service provider and the total amount for each type of service provider, information and type of complaint, along with the handling of the complaint and the settlement of such dispute, the information of representative in Thailand (for the Platform Operator who operates inside Thailand) and the Platform Operator’s consent to for ETDA to access such reported information.
The Platform Operator will be issued a registered receipt and will be able to begin operating the digital platform services once ETDA receives the aforementioned report and evidence. Any major change must be reported to ETDA within 30 days as specified in this Royal Decree. Furthermore, ETDA will provide a channel for publicizing the digital platform services’ list and status (for example, the current list of Platform Operators and those whose receipt has been revoked). Please note that the information and evidence listed above must be reported annually within 60 days from the end of the calendar year (Natural Person Platform Operator) or fiscal year (Legal Entity Platform Operator).
Platform Operators may also be required to provide users with terms and conditions of service, assess risk, prepare risk management measure, system security measure, mitigation measure and other duties as specified in the Royal Decree in order to compensate or remedy those damaged by the use of digital platform services. Plus, the ETDA shall consider announcing the rules, procedures and conditions governing the period for business termination, the transfer of digital platform services to another licensee, the management and collection of data relating to digital identity proofing and authentication and any other matters deemed appropriate in order to prevent damage, protect users and ensure that users can use the services continuously.
Platform Operators whose qualifications are required to report ETDA may continue to operate their businesses only if they report their digital platform business operations to ETDA within 90 days of the Royal Decree’s effective date. On the other hand, those who wish to discontinue such operations must notify ETDA within 90 days of the Royal Decree’s effective date as well.
There are also other details regarding the types of digital platform services, duties and various procedures which should be studied further by Platform Operators. Please note that if any law specifically governs over a specific type of digital platform services, the Platform Operator must comply with such law only if it practices in accordance with and in a manner that does not fall below the provisions of this Royal Decree.
Data Privacy Breaches: Duty to Report to the Regulator
A data privacy breach refers to the unauthorized access, use, disclosure or destruction of personal data, either by an individual or by an organization. Data privacy breaches can occur in a variety of ways, including hacking, malware attacks, insider threats or simply human error.
Data privacy breaches can have serious consequences for both individuals and organizations. For individuals, a data privacy breach can lead to the theft of personal information, such as financial data or identity information, which can be used for fraud or identity theft. For organizations, data privacy breaches can lead to legal and regulatory consequences, as well as damage to their reputation and financial losses.
Under the General Data Protection Regulation (GDPR), a data privacy breach is defined as any unauthorized access, use, disclosure or destruction of personal data. This includes both accidental and intentional breaches. If an organization experiences a data privacy breach, it is required to notify the relevant supervisory authority and the individuals whose personal data has been breached. In Thailand, Personal Data Protection Committee (“PDPC”) has officially announced on how to report an incident of personal data breach to the Office of Personnel Data Protection (“Announcement”) which describes Data Controller’s duty to notify of data breach under Section 37(4) of Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) where this Announcement shall come into force and effect since this date of the announcement, i.e. 15 December 2022.
As we all know, the Data Controller is required to notify the Office of PDPC of any personal data breach without delay and, where feasible, within 72 hours. A data breach shall have the meaning as a breach of security measures that results in unauthorized or illegal loss, access, use, amendment, alteration or disclosure of personal data, whether committed intentionally, negligently, unauthorizedly, unlawfully, through computer crime, cyber threat, flaw or other means occurred by the act of the Data Controller, Data Processor, employee, staff, contractor, agent, any related person or any other factors resulting in the Confidentiality Breach, Integrity Breach and/or Availability Breach.
When Data Controller becomes aware of or is informed of a personal data breach, the Data Controller shall evaluate the reliability of such breach without delay, whether the breach has occurred or reasonably being suspected by taking into account of organizational, technical and physical measures to confirm that a personal data breach has actually occurred. The Data Controller must conduct a risk assessment of all potential consequences for the Data Subject. For a high-risk case, the Data Controller must act independently or instruct the Data Processor to take preventive, suspending or corrective actions to ensure that the data breach is terminated or has no further impact. Furthermore, if a confirmed or reasonably suspected data breach is considered to jeopardize the Data Subject’s rights and liberties, the Data Controller must notify the Office of PDPC without delay and, where feasible, within 72 hours of becoming aware of it. Plus, the Data Controller must notify such high-risk data breaches and the remedial measures of the Data Subject as well.
Since 72 hours may be insufficient for the Data Controller and Data Processor to collect all data resulting in an inability to notify the Office of PDPC in time, in this case, the Data Controller shall prepare a reason clarification along with all documents mentioned in this Announcement and submit the same to the Office of PDPC within 15 days of becoming aware of such breach in order to have Office of PDPC consider exempting the Data Controller from liability under Section 37(4) of the PDPA, respectively.
As a result, Data Controllers and Data Processors should thoroughly read the Announcement in order to comply with the PDPA and protect the personal data that are being collected.
What the Data Controller needs to do when a Personal Data Breach occurs
The Personal Data Protection Committee (“PDPC”) is currently considering issuing a Personal Data Protection Announcement on how to report an incident of personal data breach to the Office of PDPC and whether it needs to report to the Data Subject.
According to Section 37(4) of Personal Data Protection Act B.E. 2562 (“PDPA”), a Data Controller has to notify the Office once there is a data breach without delay or within 72 hours after having become aware of the data breach. The data breach may be occurred by the Data Controller, Data Processor, Representative, any related person, or any other factors, such as an accidental, technological and computer processing system, computer crime, or cyber threat, who acts willfully, negligently, unauthorizedly, or unlawfully, affecting the completeness and accuracy of the personal data and the rights of the Data Subject. The Data Breach Category is divided into three types which are the leak of confidential personal data (Confidentiality Breach), the personal data misfiling (Integrity Breach), and inaccessibility of personal data, which can result in permanent inaccessibility or destruction (Availability Breach).
At the same time, the Data Controller is required to check its security measures in all aspects, including Organizational Measures, Technical Measures, and Physical Measures. And conduct a risk assessment of all possible effects on the Data Subject considering whether the data breach is likely to result in a high risk to the Data Subject’s rights and freedoms, the risk assessment factors as stated in the Announcement, if so, Data Controller is required to notify the Data Subject without delay, along with the remedial measures. In case where Data Controller cannot contact Data Subject for any reason, the data breach notification to Data Subject can be carried out on a public platform, such as social media or any other means by which the public can become aware of such notification. However, Data Controller is not required to notify the Office if such data breach is unlikely to result in a risk to the rights and freedoms of the Data Subject due to the reasons such as personal data being anonymous information that cannot be used to identify the Data Subject, unusable personal data due to adequate technological security measures or other reliable reasons according to the law.
Furthermore, the Data Controller must take immediate remedial action against the cause of such data breach either by restricting access to personal data or by any other means as necessary.
The data breach notification submitted to the Office must be included the details such as the number of personal data that has been leaked or violated, the name and address to contact the Data Protection Officer, consequences of a data breach, security measures that the Data Controller or Data Processor have to prevent data breach together with the remedial action in all respects, including personal, procedure and technology. In the event that the Data Controller fails to notify the Office in due time, the Data Controller must clarify reasons and details regarding the inevitability of such an offense to the Office within 15 days of becoming aware of the data breach in order for the Office to consider exempting so. The failure to comply with all of the above is an offense under the PDPA penalized by Administrative Liability with a fine of not exceeding three million Baht.
The Announcement also contains details and sample cases on data breach notification, which will guide Data Controllers in determining which cases must be reported and who must be notified. Therefore, Data Controllers should study this Announcement in order to prepare themselves in case that the data breach occurs and to be in compliance with the PDPA.
Safe Harbor: Suppression of Dissemination and Removal of Computer Data from the Computer System B.E. 2565 (2022)
Recently, the Ministerial Notification of Ministry of Digital Economy and Society (MDES) re: Procedures for the Notification, Suppression of Dissemination and Removal of Computer Data from the Computer System B.E. 2565 (2022) (the “Ministerial Notification”) was published in the Government Gazette, replacing the previous version which came into force in 2017. The Ministerial Notification lays down safe harbor procedures to be complied by service providers and social media platforms in order to be exempted from liability for cooperating, consenting, or supporting offences in relation to illegal computer data under Section 15 of the Computer Related Crime Act B.E. 2550 (2007) as amended by Computer Related Crime Act (No.2) B.E.2560 (2017) (the “CCA”).
According to the Ministerial Notification, service providers offering the following types of service could benefit from safe harbor if they can prove that they have complied with conditions specified therein.
Intermediary services, for example, facilitate computer information transmission routing, transitory communication – mere conduit, provide necessary transient storage, or hosting carried out by an automatic technical process;
System caching;
Storing information residing on systems or network at direction of users;
Linking users to computer information by using information location tools; and
Social media platform.
In general, service providers/social media platforms must transmit, storing or linking computer information in their control without any modification or interference and have no collaboration in, relation to or knowledge upon illegal activities specified in Section 14 of the CCA carried out by services users or other third parties. Also, service providers must not receive direct or indirect compensation or benefit for disseminating such illegal computer information.
In addition to the above-mentioned conditions, service providers/social media platforms must also prove that they have implemented Notice & Takedown Policy, which outlines as follows:
Notification procedures must be adopted by service providers for suppression of dissemination and removal of illegal computer data, providing service users or other third-party channels to report illegal activities. A take down notice must contain at least name and contact details of service providers/social media platforms and complaint form for service users to report, for example, details of alleged perpetration and damages occurred.
Service users can notify illegal computer information by either filing a report or a complaint to the inquiry officer or notifying service providers/social media platforms by completing the provided complaint form.
Service providers/social media platforms must respond expeditiously by suppressing the dissemination of and/or removing illegal computer data from their system as well as forwarding a copy of the complaint form to service users, members, or other relevant persons.
Furthermore, takedown measures also available to officers by issuing an order to service providers/social media platforms who are reported by an injured person, government officials and etc. to have illegal computer contents in their control. Similar to Notice & Takedown Policy adopted by service providers, upon receiving an order from officers, service providers/social media platforms must expeditiously suppress the dissemination and/or remove illegal computer data as well as forward a copy of the complaint to service users, members, or other relevant persons under their control. However, service providers/social media platforms may file an appeal against the order to the Permanent Secretary of MDES within 30 days from the receipt of order.
Rules and Policy for Transferring Personal Data to a Foreign Country under PDPA of Thailand
The Personal Data Protection Committee (“PDPC”) is currently considering for issuing a Personal Data Protection Announcement Concerning Sending or Transferring Personal Data from the Kingdom of Thailand to a Data Controller or Data Processor in a foreign country or international organization. This draft announcement will establish various standards, including binding corporate rules (“BCR”), appropriate safeguards, certification and standard contractual clauses to protect the personal data and to have the involved parties operate legally under Personal Data Protection Act B.E.2562 (“PDPA”).
The involved parties in this announcement are from the same affiliate business or group of undertakings, including the Transferer, i.e. the Data Controller in the Kingdom of Thailand, the Transferee, i.e. either a Data Controller or Data Processor in other countries or international organizations and the Sub Data Processors (if any).
Binding Corporate Rules (“BCR”) is a data protection policy among business affiliates that may be implemented for data to be transferred to ensure that personal data will be protected and transferred in accordance with the PDPA standards. BCR must certify the Data Subject’s rights as well as specify the general principles of the PDPA. Furthermore, BCR must establish appropriate safeguards to protect personal data in terms of people, processes, and technology.
The appropriate safeguard is to prevent the unauthorized or unlawful loss, access to, use, alteration, correction or disclosure of personal data and such measures must be reviewed when it is necessary or when the technology has changed in order to efficiently maintain the appropriate security and safety. The most important is that the BCR must be effective, legally binding and enforced among parties and Sub Data Processors (if any).
Furthermore, BCR must be submitted to the Office of Personal Data Protection Committee for review and certification that it is applicable and valid. Then, sending or transferring of personal data under approved BCR to a foreign country is permitted.
Such BCR will be effective only when it binds all employees, staffs and persons concerned in transferring personal data and is subject to Thai law. An example of important requirements is the duties of the Transferor and Transferee, rights of Data Subjects, dispute resolution and liability to Data Subject and cooperation with PDPC, etc. If the Transferee fails to fulfill its obligations, the Transferor has the right to terminate transferring of data, either temporarily or permanently. Moreover, if a dispute arises as a result of an improper duty and failure to fulfill such duty, and the Data Subject exercises his or her rights to seek for damages, the Transferor , Transferee, or Sub Data Processor must notify other parties and resolve the dispute jointly through mediation. Neither party can use the failure of the other involved parties to exclude or limit their liability as a defense.
In light of this, the Data Controller should follow up with this draft announcement that will be issued and become effective soon so that the Data Controller and other involved parties can properly and legally prepare for actions related to the protection of personal data transferred abroad.
Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) is a new law in Thailand, fully effective on 1 June 2022, which was enacted for the purpose of protecting personal data of data subjects.
Data subject is a person who owns his/her personal data and is the one who gives away his/her necessary personal data to a service provider (called data controller) in order to have them perform according to what both parties agreed under the contract. Therefore, personal data is something that can be used to identify individual the data subject directly or indirectly. However, the data subject does not include a juristic person and deceased person.
Rights of data subject are right to access, right to rectification, right to data portability, right to erasure, right to restriction, right to object, right to withdraw consent and right to complain.
For the data subject’s right to complaint under Section 73 of PDPA, one may file a complaint to the Office of Personal Data Protection Committee (“Office”) against an offender (i.e., data controller, data processor or any person who violates his/her rights) if his/her personal data is violated.
On 12 July 2022, there was a subordinate regulation which is the Criteria for Filing, Refusal of Acceptance, Dismissal, Consideration and Timeframe for Consideration of Complaint B.E. 2565 (2022)(“Subordinate Regulation”)specifying procedures, timeframes and documents required for filing the complaint to the Office. However, since this Subordinate Regulation has been enforced for a month, people still question the practical procedures regarding filing the complaint.
There is no fixed complaint form and there is only a list of required documents specified in the Subordinate Regulation. However, the complaint must be made in a letter consisting of the complainant’s name, address, telephone number or email address, facts with details and related information, details of damage or effects, evidence, and things that the data subject requests to do, together with a sentence certifying that the information in the letter is true.
Once a complaint letter and all documents have been well prepared, the data subject can either send the complaint by registered mail to the Office or submit it in person at the Office. Also, the Subordinate Regulation stipulated that a complaint can be submitted via an electronic channel.
An identification card of the data subject must be presented at the time of submitting the complaint. In the case that the data subject appoints an attorney. A power of attorney with a completed specifications of assigned duties and correct stamp duty together with the attorney’s certification of a copy ID card, passport or any identity document issued by the government must be submitted together with the complaint.
For the timeframe for consideration, the Subordinate Regulation has divided it into three stages as follows:
The competent official shall review and check the completeness of complaint and evidence within 15 days from receipt whether they will accept the complaint for further consideration.
After the competent official accepted such complaint, the complainant shall receive an acknowledgment receipt and complaint’s number. Then, the competent official will consider the matter as follow within another 15 days.
Whether the action specified in the complaint violates the provisions of PDPA.
Whether the complaint has grounds as specified by PDPA and it is reasonable to make a complaint.
Whether the expert committee has the authority to consider the complaint.
The competent official will then pass such complaint to the expert committee for further consideration. At this stage, the duration is not specified.
If the complaint is complete and accurate, the expert committee will further consider the complaint and result shall be categorized as one of the follows:
Dismissing, if the expert committee considers that it has no ground under PDPA.
Not accepting complaint, if the evidence is incomplete and has not been considered as a data breach.
Rendering the punishment as an administrative fine.
If there is any question during the above period, for example, incorrect or incomplete evidence, the competent official will contact the complainant until they receive all required information and documents. The complaint letter and evidence must be well prepared and sufficient to show the competent official that there is an actual violation. Please note that the expert committee will not consider the complaint if details and documents are not complete and accurate. Such complaint shall be deemed invalid, and the expert committee may dismiss the complaint.
In conclusion, for the data subject, your personal data is important, and it is something that you should keep confidentially. You should consider and select to give away your personal data to the service provider who is able to comply with PDPA and has high-security measures to collect and process your personal data.
According to the Personal Data Protection Act B.E. 2562 (PDPA) fully enforced on 1 June 2022, baseline standard of the law is to strengthen and reinforce the rights of the individual and create a much need harmonization of data protection law. Under the PDPA, most organisations are required to designate at least one individual, a natural person or a legal entity, as the data protection officer (DPO).
Currently, while the Personal Data Protection Committee (PDPC) has issued several sub-regulations, it has not yet prescribed qualifications of DPO. PDPA only sets out its roles and responsibilities. DPO roles are, among other things, to uphold the rights of data-subject which may vary from an organization to another one and to ensure legal compliance of PDPA.
Who needs a DPO?
Company’s activities requiring regular and systematic monitoring of a large scale of personal data (The Draft PDPA Sub-Relations suggests that “large scale” means data controller or data processor has in its possession of personal data of more than 50,000 data subjects or 5,000 data subjects in case of sensitive data processing within 12 months)
Public authorities including governmental agencies, state enterprises, local administrative agencies, and other state agencies.
Company’s core activities concerning collection, use or disclosure of sensitive personal data.
To have an in-house DPO might benefit from fully conversant with processes within the business entity. However, to have outsource DPO provides you an expert knowledge on specifical field and experience of working with numbers of organisation and avoids a possible conflict of interest within an organization. A DPO, under PDPA, must be independent enough to challenge the management of the organization on existing vulnerabilities. Since Thailand is still new to PDPA, to hire an in-house DPO, who is a highly qualified on PDPA, may be difficult. Thus, outsourcing this task to a qualified external firm is an option.
To outsource the Data Protection Officer (DPO), the company would benefit from:
Timesaving; while, the organization can focus on core businesses.
Meeting the independence requirements for the DPO role without compromising existing internal duties or roles.
Assurance regarding the correctness of decisions made.
Quickly access specialized, skilled and experienced consultants in the event of a personal data breach, supervisory authority investigation or other privacy impact events.
It is not accessary to set up an individua workplace, employment’s benefits and to integrate a new staff member to the cohesive work environment.
Thailand – Electronic Performance of Administrative Function
Technology has drastically changed from time to time causing the rapid growth of communication . Since then, the Electronic Transaction Act B.E. 2544 (2001) has been enacted, it supports the legal effects of electronic and commercial electronic transactions conducted electronically, as well as electronic transactions of public sector.
Even though under Section 35 of the Electronic Transaction Act B.E. 2544, it endorses applications, registrations, payments or any acts by way of electronic transactions in the public sector, most government entities prefer to remain to their own traditional way – that is non-electronic transaction. Now, the government would like to drive the digital government faster by way of issuing a new law accepting applications, registrations, payments or any acts by way of electronic in the public sector. Once it is enacted, no government entities can deny any electronic applications or transactions.
The Cabinet of Thailand recently has approved the draft Act on Electronic Performance of Administrative Function B.E. …. (“Draft Act”). This Draft Act would revolutionize how Thai citizens interact with government agencies and make a big step toward the digital government.
The Draft Act ensures the validity of applications or communications from a private sector to official or public sector via electronic method.
The Draft Act sets the same standard of suitable technology to be applied to all government entities and validity of the following which is done electronically:
Filing an application, payment or contact the public sector can made through the electronic method, except some registrations such as immoveable property, marriage, divorce, adoption or applications for ID card and passport.
In the case where an application has been made electronically, it shall be deemed that the government sector would reply electronically; unless, the applicant requests otherwise.
A government sector shall provide a copy of document and certifies for accuracy of such copy and governmental agency cannot charge the applicant any governmental fee to certify such documents.
In the case where matters required by law to obtain a license by applying to a regulator, an applicant can submit an application, document, or evidence via an electronic method.
This Draft Act shall apply to all state agencies which are not in a legislative branch, judiciary branch, independent constitutional organization, public prosecutor organization and other state agencies as specified in the Ministerial Regulation.
Currently, the Draft Act has been submitted to the House of Representatives for consideration. Procedurally, it will take a couple of years before the Draft Act becomes enforced.