New Apostille Rules Simplify Thailand Working and Retirement Visa Renewal Documents Requirement

The Immigration Bureau has issued Immigration Bureau Order No. 122/2026 (the “Order”), amending certain documentary requirements under Immigration Bureau Order No. 12/2025 for applications for renewal of visa. The Order came into effect on 28 May 2026.

Previously, where certain prescribed documents were unavailable, applicants were generally required to authenticate them through notarization by a notary public, legalization by a Royal Thai Embassy or Royal Thai Consulate-General, and super-legalization by Thailand’s Ministry of Foreign Affairs. The new Order introduces Apostille certification as an alternative method of authentication for specified documents.

Key Amendments

The amendments primarily benefit foreign nationals applying for the renewal of Non-Immigrant “B” (Business) and Non-Immigrant “O-A” (Retirement) categories. In particular, the changes are expected to benefit foreign nationals working for foreign companies operating in Thailand through their representative offices, regional offices, and branch offices set up in Thailand requiring renewal of their visa, for which the affidavits or certificates of incorporation relating to those offices are required to be submitted. The amendment also benefits foreign retirees required to submit health insurance documents or evidence of state welfare benefits issued or granted overseas.

Previously, such documents were generally required to be certified by the issuing authority and/or notarized, followed by legalization by a Royal Thai Embassy or Royal Thai Consulate-General and super-legalization by Thailand’s Ministry of Foreign Affairs. The amendment streamlines this process by reducing the number of authentication steps required for eligible documents.

The amendments also address practical difficulties faced by representative offices, regional offices, and branch offices of foreign companies in obtaining certain corporate registration documents. In practice, the Department of Business Development (DBD) may not issue particular certificates in certain circumstances The revised requirements therefore provide greater flexibility where equivalent DBD-issued documents are unavailable.

Conclusion

The Order represents a practical modernization of Thailand’s immigration procedures by introducing Apostille certification as an alternative method of authenticating documents for certain business and retirement-based applications.

Although the amendments do not alter the substantive eligibility requirements of renewal of visa, they simplify documentary compliance, reduce reliance on multiple layers of consular legalization, and offer practical solutions for foreign business entities that may encounter difficulties obtaining certain certifications in Thailand. Overall, the changes are expected to make the immigration process more efficient for both foreign businesses and foreign retirees.

Key Takeaways

The changes reflect Thailand’s continuing movement toward

Apostille certification is now recognized as an alternative to traditional embassy legalization for certain business and retirement-based extension of stay applications.

The amendments simplify document authentication and reduce administrative burdens for eligible applicants.

Foreign nationals working with representative offices, regional offices, and branch offices in Thailand may benefit from greater flexibility where equivalent DBD-issued certifications are unavailable.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPA Insights: Building Effective Privacy Governance

PDPA: The DPO Is Not Responsible for Compliance—Your Organization Is

One of the most persistent misconceptions surrounding Thailand’s Personal Data Protection Act (PDPA) is that appointing a Data Protection Officer (DPO) satisfies an organization’s compliance obligations.

In practice, many organizations regard the DPO as the person responsible for “doing PDPA.” Privacy notices, data subject requests, breach notifications, contract reviews, training, audits and even cybersecurity issues are routinely directed to the DPO, often regardless of whether the DPO has the authority, resources or operational involvement to manage those activities effectively.

This perception is understandable. The PDPA requires certain organizations to appoint a DPO, and the role naturally becomes the focal point for privacy-related matters. However, the PDPC’s recent consultation on DPOs suggests that this understanding is incomplete. Rather than placing responsibility for compliance on the DPO, the consultation reinforces a governance model in which responsibility remains with the organization itself. The DPO’s role is to advise, monitor and facilitate compliance—not to replace management’s accountability.

This distinction may appear technical, but it has significant practical consequences for how organizations should structure their privacy governance.

Compliance belongs to the organization:

Privacy compliance is often described as a legal function, yet effective compliance depends upon decisions made throughout the organization.

Marketing teams determine how customer data is used.

Human resources departments manage employee information.

Information technology teams implement technical safeguards.

Procurement negotiates contracts with service providers.

Business units decide what personal data should be collected and why.

These operational decisions cannot realistically be delegated to a single individual.

The DPO may advise on each of these activities, but the responsibility for making business decisions—and ensuring those decisions comply with the PDPA—remains with the organization.

This governance model is consistent with the broader direction of the PDPC’s recent consultations, which increasingly emphasize accountability across the organization rather than concentrating responsibility within a single compliance function.

Independence does not mean isolation:

The PDPA requires that the DPO perform their duties independently.

This requirement is sometimes misunderstood to mean that the DPO should operate separately from the business.

In practice, independence means something quite different.

A DPO should be able to provide objective advice without inappropriate influence from commercial considerations. Management should not pressure the DPO to approve questionable processing activities or discourage the DPO from identifying compliance risks.

At the same time, independence should not prevent close collaboration with business units.

An effective DPO understands the organization’s operations, participates in project planning, and provides practical advice before privacy issues become compliance problems.

The most successful DPOs are therefore integrated into decision-making while remaining sufficiently independent to challenge proposals where necessary.

The DPO should be involved early:

Privacy risks are easiest to manage before systems are implemented.

Once a customer platform has been launched, an AI tool deployed, or a vendor contract executed, addressing privacy concerns often becomes significantly more expensive.

Organizations should therefore involve the DPO during the planning stage of new initiatives.

Examples include:

  • launching new digital products;
  • introducing AI-powered customer service;
  • implementing HR technologies;
  • engaging cloud providers;
  • deploying CCTV systems;
  • expanding overseas operations.

Early involvement allows privacy considerations to be incorporated into business decisions rather than added after implementation.

Expertise matters more than job title:

The PDPA does not prescribe a single professional background for DPOs.

In practice, effective DPOs come from diverse disciplines, including law, information security, compliance, risk management and information technology.

What matters is not professional qualification alone but the ability to understand both legal requirements and operational realities.

An effective DPO should be capable of translating legal principles into practical business guidance while communicating effectively with senior management, technical specialists and operational teams.

Organizations should therefore focus on competence rather than formal titles when appointing a DPO.

Conflicts of interest deserve careful consideration:

One of the most challenging aspects of DPO governance is avoiding conflicts of interest.

Individuals responsible for determining why and how personal data is processed may struggle to provide independent oversight of those same decisions.

For example, appointing the head of marketing as DPO may create tension where marketing initiatives require objective privacy review.

Similarly, information technology leaders responsible for designing systems may find it difficult to independently assess privacy risks arising from those systems.

Organizations should therefore consider whether reporting structures, operational responsibilities and decision-making authority could compromise the DPO’s independence.

The objective is not to prohibit dual roles entirely but to ensure that privacy oversight remains objective and credible.

A successful DPO builds a privacy culture:

Perhaps the greatest misconception is that privacy compliance can be centralized.

No DPO—regardless of experience—can personally oversee every processing activity across a large organization.

Long-term success depends upon building privacy awareness throughout the business.

Training, internal guidance, standardized procedures, governance committees and clearly allocated responsibilities often contribute more to sustainable compliance than expanding the DPO’s workload.

The DPO’s most valuable contribution may therefore be enabling others to make better privacy decisions rather than making every decision personally.

Looking ahead:

The PDPC’s consultation reflects an increasingly mature understanding of the DPO function.

Rather than acting as the organization’s privacy manager, the DPO is emerging as an independent adviser who supports, challenges and guides the organization while management retains responsibility for compliance.

Organizations that recognize this distinction will be better positioned to establish sustainable governance frameworks rather than relying excessively on a single individual to solve increasingly complex privacy issues.

Key takeaways:

  • Appointing a DPO does not transfer PDPA compliance responsibilities from the organization to the DPO.
  • The DPO’s role is to advise, monitor and facilitate compliance while management remains accountable for processing decisions.
  • Independence enables objective advice but should not prevent close collaboration with business units.
  • Early involvement of the DPO in new projects helps identify and address privacy risks before implementation.
  • Organizations should carefully assess potential conflicts of interest and ensure that the DPO has sufficient authority, resources and access to senior management.
  • A mature privacy program depends on organization-wide governance and a culture of compliance, not on the DPO alone.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

Billing Software and Electronic Invoicing: Understanding Thailand’s Digital Tax Compliance Framework

Executive Summary:

As governments continue to digitalize tax administration, businesses are increasingly expected to adopt electronic invoicing solutions that comply with evolving regulatory requirements. Although the terms billing software and electronic invoicing are often used interchangeably, they represent distinct concepts that serve different commercial and legal functions.

In Thailand, billing software is not subject to a dedicated statutory or regulatory framework. Businesses are generally free to select accounting, billing, or enterprise resource planning (ERP) systems that best support their commercial operations, provided they comply with the Revenue Code and other applicable laws. Electronic invoicing, by contrast, is governed by the Revenue Department’s e-Tax Invoice & e-Receipt framework, which establishes the legal and technical requirements for issuing electronic tax invoices recognized for VAT purposes.

Understanding the distinction between these concepts is important for businesses implementing digital invoicing solutions. A billing system that efficiently generates commercial invoices does not necessarily satisfy the legal requirements for issuing electronic tax invoices. Businesses should therefore evaluate their invoicing systems not only from an operational perspective but also from a tax compliance standpoint.

Introduction:

Digital transformation has fundamentally changed the way businesses prepare invoices, maintain accounting records, and comply with tax obligations. Around the world, tax authorities have introduced electronic invoicing regimes to improve tax compliance, enhance transparency, and reduce administrative burdens for both taxpayers and regulators.

Although electronic invoicing has become an increasingly common feature of modern tax systems, countries have adopted different regulatory approaches. Some jurisdictions regulate the software used to generate invoices, while others focus on the legal validity and technical characteristics of the electronic tax documents themselves.

Thailand follows the latter approach. Rather than regulating billing software as a separate category of software, Thai law establishes a framework governing the issuance of electronic tax invoices through the Revenue Department’s e-Tax Invoice & e-Receipt system. Consequently, businesses remain free to use their preferred accounting or ERP software, provided that the electronic tax documents generated by those systems comply with the applicable legal and technical requirements.

For businesses operating in Thailand, particularly multinational enterprises implementing global ERP platforms, understanding the distinction between billing software and electronic invoicing is essential. While both are integral components of modern financial management, they perform different functions and are subject to different legal considerations.

Billing Software:

Billing software generally refers to applications used by businesses to prepare invoices, calculate taxes, record payments, manage customer accounts, and maintain accounting records. These functions support day-to-day commercial operations and are commonly integrated into accounting software or ERP systems.

Unlike some jurisdictions that regulate invoicing software, Thailand does not currently impose a dedicated legal or regulatory regime governing billing software itself. There is no statutory requirement for billing software to be licensed, certified, or approved by the Revenue Department before it can be used by businesses. Instead, Thai law focuses on the legal sufficiency of the invoices and accounting records generated by the software.

This does not mean that businesses have complete discretion in how billing systems are used. Regardless of the software selected, businesses remain responsible for ensuring that invoices comply with the Revenue Code, VAT is correctly calculated where applicable, accounting records are properly maintained, and supporting documentation is available for inspection by the tax authorities.

Accordingly, compliance under Thai law depends not on the software itself, but on whether the business uses that software in a manner that satisfies its statutory obligations. A business may therefore choose from a wide range of commercial accounting platforms, cloud-based invoicing applications, or ERP systems without obtaining prior approval from the Revenue Department.

Electronic Invoicing:

Electronic invoicing serves a different purpose. Rather than facilitating internal billing processes, it establishes the legal framework under which electronic tax invoices are recognized for VAT purposes.

Thailand’s electronic invoicing regime is principally governed by the Revenue Code, supplemented by the Electronic Transactions Act, Ministerial Regulation No. 384, and Revenue Department notifications prescribing the technical standards for electronic tax documents. Collectively, these instruments enable tax invoices and receipts to be created, transmitted, and retained electronically while ensuring their authenticity, integrity, and reliability.

Businesses wishing to issue electronic tax invoices under the Revenue Department’s e-Tax Invoice & e-Receipt framework must comply with prescribed legal and technical requirements. These include registration with the Revenue Department, generation of electronic tax documents in the prescribed format, use of appropriate electronic authentication mechanisms, transmission through approved channels where applicable, and maintenance of electronic records in accordance with the Revenue Department’s requirements.

An important characteristic of the Thai framework is that it regulates the electronic tax document rather than the accounting software used to produce it. Consequently, businesses may continue using their existing accounting or ERP systems, provided those systems are capable of generating electronic tax invoices that comply with the Revenue Department’s technical specifications. In practice, many businesses achieve this through system localization or integration with specialized e-Tax solutions or authorized service providers.

Thailand currently provides two principal electronic invoicing models. The e-Tax Invoice & e-Receipt system is designed for businesses requiring full electronic integration, while the e-Tax Invoice by Email system provides a simplified alternative for eligible businesses. Although both systems enable businesses to issue legally recognized electronic tax invoices, they differ in their technical implementation and authentication methods.

Key Takeaways:

  • Thailand does not regulate billing software as a separate legal category or require billing software to be certified or approved by the Revenue Department.
  • The Revenue Department’s e-Tax Invoice & e-Receipt framework governs the issuance of legally recognized electronic tax invoices and establishes the applicable technical and procedural requirements.
  • A commercial invoice generated by billing software does not automatically constitute an electronic tax invoice for VAT purposes.
  • Businesses implementing accounting or ERP systems should evaluate both operational functionality and compliance with Thailand’s e-Tax requirements.
  • Early coordination among finance, tax, legal, and information technology functions can help ensure a successful implementation of electronic invoicing while supporting long-term digital tax compliance.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPA Insights: Building Effective Privacy Governance

PDPA: Why Many Compliance Programs Fail Before They Begin

For many organizations, implementing Thailand’s Personal Data Protection Act (PDPA) begins with a familiar request.

“Can you send us a privacy notice?”

“Do you have a consent form we can use?”

“Can we copy the privacy policy from another company?”

These questions are understandable. Privacy notices, consent forms and cookie banners are visible. Customers can see them, business partners frequently request them during due diligence, and regulators often ask for them during investigations. Producing these documents therefore creates the impression that an organization is making tangible progress towards compliance.

Yet, in practice, this approach often starts the compliance journey in the wrong place.

The Personal Data Protection Committee’s (PDPC) recent series of draft guidelines consistently points towards a broader principle. Whether discussing legal bases, direct marketing, Records of Processing Activities (ROPAs), Data Protection Officers (DPOs), or security measures, the common theme is not documentation—it is governance. The regulator’s emerging expectation is that organizations first understand how personal data is processed before attempting to document those activities.

The consequence is significant. Many compliance programs fail not because organizations lack policies or templates, but because they build documentation before understanding the business processes those documents are intended to describe.

Compliance should begin with understanding the business—not drafting documents:

Perhaps the most common mistake is assuming that PDPA compliance starts with drafting a privacy notice.

In reality, a privacy notice should be one of the last documents prepared.

Before an organization can explain how personal data is processed, it must first understand its own processing activities. That requires data mapping and gap analysis.

Organizations should begin by asking practical questions.

  • What categories of personal data are collected?
  • Why is each category collected?
  • Which departments use the information?
  • Which vendors receive it?
  • Does the information leave Thailand?
  • How long is it retained?
  • Which legal basis supports each processing activity?

Only after these questions have been answered can an organization prepare a privacy notice that accurately reflects its operations.

A privacy notice should describe reality—not define it.

Unfortunately, many organizations reverse this process. They prepare documentation first and attempt to fit their operations into those documents afterwards. The result is often a privacy notice describing processing activities that do not exist while overlooking activities that are central to the business.

Compliance therefore begins with understanding data flows rather than drafting legal documents.

Visible documents should not be mistaken for compliance:

Another widespread misconception is that having a privacy notice, consent form and cookie banner demonstrates compliance.

These documents are important.

They are not, however, evidence that personal data is being processed lawfully.

An organization may publish an excellent privacy notice while having no documented legal basis assessments, no ROPA, no retention schedule, no vendor management procedures, no incident response plan and no understanding of how AI systems process personal data.

In other words, documentation can describe compliance without demonstrating it.

A useful distinction is this:

A privacy notice tells customers what an organization says it does. Governance demonstrates what the organization actually does.

The latter is what increasingly matters.

Every organization has different data flows:

Organizations frequently ask whether they may use another company’s privacy notice as a starting point.

While templates may provide useful drafting ideas, no two organizations process personal data in exactly the same way.

Even businesses operating within the same industry often differ significantly.

One retailer may outsource customer relationship management while another performs those functions internally.

One financial institution may process customer information entirely within Thailand while another relies extensively on overseas cloud providers.

One hospital may deploy AI-assisted diagnostic tools while another does not.

These operational differences inevitably influence legal basis assessments, retention periods, vendor management, international transfers and privacy notices.

Consequently, copying another organization’s documentation without first understanding one’s own processing activities risks producing documentation that is inaccurate from the outset.

Privacy documentation should therefore be tailored to the organization’s actual business model rather than borrowed from comparable organizations.

Consent is not the answer to every question:

Another persistent misconception is that obtaining consent automatically resolves privacy compliance.

Consent certainly plays an important role under the PDPA, but it should not become the default legal basis simply because it appears straightforward.

The more appropriate starting point is to identify the processing activity and understand why personal data is being processed.

Different activities frequently require different legal analyses.

Customer information collected to deliver purchased goods serves a different purpose from analyzing purchasing behavior to personalize future recommendations. Human resources information collected to administer payroll differs from information processed for employee engagement surveys.

Treating all processing activities as though they rely upon a single consent often oversimplifies legal requirements while creating unnecessary operational complexity.

Privacy is not the DPO’s responsibility alone:

Appointing a Data Protection Officer is another milestone that organizations sometimes mistake for compliance.

The DPO performs an important governance role, but the DPO does not “own” privacy.

Marketing determines how customer information is used.

Human resources processes employee information.

Information technology implements security measures.

Procurement appoints vendors.

Management determines business objectives.

Privacy compliance therefore depends upon decisions made throughout the organization rather than by one individual.

Organizations that rely exclusively upon the DPO often discover that privacy issues continue arising because governance has not been embedded into operational decision-making.

A ROPA is more than regulatory paperwork:

Many organizations prepare a Record of Processing Activities only because they believe the law requires one.

This perception overlooks the ROPA’s greatest value.

A well-maintained ROPA explains how personal data moves through the organization.

It identifies processing activities, legal bases, recipients, retention periods, international transfers and relationships with processors.

Perhaps more importantly, it often reveals inconsistencies that organizations had not previously recognized.

Different departments may retain identical information for different periods.

Separate business units may rely upon the same vendor.

Customer information may be transferred internationally without centralized oversight.

Viewed this way, the ROPA becomes a governance tool rather than merely a compliance document.

Cybersecurity does not equal privacy compliance:

Investment in cybersecurity has increased significantly in recent years.

Organizations deploy multi-factor authentication, endpoint detection systems, encryption technologies and internationally recognized security standards.

These investments are essential.

However, privacy compliance extends beyond technical security.

Organizations must still determine whether they collect more personal data than necessary, retain information for appropriate periods, rely upon suitable legal bases, manage processors appropriately and provide individuals with meaningful transparency.

Strong cybersecurity reduces certain risks.

It does not replace governance under the PDPA.

AI has not replaced traditional privacy principles:

Artificial intelligence has prompted many organizations to assume that entirely new privacy obligations now apply.

In reality, AI changes the scale of processing rather than the legal principles themselves.

Organizations should still ask familiar questions.

Why is personal data being processed?

What legal basis applies?

What information is being used?

Who receives it?

How are decisions documented?

AI governance therefore begins with ordinary privacy governance rather than replacing it.

Organizations that already understand their data flows will usually be better positioned to manage AI than those attempting to develop AI policies without first understanding their existing processing activities.

Compliance is not a project with an end date:

Perhaps the most damaging misconception is that PDPA compliance can be completed once and then forgotten.

Many organizations implemented privacy notices and consent forms when the PDPA first became fully enforceable.

Since then, business operations have changed considerably.

Organizations have adopted cloud platforms, AI tools, digital marketing technologies, remote working arrangements and increasingly sophisticated customer analytics.

Privacy governance should evolve alongside those changes.

Compliance should therefore be viewed as an ongoing governance function rather than a one-time legal project.

Looking ahead:

The common thread running through the PDPC’s recent draft guidance is that privacy compliance is becoming increasingly operational.

Organizations are expected not merely to produce documentation but to understand their processing activities, justify their decisions, manage risk and demonstrate accountability throughout the lifecycle of personal data.

That begins with understanding the business itself.

Organizations that start with data mapping, gap analysis and governance are likely to produce privacy notices, consent forms and internal policies that accurately reflect their operations.

Organizations that begin with templates may produce attractive documentation but still struggle to explain how personal data actually moves through the business.

Ultimately, effective PDPA compliance is not built by copying documents. It is built by understanding the organization those documents are intended to describe.

Key takeaways:

  • Effective PDPA compliance should begin with data mapping and gap analysis rather than drafting privacy notices or consent forms.
  • Privacy notices should reflect an organization’s actual processing activities and should be developed after those activities have been identified and documented.
  • Copying another organization’s privacy documentation without understanding one’s own data flows often results in inaccurate and ineffective compliance.
  • Consent is only one of several legal bases and should not be treated as the default solution for every processing activity.
  • Privacy governance is an organization-wide responsibility involving management, business units, IT, HR, procurement and legal—not only the DPO.
  • A well-maintained ROPA is a governance tool that helps organizations understand data flows, vendors and operational risks.
  • Strong cybersecurity supports privacy compliance but does not replace broader governance obligations under the PDPA.

Privacy compliance should be treated as a continuous governance function that evolves alongside changes in technology and business operations.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series

ETDA’s Proposed AI Sandbox Signals a New Phase of AI Governance

The Electronic Transactions Development Agency (ETDA) has opened a public consultation on a draft notification establishing an Artificial Intelligence (AI) Sandbox. Although the notification has not yet been adopted, it represents one of the clearest regulatory signals that Thailand is moving toward a structured governance framework for AI systems through a controlled testing environment.

For businesses developing or deploying AI solutions, the proposed AI Sandbox is more than a pilot initiative. It is likely to establish regulatory expectations that may influence future AI compliance standards across multiple sectors.

Why the AI Sandbox matters                                              

Regulatory sandboxes have long been used in the financial sector to facilitate innovation while allowing regulators to observe risks under controlled conditions. The proposed AI Sandbox extends this concept to AI technologies by providing an environment where AI systems can be tested before wider deployment.

Unlike traditional compliance regimes that focus primarily on post-deployment enforcement, an AI Sandbox emphasizes governance during the development and testing stages. This reflects an international regulatory trend toward proactive AI risk management.

Although participation in the Sandbox may initially be voluntary, organizations should not view it merely as an experimental program. Regulatory sandboxes frequently become the foundation for future best practices and may ultimately shape industry standards and supervisory expectations.

A shift toward risk-based AI governance

While the draft notification remains subject to consultation, it suggests that AI governance in Thailand is moving toward a risk-based model.

Businesses should expect greater emphasis on governance measures such as:

  • AI risk identification and assessment;
  • testing and validation before deployment;
  • documentation of AI models, datasets, and development processes;
  • human oversight over significant AI-assisted decisions;
  • ongoing monitoring throughout the AI lifecycle; and
  • governance mechanisms for accountability and incident management.

These principles are broadly consistent with international AI governance developments and demonstrate a growing expectation that organizations should be able to explain not only what an AI system does, but also how risks have been identified and managed.

Implications for businesses

The proposed framework has implications across numerous industries, particularly where AI systems influence commercial or operational decision-making.

  • Technology companies and SaaS providers
  • Software developers offering AI-enabled products may need to implement more formal governance processes throughout the product lifecycle. Technical documentation, testing records, model validation, and change management procedures could become increasingly important in demonstrating responsible AI practices.
  • Organizations that currently rely on informal development processes may eventually need governance structures comparable to those already used for cybersecurity and information security compliance.
  • Financial services and fintech
  • Financial institutions already operate within a highly regulated environment. AI governance requirements may become an additional layer of compliance where AI is used for credit scoring, fraud detection, investment services, customer onboarding, or automated decision-making.
  • Existing risk management frameworks may therefore need to expand to include AI-specific controls.
  • Healthcare and health technology
  • Healthcare providers and health technology companies using AI for diagnostics, treatment recommendations, clinical decision support, or patient management are likely to face heightened expectations regarding accuracy, validation, human supervision, and patient safety.
  • Testing within a controlled environment could become an important mechanism for demonstrating reliability before deployment.
  • HR technology
  • Organizations using AI in recruitment, employee evaluation, workforce management, or performance assessment should anticipate closer scrutiny of automated decision-making processes.
  • Transparent governance, human review, and measures to reduce discriminatory outcomes are likely to become increasingly significant compliance considerations.
  • Digital platforms
  • Platform operators deploying generative AI, recommendation algorithms, content moderation systems, or AI-powered customer services may also need stronger governance over system performance, monitoring, and accountability.
  • The ability to document how AI systems operate and respond to identified risks may become an important aspect of regulatory compliance.

Interaction with existing legal frameworks

Although the AI Sandbox is intended to facilitate innovation, participation is unlikely to exempt organizations from existing legal obligations.

Organizations testing AI systems would still be expected to comply with applicable laws, including those governing:

  • personal data protection under the Personal Data Protection Act;
  • electronic transactions;
  • cybersecurity obligations;
  • consumer protection;
  • intellectual property rights; and
  • sector-specific regulatory requirements.

For example, organizations using personal data for AI model training or testing should ensure that appropriate legal bases, transparency obligations, data security measures, and data subject rights continue to be observed.

Similarly, businesses developing generative AI applications should continue to assess potential intellectual property risks relating to training data, generated outputs, and ownership of AI-assisted content.

Preparing for future regulatory expectations

Although the draft notification has not yet entered into force, organizations should consider using the consultation period to evaluate their existing AI governance practices.

Practical steps may include:

  • identifying AI systems currently in operation;
  • classifying AI use cases according to potential risk;
  • documenting AI development and deployment processes;
  • establishing internal AI governance policies;
  • implementing human oversight for significant AI-assisted decisions;
  • reviewing contractual allocation of AI-related responsibilities with vendors and customers; and
  • ensuring that AI governance aligns with existing data protection and cybersecurity compliance programs.

Organizations that begin implementing these governance measures now are likely to be better positioned if the AI Sandbox becomes operational and if similar requirements are incorporated into future regulatory frameworks.

Looking ahead

The draft AI Sandbox notification demonstrates that Thai regulators are moving beyond high-level discussions about artificial intelligence and toward practical governance mechanisms.

Even if participation remains voluntary during its initial stages, the Sandbox is likely to influence regulatory expectations regarding responsible AI development and deployment. Businesses should therefore view the proposal not simply as a testing initiative, but as an indication of the governance standards that may shape future AI regulation.

Key takeaways

Businesses that prepare early are likely to be better positioned as AI governance requirements continue to evolve.

The proposed AI Sandbox represents a significant step toward a structured AI governance framework.

The initiative reflects a broader shift toward risk-based regulation and responsible AI development.

Organizations developing or deploying AI should begin strengthening governance, documentation, testing, and oversight processes.

Existing obligations under data protection, cybersecurity, consumer protection, and intellectual property laws will continue to apply during AI development and testing.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Super License Reform Moves to Final Stage Before Becoming Law

In our previous article, “Super License: The Draft Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public,” we discussed the proposed overhaul of the administrative licensing regime and its potential to fundamentally modernize public services and regulatory approvals.

Super License: The Draft Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public – The Legal Co., Ltd.

The legislative process has now reached a significant milestone. The Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public B.E. 2569 has been approved by Parliament and is currently awaiting publication in the Government Gazette before coming into force. Once effective, the new legislation will repeal the Facilitation of Licensing by Government Agencies Act B.E. 2558 (2015) and introduce a substantially broader and more integrated framework for government licensing and public services.

A Shift from Licensing Control to Public Service Facilitation:

The new legislation reflects a significant policy shift in the administration of regulatory approvals. Rather than focusing solely on licensing procedures, it establishes a broader framework designed to improve the overall delivery of government services by emphasizing efficiency, transparency, digital integration, and reduced administrative burdens.

The scope of the law extends beyond traditional licensing procedures to cover registrations, notifications, approvals, and various public services provided by government agencies. This broader application aims to establish consistent administrative standards across the public sector while making interactions with government agencies more predictable and user-friendly.

Greater Transparency Through Mandatory Public Handbooks:

One of the most significant reforms is the enhanced requirement for government agencies to prepare comprehensive public handbooks.

These handbooks must clearly specify:

  • application procedures;
  • required documents;
  • statutory processing periods;
  • applicable fees;
  • approval criteria;
  • conditions imposed on applicants; and
  • written guidelines governing the exercise of official discretion.

Requiring agencies to disclose how discretion will be exercised represents an important development. It is intended to reduce inconsistent decision-making, improve legal certainty, and minimize opportunities for arbitrary administrative actions.

Digital Government and “Once-Only” Documentation:

The legislation further advances the government’s digital transformation policy by requiring agencies to utilize electronic information already available within government systems.

Where government agencies already possess information through interconnected databases, applicants generally should not be required to submit the same documents repeatedly. This “once-only” principle is expected to reduce paperwork significantly and improve the overall efficiency of administrative procedures.

The legislation also supports greater use of electronic application systems and centralized digital service platforms.

The Super License Mechanism:

Perhaps the most anticipated feature is the introduction of the Super License mechanism.

For business activities designated by the Cabinet, applicants will be able to obtain a principal license that automatically covers related subsidiary approvals normally issued by multiple government agencies. Instead of pursuing numerous sequential approvals, businesses will be able to complete much of the licensing process through a single application.

Although the categories of businesses eligible for the Super License mechanism will be determined through subsequent implementing measures, the reform is expected to benefit sectors that traditionally require multiple regulatory approvals, including manufacturing, hospitality, energy, and certain service industries.

The practical effectiveness of this mechanism will ultimately depend upon the implementing regulations and the level of coordination among participating agencies.

Faster Licensing Procedures:

The legislation introduces several measures intended to shorten administrative timelines.

Government agencies will be required to review applications promptly upon receipt, notify applicants immediately if documents are incomplete, and adhere to published processing periods. Where delays become unavoidable, agencies must notify applicants and explain the reasons for any extension.

In addition, the legislation provides for:

  • centralized application centers;
  • electronic submission and tracking systems;
  • expedited processing channels for eligible matters;
  • simplified renewal procedures for certain licenses; and
  • multilingual services where appropriate.

Collectively, these measures are designed to reduce procedural uncertainty while improving the overall applicant experience.

Deemed Approval for Certain Applications:

One of the most closely watched reforms is the introduction of a form of deemed approval.

For specified categories of lower-risk activities, where the responsible agency fails to complete consideration within the prescribed timeframe and does not properly extend the review period, the application may be treated as approved by operation of law.

This mechanism is intended to encourage administrative efficiency while providing greater certainty for businesses. However, it is not expected to apply universally, particularly where public safety, environmental protection, national security, or other significant public interests require substantive regulatory review.

Provisional Operations for Low-Risk Activities:

The legislation also introduces mechanisms allowing certain low-risk businesses to commence operations through notification or registration before obtaining full approval.

This represents a notable departure from the traditional approach, under which businesses generally must wait until all approvals have been formally issued before commencing operations. The reform seeks to facilitate earlier economic activity while maintaining appropriate regulatory oversight.

Increased Accountability for Government Agencies:

The legislation imposes stronger obligations on public officials responsible for licensing and service delivery.

Failure to comply with statutory procedures—such as requesting unnecessary documents, failing to meet prescribed timelines without justification, or otherwise violating procedural requirements—may constitute disciplinary misconduct.

These accountability measures reinforce the legislation’s broader objective of improving public confidence in administrative decision-making.

What Businesses Should Do Next:

Although the legislation has completed the parliamentary process, businesses should recognize that it will not become effective until publication in the Government Gazette.

In the meantime, companies that regularly interact with licensing authorities should begin assessing how the new framework may affect their operations. Particular attention should be paid to businesses that currently require approvals from multiple agencies, as they may eventually benefit from the Super License mechanism once implementing regulations identify eligible sectors.

Businesses should also monitor forthcoming subordinate legislation, ministerial regulations, and administrative guidelines, which will determine many of the practical details governing implementation.

Key Takeaways:

  • Businesses should begin reviewing their regulatory compliance strategies and monitor the issuance of subordinate legislation that will govern implementation of the new regime.
  • Parliament has approved the new Act, which is now awaiting publication in the Government Gazette before becoming effective.
  • The legislation replaces the existing licensing facilitation framework with a broader law covering licensing, registrations, notifications, approvals, and public services.
  • The new framework emphasizes transparency, digital government, reduced administrative burdens, and standardized procedures.
  • The Super License mechanism has the potential to significantly simplify regulatory approvals for businesses requiring multiple licenses, although further implementing regulations will determine its practical scope.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles: Super License: The Draft Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public – The Legal Co., Ltd.

Other Articles

Thailand’s New Investigation Policy on Nominees Matter

The Government of Thailand has launched a nationwide investigation campaign targeting the illegal use of Thai “nominees” — local Thai citizens hired by foreign investors to circumvent restrictions on land ownership and business operations. Enforcement has been concentrated in Thailand’s major economic and tourism hubs, including Phuket, Chiang Mai, and Bangkok.

Action Plan and Policy

The campaign reflects a government priority to ensure fair competition and transparency within the local economy. It is being implemented jointly by 23 Thai government departments, including the Royal Thai Police, the Department of Business Development (DBD), and the Department of Lands. Under the action plan, authorities are re-examining corporate registrations, tracing the source of funds used by Thai shareholders, and reviewing companies in tourist areas with suspicious or unusual ownership structures.

Current Status and Practices

Enforcement efforts to date have produced significant results. Officials report that 172 land plots in the southern economic provinces — covering approximately 51 acres and valued at roughly 1.67 billion baht — are currently under investigation. As a result, courts have issued 107 arrest warrants, leading to 65 arrests of Thai nominees and foreign investors so far.

Government officials have disclosed that Israeli nationals represent the largest group implicated in these illegal nominee arrangements, followed by French, Russian, and other European nationals. The sectors most frequently affected include hotels, resorts, restaurants, and cannabis shops. A common scheme involves registering low-income Thai employees or local citizens as majority shareholders holding more than 50% of company shares — an arrangement that is often easy to identify, since these individuals typically lack the personal savings or income needed to fund such large-scale investments.

The legal consequences of enforcement are becoming increasingly severe. In recent rulings in Surat Thani — the southern province home to the popular tourist destination Koh Phangan — courts have sentenced convicted nominees and foreign investors to prison terms and fines, and ordered them to divest illegally acquired land within a strict timeframe of 180 days to one year.

Future Steps and Business Implications

This intensified enforcement signals a permanent shift toward stricter regulatory oversight of foreign investment in Thailand. The government is now expanding investigations beyond economic and tourism centers to other regions nationwide, aiming for comprehensive enforcement against nominee structures across the country.

The interagency screening process will introduce stricter background and financial checks at both the company registration and land-transfer stages. As a result, foreign investors should expect more rigorous scrutiny regarding the source of their Thai partners’ investment funds. The government also plans to involve the Anti-Money Laundering Office (AMLO) to freeze and seize bank accounts and assets linked to nominee networks.

Key Takeaways

  • AMLO will be engaged to freeze bank accounts and seize assets connected to nominee networks.
  • Thailand is enforcing its new anti-nominee policy nationwide, with particular focus on — but not limited to — major economic provinces.
  • The 23-department investigation framework enables deeper scrutiny of business funding and shareholder backgrounds, meaning investors should anticipate more intensive compliance checks.
  • Investigations are concentrated on, but not limited to, hotels, resorts, restaurants, and cannabis shops with suspicious Thai shareholding structures.
  • Courts are issuing prison sentences, fines, and mandatory orders to divest illegally acquired land within one year.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand’s Draft Immigration Act and Hotel Act: A Major Step Towards Digitalization and Regulatory Reform

Background

Thailand is taking another significant step in its regulatory reform agenda through proposed amendments to the Immigration Act, B.E. 2522 (1979), and the Hotel Act, B.E. 2547 (2004). The draft legislation forms part of the government’s broader Regulatory Guillotine initiative, which seeks to eliminate unnecessary legal requirements, simplify administrative procedures, and reduce compliance burdens for both businesses and the public.

The proposed amendments are also intended to enhance Thailand’s competitiveness by creating a more foreigner-friendly regulatory environment that encourages investment, facilitates tourism, and supports economic growth. At the same time, the reforms modernize enforcement by replacing criminal fines for minor regulatory violations with administrative (disciplinary) fines, consistent with Section 77 of the Constitution of the Kingdom of Thailand.

1. Draft Immigration Act (No. ..), B.E. ….

1.1 Modernization of Administrative Structure

Draft Sections 3 and 4 update the terminology used throughout the Immigration Act to reflect the current organizational structure of the Royal Thai Police. The definition of “Director-General” is repealed, and all references to the “Director-General” are replaced with “Commissioner-General of the Royal Thai Police.” In addition, the term “Immigration Division” is updated to “Immigration Bureau.”

1.2 Removal of Outdated and Redundant Reporting Requirements

One of the most significant reforms is the reduction of reporting obligations imposed on foreign nationals.

Under Draft Section 5, which amends Section 37 of the Immigration Act:

  • Section 37(1) is repealed, removing the prohibition on temporary residents engaging in employment. Because employment of foreigners is already governed by the Foreign Business Act, B.E. 2542 (1999), and the Emergency Decree on the Management of Foreign Workers, B.E. 2560 (2017), this provision is considered redundant.
  • Section 37(2) is repealed, abolishing the requirement for foreigners to notify immigration officials of their place of residence. This obligation duplicates the TM30 reporting requirement already imposed on property owners, possessors, and hotel operators.
  • Sections 37(3) and 37(4) are repealed, eliminating the requirements to report changes of residence and temporary travel to another province exceeding 24 hours. These obligations had already been exempted in practice under the Royal Thai Police Regulations B.E. 2563 (2020).
  • Section 37(5) is retained, preserving the existing 90-day reporting requirement for long-term foreign residents. However, the Commissioner-General of the Royal Thai Police will be empowered to prescribe more flexible reporting methods, procedures, and timeframes.

1.3 Elimination of Duplicate Hotel Reporting

Draft Section 6 repeals Section 38 of the Immigration Act, removing the requirement for hotel operators to submit duplicate reports to immigration authorities. Hotel managers will instead report guest information solely under the Hotel Act, through a single, unified reporting mechanism.

1.4 Flexible Permanent Residence Quotas

Draft Section 7 repeals Section 40 of the Immigration Act, removing the existing statutory quota of 100 permanent residence approvals per nationality and 50 approvals for stateless persons each year. Annual quotas will instead be determined by the government based on Thailand’s prevailing economic and social circumstances.

1.5 Reform of Penalties

Draft Sections 8 and 9 repeal Sections 75, 76, and 77 of the Immigration Act, replacing criminal penalties for minor reporting violations with administrative (disciplinary) fines. This amendment reflects the policy set out in Section 77 of the Constitution, under which criminal sanctions are reserved for serious misconduct.

1.6 Transitional Provisions

Draft Section 10 provides that existing procedures relating to residence reporting, address notifications, and permanent residence applications will remain in effect for a transitional period of up to one year after the Draft Act comes into force.

1.7 Administration of the Act

Draft Section 11 designates the responsible Minister to oversee implementation and ensure continuity throughout the transition period.

2. Draft Hotel Act (No. ..), B.E. ….

2.1 Alignment of Definitions

Draft Section 3 introduces the definition of “Foreigner” into the Hotel Act, adopting the same meaning as under the Immigration Act to ensure consistency between the two statutes.

2.2 Digitalization of Hotel Guest Registration

Draft Section 4, which repeals and replaces Sections 35 and 36 of the Hotel Act, modernizes hotel guest registration by requiring hotel managers to maintain guest records electronically.

Hotel managers will be required to collect only the information necessary for regulatory purposes and to submit guest registration data electronically to the Registrar every 24 hours. The Registrar will then automatically transmit information relating to foreign guests to the Immigration Bureau, establishing a single-window reporting mechanism.

The amendment also authorizes the Department of Provincial Administration (DOPA) and the Registrar to compile and disclose guest registration information to other government agencies, where such disclosure is authorized by law and serves a legitimate public purpose.

In addition, Draft Section 9 requires DOPA to establish and maintain the electronic registration platform.

2.3 Transition to Paperless Administration

Draft Section 5 repeals Section 37 of the Hotel Act, eliminating the requirement for hotel operators to obtain replacement paper registers where records have been lost or destroyed. This amendment supports the transition to a fully electronic registration system.

2.4 Reform of Penalties

Draft Sections 7 and 8 amend the penalty provisions by replacing criminal sanctions with administrative (disciplinary) fines for violations of Sections 35 and 36. Part 2 of the Act is also renamed to reflect the revised enforcement framework.

2.5 Transitional Provisions

Draft Sections 10 and 11 permit hotels to continue using existing registration methods and forms, including the traditional Ro.Ro. 4 register, until the new electronic system and prescribed digital forms become fully operational.

2.6 Entry into Force

The responsible Minister will oversee implementation throughout the transitional period. The Draft Act will enter into force 30 days after its publication in the Royal Gazette.

Conclusion

The Draft Immigration Act and the Draft Hotel Act together represent a significant milestone in Thailand’s regulatory reform agenda. By eliminating overlapped requirements, introducing integrated digital administration, and replacing criminal penalties with proportionate regulatory fines, the proposed legislation seeks to create a more efficient legal framework while maintaining effective immigration control.

If enacted, these reforms are expected to reduce compliance costs for businesses, simplify immigration procedures for foreign nationals, improve inter-agency coordination, and strengthen Thailand’s attractiveness as a destination for international investors, skilled professionals, and tourists.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Draft Laws on the Extension and Expansion of Tax Measures Supporting Electronic Tax Systems

In the context of accelerating digital adoption worldwide, the Thai Revenue Department of the Ministry of Finance (the “RD“) is advancing Thailand’s digital transformation of tax administration and services by proposing two draft laws to the Cabinet on 16 June 2026. The Cabinet approved both draft laws in principle, following the affirmation of the Office of the National Economic and Social Development Council (NESDC), the Budget Bureau, and the Electronic Transactions Development Agency (the “ETDA“). The RD positions these draft laws as key mechanisms to reinforce the longstanding effort to promote electronic tax systems (the “e-Tax Systems”), encompassing e-Tax Invoice, e-Receipt, and e-Withholding Tax. The two draft laws are as follows:

  • Draft Royal Decree issued under the Revenue Code governing the Exemption from Revenue Taxes (No. B.E. … (the “Draft Royal Decree“); and
  • Draft Ministerial Regulations issued under the Revenue Code governing the Income Taxes (No. ) B.E. … (the “Draft Ministerial Regulations“).

Together, the two draft laws will broaden the scope of eligibility for tax incentives and extend the implementation period of existing tax measures relating to e-Tax Systems, as currently prescribed under the Royal Decree issued under the Revenue Code governing the Exemption from Revenue Taxes (No. 766) B.E. 2566 (2023) (the “Royal Decree No. 766”) and the Ministerial Regulations issued under the Revenue Code governing the Income Taxes (No. 389) B.E. 2566 (2023) (the “Ministerial Regulations No. 389”), respectively. In addition, the proposed drafts are designed to encourage greater cooperation from the private sectors — specifically, business operators acting as service providers of e-Tax Systems (the “Service Providers“) — by offering tax incentives to offset the costs associated with meeting the ETDA’s security standards and investing in the requisite electronic infrastructure. This is intended to reduce the financial burden on qualifying entities, simplify tax administration for taxpayers with limited familiarity with digital systems, and improve the overall efficiency of e-Tax Systems.

Tax Measures under Royal Decree No. 766

The measures promoting investment in e-Tax Systems were introduced under Royal Decree No. 766 and were applicable from 1 January 2023 to 31 December 2025. Companies or juristic partnerships that acted as Service Providers of e-Tax Invoice and e-Receipt services, e-Filing services, e-Stamp Duty services, or special account data collection services for electronic platforms were entitled to a corporate income tax exemption equivalent to twice the amount of qualifying investment expenses. Eligible expenses are divided into three main categories, each subject to specific terms and conditions:

  1. Expenses from investment in e-Tax Invoice and e-Receipt systems — comprising expenses incurred in the preparation of electronic data collection systems and the acquisition of software, computers, related electronic equipment, and other devices used to create, transmit, receive, or store such data. Excluded from this category are repair expenses for such equipment and expenses arising from electronic data operations that fall outside the scope of e-Tax Invoice and e-Receipt system services.
  2. Expenses from investment in e-Withholding Tax systems — comprising expenses incurred in the preparation of tax remittance systems and the acquisition of software, electronic certificate storage devices, computers, or other devices used for tax remittance. Repair expenses for such equipment are excluded.
  3. Fees for the use of e-Tax Invoice, e-Receipt, and e-Withholding Tax systems — comprising service charges or fees paid to Service Providers for the preparation or transmission of electronic data, electronic certificates, or electronic storage services for tax remittance through such systems.

Pursuant to the Royal Decree No. 766, assets or funds utilized under categories 1 and 2 above must satisfy all of the following criteria:

a. Must not have been previously used;
b. Must be eligible for depreciation deductions and must be acquired and available by 31 December 2027;
c. Must be located in Thailand;
d. Must be used in the business for not fewer than three consecutive accounting periods beginning from the first accounting period in which such assets or funds are acquired and available;
e. Must not be eligible for any other tax benefits under applicable law; and
f. Must not be eligible for tax exemptions, whether in whole or in part, under investment promotion law, the law on enhancement of competitiveness in target industries, or Eastern Economic Corridor (EEC) laws.

Draft Royal Decree and Key Amendments

Since the implementation of the tax measures under Royal Decree No. 766, Service Providers have faced increasing financial burdens arising from their legal obligation to comply with the ETDA’s security standards governing the management of electronic data received from taxpayers. These obligations entail additional costs for electronic data system audits and assessments conducted by the ETDA. According to data collected by the RD and other relevant authorities, such requirements have resulted in average annual costs of approximately THB 250,000 per Service Provider.

The Draft Royal Decree seeks to support Thailand’s digital transformation objectives while preserving the existing investment promotion framework, including the same terms, conditions, and exclusions established under Royal Decree No. 766. Accordingly, the draft law retains the three categories of eligible expenses described above. The key amendments introduced are: (1) an extension of the implementation period from 1 January 2026 to 31 December 2027, and (2) the introduction of a new fourth category of eligible expense, as follows:

  1. Fees for the use of information system audit and assessment services — comprising fees or service charges paid by a Service Provider to the ETDA for the audit and assessment of electronic data systems used in connection with the provision of e-Tax Invoice and e-Receipt services, e-Filing services, e-Stamp Duty services, or special account data submission services for electronic platform operators.

Under category 4, Service Providers will be entitled to a tax exemption equivalent to twice the amount of fees paid to the ETDA for information system audit and assessment services. This measure is designed to alleviate the financial burden arising from compliance requirements, encourage greater private-sector participation in the RD’s digital tax ecosystem, and ultimately enhance service quality for taxpayers and strengthen Thailand’s competitiveness in the digital economy.

Tax Measures under Ministerial Regulations No. 389

Under Ministerial Regulations No. 389, measures promoting the use of the e-Withholding Tax system were applicable from 1 January 2023 to 31 December 2025. These measures provided tax benefits in the form of reduced withholding tax and income tax rates for both juristic persons (excluding foundations and associations) and individuals making payments through the e-Withholding Tax system. Specifically, the applicable withholding tax rate was reduced from 5% to 3%, and the applicable income tax rate was reduced from 2% to 1%. The reduced income tax rates applied to the following categories of assessable income under the Revenue Code:

  1. Juristic persons (excluding foundations and associations) — income derived from employment duties or positions, including commission fees and bonuses; goodwill and royalty fees; rental income from assets; income from liberal professions; income from contracting services; and income from hire-of-work services, prizes from contests, competitions, or lucky draws, and other service income.
  2. Individuals — rental income from assets; income from liberal professions; income from contracting services; income from hire-of-work services, prizes from contests, competitions, or lucky draws, and other service income; and income of public entertainers resident in Thailand.

Draft Ministerial Regulations and Key Amendments

The measures implemented under Ministerial Regulations No. 389 have materially contributed to Thailand’s digital transformation and have significantly encouraged taxpayers — including businesses, foreign entities, and individuals — to manage their withholding tax and income tax obligations through the RD’s electronic platform. In recognition of this success, the RD has proposed a new Draft Ministerial Regulations to extend the application of these measures for an additional two years, from 1 January 2026 to 31 December 2027.

Pending the entry into force of the Draft Ministerial Regulations, the Ministry of Finance issued the Notification of the Ministry of Finance Regarding the Extension of the Deadline for Additional Fund Remittance through the e-Withholding Tax System, dated 6 February 2026. This notification serves as an interim measure to bridge the gap until the new regulations take effect, permitting taxpayers who made payments through the e-Withholding Tax system between 1 January and 31 March 2026 to remit any additional withholding tax by 30 April 2026, thereby preserving access to the reduced rates during the transitional period.

Summary and Key Takeaways

Businesses are advised to monitor the formal enactment of these draft laws to assess their eligibility for the extended tax incentives.

The RD has proposed two draft laws aimed at reducing compliance costs and encouraging greater private-sector participation in Thailand’s digital tax ecosystem.

The Cabinet, together with other relevant government authorities, has approved in principle both the Draft Royal Decree and the Draft Ministerial Regulations, which extend tax incentives for the use of e-Tax Systems through 31 December 2027.

The Draft Royal Decree introduces a new category of eligible expenses, allowing Service Providers to claim a tax exemption equal to twice the ETDA audit and assessment fees incurred.

Tax incentives under Royal Decree No. 766 for investments in, and the use of, e-Tax Systems — including e-Invoice, e-Receipt, and e-Withholding Tax — will continue under the extended regime.

The Draft Ministerial Regulations extend the reduced withholding tax and income tax rates applicable to qualifying payments made through the e-Withholding Tax system.

Pending the new regulations, the Ministry of Finance has issued an interim notification to preserve access to e-Withholding Tax incentives during the transitional period.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

PDPC Certification: Turning Privacy Compliance into a Competitive Advantage

The Office of the Personal Data Protection Committee (PDPC) has recently introduced a formal certification framework for personal data protection under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The framework establishes a mechanism through which organizations may obtain certification and display certification marks demonstrating adherence to recognized data protection standards.

While many organizations may initially view certification as another compliance exercise, the broader significance of the new framework lies in its potential to transform privacy compliance from a legal obligation into a strategic business asset. As customers, business partners, investors, and regulators place increasing emphasis on data governance, certification offers organizations an opportunity to distinguish themselves in an increasingly competitive marketplace.

Privacy as a Business Differentiator:

Over the past several years, data privacy has evolved from a niche compliance issue into a boardroom-level concern. High-profile data breaches, growing public awareness of privacy rights, and increasingly stringent regulatory requirements have elevated privacy protection into a key component of corporate governance.

As a result, organizations are increasingly expected not only to comply with legal requirements but also to demonstrate that compliance in a credible and transparent manner.

The new certification framework addresses this need by providing a mechanism through which organizations can obtain independent recognition of their privacy management practices. Rather than merely asserting compliance, certified organizations can point to a formal assessment conducted under a framework recognized by the PDPC.

In many industries, this distinction may prove valuable. Consumers are becoming more selective about how their personal information is collected, used, and protected. Organizations that can demonstrate a higher level of commitment to privacy may gain a competitive advantage over those that rely solely on contractual assurances or privacy notices.

Strengthening Customer Trust:

Trust is often one of the most valuable intangible assets an organization possesses. In the digital economy, that trust is closely linked to how personal data is managed.

Organizations routinely collect personal information from customers, employees, suppliers, and business partners. Any perceived weakness in data protection practices can quickly damage brand reputation and customer confidence.

Certification can help bridge the trust gap by providing independent verification that an organization has implemented appropriate data protection controls. Customers may view certification as evidence that an organization takes privacy obligations seriously and has invested in developing robust governance measures.

For businesses operating in sectors involving extensive personal data processing—such as financial services, healthcare, technology, telecommunications, hospitality, retail, and e-commerce—the ability to demonstrate recognized privacy standards may become an increasingly important competitive differentiator.

Facilitating Business-to-Business Relationships:

The benefits of certification may extend well beyond customer-facing activities.

Organizations increasingly conduct privacy and cybersecurity due diligence before engaging vendors, service providers, and business partners. Privacy questionnaires, vendor assessments, and contractual compliance reviews have become standard features of commercial transactions.

A recognized certification may help organizations streamline these processes by providing objective evidence of their privacy governance capabilities. Business partners may gain greater confidence in certified organizations, reducing the need for extensive verification exercises and accelerating commercial negotiations.

This may be particularly beneficial for service providers that process personal data on behalf of clients, including cloud service providers, software companies, outsourcing providers, human resources service providers, and professional service firms.

As privacy-related contractual obligations become more sophisticated, certification may increasingly serve as a practical tool for demonstrating compliance readiness.

Enhancing Corporate Governance:

One of the most significant benefits of certification may be the strengthening of internal governance structures.

Organizations pursuing certification are likely to establish clearer accountability mechanisms, more structured policies, improved risk management processes, and stronger oversight of personal data processing activities.

These governance improvements often extend beyond privacy compliance itself. Well-designed privacy programs frequently contribute to broader organizational objectives, including operational efficiency, information security, risk management, and regulatory compliance.

In this respect, certification should not be viewed merely as a badge or marketing tool. The process of achieving and maintaining certification may encourage organizations to embed privacy considerations more deeply into their governance culture and decision-making processes.

Supporting Regulatory Engagement:

Certification does not eliminate an organization’s legal obligations under the PDPA, nor does it provide immunity from regulatory enforcement.

Nevertheless, certification may serve as evidence that an organization has implemented structured and recognized measures to protect personal data.

Should a regulatory inquiry, investigation, or enforcement action arise, certification may help demonstrate that the organization has adopted a proactive and accountable approach to compliance. While each case will depend on its specific facts and circumstances, organizations that can demonstrate established governance frameworks may be better positioned when engaging with regulators.

This reflects a broader shift in privacy regulation globally, where regulators increasingly focus on accountability and governance rather than merely technical compliance.

Alignment with International Privacy Developments:

The introduction of a certification framework also aligns with broader international developments in privacy regulation.

The European Union’s General Data Protection Regulation (GDPR) recognizes data protection certification mechanisms under Articles 42 and 43 as tools for demonstrating compliance with data protection requirements. Although GDPR certification schemes are still developing across Europe, the underlying principle is clear: independent certification can strengthen trust, transparency, and accountability in personal data processing.

The PDPC’s certification framework follows a similar philosophy. Rather than relying exclusively on enforcement mechanisms, the framework encourages organizations to demonstrate compliance proactively through recognized standards and independent assessment.

For multinational organizations, this development may be particularly significant. Many businesses already operate under global privacy frameworks and seek consistency across jurisdictions. The availability of a domestic certification mechanism may help organizations align local compliance initiatives with broader international privacy governance strategies.

Supporting Cross-Border Business Opportunities:

As businesses increasingly participate in regional and global digital ecosystems, privacy credentials can become an important factor in commercial decision-making.

Foreign customers, investors, and business partners often assess privacy governance capabilities before entering into business relationships involving personal data processing. Organizations that can demonstrate recognized privacy standards may enjoy greater credibility during these assessments.

Certification may therefore provide advantages when competing for international business opportunities, participating in global supply chains, or providing services to overseas customers.

While certification alone will not satisfy all cross-border compliance requirements, it may serve as a valuable indicator of organizational maturity and commitment to responsible data management.

Looking Ahead:

The introduction of the PDPC’s certification framework represents more than a new compliance mechanism. It signals the continuing evolution of privacy regulation toward a model centered on accountability, governance, and demonstrable trustworthiness.

Organizations that view certification solely as a regulatory requirement may overlook its broader strategic value. In an environment where privacy expectations continue to rise, certification has the potential to strengthen customer confidence, facilitate commercial relationships, enhance corporate governance, and support long-term business growth.

For many organizations, the most significant benefit of certification may ultimately be its ability to transform privacy compliance from a cost center into a source of competitive advantage.

Key Takeaways:

  • The PDPC has introduced a formal certification framework for personal data protection under the PDPA.
  • Certification enables organizations to demonstrate privacy compliance through independent assessment and recognition.
  • Certified organizations may strengthen customer trust and enhance their market reputation.
  • Certification can facilitate vendor due diligence and improve business-to-business relationships.
  • The framework encourages stronger governance, accountability, and risk management practices.
  • Certification may help organizations demonstrate proactive compliance efforts when engaging with regulators.
  • The framework aligns with international developments, including certification mechanisms recognized under the GDPR.
  • Organizations engaged in cross-border business activities may benefit from the increased credibility and trust that certification can provide.
  • Privacy certification should be viewed not merely as a compliance tool, but as a strategic asset capable of creating competitive advantage.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles