Cabinet Approves Draft Ministerial Regulation Introducing Per-Item Fees for DBD Data Linkage Services

On August 7, 2026, The Deputy Government Spokesperson announced that the Cabinet of Thailand (“Cabinet”) has approved in principle a draft Ministerial Regulation Prescribing Fee Rates and Fee Exemptions for Registration, Requests for Document Inspection, Requests for Certified Copies, and Other Fees Relating to Partnerships and Limited Companies B.E. …. (“Draft Regulation”), as proposed by the Ministry of Commerce (“MOC”). The Draft Regulation has been referred to and is currently under the Office of the Council of State’s review. The Cabinet also instructed the MOC to take into account comments from the Office of the National Economic and Social Development Council regarding this Draft Regulation.

Background

Members of the public and businesses can currently verify juristic person information through a data linkage between the Department of Business Development (“DBD”) computer network and the user’s own system. Under the Ministerial Regulation Prescribing Fee Rates, Fee Reductions and Fee Exemptions Relating to Partnerships and Limited Companies B.E. 2563 (2020) (the “2563 Regulation”), a fee of THB 30 is charged per data set, with each set comprising six items:

  • name of the partnership or limited company
  • director information
  • number and names of authorized directors
  • registered capital
  • head office and branch locations
  • corporate objectives

The current system does not permit partial data requests: a user seeking only a single item — for example, registered capital — must nevertheless pay THB 30 for the full data set. The MOC considers this structure an unnecessary cost burden on both the public and private sectors, an obstacle to digital government development, and inconsistent with modern business practices that call for selective data access.

The Draft Regulation therefore aims to lower data-linkage service costs for juristic person verification by the public and private sectors. It also seeks to encourage corporate transactions through reliable electronic platforms, accelerate digital transformation in government, facilitate inter-agency data integration, and enable the DBD to expand its service coverage.

Key Changes

  • Introduction of a per-item fee. A new fee of THB 5 per individual item will apply to company certificate data. Users may still request the complete data set at the existing rate of THB 30, while the installation fee for the data linkage program remains THB 3,000 per instance. This allows users to select and pay only for the items they require.
  • Removal of the expired e-Registration discount. Clause 4 of the 2563 Regulation — which granted a 50 percent reduction on certain registration fees for partnerships and limited companies filing through the electronic juristic person registration system between 1 January 2021 and 31 December 2023 — will be deleted, as the discount period has already lapsed.

Key Takeaways

  • Users of the DBD data linkage service will be able to obtain individual certificate items at THB 5 each, rather than paying THB 30 for the full six-item data set.
  • For a typical two-item request, cost will fall from THB 30 to THB 10.
  • The THB 3,000 installation fee and the THB 30 full-set option are retained; all other registration and document fees are unaffected.
  • The Draft Regulation remains subject to review by the Office of the Council of State and is not yet in force. Businesses relying on the data linkage service should monitor the Royal Gazette for the effective date.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

From Grants to Equity: Government Innovation Agency Can Now Invest in Startups

A significant change to the legal framework for government support of innovation has opened the door to direct public-sector investment in startups and innovation businesses. The National Innovation Agency (Public Organization), the government agency responsible for promoting and supporting innovation (the “NIA”), has been granted expanded statutory powers to hold shares, become a partner, co-invest with other persons or entities, and participate in certain venture capital structures. This marks an important shift from the NIA’s traditional role as a provider of grants and financial support toward a model under which it may participate as an investor and acquire an economic interest in the businesses it supports.

The change was introduced by the Royal Decree Establishing the National Innovation Agency (Public Organization) (No. 3) B.E. 2569 (2026). In addition to expanding the NIA’s objectives to cover the development of innovation beyond the research and development stage toward commercialization, the amendment expressly authorizes the NIA to hold shares, become a partner, or participate in joint investments with individuals or legal entities in businesses connected with its statutory objectives. It may also invest in trusts established to conduct venture capital activities. Importantly, however, the NIA’s principal purpose in holding shares or participating in investments must not be the pursuit of profit, and the exercise of these investment powers is subject to criteria prescribed by the Council of Ministers.

From Funding Agency to Investor:

The distinction between a grant and an investment is significant. Under the traditional grant model, government funding supports a project or business without the government ordinarily acquiring an ownership interest. Equity investment creates a different relationship: the government agency may become part of the company’s capital structure, with its interest potentially affected by valuation, dilution, subsequent financing rounds, corporate restructurings, and an eventual exit. The amendment therefore does more than create another source of funding. It establishes the legal basis for the NIA itself to participate in the investment relationship.

This development may be particularly relevant for startups that have progressed beyond the stage at which grants alone can support their growth but remain too early or risky to attract sufficient private capital. The financing gap can be particularly significant for deep-tech and other innovation-driven businesses, where substantial capital may be required for product development, testing, regulatory approvals, manufacturing scale-up, intellectual property protection, and market entry before sustainable revenues are generated. Government equity or co-investment can potentially help bridge this gap and, by sharing part of the investment risk, encourage private investors to participate.

The NIA has announced that it intends to implement its expanded investment role through an initiative referred to as “NIA Venture,” using government funding as catalytic capital to encourage additional private investment. The announced framework includes investment through PE Trust structures, strategic investment through holding companies and other fund structures, and Corporate Co-Funding alongside qualified private investors, particularly for Seed to Series A businesses. The NIA has also announced an initial allocation model of approximately 40% for PE Trust, 30% for Holding Company, and 30% for Corporate Co-Funding. These investment channels and allocations are implementation measures announced by the NIA and should be distinguished from the statutory powers established by the Royal Decree itself.

What This Means for Startups and Investors:

The new powers do not give the NIA unrestricted authority to invest public funds in any startup. Investments must relate to the NIA’s statutory objectives, its principal purpose in participating in an investment must not be profit-seeking, and the relevant investment activities are subject to criteria prescribed by the Council of Ministers. Accordingly, the Royal Decree establishes the legal authority to invest, while the practical availability of NIA investment will depend on the applicable eligibility requirements, investment limits, approval procedures, governance arrangements, and other implementing conditions.

For founders, having a government organization on the cap table may create opportunities but also raises issues that should be considered at the outset. The investment terms will need to address valuation and dilution, the class and rights of shares acquired by the NIA, governance and information rights, and the company’s ability to raise subsequent financing. This is particularly important because later-stage venture capital investors may require preferred shares, liquidation preferences, anti-dilution protection, board representation, reserved matters, and other investor protections. An early government investment should therefore be structured in a way that does not unnecessarily complicate future financing rounds.

Exit arrangements may also require particular attention. Unlike a conventional venture capital fund, a public organization operates within a statutory and administrative framework governing its investments and assets. The ability of the NIA to sell, transfer, or otherwise realize its investment may therefore need to be considered when drafting shareholders’ agreements and investment documents, particularly in anticipation of a trade sale, secondary transaction, restructuring, or public offering. Startups should also anticipate potentially greater due diligence, reporting, and compliance requirements where public funds are involved.

The amendment is equally relevant to venture capital funds, corporate venture capital investors, and other private investors. Co-investment with the NIA could allow public and private capital to be combined in transactions that might otherwise be difficult to finance. However, the parties will need to consider how valuation is determined, whether investors subscribe for the same class of shares, how governance rights are allocated, how follow-on rounds are handled, and how exit decisions are made. Any conditions attached to government investment should also be assessed carefully to ensure that they do not unnecessarily restrict the company’s future operations, restructuring, overseas expansion, intellectual property arrangements, or ability to raise additional capital.

A New Model for Innovation Financing:

The amendment reflects a broader shift in the government’s approach to innovation financing. Grants and other forms of financial assistance remain important, particularly during research and early product-development stages, but they may not provide sufficient capital to take successful innovation from research to commercial scale. Allowing the government innovation agency to use equity and venture investment structures provides an additional tool for addressing that financing gap and may enable public capital to attract rather than replace private investment.

At the same time, the framework deliberately distinguishes the NIA from an ordinary commercial venture capital investor. Its investment activities must advance its statutory objectives, and profit cannot be the principal purpose of its participation. The success of the new model will therefore depend on achieving a balance between protecting public funds and providing sufficient commercial flexibility for startups to raise capital, grow, restructure, and eventually provide an exit for their investors.

Key Takeaways:

  • The government innovation agency now has express statutory authority to hold shares, become a partner, co-invest with other parties, and participate in specified venture capital structures.
  • This represents a shift from a model centered on grants and financial assistance toward one that can also include equity and co-investment.
  • The investment authority is subject to important limitations: investments must relate to the agency’s statutory objectives, profit must not be its principal purpose, and the exercise of the relevant powers is subject to criteria prescribed by the Council of Ministers.
  • The announced NIA Venture initiative includes PE Trust, Holding Company, and Corporate Co-Funding channels, but these are implementation arrangements rather than investment structures prescribed by the Royal Decree itself.
  • Startups should consider the effect of government investment on their cap table, governance, future fundraising, reporting obligations, and exit arrangements.
  • Private investors considering co-investment should assess how public-sector investment conditions interact with conventional venture capital terms and future financing rounds.
  • The practical impact of the reform will ultimately depend on the implementing criteria and the investment structures adopted under the new statutory framework.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Big Data: Thailand Approves National Strategy to Accelerate AI and Data-Driven Economy

Thailand’s Cabinet has acknowledged the draft National Big Data Strategy, establishing the country’s first comprehensive policy framework for the development and use of big data as a foundation for digital government, artificial intelligence (AI), and a data-driven economy.

The strategy is intended to provide a unified direction for government agencies to improve data management, strengthen digital infrastructure, and promote the practical use of data in both the public and private sectors.

Why the strategy matters:

Although the strategy is not legislation and does not itself impose new legal obligations, it signals the Government’s long-term policy direction. Businesses operating in Thailand—particularly technology companies, cloud service providers, AI developers, healthcare providers, financial institutions, and organizations handling government-related data—should expect increased public investment and regulatory attention in data governance and AI.

The strategy also reinforces the Government’s objective of using data as a strategic national asset to improve public administration, support economic growth, and enhance Thailand’s digital competitiveness.

Key objectives:

According to the announcement, the strategy seeks to:

  • establish an integrated national big data ecosystem;
  • improve evidence-based policy making through better use of government data;
  • support AI adoption across government and industry;
  • enhance Thailand’s digital competitiveness; and
  • promote responsible and systematic use of data.

The Government has also set measurable goals, including increasing the economic value generated from big data and positioning Thailand among the world’s leading countries in big data capability.

Four strategic pillars:

The strategy consists of four principal initiatives.

1. Building national data infrastructure

The Government plans to strengthen core digital infrastructure through initiatives such as:

  • Government Cloud;
  • Government Data Catalog; and
  • National Big Data Platform.

These projects are intended to improve interoperability and enable more effective data sharing among government agencies.

2. Expanding practical use of data

The strategy encourages wider use of data analytics to address national priorities, including:

  • healthcare;
  • tourism;
  • environmental management;
  • agriculture; and
  • trade and economic development.

This reflects the Government’s intention to move beyond data collection toward data-driven decision-making.

3. Accelerating AI adoption

A significant component of the strategy is the promotion of AI across the public and private sectors.

The Government intends to:

  • expand AI applications in government services and industry;
  • support development of Thai-language AI models; and
  • establish datasets suitable for AI development.

These initiatives may create opportunities for AI developers, cloud providers, data platform operators, and businesses offering AI-enabled solutions.

4. Developing human capital

Recognizing that technology alone is insufficient, the strategy also emphasizes workforce development by increasing the number of professionals with expertise in big data and AI.

The Government aims to significantly expand the pool of skilled personnel capable of supporting Thailand’s digital transformation.

Legal and regulatory implications:

The strategy itself does not amend Thailand’s existing legal framework, including laws governing personal data protection, cybersecurity, or digital government.

Nevertheless, it indicates that future regulatory and policy initiatives are likely to focus on:

  • enhanced government data governance;
  • improved standards for data interoperability;
  • greater integration of public-sector datasets;
  • expanded use of AI in government services; and
  • stronger digital infrastructure supporting government cloud and data-sharing initiatives.

Organizations participating in government projects or processing government-related data should therefore continue monitoring future implementing measures, technical standards, procurement requirements, and sector-specific regulations that may follow.

Looking ahead:

The National Big Data Strategy represents an important policy milestone in Thailand’s digital transformation agenda. While much of its implementation will depend on future projects, funding, and regulatory measures, the strategy demonstrates the Government’s commitment to treating data and AI as key drivers of economic development and public-sector modernization.

For businesses, the announcement suggests increasing opportunities in AI, cloud computing, digital infrastructure, and government technology, while reinforcing the importance of robust data governance and regulatory compliance.

Key takeaways:

  • Businesses involved in AI, cloud services, digital infrastructure, and government technology should monitor future implementing regulations, technical standards, and procurement initiatives arising from the strategy.
  • Thailand has adopted its first comprehensive national strategy for big data development.
  • The strategy serves as a policy framework rather than creating immediate legal obligations.
  • Four priorities include national data infrastructure, wider use of data analytics, AI adoption, and workforce development.
  • Government investment is expected to accelerate in cloud infrastructure, data platforms, and AI ecosystems.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Breaking Down Government Data Silos: New Rules on Inter-Agency Sharing of Personal Information

A new Royal Decree has established a legal framework requiring government agencies to share personal information under their control with other government agencies for specified electronic data-linkage purposes.

The Royal Decree on Disclosure of Personal Information Controlled by Government Agencies to Other Government Agencies B.E. 2569 (2026) (the “Royal Decree”) represents an important development in the government’s efforts to move away from fragmented, agency-specific databases toward greater interoperability of public-sector information.

The measure is intended to enable government agencies to use more complete and accurate information in policymaking, public services and targeted welfare programs, while reducing the burden on individuals of repeatedly submitting information already held by the government. The framework is also intended to contribute to greater transparency and more effective law enforcement.

Legal basis for inter-agency disclosure:

The Royal Decree is issued pursuant to Section 24(9) of the Official Information Act B.E. 2540 (1997).

Section 24 of the Official Information Act establishes, as a general rule, that a government agency may not disclose personal information under its control to another government agency or another person without the prior or contemporaneous written consent of the person concerned, subject to specified statutory exceptions.

Section 24(9) permits disclosure in other cases prescribed by Royal Decree.

The new Royal Decree uses this statutory mechanism to provide a specific legal basis for government-to-government disclosure of personal information falling within its scope. As a result, qualifying disclosure under the Royal Decree does not depend on obtaining the individual’s written consent on each occasion.

This is important because large-scale government data interoperability would be difficult to implement if each transfer of information between government agencies required separate consent from every affected individual.

From isolated databases to connected government:

The policy underlying the Royal Decree is broader than simply permitting one government agency to send information to another.

Government agencies hold significant amounts of information about individuals, but that information has traditionally been maintained within separate administrative systems. Where relevant information is distributed among different agencies, the government may not have ready access to the complete information required for policymaking, public services or welfare administration.

The Royal Decree is intended to address this fragmentation by enabling electronic linkage of personal information held across government agencies.

The stated objectives include allowing government policies and measures, government services and targeted welfare programs to be based on accurate and complete information. Greater data linkage is also intended to improve the efficiency of government services, reduce administrative burdens on the public, promote transparency and enhance the effectiveness of law enforcement.

In practical terms, the framework supports a move toward the principle that individuals should not continually be required to provide one government agency with information that is already held by another government agency where the conditions for lawful data linkage are satisfied.

Government agencies may be required to disclose information:

A significant feature of the Royal Decree is that it does not merely provide government agencies with a general permission to share personal information.

It establishes a framework under which a government agency controlling personal information must disclose that information to another government agency where the information is requested for purposes falling within the Royal Decree.

The relevant data linkage is intended to support the preparation and provision of government services and the provision of targeted welfare through electronic means.

This gives the Royal Decree practical significance beyond an ordinary exception to a confidentiality rule. It provides the legal infrastructure for systematic government data interoperability.

The receiving agency also assumes obligations:

Greater availability of government-held information is accompanied by safeguards.

A government agency requesting and receiving personal information must safeguard that information. Importantly, it may not further disclose the information to an outside person.

This restriction is an important limitation on the scope of the new regime. The Royal Decree should therefore not be understood as making personal information freely transferable simply because it has entered an interconnected government information system.

The legal authorization concerns disclosure within the framework established by the Royal Decree. Once information has been received, the recipient agency remains responsible for protecting it and complying with the restrictions applicable to its subsequent disclosure.

The required safeguards are also linked to criteria and conditions prescribed by the competent authority and cybersecurity requirements. Consequently, implementation of the Royal Decree is as much an information-governance issue as a data-access issue.

Targeted welfare and government services:

One of the clearest practical applications of government data linkage is the provision of targeted welfare.

Eligibility for government assistance may depend on information maintained by several different authorities. Without data linkage, individuals may have to obtain documents from one agency and submit them to another, while the agency administering the benefit may have difficulty independently establishing a complete picture of the applicant’s circumstances.

Electronic linkage can potentially change this process.

Where legally permitted, the administering agency may obtain relevant information directly from government data already available elsewhere. This can make eligibility assessment more accurate, reduce duplicate documentation and enable welfare programs to be directed more effectively toward intended recipients.

The same principle can apply more broadly to government services. Greater interoperability can reduce repeated requests for information and allow government agencies to make administrative decisions using more complete information.

Transparency and law enforcement:

The Royal Decree also has implications beyond welfare and administrative services.

The stated rationale includes increasing transparency within government and improving the effectiveness of law enforcement. Information that appears unremarkable when held in a single agency’s database may have greater significance when lawfully linked with information held by other agencies.

Inter-agency data linkage can therefore provide government authorities with a more complete information base for identifying inconsistencies, verifying information and carrying out their statutory functions.

This capability may be particularly relevant where investigations or enforcement activities require information held by several government bodies.

However, the Royal Decree should not be characterized as creating a general law-enforcement database or an unrestricted investigative power. Its significance lies in providing a statutory mechanism for disclosure and electronic data linkage within the scope established by the Royal Decree.

Data sharing does not mean unrestricted data use:

An important compliance point is the distinction between access to information and freedom to use or disclose that information.

The fact that one government agency is legally entitled to obtain information from another does not mean that information becomes unrestricted once transferred.

Government agencies implementing data-linkage arrangements should therefore consider controls covering at least:

  • the authority and purpose for requesting information;
  • identification of the information required;
  • authentication of requesting agencies and authorized personnel;
  • access controls within the receiving agency;
  • secure electronic transmission;
  • logging and traceability of access and transfers;
  • cybersecurity safeguards;
  • retention and management of linked information; and
  • controls preventing unauthorized onward disclosure.

These controls are particularly important because increased interoperability can increase the consequences of inadequate security. A weakness in one interconnected system may potentially expose information originating from several agencies.

Relationship with personal data protection requirements:

The Royal Decree should also be understood within the broader legal framework governing personal information.

Its immediate statutory basis is the Official Information Act, and it establishes a specific mechanism permitting inter-agency disclosure that would otherwise be subject to the restrictions in Section 24 of that Act.

However, the existence of a statutory basis for disclosure should not automatically be equated with unlimited authority to process the information for any subsequent purpose.

Government agencies participating in data-linkage arrangements should therefore identify the legal authority supporting each stage of the information lifecycle—including collection, disclosure, receipt, use, retention, security and any subsequent disclosure—and consider other applicable personal data protection and cybersecurity requirements.

The distinction is particularly important as government systems become increasingly interconnected. Legal authority to receive information is only one component of lawful and responsible data governance.

A significant step toward data-driven government:

The Royal Decree represents a structural change in the management of government-held personal information.

The traditional model in which each government agency maintains its own information and individuals repeatedly provide substantially the same information to different authorities is increasingly being replaced by a model based on controlled interoperability.

If implemented effectively, the new framework should enable government agencies to make greater use of information already available within the public sector, improve the accuracy of public services and welfare programs, and reduce unnecessary administrative burdens on individuals.

The corresponding challenge is governance.

The more effectively government information systems are connected, the more important it becomes to ensure that access is authorized, purposes are properly defined, information is adequately protected and subsequent disclosure remains controlled.

The Royal Decree therefore represents not simply an expansion of government access to data, but a move toward a more integrated model of public-sector data governance.

Key Takeaways:

  • The Royal Decree marks an important shift from government data held in separate institutional silos toward controlled, interoperable public-sector data infrastructure.
  • The Royal Decree establishes a statutory mechanism for the disclosure of personal information between government agencies for qualifying electronic data-linkage purposes.
  • Its legal basis is Section 24(9) of the Official Information Act, which allows exceptions to the general restriction on disclosure of government-controlled personal information without written consent.
  • The framework goes beyond merely permitting voluntary data sharing and supports systematic interoperability between government information systems.
  • A government agency receiving information under the framework must safeguard the information and is restricted from further disclosure to an outside person.
  • The framework is intended to support more accurate policymaking, more efficient government services and targeted welfare, reduced administrative burdens on the public, greater transparency and more effective law enforcement.
  • Government agencies should not treat authorization to receive information as unrestricted authority to use or further disclose it. Purpose limitation, access controls, cybersecurity and information governance remain central to implementation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

From Voluntary Guidance to Legal Accountability: The Changing Rules for Digital Platforms

Digital platform regulation is entering a new phase. Recent developments indicate a shift from a framework centered largely on registration, disclosure, and risk management toward a more substantive model addressing platform conduct, seller accountability, fee transparency, and potentially the allocation of liability between platforms and businesses operating through them.

Two developments illustrate this direction particularly well. The first is the proposed Digital Platform Economy Act, which is being developed as a broader statutory framework for the platform economy. The second is the Electronic Transactions Development Agency (ETDA) Guideline on Transparency and Fairness in Digital Platform Service Fees, which establishes voluntary best practices for the disclosure and adjustment of platform fees. Although the guideline is not mandatory and the proposed Act has not yet been enacted, considered together they provide a useful indication of the regulatory principles increasingly shaping oversight of digital platforms: transparency, fairness, accountability, and greater protection for users and consumers.

A New Regulatory Framework for Digital Platforms:

Digital platform services are currently regulated under the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification. The existing regime establishes notification requirements and imposes various obligations depending on the nature, size, and risk profile of a platform. The proposed Digital Platform Economy Act would represent a significant further development. The government has accelerated work on the legislation, with the current policy timetable contemplating submission to the Cabinet before the draft proceeds to Parliament. As the legislation remains under development, however, both its provisions and legislative timetable remain subject to change.

The emerging framework indicates several areas that platform operators should monitor closely. These include registration and disclosure of information concerning platform operations and revenue, as well as measures intended to give regulators greater visibility over businesses participating in the platform economy. Territorial scope will be particularly important for multinational businesses, since a platform providing services into the local market may potentially become subject to regulatory requirements even where the operator does not have a conventional physical presence in the jurisdiction.

Another important area concerns businesses and individuals offering goods or services through platforms. The regulatory direction increasingly places platforms in the position of gatekeepers rather than merely passive intermediaries. Existing regulatory measures already require certain platforms to obtain and verify seller information and implement risk-management measures concerning goods and services offered through their systems. The proposed legislation appears likely to develop this approach further, making seller onboarding, identity verification, record keeping, monitoring, and enforcement increasingly important compliance functions rather than merely commercial processes.

The Emerging Question of Platform Liability:

Perhaps the most significant issue to monitor is the extent to which a platform may bear responsibility for harm arising from transactions conducted through its service. Platform operators have traditionally characterized themselves as intermediaries connecting independent sellers with customers, and their terms and conditions commonly distinguish the platform from the seller responsible for the underlying goods or services.

The proposed regulatory approach may reduce the practical significance of that distinction. Discussions surrounding the Digital Platform Economy Act contemplate circumstances in which platforms could bear joint responsibility for consumer harm, particularly where the platform fails to perform duties imposed on it. The precise scope of any liability will depend on the final statutory language, including the conduct that triggers liability, available defenses, and the relationship between the new regime and existing consumer protection laws.

If enacted broadly, such liability could materially alter the allocation of risk in the platform economy. Seller verification and monitoring would no longer be viewed simply as regulatory procedures; they could become directly relevant to a platform’s financial exposure when consumers suffer loss. Contractual provisions placing responsibility on sellers, including indemnities, may remain important but would not necessarily protect a platform from independent statutory liability. Platform operators should therefore monitor the liability provisions particularly closely as the draft progresses.

Fee Transparency and Fairness:

While the proposed Act represents the potential development of mandatory statutory obligations, ETDA has adopted a softer regulatory approach to another significant platform issue: fees. Its Guideline on Transparency and Fairness in Digital Platform Service Fees is intended as voluntary best practice rather than direct price regulation. The guideline does not prescribe maximum commissions or other charges. Instead, it focuses on whether users can understand what they are being charged, what services they receive in return, and how changes to those charges are made.

Platforms are encouraged to present fee information clearly and in an accessible manner, including an explanation of individual fee items, the services or benefits associated with them, and the basis or method used to calculate the charges. This is particularly relevant where the actual cost of participating on a platform extends beyond a headline commission and may include advertising, promotional, affiliate, payment-related, or other service fees. The regulatory concern is therefore not simply whether a particular commission is high or low, but whether users can reasonably determine and evaluate the overall economic cost of using the platform.

The guideline also addresses changes to platform fees. It recommends that users receive at least 15 days’ advance notice of fee changes, together with information concerning the reason for the change, its scope and potential impact, and channels for inquiries or feedback. The guideline also contemplates a consultation process in connection with fee changes. Platforms should therefore distinguish between merely notifying users that a fee will change and maintaining a process that reflects the broader principles of transparency, consultation, and fairness contemplated by the guideline.

Fairness extends beyond disclosure. Platforms are encouraged to avoid unnecessary duplication of charges and to distinguish clearly between compulsory fees and charges for additional services. Optional services should correspond to genuine additional benefits rather than becoming effectively mandatory through the design or operation of the platform. The objective is not direct government control of platform pricing, but a framework in which platforms can explain how fees are determined and users can understand the true costs of participating in the platform ecosystem.

From Voluntary Guidance to Legal Accountability:

Considered separately, the proposed Digital Platform Economy Act and the fee guideline address different regulatory issues. Considered together, however, they reveal a broader trajectory. The fee guideline represents soft regulation, under which regulators articulate expectations concerning fair market conduct and encourage platforms voluntarily to incorporate those principles into their business practices. The proposed legislation points toward harder regulatory intervention, potentially involving registration, disclosure, seller verification, statutory duties, enforcement mechanisms, and greater responsibility for consumer harm.

This distinction is important for businesses. Voluntary guidance should not necessarily be treated as irrelevant simply because it does not create directly enforceable obligations. Such guidance may establish regulatory expectations concerning reasonable industry conduct, identify practices receiving regulatory scrutiny, and indicate areas in which more formal intervention could eventually follow if voluntary measures prove insufficient.

The broader development is therefore not simply an increase in the number of rules applicable to digital platforms. It reflects a gradual change in the regulatory conception of the platform itself. As platforms exercise greater control over seller admission, product visibility, payment mechanisms, fees, and transactions, regulators increasingly expect them to accept corresponding responsibilities for how those ecosystems operate.

Preparing for the Next Stage of Platform Regulation:

Platform operators need not wait for the proposed legislation to be enacted before reviewing their compliance architecture. Seller onboarding and verification procedures should be assessed to determine what information is collected, how identities and business credentials are verified, how information is updated, and what happens when inaccurate information or unlawful activity is detected. Systems should also retain sufficient records to demonstrate that verification, monitoring, complaints, and enforcement procedures have actually been followed.

Fee structures warrant similar attention. Platforms should consider whether users can readily identify the overall economic cost of using their services and whether compulsory fees, optional services, promotional charges, advertising costs, and other charges are adequately explained. Procedures for changing fees should also be reviewed against the transparency, advance-notice, and consultation principles reflected in ETDA’s guideline.

Finally, contractual arrangements with sellers should be considered together with operational compliance. If the new legislation imposes independent statutory duties on platforms, contractual provisions allocating responsibility entirely to sellers may have limited effect against claims brought directly against the platform. Indemnities, suspension rights, seller information obligations, insurance arrangements, record keeping, and mechanisms for recovering losses should therefore form part of a broader risk-management framework rather than being treated as substitutes for regulatory compliance.

Key Takeaways:

  • Digital platform regulation is moving beyond registration and disclosure toward greater operational accountability.
  • The proposed Digital Platform Economy Act may expand requirements concerning platform registration, business information, seller verification, platform conduct, and consumer protection. Its final provisions should be monitored as the legislative process progresses.
  • Potential joint liability for consumer harm may be one of the most significant developments because it could alter the traditional allocation of responsibility between platforms and independent sellers.
  • ETDA’s fee guideline remains voluntary and does not constitute direct price regulation, but it establishes regulatory expectations concerning fee transparency, fairness, advance notice, and consultation.
  • Platform operators should consider reviewing seller verification, monitoring, fee disclosures, change-management procedures, contractual risk allocation, and record-keeping systems before the new statutory framework is finalized.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand-Australia Strategic Partnership 2026–2029: Advancing Cybersecurity, Economic Resilience, Cross-Border Crime Cooperation, and Support for SMEs and Startups

Earlier, Thailand’s Cabinet approved the Joint Plan of Action to Implement the Thailand-Australia Strategic Partnership for 2026–2029. The four-year framework succeeds the 2022–2025 Plan and will be signed during the Thai Prime Minister’s official visit to Australia on 17–20 August 2026. It reaffirms the Strategic Partnership elevated in 2020 and provides a practical roadmap for cooperation across five pillars: political and security affairs; economic and trade relations; sectoral collaboration; people-to-people links; and regional and sub-regional engagement (including ASEAN, the Mekong, and the Indo-Pacific).

Two accompanying Joint Statements—one on combating transnational crime and one on strengthening economic cooperation—were approved in parallel. Together they signal a pragmatic, results-oriented deepening of ties with direct relevance for businesses, technology firms, and innovation ecosystems in both countries.

Cybersecurity and Digital Cooperation within the Security Pillar:

The political and security pillar explicitly covers defense cooperation, non-traditional security challenges (including cyber), good governance, and critical technologies. This builds on the existing Memorandum of Understanding on Cyber and Digital Cooperation between Thailand’s Ministry of Digital Economy and Society and Australia’s Department of Foreign Affairs and Trade. That MoU promotes information exchange, best-practice sharing on cybersecurity strategies and laws, protection of critical infrastructure, and a secure, open internet that supports digital trade and innovation.

The new Plan is expected to operationalize these commitments further, creating opportunities for Australian cybersecurity providers, Thai digital-security firms, and joint public-private initiatives focused on threat intelligence, capacity building, and resilience of critical infrastructure. In a region facing rising cyber risks, closer bilateral alignment also strengthens Thailand’s position within ASEAN and Indo-Pacific cyber frameworks.

Joint Statement on Transnational Crime: Targeting Online Scams and Related Threats

The dedicated Joint Statement on combating transnational crime prioritizes online scams/fraud, narcotics trafficking, human trafficking, and money laundering. Cooperation will proceed through bilateral channels and ASEAN mechanisms. This reflects the reality that sophisticated cyber-enabled crime—particularly large-scale online investment and romance scams operating from the region—has become a shared security and economic threat.

Existing operational links between the Royal Thai Police and the Australian Federal Police, including intelligence sharing and joint operations against cybercrime and financial crime networks, provide a foundation. The new Statement is likely to expand structured coordination, capacity building, and disruption of illicit financial flows. For the private sector this translates into stronger expectations around know-your-customer and anti-money-laundering compliance, potential public-private partnerships on fraud detection, and reduced exposure of legitimate businesses and consumers to scam ecosystems.

Economic and Trade Pillar: Resilience, Clean Energy, and Multilateral Trade:

The economic pillar emphasizes growth, resilient supply chains capable of withstanding global volatility, the clean-energy transition, and a robust multilateral trading system. It sits alongside long-standing instruments—the Thailand-Australia Free Trade Agreement (TAFTA), the Regional Comprehensive Economic Partnership (RCEP), and the Strategic Economic Cooperation Arrangement (SECA), which was renewed in late 2025 through 2028.

Two-way goods and services trade reached approximately A$32.4 billion in 2025, underscoring the commercial weight of the relationship. The Plan and the parallel Joint Statement on economic cooperation are expected to facilitate further trade facilitation, agricultural collaboration, and digital-economy linkages while supporting diversification of supply chains.

Opportunities for SMEs and Startups:

Although the full Plan has not yet been published in detail, official summaries highlight support for startups and SMEs, particularly through science, technology, innovation, and digital cooperation. This continues themes already present in the original Strategic Partnership Declaration, which called for extensive digital-economy collaboration to accelerate business growth, including for startups and SMEs, and to develop a digital-ready workforce.

Sectoral cooperation under the Plan spans agriculture, education, climate action, energy, infrastructure, science and innovation, public health, environment, disaster management, and gender equality/social welfare. For technology-oriented SMEs and startups these areas open concrete avenues:

•  Digital and cyber solutions for agriculture, supply-chain resilience, and clean-energy systems.

•  Innovation partnerships, research collaboration, and technology transfer with Australian counterparts.

•  Access to capacity-building, skills development, and potential co-investment or market-entry support under SECA and related mechanisms.

•  Participation in people-to-people exchanges that build networks and talent pipelines.

Australian firms offering cybersecurity tools, digital platforms, agritech, cleantech, or fintech solutions, and Thai startups seeking capital, technology, or export pathways to Australia and the broader Indo-Pacific, stand to benefit from the clearer policy framework and high-level political endorsement.

Looking Ahead

The Joint Plan of Action is a political framework rather than a legally binding treaty. Its value will be realized through concrete projects, dialogues, and private-sector engagement after the formal signing in mid-August 2026. Businesses and legal practitioners should monitor implementing arrangements under the cyber MoU, SECA work programs, and any new working groups on digital economy, innovation, or transnational crime.

For companies operating at the intersection of technology, trade, and compliance, the 2026–2029 Plan reinforces Thailand-Australia cooperation as a practical platform for managing cyber risk, building resilient commercial relationships, and accessing opportunities in a strategically important bilateral partnership.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Moves Toward a Dedicated Regulatory Framework for Data Centers

Thailand may soon take a significant step toward regulating its rapidly expanding data center industry. According to recent reports, the government is preparing a Prime Minister’s Office Regulation that would establish a dedicated framework for overseeing data center operations, with particular emphasis on resource management, environmental impacts, and centralized regulatory oversight. While the proposed regulation has not yet been issued, it signals a potential shift from Thailand’s current investment-driven approach toward a more comprehensive regulatory model for the sector.

Background:

Thailand has become an increasingly attractive destination for data center investment due to strong government incentives, growing cloud adoption, and its strategic location in Southeast Asia. However, the rapid expansion of large-scale facilities has also raised concerns regarding infrastructure capacity, particularly electricity and water consumption.

According to the reported proposal, the government intends to introduce a dedicated regulatory mechanism to better coordinate oversight of the industry and manage its broader impacts on national resources.

Proposed regulatory framework:

The reported proposal indicates that the Prime Minister’s Office Regulation would establish a new committee responsible for supervising data center activities. Its responsibilities would reportedly include:

  • overseeing the overall development of the data center industry;
  • assessing the impacts of data center investments;
  • monitoring resource consumption, particularly electricity and water usage;
  • coordinating regulatory oversight among relevant government agencies; and
  • supervising approvals, permits, and compliance monitoring.

Although further details have not yet been published, the proposal suggests that the government intends to create a more centralized oversight structure than currently exists.

Addressing fragmented regulation:

At present, data center projects typically interact with multiple government agencies depending on the nature of the project. Investors may require approvals or incentives from different authorities, while utility arrangements are often negotiated separately.

The reported proposal appears intended to address this fragmented regulatory landscape by introducing a dedicated governance mechanism specifically focused on data centers.

Greater focus on infrastructure and resource management:

A notable feature of the proposal is its emphasis on resource planning.

According to the reports, the government has identified several concerns, including:

  • increasing electricity demand from large-scale data centers;
  • substantial water consumption required for cooling systems;
  • challenges in forecasting future resource demand; and
  • overlapping arrangements for water supply that may complicate national infrastructure planning.

The proposal therefore appears to reflect a policy objective of integrating data center development with broader infrastructure and environmental planning rather than regulating the industry solely from an investment perspective.

Different treatment for existing and future projects:

The reported framework would distinguish among three categories of data centers:

Existing operating facilities

Existing operators may become subject to audits or assessments focusing on matters such as resource consumption, temperature management, and noise impacts.

Approved projects under development

Projects that have already received approvals but are not yet operational may be required to comply with additional regulatory conditions before commencing operations.

Future applicants

New projects may become subject to a comprehensive regulatory regime addressing matters such as:

  • sustainable water management;
  • reserve water sources;
  • environmental impacts; and
  • measures designed to reduce adverse impacts on surrounding communities.

This tiered approach suggests that the government is seeking to avoid disrupting ongoing investments while progressively strengthening regulatory requirements for future developments.

Potential changes to location planning:

The reports also indicate that the government is considering a more strategic approach to determining where future data centers should be located.

Rather than concentrating additional facilities in existing investment hubs, policymakers are reportedly evaluating locations with stronger electricity and water infrastructure, including areas near major power generation facilities. The government has also indicated that supporting digital infrastructure, such as fiber-optic networks, could be expanded if new data center clusters are developed.

What investors should watch:

Although the proposal remains at the policy stage, investors and operators should monitor several issues as the framework develops:

  • the legal authority under which the new committee will operate;
  • whether additional licensing or approval requirements will be introduced;
  • technical standards relating to electricity, water use, and environmental impacts;
  • transitional requirements applicable to existing operators; and
  • the interaction between the new framework and existing approvals issued by sector-specific regulators.

The final regulatory approach will determine whether the proposed framework primarily serves as a coordination mechanism or introduces substantive compliance obligations for the industry.

Key takeaways:

  • Thailand is reportedly preparing a dedicated regulatory framework for data centers through a proposed Prime Minister’s Office Regulation.
  • The proposal reflects increasing government attention to electricity consumption, water usage, and environmental impacts associated with large-scale data center investments.
  • A new committee may be established to coordinate oversight of approvals, compliance, and resource management.
  • Existing facilities, projects under development, and future investments could become subject to different regulatory requirements.
  • Although the proposal has not yet been formally issued, investors planning data center projects in Thailand should closely monitor further regulatory developments, as they may significantly affect project planning, compliance obligations, and site selection.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

TCCT Establishes Two Subcommittees to Strengthen Trade Competition Oversight

The Trade Competition Commission of Thailand (“TCCT”) has appointed two subcommittees to oversee digital platform businesses and to establish competition rules for modern wholesale and retail businesses (“Modern Trade”). The move is intended to curb unfair trade practices and strengthen law enforcement in step with rapidly evolving trade dynamics.

1. Subcommittee on Considering Guidelines for the Oversight and Deterrence of Trade Practices in Digital Platform Businesses

This subcommittee’s primary mandate is to study, analyze, and collect data on the business models, commercial conditions, and trade practices of digital platform businesses, and to assess their impact on trade competition, business operators, consumers, and other stakeholders. It will drive more intensive regulatory measures for digital platform businesses and prepare proposals, guidelines, codes of conduct, criteria, announcements, regulations, and policy recommendations for the TCCT’s consideration.

The subcommittee will also coordinate with government agencies, the private sector, business operators, and other relevant stakeholders across all sectors to oversee and deter trade practices that may affect competition in digital platform businesses, and to promote free and fair competition more broadly.

2. Subcommittee on Determining Guidelines and Action Plans Regarding Competitive Conditions in Modern Wholesale and Retail Businesses

This subcommittee is tasked with studying, analyzing, and monitoring the market structure of modern wholesale and retail businesses; building a database to analyze retail market concentration and its impact on small-scale operators; and recommending guidelines and measures for overseeing competition in the retail sector.

Objectives of the Subcommittees

The subcommittees will study trade practices in digital platforms and in the modern wholesale-retail market to keep pace with shifting business dynamics and to investigate practices with anti-competitive effects. Each subcommittee will determine oversight guidelines and accelerate the promotion of fair trade so all parties can compete on equal terms.

The subcommittees will integrate efforts across relevant agencies, apply existing law to address exploitation or competitive pressure affecting the majority of business operators nationwide, and enforce compliance with guidelines the TCCT has already issued — notably the TCCT Notification on Guidelines for Considering Unfair Trade Practices and Acts that Monopolize, Reduce, or Restrict Competition in Multi-Sided Platform Business Operations for Digital Platform Services of Goods or Services (E-Commerce), in effect since March 25, 2026. They will also continue overseeing platform service businesses and Modern Trade going forward.

Background

Rapidly shifting competitive conditions and an influx of foreign capital have affected domestic operators, particularly SMEs and small-scale retailers. This has driven a sharp rise in complaints to the TCCT concerning online trading practices and the expansion of retail formats into community areas.

A particular concern is the continued increase in Gross Profit (GP) fees — the revenue-share or fee percentages that merchants pay to platforms. Higher GP rates compress net margins for SMEs, which may in turn force price increases that are ultimately passed on to consumers.

According to TCCT data:

  • E-commerce platforms and Modern Trade are currently among the leading competition concerns for small-scale operators at the grassroots of the Thai economy. In the first six months of this year alone, 21 platform-related complaints were filed, involving transactions collectively worth hundreds of billions of baht.
  • During fiscal year 2025 (October 1, 2024 – September 30, 2025), the TCCT received 78 complaints in total. Of these, 40 were not accepted for consideration, 9 were settled, and the remaining 29 are under investigation — most involving platforms, franchises, logistics and transport, digital platforms, and general commerce.

Through its Mobile Competition Clinic project, the TCCT has previously conducted on-site visits in several provinces to hear directly from business operators. Findings included:

Krabi Province:

  1. Online platform issues, including being forced to use specific transport providers and reduced product visibility due to algorithmic ranking.
  2. Online Travel Agency (OTA) platform issues, including price-parity clauses that prohibit hotels from listing lower rates on their own websites than on OTAs.
  3. Unfair trade practices between SMEs and Modern Trade operators, including redundant fee charges and additional GP fees imposed without prior notice.
  4. Palm oil pricing structure issues affecting local farmers.

Chiang Mai and Lamphun Provinces:

  1. Online platform issues, including algorithmic ranking practices that favor a platform’s own affiliated transport services.
  2. Unfair trade practices between SMEs and Modern Trade operators, including credit-term disputes, GP fee collection, and unfair contract terms.
  3. Pricing issues in agricultural product procurement.

Current Priorities and Enforcement Timeline

The TCCT is accelerating proactive oversight across four key business groups: (1) digital platforms, (2) wholesale and Modern Trade, (3) ride-hailing platform services, and (4) online travel booking platforms (OTAs). The newly formed subcommittees will study, analyze, and propose oversight guidelines, and investigate practices affecting competition across all four groups, with findings due by the fourth quarter of 2026. This will include updated operational guidelines designed to keep pace with evolving trade practices.

This initiative marks a deliberate shift in the TCCT’s enforcement approach — from a largely reactive, complaint-driven model to proactive market inspections that do not wait for formal complaints. On-site visits to gather in-depth input from business operators will remain central to this approach, with the TCCT aiming to demonstrate tangible results within the next six months.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Managing Regulatory Due Diligence for Cross-Border Investors in Financial and Digital Asset Businesses

Introduction:

Cross-border investments in financial services and digital asset businesses present unique regulatory challenges that extend well beyond traditional legal or financial due diligence. Whether an investor is acquiring a licensed payment service provider, a securities business, a digital asset exchange, or a fintech company operating under sector-specific regulation, the value of the transaction can depend as much on the target’s regulatory standing as on its commercial performance.

Unlike ordinary commercial businesses, regulated entities operate under continuing supervision. Their ability to conduct business depends not only on maintaining the necessary licenses but also on demonstrating ongoing compliance with governance requirements, prudential standards, anti-money laundering obligations, cybersecurity controls, and consumer protection rules. A company with strong financial performance may nevertheless represent a significant acquisition risk if its regulatory compliance has deteriorated or if it is subject to undisclosed supervisory concerns.

For cross-border investors unfamiliar with the Thai regulatory landscape, regulatory due diligence is therefore not merely a legal exercise. It is an essential component of transaction risk assessment and should begin early in the acquisition process.

Looking Beyond the License:

One of the most common misconceptions among foreign investors is that verifying the existence of a regulatory license is sufficient. In reality, the existence of a license represents only the starting point of the analysis.

Many regulated businesses have evolved over time, expanding their products and services beyond the scope originally contemplated when their licenses were granted. A fintech company may initially have operated as an electronic payment platform before introducing digital lending, cross-border remittance services, or digital asset-related products. Each new business activity may require separate regulatory approval or may be subject to different supervisory requirements.

Regulatory due diligence should therefore examine whether every revenue-generating activity falls within the scope of the target’s existing licenses and whether any exemptions relied upon remain available. It is equally important to determine whether any license conditions have been imposed by regulators and whether the company has complied with those conditions throughout its operations.

Regulatory Approval May Determine Whether the Transaction Can Close:

Unlike acquisitions involving ordinary commercial companies, transactions involving regulated financial businesses frequently require regulatory approval before completion. In some sectors, a change in significant shareholding or control may not become legally effective until the relevant regulator has approved the transaction. Other regulatory regimes may require post-closing notifications or impose “fit and proper” assessments on incoming shareholders, directors, or senior management.

Consequently, regulatory due diligence should identify not only the approvals required for the target’s day-to-day operations but also those triggered by the proposed acquisition itself. Failure to identify these requirements early can delay completion, affect financing arrangements, or require restructuring of the transaction.

Cross-border investors should also consider whether foreign ownership restrictions, residency requirements, or limitations on board composition may influence the post-closing governance structure.

Compliance Culture Often Matters More Than Written Policies:

Modern financial regulators increasingly assess how compliance operates in practice rather than whether a company simply maintains a complete set of written policies.

Accordingly, regulatory due diligence should extend beyond reviewing compliance manuals and internal procedures. Investors should seek evidence that compliance functions are adequately resourced, that internal reporting mechanisms operate effectively, and that senior management actively oversees regulatory risk.

The company’s interactions with regulators may provide particularly valuable insight. Inspection reports, supervisory correspondence, warning letters, remediation plans, and historical enforcement actions often reveal recurring compliance weaknesses that are not apparent from corporate documentation alone. Even where no formal penalties have been imposed, repeated supervisory findings may indicate weaknesses in governance or internal controls that require significant remediation after closing.

Technology Risk Has Become a Core Regulatory Issue:

Technology is now central to regulatory supervision of financial institutions and digital asset businesses. Cybersecurity failures, operational disruptions, and weaknesses in technology governance increasingly attract regulatory attention regardless of whether they result in customer losses.

For investors, this means regulatory due diligence should include an assessment of cybersecurity governance, incident response procedures, disaster recovery planning, outsourcing arrangements, cloud service management, and operational resilience frameworks. Businesses operating digital asset platforms should also be assessed for wallet security, custody arrangements, transaction monitoring systems, and market surveillance capabilities.

Technology deficiencies may not immediately affect valuation but can require substantial investment after completion to satisfy regulatory expectations.

AML and Financial Crime Controls Remain High-Risk Areas:

Anti-money laundering and counter-terrorism financing compliance continues to be among the highest enforcement priorities for financial regulators. Deficiencies in customer due diligence, transaction monitoring, sanctions screening, or suspicious transaction reporting can expose regulated businesses to substantial regulatory sanctions and reputational damage.

Investors should therefore evaluate not only the target’s written AML policies but also the effectiveness of their implementation. Questions such as how high-risk customers are identified, how beneficial ownership is verified, and how suspicious transactions are escalated can provide a clearer picture of the target’s compliance maturity than policy documents alone.

Where previous regulatory inspections have identified AML deficiencies, investors should assess whether remediation has been completed and whether regulators remain satisfied with the company’s corrective measures.

Data Protection and Outsourcing Should Not Be Overlooked:

Financial institutions increasingly rely on external service providers for cloud infrastructure, customer verification, payment processing, and cybersecurity services. While outsourcing may improve operational efficiency, regulators continue to emphasize that responsibility for regulatory compliance ultimately remains with the licensed entity.

Accordingly, regulatory due diligence should review the contractual framework governing outsourced services, the company’s oversight of critical vendors, and its contingency planning should key service providers become unavailable.

Similarly, businesses handling significant volumes of customer information should be assessed for compliance with personal data protection requirements, particularly where customer information is transferred across borders or processed by third-party vendors.

Due Diligence Findings Should Shape Transaction Documents:

Regulatory due diligence should not end with the preparation of a report. Its findings should directly influence transaction structuring and the allocation of risk between buyer and seller.

Where significant compliance concerns are identified, investors may seek enhanced representations and warranties regarding licensing, regulatory compliance, anti-money laundering controls, cybersecurity, and data protection. Specific indemnities may be appropriate for known regulatory investigations or historical compliance failures. In some cases, buyers may also require identified deficiencies to be remediated as conditions precedent before closing.

Integrating regulatory due diligence into transaction documentation helps ensure that regulatory risks are appropriately allocated and reduces the likelihood of post-completion disputes.

Conclusion:

As financial regulation becomes increasingly complex and technology-driven, regulatory due diligence has evolved from a narrow licensing review into a comprehensive assessment of an institution’s regulatory health. For cross-border investors, understanding how a target interacts with regulators, manages compliance risks, and maintains operational resilience is often as important as evaluating its financial performance.

A well-executed regulatory due diligence exercise enables investors to identify hidden regulatory exposures, anticipate approval requirements, negotiate more effective contractual protections, and develop realistic post-acquisition integration plans. In regulated financial and digital asset sectors, it is often the quality of regulatory compliance—not simply the quality of the business—that ultimately determines whether an investment achieves its intended value.

Key Takeaways:

  • In acquisitions involving financial and digital asset businesses, robust regulatory due diligence is essential to preserving investment value and minimizing post-closing regulatory exposure.
  • Regulatory due diligence should evaluate the target’s overall regulatory health rather than simply confirming the existence of licenses.
  • Investors should assess governance, supervisory history, AML/CTF controls, cybersecurity, data protection, outsourcing arrangements, and change-of-control requirements alongside licensing compliance.
  • Early identification of regulatory risks helps facilitate transaction planning, regulatory approvals, and appropriate contractual risk allocation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

BOT: Bank of Thailand Introduces Stricter Rules on Large Cash Transactions to Combat Illicit Flows

The Bank of Thailand (BOT) is set to implement enhanced oversight on significant cash movements as part of efforts to address gray-area financial activities, reduce risks of money laundering, and promote greater transparency in the financial system.

Under the upcoming regulations, financial institutions will soon be required to perform detailed customer due diligence for any cash withdrawal exceeding 5 million baht in a single transaction. Customers must clearly explain the source of the funds and the intended purpose of the cash. If the explanation is unsatisfactory or unverifiable, banks may restrict or decline to process the transaction.

This measure primarily targets unusual or high-risk cash usage that could be linked to informal, unregulated, or illicit activities. In a later phase, similar requirements will apply to cash deposits of 5 million baht or more, where the origin of the funds must also be justified.

The BOT has indicated that legitimate needs—such as those of small and medium-sized enterprises (SMEs), individuals conducting regular business operations, or other verifiable purposes—will continue to be accommodated, provided appropriate documentation and explanations are provided. However, the rules aim to make large-scale cash handling more accountable and discourage reliance on physical currency for questionable purposes.

Looking ahead, after an initial implementation period and evaluation of impacts (including any effects on ordinary users), the threshold may be lowered to 3 million baht for both withdrawals and deposits to further strengthen controls.

These changes form part of broader initiatives to tackle structural economic vulnerabilities, encourage electronic payments where practical, and limit opportunities for crime or opaque transactions.

Impact on the Public:

Most everyday individuals and small businesses will remain largely unaffected, as transactions below the 5 million baht threshold face no new requirements, and legitimate large needs can proceed with proper justification.

People or entities accustomed to handling large cash amounts (e.g., for property deals, business purchases, or other high-value activities) will need to prepare explanations and supporting evidence in advance, potentially adding time and documentation steps at the bank.

Those involved in informal or gray-area dealings may find it significantly harder to move large sums in cash without scrutiny, increasing the risk of restrictions or reporting to authorities.

Overall, the shift promotes safer, more traceable financial habits while aiming to reduce crime risks associated with large cash volumes and ease burdens through related reviews of common banking fees.

Key Takeaways:

Implementation is expected in the near future (early to mid-March timeframe), giving the public time to adjust to more accountable cash handling practices.

Cash withdrawals over 5 million baht will require clear justification of purpose and source; unsatisfactory explanations may lead to restrictions.

The rules will later extend to large cash deposits and could lower the threshold to 3 million baht after review.

Legitimate users (e.g., SMEs and individuals with valid reasons) can continue transactions by providing details—no outright ban is intended.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles