Cannabis Control Bill Moves Forward: Medical Use Takes Center Stage

Background: From Decriminalization to a Dedicated Regulatory Framework

The Cabinet has approved the draft Cannabis Control Act (the “Cannabis Control Bill”), marking another significant step toward establishing a dedicated statutory framework for cannabis following its removal from the narcotics list. The Bill is intended to address regulatory gaps that have existed while cannabis has largely been regulated through the existing framework for controlled herbs and subordinate legislation. The Ministry of Public Health has emphasized that the central policy underlying the Bill is the use of cannabis for medical and health purposes rather than recreational consumption. Before submission to the Cabinet, the responsible authorities conducted regulatory impact assessments and several rounds of public consultation.

What the Bill Would Regulate:

The Bill would introduce an integrated regulatory system covering the cannabis supply chain. According to information released by the Ministry of Public Health, it provides for a national cannabis committee and licensing requirements for activities including cultivation, production, importation, exportation, and sale. The framework is intended to make cultivation sources traceable and to provide clearer controls over cannabis flowers and other regulated activities. It also includes protections for children, young persons, pregnant women and other vulnerable groups, restrictions on advertising and marketing of cannabis flowers and smoking equipment, and clearer penalties for violations. The proposed framework distinguishes legitimate medical treatment and research from recreational use, with recreational consumption subject to regulatory restrictions and penalties.

Cabinet Approval Does Not Mean the Bill Is Yet Law:

Cabinet approval is only one stage of the legislative process. The Cannabis Control Bill must next be submitted to the House of Representatives, where legislation is considered in three readings. If approved, it proceeds to the Senate. Depending on whether the Senate approves, rejects or amends the Bill, further parliamentary procedures may be required. Once the Bill has obtained parliamentary approval, it proceeds through the constitutional process for royal assent and publication in the Royal Gazette. It will become legally effective in accordance with the commencement provision in the enacted legislation. The provisions described above therefore remain subject to amendment during parliamentary consideration.

Tighter Controls Are Already in Force:

The proposed Act should also be distinguished from regulatory changes that are already in force. Existing ministerial regulations have tightened the rules applicable to cannabis flowers and are expressly intended to restrict their use to medical purposes. Under the current framework, existing licensees may generally continue operating until their licenses expire, but businesses seeking to continue thereafter must satisfy the applicable requirements under the new licensing regime. Guidance issued by the Department of Thai Traditional and Alternative Medicine indicates that the medical cannabis framework is centered on specified categories of licensed establishments and the involvement of authorized healthcare professionals. Cannabis businesses should therefore not wait for the Cannabis Control Bill to become law before reviewing their operating models, licenses, sourcing arrangements, premises, and professional-supervision requirements.

Key Takeaways:

  • Cabinet approval is an important legislative milestone, but the Cannabis Control Bill is not yet effective law and remains subject to parliamentary consideration and possible amendment.
  • The proposed framework focuses on medical and health use rather than recreational use, with regulatory controls extending across the cannabis supply chain.
  • Licensing, traceability, advertising restrictions, protection of vulnerable groups, and stronger enforcement mechanisms are central features of the proposed regime.
  • A tighter medical-use regime for cannabis flowers is already operating under existing subordinate legislation, independently of the pending Bill.
  • Existing cannabis businesses should review their current licenses and assess whether their operations will satisfy the applicable medical-use regulatory requirements when renewal or a new license becomes necessary.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Cabinet Extends Skills Development Programs to 2031 to Strengthen Industry-Ready Skills

Executive Summary

On September 15, 2026, the Thai Cabinet approved an extension and strategic realignment of the “New-Breed Vocational and Graduate” development initiatives, spearheaded by the Ministry of Higher Education, Science, Research and Innovation (MHESI). The program’s timeline has been extended from its original 2026 (B.E.2569)  completion date to 2031 (B.E.2574), backed by a remaining budget allocation of THB 3.1 billion.

Designed to combat persistent talent shortages in advanced economic sectors, this policy pivots toward a “Skills-First, Degree Later” framework, focusing intensely on practical, industry-aligned competencies in high-growth technology and manufacturing clusters. For domestic and multinational enterprises operating in Thailand, this extension signals a major opportunity to collaborate with academic institutions, tap into government-backed workforce subsidies, and bridge critical talent gaps.

1. Key Highlights of the Cabinet Resolution

  • The initiative’s execution period is officially extended through 2031, providing long-term regulatory and funding stability for workforce planning.
  • The extended program aims to upskill and reskill 81,600 individuals, split between 80,000 enrollees in Non-Degree professional certificate courses and 1,600 enrollees in formal degree pathways.
  • Priority is heavily weighted toward 10 Future Growth Engine industries, including Semiconductors, Artificial Intelligence (AI), Electric Vehicles (EVs), High-Value Medical and Health Services, and Small and Medium Enterprises (SMEs).
  • The curriculum shifts to agile Non-Degree programs (3–4 months or 9 credits) allowing participants to accumulate academic credits that can be transferred toward a full degree later. Crucially, at least 50% of the learning hours must involve hands-on practical training within actual business enterprises.
  • Other key ministries (such as the Ministry of Labor, Ministry of Industry, and NESDC) have aligned with the policy, emphasizing unified database tracking, integrated KPIs, and institutional mentoring models to elevate readiness across all participating universities and firms.

2. Strategic Benefits for Businesses

Employers and corporate investors stand to gain multiple strategic advantages under the extended 2031 (B.E.2574) framework:

  • Direct Access to Pre-Vetted, Job-Ready Talent: Because the curriculum is co-designed around the specific technical requirements of high-tech and future industries, participating enterprises bypass traditional onboarding and retraining bottlenecks.
  • Cost-Efficient Talent Incubation: Companies can leverage government-subsidized frameworks to train workers on real company projects. The requirement for 50% practical workplace training means businesses effectively gain dedicated project contributors while shaping them into permanent hires.
  • Alignment with Thailand 4.0 Incentives: Participation strengthens a corporation’s profile when aligning with Thailand Board of Investment (BOI) criteria, particularly regarding human capital development, R&D collaboration, and technology transfer mandates.
  • Enhanced Retention and Higher Productivity: Historical data from the 2018–2025 (B.E.2561-2568) phase demonstrated that graduates of these programs experienced higher initial employment rates and wages compared to standard curricula, translating to lower turnover and higher operational efficiency for employers.

3. Legal and Compliance Preparation for Businesses

To maximize the benefits of this initiative while mitigating regulatory risks, corporate legal and human resources teams should proactively address the following legal and operational steps:

  • Review and Restructure Internship & Trainee Agreements: As students must complete at least 50% of their curriculum via practical work placement, companies must ensure their standard internship contracts comply with Thai Labor Protection Act provisions, particularly concerning non-employee student trainees, confidentiality obligations, and intellectual property (IP) assignment.
  • Secure Intellectual Property (IP) and Invention Assignments: Given that trainees will be embedded in core R&D, technology, and AI operations, robust IP assignment clauses must be integrated into agreements to ensure that any innovations, code, or proprietary designs developed during the program vest fully with the corporate employer.
  • Data Protection and Cross-Border Compliance (PDPA): With the program emphasizing digital skills, data analytics, and inter-agency database integration, companies must ensure that handling and sharing employee or trainee performance metrics with MHESI or partner universities strictly complies with the Personal Data Protection Act (PDPA).
  • Formalize Institutional Partnerships: Enterprises wishing to access the 81,600 target talent pool should formalize Memorandums of Understanding or consortium agreements with participating MHESI-approved universities (numbering over 123 institutions) to secure priority placement for cohorts tailored to their corporate needs.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Seeks U.S. Investment in AI and Digital Infrastructure

Executive Summary

During an official diplomatic mission to New York, a high-level Thai delegation led by the Prime Minister and Minister of Interior, accompanied by the Deputy Prime Minister and Minister of Commerce, and the Minister of Digital Economy and Society (“DES”), engaged in strategic discussions with global financial and technology leadership—including senior executives from Bank of America (“BofA”), Microsoft Corporation, and Pacific Investment Management Company LLC (“PIMCO”). Joined by senior representatives from the Stock Exchange of Thailand (SET) and the Federation of Thai Capital Market Organizations (FETCO), the delegation presented Thailand’s policy roadmap to over 25 major institutional fund managers representing more than USD 40 trillion in assets under management (AUM).

The discussions focused primarily on foreign direct investment (FDI) opportunities in Thailand’s rapidly expanding digital economy—specifically targeting Artificial Intelligence (“AI”), data center architecture, cybersecurity, digital infrastructure, and clean energy transition to support energy-intensive tech operations. To reinforce global investor confidence, the Thai government emphasized its neutral, balanced foreign policy between the United States and China, focusing on mutual economic benefit without taking sides. Furthermore, the delegation expressed gratitude to Microsoft Corporation for its ongoing support of Thailand’s accession process to the Organization for Economic Co-operation and Development (“OECD”) as a structural catalyst to elevate domestic regulatory frameworks, legal productivity, and regional supply chain competitiveness.

Benefits for Thai Business Operators and Local Investors

The Thai government’s focused push to position the country as Southeast Asia’s digital and AI hub creates significant structural advantages for domestic commercial entities and institutional investors:

  • Local Tech, Telecom, and Infrastructure Developers: Domestic companies operating in telecommunications, cloud hosting, and data center facilities stand to benefit directly through joint ventures, technical knowledge transfer, and strategic co-investments with major U.S. technology leaders such as Microsoft Corporation.
  • Renewable Energy and Utility Operators: As large-scale AI processing and data center operations require sustainable power, local clean energy providers gain direct commercial opportunities through long-term Power Purchase Agreements (PPAs) and green energy solution partnerships.
  • Export and Technology-Driven Supply Chains: Alignment with international technology and OECD standards enhances the global competitiveness of Thai enterprises, facilitating seamless integration into multinational supply chains and technology networks.
  • Thai Capital Market and Local Financial Institutions: Sustained engagement with top-tier asset managers like PIMCO and BofA stimulates foreign portfolio allocations toward domestic debt and capital markets, lowering capital costs and enhancing liquidity for local corporate issuers seeking digital transformation financing.

Preparation for Thai Business Operators and Investors: Strategic and Legal Roadmaps

To effectively absorb foreign direct capital, leverage advanced U.S. technology, and ensure seamless commercial integration, domestic business operators and local investors should address key regulatory, legal, and operational considerations:

1. Compliance with the Upcoming Draft Digital Infrastructure Act for Data Center Operators

Under the pending Draft Digital Infrastructure Business Operation Act, data center operators face an evolving regulatory landscape:

  • Licensing & Corporate Setup: Operators shall incorporate as a Thai limited or public limited company, secure an operating license from the Ministry of Digital Economy and Society (DES), and post performance financial guarantees.
  • Resource & Environmental Standards: High-energy operations shall meet mandatory clean energy consumption ratios, strictly manage power/water usage effectiveness (PUE/WUE), comply with zoning rules, and undergo Environmental Impact Assessments (EIA).
  • Local Data Storage: The bill enforces data localization for domestic personal and corporate data, permitting overseas transfers only under specific legal exemptions.

2. Data Governance, Cross-Border Transfer, and Cybersecurity Compliance

In tandem with sector-specific data center rules, domestic entities shall maintain full compliance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA) and the Cybersecurity Act B.E. 2562 (2019). Companies partnering with multinational cloud or AI providers shall review cross-border data transfer mechanisms and cloud infrastructure security protocols to ensure strict regulatory alignment.

3. Intellectual Property (IP) Protection and Technology Licensing

Collaboration with foreign technology providers involves processing proprietary algorithms and advanced software solutions. Thai business operators shall establish comprehensive IP protection strategies under the Patent Act B.E. 2522 (1979) and the Copyright Act B.E. 2537 (1994). Commercial contracts shall explicitly define IP ownership rights, technology licensing terms, source code access, and non-disclosure obligations (NDAs) for co-developed AI solutions.

4. Corporate Structuring, Green ESG Alignment, and Investment Incentives

Foreign partnerships and joint venture arrangements shall comply with statutory foreign equity limitations prescribed under the Foreign Business Act B.E. 2542 (1999) (FBA). Additionally, local enterprises should structure corporate vehicles to align with international ESG metrics and capitalize on green investment privileges granted by the Board of Investment (BOI) or regulatory incentives within the Eastern Economic Corridor (EEC) framework.

5. Workforce Upskilling and Legal Governance for AI Integration

Local companies integrating enterprise AI solutions should update internal employment contracts, acceptable use policies, and compliance manuals to account for AI-driven workflows. Organizational governance frameworks should adhere to national guidelines—such as the Thailand National AI Strategy and Action Plan—ensuring transparent algorithmic risk management and proper employee training on data privacy and cyber defense.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

ETDA’s TTR Guidance: A New Framework for E-Marketplace Fee Transparency

The Electronic Transactions Development Agency (ETDA) has issued new guidance introducing the concept of the Total Take Rate (TTR) for e-marketplaces. The guidance is intended to give merchants a clearer and more comparable picture of the total fees and expenses associated with selling through an e-marketplace, particularly before they decide whether to participate in a campaign, promotional program, or additional service.

The initiative responds to an increasingly complex fee structure in the e-commerce ecosystem. A merchant’s cost of selling through an e-marketplace may extend well beyond the headline commission rate and include payment processing fees, infrastructure or system fees, campaign participation costs, merchant-funded discounts, advertising fees, affiliate fees, and charges for additional services. Because these charges may use different names, rates, and calculation bases, merchants may find it difficult to determine the actual economic cost of a transaction. The TTR framework is designed to address this information gap by presenting the aggregate financial impact in a standardized and understandable form. (ETDA⁠)

What is the Total Take Rate?

Under the guidance, TTR generally represents the total fees and expenses borne by a merchant in connection with the sale of a product, expressed as a percentage of the net product price. The net product price is essentially the initial selling price after deducting discounts for which the merchant is responsible. TTR should be presented both as a percentage and as an actual monetary amount so that merchants can see how platform charges affect the proceeds they expect to receive. (ETDA⁠)

The guidance divides TTR into three components:

Baseline TTR represents the aggregate fees ordinarily necessary for an order to take place and be completed. These may include commissions, payment processing fees, and infrastructure fees, without including costs attributable to campaigns or additional services.

Scenario TTR takes the Baseline TTR and adds the costs associated with a particular campaign or additional service that the merchant is considering. Depending on the arrangement, these may include additional discounts, campaign participation charges, advertising fees, affiliate fees, or fees for special programs.

Incremental TTR represents the difference between the Scenario TTR and Baseline TTR. It therefore gives the merchant a relatively straightforward indication of the additional economic burden associated with participating in the proposed campaign or additional service. (ETDA⁠)

This distinction is important because a platform’s headline commission rate may provide only a partial picture of the actual cost of a sale. By comparing the Baseline and Scenario TTR, a merchant can assess the financial position both with and without participation in a particular campaign.

Disclosure before the merchant commits:

A central feature of the guidance is the timing of disclosure. Relevant TTR information should be made available at the point at which the merchant is making the commercial decision, particularly before confirming participation in a campaign or additional service.

The platform should provide information that allows the merchant to understand the Baseline TTR, the Scenario TTR, the resulting Incremental TTR, and the estimated net proceeds. The objective is to enable the merchant to assess the economic consequences before committing, rather than discovering the full cost only after the transaction has taken place.

The guidance therefore encourages platforms to place TTR information at relevant decision points, such as product pricing pages, fee information pages, seller dashboards, and, importantly, the screen presented before a merchant confirms participation in a campaign or additional service. Information should be presented clearly and accessibly rather than being obscured in detailed terms and conditions or links that are difficult to locate. (ETDA⁠)

TTR calculation tools:

The guidance also encourages e-marketplaces to provide merchants with a TTR calculation tool that is easy to use and available without an additional charge.

Such a tool could allow a merchant to select a particular product or SKU and enter relevant variables, including the selling price, merchant-funded discounts, campaign participation, and applicable fees. The resulting calculation should enable the merchant to compare the cost of selling under the ordinary arrangement with the cost that would apply if the merchant participates in the proposed campaign or additional service.

The output should show relevant fees in both monetary and percentage terms and provide an estimate of the merchant’s net proceeds. Where sufficient information is available, the tool may also show gross profit and the break-even selling price. The guidance additionally contemplates merchants being able to save or download calculation results for subsequent verification. (ETDA⁠)

This aspect of the guidance may have practical implications beyond simply adding another disclosure to a platform’s terms of service. E-marketplace operators may need to consider whether their merchant interfaces, campaign enrollment processes, fee databases, and internal calculation systems are capable of generating sufficiently accurate TTR information at the point when a merchant makes its decision.

Changes to fees affecting TTR:

The guidance also addresses subsequent changes to the fee structure. Where a platform changes a fee rate, calculation base, collection method, or other condition affecting TTR, it should generally notify merchants at least 30 days in advance.

The information should allow merchants to compare the position before and after the change and understand how the change affects the Baseline TTR and Scenario TTR. This gives merchants an opportunity to assess the commercial consequences and adjust their pricing or participation strategy before the new fee structure applies. (ETDA⁠)

This approach reflects a broader transparency objective: merchants should not merely know that a particular fee has changed, but should also be able to understand how that change affects the overall cost of using the platform.

Transparency after the transaction:

The TTR framework does not end once the merchant has agreed to participate in a campaign. The guidance also encourages transparency after a transaction has been completed.

Merchants should be able to review the fees actually deducted and compare them against the TTR previously estimated. Where the amounts differ, the platform should provide sufficient information to explain the discrepancy. Possible reasons could include the actual use of coupons, product returns, refunds, or changes in the merchant’s status.

ETDA also recommends that calculation histories and actual fee information remain accessible through the platform for at least three months and that merchants be able to save or download relevant information. Annual summaries are also contemplated to assist merchants in evaluating the overall cost of selling through the platform. (ETDA⁠)

A transparency framework, not a fee cap:

An important point is what the TTR guidance does not do. It does not prescribe a maximum commission or impose a ceiling on the amount that an e-marketplace may charge. ETDA describes its purpose as improving the completeness, transparency, comparability, and verifiability of fee information so that merchants can make informed commercial decisions. (ETDA⁠)

The legal status of the instrument should therefore be understood accordingly. ETDA places the TTR guidance within its category of “Best-practice/Self-Regulation” measures rather than mandatory platform rules. (ETDA⁠) The guidance should therefore not be characterized as immediately imposing a statutory obligation on every e-marketplace to implement the TTR model exactly as described.

Nevertheless, the distinction between guidance and mandatory regulation should not obscure its practical importance. The TTR framework provides a detailed regulatory benchmark for how ETDA considers platform fee transparency should operate. E-marketplace operators should therefore consider the guidance when reviewing their fee structures, merchant-facing disclosures, campaign enrollment processes, and supporting IT systems.

Why TTR matters for merchants:

For merchants, the principal benefit of the TTR model is that it changes the focus from individual fee rates to the aggregate economic effect of selling through the platform.

Consider a product with an initial price of THB 1,000 where the merchant bears a THB 100 discount, producing a net product price of THB 900. ETDA illustrates how a Baseline TTR of 12.96% would correspond to approximately THB 116.63 in baseline charges and estimated net proceeds of THB 783.37. If participation in a campaign creates another THB 108 of costs, the Scenario TTR would rise to 24.96%, with the Incremental TTR showing an additional 12 percentage points and estimated net proceeds falling to THB 675.37. (ETDA⁠)

The example illustrates the commercial rationale behind the framework. A merchant considering a campaign should be able to assess not simply whether the campaign may increase sales, but also how much additional revenue or volume would be required to offset the additional platform costs.

Practical implications for e-marketplace operators:

For platform operators, implementation of the TTR framework is potentially a product, compliance, and systems issue rather than merely a matter of revising contractual terms.

Platforms may need to map the different charges imposed on merchants, identify the relevant calculation bases, distinguish baseline costs from campaign-specific or additional costs, and ensure that their systems can calculate and present the resulting TTR accurately. Merchant dashboards and campaign enrollment interfaces may also need to be designed so that relevant information is available before the merchant confirms participation.

Operators should also consider whether their post-transaction records allow merchants to reconcile estimated and actual charges and whether changes to fees can be communicated in a manner that explains their overall TTR impact rather than merely announcing a revised percentage for an individual fee.

For merchants, meanwhile, TTR could become a useful metric for comparing the economic effect of different campaigns and services. In particular, the Incremental TTR provides a relatively direct way of assessing the additional cost of a campaign against its expected contribution to sales.

Key takeaways:

  • ETDA has introduced TTR as a framework for improving transparency over the aggregate fees and expenses borne by merchants selling through e-marketplaces.
  • TTR is divided into Baseline TTR, Scenario TTR, and Incremental TTR, allowing merchants to distinguish ordinary transaction costs from the additional costs associated with campaigns or additional services.
  • The guidance emphasizes disclosure before a merchant commits to a campaign or additional service, rather than relying solely on general fee schedules or contractual terms.
  • E-marketplaces are encouraged to provide accessible TTR calculation tools showing fees, estimated net proceeds, and other relevant financial information in both monetary and percentage terms.
  • Changes affecting TTR should generally be notified to merchants at least 30 days in advance, together with information enabling them to understand the impact of the change.
  • Merchants should be able to compare estimated TTR with fees actually deducted after transactions and access historical fee information.
  • The TTR framework does not impose a cap on platform fees. It is currently presented by ETDA as a best-practice/self-regulatory measure aimed at transparency and informed decision-making rather than direct price regulation.
  • Although not framed as an immediately mandatory fee-control regime, the guidance provides e-marketplace operators with a detailed regulatory benchmark against which their fee disclosure practices and merchant-facing systems can be reviewed.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

DIP e-Exchange: A New Framework for Accessing and Using IP Data

The Department of Intellectual Property (DIP) has launched DIP e-Exchange, a new platform designed to enable government agencies and private-sector organizations to connect with and exchange intellectual property (IP) information held by the DIP. The initiative goes beyond providing another online search facility. It establishes an application programming interface (API)-based infrastructure through which eligible organizations can potentially integrate official IP information into their own systems and workflows.

The DIP describes the platform as part of its development of an IP data infrastructure that allows information to be exchanged between organizations in a standardized and secure manner. The new system replaces the DIP’s previous API channel for existing participating organizations and is provided without charge. The DIP also emphasizes compliance with government data governance and information security requirements.

From IP Records to Usable Business Data:

The DIP e-Exchange currently provides APIs covering six categories of IP information: copyright, geographical indications, petty patents, design patents, invention patents, and trademarks. The DIP’s announcement indicates that the information available through the system includes, for example, granted or published patent information, trademark and rights-holder information, and information concerning copyright works and persons who have notified copyright information to the DIP.

This is significant because IP registry information has traditionally been approached primarily as information to be searched when a particular legal or commercial need arises. An API-based infrastructure offers a different model. Instead of requiring a user to conduct an individual search and manually incorporate the results into another process, an authorized organization’s system can potentially retrieve relevant information directly from the DIP and use that information within its own digital workflow.

The DIP has identified a broad range of potential applications. These include verifying the existence of IP rights in public- and private-sector transactions, supporting the development of higher-value products and services through IP, assisting IP valuation for SME financing, facilitating research and analysis, and enabling enforcement authorities to verify IP rights more efficiently.

Implications for IP Transactions and Financing:

The new infrastructure could be particularly relevant to transactions in which the existence, ownership, or status of IP rights needs to be verified. IP information is routinely relevant to mergers and acquisitions, investments, licensing, technology transfers, financing arrangements, enforcement actions, and IP due diligence. Where organizations regularly undertake these activities, direct access to official data may allow some verification processes to be incorporated into existing compliance, transaction, or portfolio-management systems.

The potential application to financing is particularly noteworthy. One practical challenge in IP-based financing is obtaining reliable information concerning the underlying asset. The DIP specifically identifies the use of IP information for IP valuation in connection with financial institutions’ lending to SMEs as one potential application of the platform.  Easier access to authoritative registry information could therefore contribute to the information infrastructure necessary for financial institutions and other stakeholders to assess IP assets.

However, data obtained from the DIP should not be regarded as a substitute for legal due diligence. Registry information is only one component of determining the legal and commercial position of an IP asset. Depending on the transaction, separate investigation may still be required regarding matters such as chain of title, licenses, assignments, security interests, contractual restrictions, pending disputes, actual use of trademarks, unregistered rights, and the validity or enforceability of particular rights. The legal significance of information retrieved through the system must therefore be distinguished from the efficiency with which that information can be obtained.

Information Security and Data Governance:

DIP e-Exchange is intended for legal entities in both the public and private sectors whose activities relate to IP and that maintain appropriate information security arrangements. Organizations seeking access are required to register and submit supporting documentation to the DIP.

The supporting documentation identified by the DIP includes a request for data connectivity, an MOU where applicable, the relevant service application form, and either evidence of ISO/IEC 27001 certification or the organization’s information security policies and practices.  The platform’s technical documentation also indicates that API access operates through an authorization token, illustrating that access is controlled rather than being an unrestricted bulk-data facility.

These requirements highlight an important distinction between making IP information available for individual public searches and permitting systematic access to government data through APIs. Once information can be retrieved and processed at scale, issues of cybersecurity, access control, permitted use, data retention, system integrity, and internal accountability become increasingly important.

Organizations considering connection to DIP e-Exchange should therefore approach implementation as both an IP-data project and a data-governance project. Appropriate internal controls may need to address who is authorized to access the system, the purposes for which information may be retrieved, how retrieved information is stored and incorporated into other databases, and how access and use are monitored.

Toward Interoperable IP Infrastructure:

The broader significance of DIP e-Exchange is the movement from digitization toward interoperability in IP administration.

Digitization allows applicants, rights holders, professionals, and members of the public to interact electronically with the DIP. Interoperability goes a step further: it enables official IP information to become part of the digital processes of other organizations. Instead of government data remaining within a standalone database that must be consulted separately, standardized APIs can potentially allow that data to interact with other systems.

This may create opportunities well beyond conventional IP searches. Businesses and service providers could potentially incorporate official IP information into portfolio-management and transaction systems; financial institutions could use relevant data as part of IP valuation and financing processes; researchers could conduct more systematic analysis; and enforcement agencies could verify rights more efficiently. The DIP itself has characterized IP information as capable of supporting public services, policy analysis, and the development of future digital services.

The practical value of DIP e-Exchange will ultimately depend on matters such as the scope and quality of the available data, the frequency with which it is updated, the conditions governing access and use, and the extent to which organizations integrate the APIs into their operational systems. Nevertheless, the platform represents an important change in how official IP information can be accessed and potentially used.

For businesses, financial institutions, technology companies, research organizations, IP professionals, and other organizations that regularly process IP information, the relevant question may increasingly shift from whether official IP information is available online to how authoritative IP data can be securely incorporated into the systems through which legal and commercial decisions are made.

Key Takeaways:

DIP e-Exchange introduces API-based access to official IP information, covering copyright, geographical indications, petty patents, design patents, invention patents, and trademarks.

The potential uses extend beyond conventional registry searches. The DIP identifies transaction verification, IP valuation and financing, research, enforcement, and development of digital services among the intended applications.

API access may facilitate the integration of IP information into organizational workflows, including due diligence, portfolio management, financing, and compliance processes.

Registry data does not replace legal due diligence. Ownership, contractual rights, chain of title, disputes, unregistered rights, and validity or enforceability issues may still require separate investigation.

Information security is a central feature of the framework. Organizations seeking access are expected to demonstrate appropriate information security standards, policies, or practices.

The initiative represents a broader transition toward interoperable IP infrastructure, in which government-held IP information can potentially become part of the digital systems used to make legal, financial, and commercial decisions.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Employee Welfare Fund Contributions: What Employers Need to Know

Employers falling within the scope of the Labor Protection Act are required to make contributions to the Employee Welfare Fund, creating an additional payroll and compliance obligation alongside social security contributions. The regime is particularly relevant to employers with at least 10 employees that have not established a provident fund or other employee welfare arrangement satisfying the statutory exemption. The Ministry of Labor estimates that approximately 105,416 establishments and 5.57 million employees will be covered.

Who Is Required to Contribute?:

Employees of businesses employing at least 10 employees are generally required to participate in the Employee Welfare Fund. An exemption applies where an employer has established a provident fund under the Provident Fund Act or provides qualifying welfare arrangements for employees upon termination of employment or death. Employers should therefore review their existing benefit arrangements carefully rather than assume that merely having a provident fund automatically exempts their entire workforce.

Contribution Rates and Employer Responsibilities:

From 1 October 2026 through 30 September 2031, employees must contribute 0.25% of wages, with employers contributing an additional 0.25%. From 1 October 2031 onward, the contribution rate increases to 0.50% for each side. The employer is responsible for deducting the employee contribution from wages, adding its own contribution, and remitting both amounts to the Fund. For example, for monthly wages of THB 30,000, the employee and employer would initially contribute THB 75 each, resulting in a total monthly contribution of THB 150.

Employers should review payroll settings, employee classifications, provident fund coverage, and contribution procedures. Failure to remit contributions in full may result in an additional payment of 5% per month on outstanding contributions. Failure to submit required information or the submission of false information may also expose an employer to imprisonment for up to six months, a fine of up to THB 10,000, or both.

Other Tax and Payroll Compliance Points:

Individuals subject to the half-year personal income tax return (PND 94), principally those deriving income under Sections 40(5)–(8) of the Revenue Code, generally have a 30 September filing deadline, extended to 8 October for electronic filing. The reduced 7% VAT rate remains in effect, while the Social Security Fund wage ceiling for employees insured under Section 33 is THB 17,500 per month, resulting in a maximum monthly contribution of THB 875 each for the employee and employer.

The Social Security Fund and Employee Welfare Fund are separate regimes. Employers falling within the scope of both must therefore account for both contribution obligations when configuring payroll and calculating employment costs.

Key Takeaways:

Employers with at least 10 employees should determine which employees are subject to the Employee Welfare Fund and whether existing provident fund or welfare arrangements satisfy the statutory exemption. Payroll systems should be configured for the applicable employee deduction and corresponding employer contribution, with particular attention to the potentially significant 5% monthly additional payment for late or incomplete remittances.

Employers should also consider the Employee Welfare Fund together with their broader payroll compliance obligations, including social security contributions and applicable tax requirements. A coordinated review of payroll systems, employee coverage, and existing benefit arrangements can help identify compliance gaps before they result in additional payments or penalties.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

Amendments to TCCT Notifications: Modernizing Thailand’s Market Dominance and Merger Control Frameworks

Driven by the rapid transformation of modern trade alongside increasingly complex business operations, concerns regarding unfair market practices and anti-competitive conduct in Thailand have escalated substantially. To address these concerns, the Trade Competition Commission of Thailand (“TCCT”) has drafted three notifications to modernize market oversight and ensure clear, robust legal standards. These Drafts update market dominance criteria and refine merger control concepts by establishing clearer monetary thresholds, including explicit rules on affiliate sales aggregation.

Accordingly, the TCCT has released the following draft notifications (“Drafts”):

1.     Draft Notification on Rules for Determining Business Operators with Market Dominance (“Draft Market Dominance Notification”)

2.     Draft Notification on Rules, Procedures, and Conditions for Seeking Permission and Granting Approval for Business Combinations (No. ..) B.E. …. (“Draft Merger Approval Notification”)

3.     Draft Notification on Rules, Procedures, and Conditions for Reporting the Results of Business Combinations (No. ..) B.E. …. (“Draft Merger Reporting Notification”)

These Drafts, presently open for public feedback between September 22 and October 21, 2026, represent a significant update to Thailand’s trade competition and merger control framework. By revising market dominance criteria, refining the definition of a monopoly, and updating thresholds for mergers that may significantly reduce competition, these changes aim to eliminate regulatory ambiguity, close corporate loopholes regarding sales aggregation across affiliated entities, adapt to modern business models, and foster fair market competition.

Key Objectives

1. Draft Market Dominance Notification

·        Repeal of the Previous Notification

This Draft explicitly repeals the Notification of the TCCT regarding Criteria for Determining Business Operators with Market Dominance, dated November 10, B.E. 2568 (2025).

·        Revised Quantitative Thresholds for Market Dominance

The Draft mandates that a business operator shall be regarded as holding market dominance if it meets either of the following quantitative conditions:

o   Single Entity: A single operator in any product or service market that commanded a market share of 33% or higher and generated sales revenue of 500 million THB or more in the preceding year.

o   Two Entities Combined: Any two operators in a given market that held a combined market share of 75% or higher in the preceding year. However, this rule exempts any operator within the pair whose individual annual sales were below 500 million THB or whose market share was less than 10%.

·        Aggregation of Market Share for Corporate Affiliates

The proposed provision directs the authority to aggregate the market shares and sales revenues of business entities sharing policy-level management or controlling power, explicitly declaring all affiliated entities within such a group as dominant operators.

·        Qualitative Assessment Criteria for Dynamic and Digital Platform Markets

The proposed amendments exempt dynamic markets—such as rapidly evolving industries, short-term supply/demand fluctuating markets, and digital platforms—from the quantitative thresholds outlined above. Instead, regulators are instructed to determine dominance using qualitative metrics, including barriers to market entry, buyer power, and relevant regulatory frameworks.

2. Draft Merger Approval Notification

·             Redefining “Monopoly”

The TCCT has revised the definition of “Monopoly” under the Notification of the TCCT on Rules, Procedures, and Conditions for Seeking Permission and Granting Approval for Business Combinations B.E. 2561 (2018). The new provision combines an annual sales threshold of 500 million THB or more with the existing qualitative criteria of single-operator price and output control.

3. Draft Merger Reporting Notification

·          Redefining “Mergers that May Significantly Reduce Competition”

The Draft Notification updates the definition of mergers that significantly reduce competition under the Notification of the TCCT on Rules, Procedures, and Conditions for Reporting the Results of Business Combinations B.E. 2561 (2018). The revised rule establishes a combined annual sales threshold of 500 million THB or more for transactions that do not create a monopoly or dominance. Furthermore, it explicitly directs the authority to aggregate sales revenues from all policy-linked or common-control affiliates.

Implementation and Public Participation

These proposed amendments mark an important milestone for competition regulation in Thailand. It is crucial that all stakeholders—including businesses, industry associations, and consumer advocates—thoroughly examine the text and submit insightful feedback while the consultation window remains open. Direct involvement from all sectors will play a pivotal role in shaping a balanced regulatory environment that aligns rigorous oversight with commercial realities.

Conclusion

The proposed amendments to the TCCT notifications mark a pivotal shift toward a more transparent, predictable, and modern trade competition framework in Thailand. By establishing clear monetary thresholds of 500 million THB, mandating sales aggregation across corporate affiliates, and introducing qualitative evaluations for dynamic digital markets, these Drafts effectively close long-standing regulatory loopholes. Ultimately, this comprehensive reform balances rigorous antitrust oversight with practical commercial realities, fostering a fair competitive landscape while strengthening long-term consumer welfare.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

When Health Data Moves Beyond Its Original Purpose

Large-scale health screening programs can generate datasets of exceptional value. Information initially collected to assess an individual’s health may later be useful for population-health planning, epidemiological studies, academic research, development of healthcare technologies, or collaboration among public authorities, hospitals and research institutions. At the same time, such projects illustrate one of the more difficult questions under the Personal Data Protection Act (PDPA): when may health data collected for one purpose subsequently be used or disclosed for another?

A recent consultation submitted to the data protection regulator in connection with health information collected through a large-scale screening program brings several of these issues into focus. Rather than discussing the regulator’s conclusions in that particular matter, this article examines the compliance questions the scenario raises for organizations handling health and data collection.

Health information requires a two-layer legal analysis:

The starting point is that health information is expressly classified as sensitive personal data under Section 26 of the PDPA. As a general rule, collecting such information without the data subject’s explicit consent is prohibited unless one of the statutory exceptions applies.

This is important because organizations sometimes begin their analysis with Section 24, particularly Section 24(1), which permits the collection of personal data without consent for historical or archival purposes in the public interest, or for research or statistical purposes, provided appropriate safeguards are implemented.  For ordinary personal data that may be the principal legal-basis analysis. For health data, however, satisfying Section 24 does not by itself resolve the issue. The processing must also be capable of being justified under the special rules applicable to sensitive personal data in Section 26.

Section 26 contains several potentially relevant exceptions, including processing necessary for certain health-related purposes where the statutory requirements are satisfied. The applicable exception will depend on the nature of the project, the statutory functions of the organizations concerned, who performs the processing, and the purpose for which the health information is being used.  Consequently, describing a project simply as “research” or “public health” should not be treated as a substitute for identifying the precise statutory basis supporting each processing operation.

Secondary use is a separate question:

A second issue is purpose limitation. Section 21 requires a controller to collect, use or disclose personal data in accordance with the purpose communicated to the data subject. Using the information for a different purpose generally requires notification of the new purpose and consent, unless the PDPA or another law permits the new processing.

This distinction becomes particularly important where information was originally collected to provide an individual health screening service but is later proposed to be used for research, analytics, public-health planning or development of new systems. The question is not merely whether research can, in the abstract, be conducted without consent. The organization should identify what the original purpose was, what the subsequent purpose is, and what provision of law permits the transition from one to the other.

The PDPA recognizes research and statistical activities in a number of places and also contemplates situations in which providing an individual notice may be impossible or seriously obstruct the achievement of scientific, historical or statistical research. In such circumstances, however, appropriate safeguards for the rights, freedoms and interests of data subjects remain important.  This makes research governance more than an exercise in selecting a lawful basis: data minimization, access restrictions, security controls, retention limits and the manner in which research results are disclosed all become part of the compliance analysis.

Removing names may not end the PDPA analysis:

Another recurring issue is whether health data can simply be “de-identified” before being transferred or used for research.

The distinction between genuinely anonymous information and information from which direct identifiers have merely been removed is critical. Removing a person’s name, identification number or telephone number does not necessarily mean that the person can no longer be identified. Health datasets frequently contain combinations of age, location, diagnosis, treatment history, dates and other variables that may permit identification when combined with other information.

The PDPA itself distinguishes between personal data and information that has been made incapable of identifying the data subject. For example, it expressly recognizes anonymization as one possible means of dealing with data in connection with a deletion request.  Organizations should therefore avoid treating “de-identification”, “pseudonymization” and “anonymization” as interchangeable concepts.

As a practical matter, data linked to a code while a corresponding key remains available should normally be treated cautiously as personal data. Whether a dataset has become genuinely anonymous should be assessed against the realistic possibility of re-identification, including identification through combination with information held separately. For valuable health datasets, this may require both technical controls and organizational restrictions rather than simply deleting direct identifiers.

Who is the controller when several organizations participate?

Large-scale health projects commonly involve several participants: a government agency may establish the program, hospitals may collect samples and examination results, a university may analyze the information, an IT provider may host the database and separate researchers may later obtain datasets.

The labels used in the collaboration agreement are not necessarily decisive. The relevant question is who determines the purposes and essential means of each particular processing activity. A participant acting solely on documented instructions may have a processor role, whereas an institution that determines its own research question and decides how information will be analyzed may itself exercise controller functions.

The same institution may therefore occupy different roles at different stages of a project. That distinction matters because the PDPA imposes different obligations on controllers and processors, and because disclosure from one independent controller to another requires its own legal justification rather than merely a data processing agreement.

Organizations managing collaborative health projects should consequently map the data flow and the decision-making structure, rather than assigning a single PDPA label to each institution for the project as a whole.

Data sharing is itself a processing activity:

Where health information is disclosed to another organization, it is not enough that the recipient intends to conduct worthwhile research. Section 27 restricts the use and disclosure of personal data unless consent has been obtained or the information was collected under an applicable statutory exception. It also restricts a recipient from subsequently using the information for purposes beyond those communicated when obtaining the data.

This means that data-sharing arrangements should identify, among other matters, the purpose of disclosure, categories of information involved, respective legal bases, permitted uses, security measures, retention and deletion arrangements, onward disclosure restrictions, handling of data-subject rights, breach responsibilities and the respective controller or processor status of the parties.

The existence of a data-sharing agreement is valuable evidence of governance, but the agreement does not itself create a lawful basis that does not otherwise exist under the PDPA.

International research creates an additional layer:

Where research collaborators, cloud providers or analytical systems are located outside Thailand, the international-transfer provisions must also be considered independently of the lawful basis for the underlying research.

Section 28 establishes the principle that transfers should be made to destinations having an adequate standard of personal data protection, subject to specified statutory exceptions.  Section 29 provides mechanisms concerning transfers within groups and permits other safeguards in circumstances prescribed under the statutory framework.

Accordingly, an organization may have a valid domestic basis to process health information for a particular purpose but still need to address a separate transfer question before making the information accessible overseas. This is especially relevant where data is stored on international cloud infrastructure or foreign researchers are given remote access to a Thai database; an organization should not assume that the absence of a physical file transfer necessarily removes the cross-border issue.

Why these issues extend beyond healthcare:

Although health screening provides a particularly clear example because Section 26 applies, the underlying questions are much broader. Businesses increasingly seek to reuse datasets originally collected for operational purposes to train algorithms, develop AI systems, perform behavioral analytics or create new products. The same sequence of questions frequently arises: What was the original purpose? What is the proposed secondary purpose? Does the new processing have an independent legal basis? Are sensitive data involved? Can the information genuinely be anonymized? Who determines the new purpose? Will another organization receive the data? Will it become accessible outside Thailand?

The regulatory risk often arises not because the organization lacks a legitimate business or public-interest objective, but because these questions are addressed only after a valuable dataset has already been created. Building secondary-use governance into the data lifecycle from the beginning is therefore considerably safer than attempting to reconstruct the legal basis when a research or AI opportunity later emerges.

Key Takeaways:

  • Health data requires special treatment: An organization relying on a research basis under Section 24 must still address the sensitive-data requirements of Section 26.
  • Secondary use should be analyzed separately from original collection: A lawful basis for collecting health information does not automatically authorize every later research, analytics or development purpose.
  • Removing names is not necessarily anonymization: The ability to identify an individual through remaining data or other available information remains relevant.
  • Roles should be determined activity by activity: A university, hospital, government agency or technology provider may have different controller or processor roles at different stages of the same project.
  • A contract does not replace a lawful basis: Data-sharing agreements and processing agreements are governance tools; they do not themselves legalize a disclosure.
  • Cross-border access adds another compliance layer: International transfer requirements must be considered separately from the legal basis for the underlying research.
  • Research and AI projects benefit from governance by design. Organizations should determine secondary-use rules, access controls, anonymization standards and data-sharing procedures before datasets are repurposed.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Criteria and Conditions for Allowing Foreign Nationals to Use Automated Passport Control Channels

Background

The Immigration Bureau introduced Automated Passport Control Channels under the Order No. 322/2566 (the “Previous Order”), effective 15 December 2023, to support tourism and improve immigration processing efficiency.

However, the original framework was relatively narrow in scope, covering only a limited group of foreign nationals and restricting outbound automated processing to Suvarnabhumi Airport. To enhance accessibility and accommodate a wider range of travelers, the Immigration Bureau subsequently issued the Order No. 196/2569 (the “Current Order”), which substantially expands the scope of the Automated Passport Control System.

Immigration Bureau Order No. 196/2569

To further facilitate immigration clearance for foreign travelers, the Immigration Bureau issued the Current Order, effective on 24 August 2026. The Current Order significantly expands access to Automated Passport Control Channels by broadening eligible nationalities, visa categories, and airport checkpoints. Here is what has been changed compared to the previous order.

  1. Expanded Eligible Nationalities

The most significant change is the expansion of eligible nationalities from only Singapore and Hong Kong under the Previous Order to 33 countries and territories under the Current Order.

The expanded list now includes major business and tourism markets such as the United Kingdom, Japan, South Korea, Australia, New Zealand, Germany, France, Switzerland, Italy, the Netherlands, Sweden, Norway, Denmark, Finland, Belgium, Austria, Canada, and Singapore.

As a result, a substantially larger number of foreign travelers are now eligible to use Automated Passport Control Channels when entering and departing Thailand.

  • Expanded Visa Eligibility

The Previous Order primarily limited access to permanent residents, diplomats, government representatives, and certain designated individuals.

Under the Current Order, eligibility has been extended to holders of specified Non-Immigrant Visas as listed in its Appendix, covering a wider range of foreign nationals residing, working, studying, investing, or living with family members in Thailand.

  • Expanded Airport Access

Under the Previous Order:

  • Inbound automated channels were available only to a limited group of foreign nationals and specific type of passport holders.
  • Outbound automated channels were available only at Suvarnabhumi Airport.

Under the Current Order:

  • Eligible foreign nationals as listed in its Appendix can use automated channels for both inbound and outbound travel.
  • Access is available at any international airport equipped with the Automated Passport Control System.
  • Operational Improvements

The Current Order also introduces procedures enabling immigration officers to promptly correct minor system errors, including issues related to visa classification, period-of-stay records, and automated overstay alerts, thereby helping to reduce delays and unnecessary processing.

  • Broader Coverage of Eligible Travelers

The Current Order also broadens eligibility to include:

  • Business: employees, executives, assignees, and investors;
  • Education: teachers, researchers, and students;
  • Family: spouses, parents, children, and other qualifying family members of Thai nationals, permanent residents, and eligible foreign residents.  

It is crucial to note that each criterion is evaluated independently. Therefore, if a foreigner fits into one of the eligible groups (such as holding a qualifying visa or belonging to an eligible nationality), they will be allowed to use the automated channels

Practical Examples

  1. Long-Term Business Professionals and Expatriates Holding Non-Immigrant “B” Visas

Under the Previous Order:

  • Inbound: No access to the Automated Passport Control System was allowed; even senior executives of multinational companies and citizens of major economies such as the United States, the United Kingdom, Japan, and China. They  were required to use manual immigration counters.
  • Outbound: The Automated Passport Control System is available only at Suvarnabhumi Airport.

Under the Current Order:

  • Inbound and Outbound: It is accessible at any international airport equipped with the Automated Passport Control Channels, provided the traveler qualifies under the Appendix of the Current Order and holds a valid re-entry permit where required.
  • Short-Term Business Travelers and Tourists

Under the Previous Order:

  • Inbound: No access to the Automated Passport Control System was allowed, except for Singaporean and Hong Kong passport holders.
  • Outbound: The Automated Passport Control System is available only at Suvarnabhumi Airport.

Under the Current Order:

  • Inbound and Outbound: Eligible travelers from countries listed in the Appendix to the Current Order, including the United States, Japan, China, and the United Kingdom, can use Automated Passport Control Channels at any international airport equipped with the Automated Passport Control System.

Key Takeaways

  • Significant Expansion: Eligibility has increased from only two nationalities to 33 countries and territories under the Current Order.
  • Broader Access: Business travelers, expatriates, investors, academics, students, and family-based visa holders can now benefit from automated immigration processing.
  • Nationwide Availability: Automated outbound processing is no longer limited to Suvarnabhumi Airport, and it is now being used at any international airport equipped with the system.
  • Improved Efficiency: Immigration officers are now authorized to resolve minor system errors immediately, helping to reduce delays and unnecessary procedures.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Social Commerce Overhaul: From Seller Verification to Influencer Accountability

The regulatory gap created by social commerce:

Social commerce has blurred many of the distinctions on which traditional e-commerce regulation was built. A consumer may discover a product through an influencer, encounter promotional content on a social-media platform, communicate directly with a seller through the same platform, and complete the purchase without ever visiting a conventional online marketplace. The seller, the person promoting the product, the person paying for the advertisement, and the platform carrying the content may all be different parties. This structure creates a regulatory challenge because consumer protection laws have traditionally focused on businesses supplying goods or services and unlawful advertising, while digital-platform regulation has focused principally on platform operators. Social commerce sits between these regimes. Recent regulatory initiatives indicate that this gap is gradually being addressed—not through a single “social commerce” law, but through complementary regulatory work-streams involving the Electronic Transactions Development Agency (ETDA) and the Office of the Consumer Protection Board (OCPB).

ETDA: From online marketplaces to identifying sellers and advertisers

The regulatory framework for digital commerce has already moved beyond conventional marketplace websites. Under the Digital Platform Services (DPS) framework, ETDA regulates qualifying digital platform services and has progressively developed requirements and guidance concerning online marketplaces, product and seller information, advertising, notice-and-takedown mechanisms, and other aspects of platform governance. Social media is increasingly relevant to this framework because commercial activity can take place within services that were not originally designed as conventional marketplaces. ETDA has also identified social commerce as an area requiring further regulatory attention.

A particularly important development is the increasing emphasis on the identity and traceability of sellers and advertisers. ETDA’s existing advertising guidance recommends that platforms establish procedures for checking advertiser information and verifying identity, maintain relevant advertiser records, and use mechanisms such as watchlists, blacklists, and whitelists. It also addresses screening advertisements before publication and monitoring them afterward through reporting and flagging mechanisms. ETDA’s developing measures for social-media platforms build on this approach by contemplating risk-based identification and verification of users, sellers, and persons placing advertisements. The underlying regulatory objective is increasingly clear: commercial activity conducted through social media should not permit the persons behind a seller account or paid advertisement to remain effectively unidentifiable. For social-commerce businesses, advertiser and seller identification may therefore become an increasingly important part of the platform compliance infrastructure.

OCPB: Bringing influencers into the consumer-protection framework

A parallel development is occurring under consumer protection law. The OCPB has proposed a substantial amendment to the Consumer Protection Act aimed at modernizing the framework for digital commerce and contemporary advertising practices. One of its significant features is the proposed expansion of responsibility within the advertising ecosystem, including persons hired to advertise goods or services. If enacted in its proposed form, this could bring influencers, content creators, and other persons engaged to promote products more directly within the statutory consumer-protection framework. This is particularly important for influencer marketing, where the traditional distinction between an advertiser and the medium carrying an advertisement can be difficult to maintain. Influencers may create promotional content themselves, demonstrate products, repeat claims supplied by brands, integrate commercial messages into personal recommendations or entertainment, provide purchasing links, and participate in affiliate arrangements. The person communicating the advertising message can therefore play a much more active role in influencing the consumer’s decision than a conventional advertising medium.

The OCPB initiative addresses a different part of the social-commerce problem from ETDA’s platform regulation. ETDA’s developing framework focuses substantially on the platform and the identification and traceability of persons using it for commercial activity, while the OCPB proposal strengthens responsibility for the consumer-facing commercial message and the persons participating in communicating that message. The proposed Consumer Protection Act amendment remains draft legislation, so its final scope may change during the legislative process. Nevertheless, its direction is important for brands, agencies, influencers, and content creators because compliance may increasingly extend beyond the business that ultimately supplies the product.

Two regulatory layers across one transaction:

The interaction between these initiatives is perhaps the most significant feature of the emerging framework. Consider a typical social-commerce transaction: a brand engages an influencer to promote a product; promotional content appears on a social-media service; the content directs consumers to a seller operating through that platform or another online channel; and a consumer purchases the product after relying on representations contained in the promotional content. Different regulatory obligations can potentially attach at several points along that chain. The platform may increasingly be expected to identify sellers and advertisers, retain information permitting them to be traced, screen certain advertisements, monitor problematic content, and provide mechanisms for responding to complaints or unlawful activity. The seller or brand remains subject to applicable consumer-protection and product-specific requirements. At the same time, the OCPB amendment could place influencers and other persons hired to advertise more directly within the consumer-protection regime.

The emerging division can therefore be summarized as follows: ETDA is developing the infrastructure of accountability, while OCPB is extending accountability through the advertising chain. The distinction is not absolute. ETDA’s role extends beyond identity verification into advertising screening and monitoring, while OCPB already exercises broad authority over consumer-facing advertising. The regulatory regimes should therefore be understood as overlapping layers rather than completely separate jurisdictions. Together, however, they address a central weakness of social commerce: the difficulty of identifying and allocating responsibility among the multiple parties involved between the creation of an advertisement and the eventual consumer transaction.

From regulating the seller to regulating the commercial chain:

These developments point toward a broader change in the regulation of digital commerce. Traditional e-commerce could largely be conceptualized around the consumer, the online seller, and the marketplace facilitating the transaction. Social commerce introduces additional actors: platforms distribute commercial content, advertisers may be different from sellers, influencers and content creators communicate product claims, and transactions can move from public social-media content into private messaging or other channels. The emerging regulatory framework increasingly follows this entire chain. Instead of asking only who sold the product, regulators are developing mechanisms that can also address who promoted it, who paid for or arranged the advertisement, who communicated the claims, and which platform facilitated the commercial interaction.

For businesses, social-commerce compliance should therefore no longer be treated solely as an issue for the legal entity making the final sale. Brands will need to consider how influencers and advertisers are selected, instructed, and supervised; whether advertising and product claims can be substantiated; what information must be supplied to platforms; and how responsibility is allocated contractually among brands, agencies, influencers, and other participants. Influencer and advertising agreements may require greater attention to regulatory compliance, disclosure and approval procedures, substantiation of claims, record-keeping, corrective measures, content removal, and cooperation with platforms or regulators. Platforms face a different compliance trajectory, with increasing expectations around identification, verification, screening, monitoring, traceability, and intervention where commercial activity creates risks for consumers.

An emerging social-commerce framework:

There is not yet a single comprehensive regulatory instrument governing social commerce. Instead, a network of complementary rules is emerging to regulate different stages of the same commercial activity. ETDA’s DPS framework and related initiatives provide the platform-governance layer; developing seller and advertiser verification requirements strengthen identification and traceability; and the proposed Consumer Protection Act amendment would strengthen the consumer-facing advertising layer by potentially extending responsibility more directly to influencers and other participants in the advertising process. Viewed together, these developments suggest that social commerce is moving toward end-to-end accountability—from the identity behind an advertisement to the person delivering the commercial message and ultimately to the transaction with the consumer.

Key Takeaways:

The social-commerce regulatory framework is developing through several complementary initiatives rather than one dedicated law. ETDA is strengthening the platform side of the equation, particularly the identification and traceability of sellers and advertisers, while OCPB is seeking to strengthen responsibility on the consumer-facing side, including the role of influencers and other persons engaged in advertising. Businesses operating through social commerce should therefore look beyond seller compliance alone. Brands, sellers, advertising agencies, influencers, content creators, and digital platforms increasingly form parts of the same regulated commercial chain, and the compliance focus is shifting from responsibility for the final sale toward accountability throughout the process by which a consumer encounters, evaluates, and purchases a product online.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles