Thailand currently has no specific law or regulation relating to the metaverse. As a result, the metaverse is governed by general laws and regulations such as the Civil and Commercial Code (CCC), the Electronic Transactions Act B.E. 2544 (2001), the Personal Data Protection Act B.E. 2562 (2019) (PDPA), IP laws and the Cyber Security Act B.E. 2562 (2019) (CSA).
As the metaverse has a persistent virtual environment that allows access to and the co-working of many individual virtual realities, it is likely that a legal relation or a legal dispute may arise in the metaverse. Any agreement or contract made in the metaverse is considered valid under Thai law if the electronic signature can be identified and verified by the signatory as being their own, and if the method/channel used for the signing is reliable for the purpose for which the data is generated or sent, taking into account the circumstances of an agreement between the parties under the Electronic Transactions Act B.E. 2544 (2001).
Furthermore, the relevance of the PDPA may be triggered insofar as personal data is used in the platform. In addition, real-time interaction activities that may occur are likely to involve biometrics data in connection with motion or sentimental expression considered as sensitive data. Consequently, metaverse developers must include a channel/methodology to obtain explicit consent from the user prior to collecting and processing data, and to ameliorate data protection measurements by complying with the PDPA.
Looking into transactions, metaverse platforms necessitate the use of digital assets as a form of payment for goods and services. However, the legislation to facilitate the use of digital assets as a means of payment in Thailand is inadequate.
With respect to IP in the metaverse, Thailand has ensured rights regarding IP in the Copyright Act B.E. 2537 (1994) (CRA), the Patent Act B.E. 2522 (1979) (PA) and the Trademark Act B.E. 2537 (1994). As a result, certain assets in the metaverse, such as computer software, NFTs, software processes, etc, will be protected under Thai IP law, subject to compliance with the relevant laws.
Even though there is legislation in Thailand covering this cutting-edge technology, the laws tend to be defensive instruments rather than preventative as most of them, such as the CSA, designate a committee to create plans or measurements to handle issues that may arise. Following the introduction of the metaverse, Thailand’s government sector is currently in the primary stage in matters regarding this, such as law enforcement, jurisdiction, legislation, etc.
Master Plan for Digital Economy B.E. 2561-2565 (2018–2022)
Thailand currently has the Development of Digitality for Economy and Society Act B.E. 2560 (2017), under which the Master Plan for Digital Economy B.E. 2561-2565 (2018–2022) was prescribed. The plan focuses on four strategies:
In order to accomplish these goals, the plan drives the following ten programmes:
According to the Performance Report produced by the Digital Economy Promotion Agency, three of the strategies have met the target, but the improvement of infrastructure to support digital innovations has not occurred. Moreover, amendments and updates to certain laws and regulations have been planned, as follows:
Master Plan for Digital Economy B.E. 2566-2570 (2023–2027)
This was recently prescribed, with the aim of developing a strong, resilient and dynamic digital economy and society with advanced human capital, technology and innovation. This recent plan focuses on four strategies:
Digital Asset Businesses Emergency Decree B.E. 2561 (2018) (DAB)
The DAB was promulgated to address the rising trend of cryptocurrency usage and investments with an exorbitant amount of capital in various digital currency brokers in recent years. The DAB empowered the Securities and Exchange Commission (SEC) to prescribe policies for encouragement and development, together with regulating digital currency and digital currency operators.
After the DAB was enforced, substantial numbers of businesses associated with cryptocurrencies and digital tokens have obtained applicable licences from the SEC. The licence categorises the operators into the following types of business operation:
Digital asset businesses
Digital asset businesses under the DAB are categorised into three types:
Those who intend to operate a digital asset business shall be approved by the Minister of Finance upon recommendation of the SEC. In undertaking digital asset businesses, the approved operators shall comply with the rules, conditions and procedures as specified in the notification of the SEC, such as:
When any digital asset business is in a situation where its financial condition or operation may cause damages to the public or is in violation of relevant regulations, the SEC is empowered to order such business to rectify the problem or it can temporarily suspend the business operation wholly or partially. If the digital asset business still fails to comply or has repeated the violations, the Minister of Finance is empowered to revoke business approval, upon a recommendation from the SEC.
Preventing the exploitation of digital assets to facilitate illegal transactions
The DAB obliges issuers of digital tokens who are willing to accept cryptocurrencies in the offering process, or operators of digital asset businesses who are willing to accept cryptocurrencies from the counterparties in any transaction, to only accept cryptocurrencies obtained from or deposited with operators of digital asset businesses that are regulated/licensed under the DAB. The rationale is to preserve the integrity of markets by ensuring that the cryptocurrencies being transacted come from traceable sources.
Furthermore, the DAB states that digital asset businesses and ICO portals are considered “Financial Institutions” under the Anti-Money Laundering Act B.E. 2542 (1999), to prevent the exploitation of digital assets as a channel for money laundering.
Maintaining financial and economic stability
Where transactions, business operations or other activities related to digital assets may significantly affect the stability of the national financial system or economy, the Minister of Finance, upon approval of the Cabinet, is empowered to prohibit digital asset businesses from engaging in any digital asset-related activity, or to suspend their operations wholly or partially.
Preventing unfair trading practices
The DAB imposes offences of unfair trading in relation to the purchase, sale or exchange of digital assets taking place in a Digital Asset Exchange in a similar manner to the corresponding provisions in the Securities and Exchange Act B.E. 2535 (1992), such as false dissemination, insider trading, front running and market manipulation. This is to ensure that secondary markets for digital assets are fair, transparent and efficient, market integrity is preserved, and investors are protected.
Electronic transaction services using cloud and edge computing are common in Thailand due to the rapid advancement of technologies in the country. The notification regarding Guidelines for Using Cloud Services B.E. 2562 (2019) (NGCS) was issued by the Electronic Transactions Commission (ETC) under the Electronic Transactions Act (ETA) B.E. 2544 (2001).
The NGCS provides cloud computing service guidelines, as follows.
Technical Precautions
Service providers shall have safeguards for technical security and reliability, such as Virtual Infrastructure, access control identity verification, System Development Life Cycle (SDLC), maintain the security in software development and Application Programming Interface (API), etc.
Service Efficiency
A cloud computing user shall consider the efficiency of the service in the Service Level Agreement, which covers points such as availability, response time, capacity, service support and an exit plan.
Security
A cloud computing user shall consider the security measurements of the service in the Service Level Agreement, which covers points such as international standard reliability, authentication level and outsourcing, data classification and key access control policy, security management and incident reports, data entry and system usage verification, vulnerability assessments and penetration testing, and good governance.
Data Management
A cloud computing user shall consider the Service Level Agreement in regard to data classification, data reserve and recovery, data cycle and data transfer.
Financial Institutions
The Bank of Thailand (BOT) has notified the Criteria for Supervising Information Technology Risk, SorNorSor. 21/2562 (2019) (“BOT notification”), which focuses mainly on regulating the IT outsourcing of finance institutions, such as cloud computing, which must be the subject of an annual IT report submitted to the BOT. The BOT notification also prescribes the Third-Party Risk Management Implementation Guideline (“BOT Guideline”), under which finance institutions must comply with the BOT notification. The BOT Guideline mainly targets risk governance, third-party risk management and BOT IT outsourcing reports.
In regard to cloud computing, financial institutions shall maintain the confidentiality of clients' personal data, as prescribed in the PDPA and the BOT notification regarding Market Conduct B.E. 2563 (2020) (“Market Conduct notification”). The Market Conduct notification focuses on supervising the protection of clients' personal data and the disclosure thereof to a third party.
Insurance
The Office of Insurance Commission (OIC) notified the OIC notification regarding the criteria to supervise and manage the information technology risk of insurance companies B.E. 2563 (2020) (“OIC notification”). Consequently, the Guideline of Supervising the Use of IT Outsourcing Service B.E. 2564 (2021) (“OIC Guideline”) was prescribed to comply with the OIC notification. The OIC Guideline mainly targets the supervision of IT outsourcing, the risk management of IT outsourcing, the criteria involved in outsourcing, the model for insurance companies to manage unexpected scenarios, business continuity management (BCM), outsourcing security and IT outsourcing reports.
In regard to cloud computing, the company shall have an international data protection standard, such as data encryption and key management. In addition, the company shall have measurements to recall all user data from the outsourcer and ensure that the outsourcer is competent to destroy users' data after the termination of service. Moreover, the outsourcer shall maintain data protection standards that comply with the relevant laws and international standards.
Thailand has no specific law or regulation relating to artificial intelligence (AI) and big data. As a result, AI and big data are governed by general laws and regulations, such as the CCC, intellectual property law and personal data protection law. This represents a challenge for those involved with these subject matters, as the general laws must be used and applied in any disputes that arise. Regarding personal data, the data controller must comply with the specific regulations under the PDPA, which will apply across all businesses that involve the collection, disclosure and/or utilisation of personal data.
There are debates in Thailand on the status of AI as a property or non-property. However, the CCC defines “property” as corporeal objects and incorporeal objects that are susceptible of having a value and of being appropriated. Therefore, AI may be considered as property (incorporeal object) under Thai law if it has a value.
AI as a property is protected by the intellectual property law. To begin with, the CRA protects computer programs, which it defines as instructions, sets of instructions or any other things that are used with a computer so as to operate the computer or to generate an output, whatever the computer language is. Therefore, the CRA only protects the source code, and not the algorithm. If a product was created by AI, the copyright of the product would belong to the owner of the AI.
However, the PA does not protect the invention of computer programs and scientific or mathematical rules or theories. “Algorithm” has been defined in academic circles as a part of a scientific or mathematical theory, so AI is not protected under the PA.
Looking into the liabilities in the event that AI causes damages, the injured person can take action under general laws such as tort law under the CCC, with the liability stipulated by law falling to the AI controller or possessor unless it can be proved that the injury results from force majeure or is the fault of the injured person.
Thai laws apply specific requirements – such as insurance, minimum capitalisations or individual licences – on the primary business operation alone, without further considering the technology or platform with which the business operates. As a result, business operators are not subject to additional regulations, particularly those pertaining to AI and big data.
There is currently no specified law to regulate internet of things (IoT) devices in Thailand. The CSA focuses on regulating, planning, coping with and minimising cyber threats to the security of the state, government services, banking and finance, media and telecommunications, logistics, energy and public utilities and public health, through committees under the CSA.
The Industrial Product Standard Act B.E. 2511 (1968) (ISPA) – which indicates industrial product standards and prevents price competitions among manufacturers that lead to lower product quality – cannot be a tool to regulate IoT importers or manufacturers regarding systems or personal data due to the ISPA targeting the regulation of physical products.
However, there are laws and regulations related to the IoT, as follows.
Computer-Related Crime Act B.E. 2550 (2007) (CRCA)
The CRCA prescribes preventative and suppression measures in the event of a person (or persons) causing a computer system to not operate as ordered or to operate incorrectly, or illegally accessing another person’s computer data in order to modify or destroy the data or utilise the computer system to disseminate false computer data or obscene images, causing damage affecting the economy, society and state security, including peace and the good morals of the people.
The IoT is defined as a computer system under the CRCA, and is therefore subject to criminal punishments. However, the CRCA cannot be considered as a mechanism to protect the preventative use of IoT devices and the safety of use, nor for requiring IoT devices to have appropriate security systems in order to prevent offences committed against an IoT device.
PDPA
The PDPA indicates the obligations for organisations that collect, use or disclose personal data to be cautious and maintain the standards of data security as prescribed by the PDPA. Moreover, the PDPA prescribes data subject rights regarding requests to:
As a result, the data controller that received the personal data via the IoT must obtain consent from the data subject in order to collect, use or disclose said data without causing any damages or operating beyond the consent of the data subject. Failure to comply with the PDPA may lead to complaints and administrative or criminal penalties.
The PDPA may assure IoT users of the obligations that require IoT device manufacturers to create a path to obtain consent in each utilisation of IoT devices. However, some IoT devices require users to give consent in several accesses of personal data, such as location tracking, cookies and internet usage, which leads to abundant personal data; if the user or data subject did not give consent, the IoT device could not be used under the terms and conditions imposed by the IoT service provider.
The Radio Communications Act B.E. 2498 (1955) (RCA)
The RCA requires a business operator who performs transactions (such as producing, possessing, trading, importing and exporting) on radio communication equipment to obtain a licence from the National Broadcasting and Telecommunications Commission (NBTC) before commencing any such transaction. Such transactions must be reported to the NBTC or subject to an importation licence obtained from the NBTC.
There is a licence exemption for specific radio communication equipment, such as that using Wi-Fi 2.4GHz. The NBTC may also issue a Notification on exemptions on a case-by-case basis. In addition to the licence requirement, such radio communication equipment must meet the technical and safety standard prescribed by the NBTC. Therefore, each radio communication equipment's technical and safety standard shall be specified in the NBTC Notification.
In Thailand, audio-visual media services (eg, TV, radio) are regulated by the NBTC under the Broadcasting and Television Business Act B.E. 2551 (2008) (“Broadcasting Act”). The content of films, videos and their advertising media are also regulated under the Film and Video Act B.E. 2551 (2008). Therefore, a censorship committee of officials will review, approve or censor the content of films, videos and advertisements, and approve other film and video-related activities in Thailand, such as the production or distribution of foreign films.
The Broadcasting Act categorises licences for audio-visual media service into three types, each of which has the following foreign ownership restrictions.
An applicant must be of Thai nationality, must not be on a probationary period restricting them from using the licence, and cannot have exceeded three years of a licence withdrawal period. The approval process usually takes up to 60 days after submitting all the necessary documents. If approved, the applicant will be granted the right to operate under the express terms of the given licence. A broadcasting schedule may be allocated to other licensed broadcasters if the broadcaster complies with the rules and regulations prescribed by the NBTC.
The NBTC will grant a seven-year term for sound broadcasting licensees and five years for television broadcasting licensees. Licences may be renewed 90 days before expiry. Licensees must pay annual fees for their respective licences.
Under the Notification regarding Broadcasting and Television Business Licence fee, there are fees for a licence application consideration (which depends on the type of licence) and an annual fee. The annual fee is collected at progressive rates, as follows:
These requirements do not apply to video-sharing platform services or over-the-top (OTT) services (eg, video platforms with user-generated content or videos on demand). According to the NBTC, the scope of what constitutes “broadcasting” will be determined with the goal of regulating OTT Services. OTT operators have been informed that they must register themselves with the NBTC and that they would be governed by specific rules and regulations, regardless of nationality.
Organisation to Assign Radio Frequency and to Regulate Broadcasting and Telecommunications Services Act B.E. 2553 (2010) (“NBTC Act”)
The NBTC Act defines “Telecommunications service” as a service that sends, transmits or receives signs, letters, figures, pictures, sounds, codes or anything else made comprehensible by frequency waves, wireless, lighting, electromagnetic systems or any other systems, or other activities prescribed by law to be telecommunications services. Therefore, a device that meets this definition is deemed to fall within the scope of Thai telecommunications rules.
The NBTC Act establishes the NBTC as an independent broadcasting and telecommunications business regulator. Subject to supervision by the NBTC, the Telecommunications Committee regulates telecoms business in compliance with the Telecommunications Business Act B.E. 2543 (2001) (“TA”), which applies to operators of telecommunications services.
Telecommunications licences are divided into the following three types:
The TA imposes various foreign ownership restrictions for each type of telecoms licence, as follows:
The different categories of licences cover various services as indicated in the operator’s licence application. The applicant must be a legal person as established under Thai law, and must not be a bankrupt or a party that has previously had a telecommunications licence revoked. In addition, technical and commercial information relating to the business operations of the applicant – including the network structure, financial investment plan, marketing plan, service details and equipment details – must be provided to the NBTC for its consideration.
The approval of all types of licences usually takes approximately 60 to 90 days after all necessary documents and information have been submitted to the NBTC. If approved, the applicant will be granted the right to operate strictly under the express terms of the licence. Licensees must pay annual fees for their respective licences.
NBTC Inspection
Business operators who wish to manufacture, sell or import devices that have been inspected and approved by the NBTC shall not be required to provide samples of such devices for the NBTC’s inspection and approval; they can skip the inspection process and go straight for the manufacture, sell or import certificate.
However, the operator must provide samples of any devices that have not yet been inspected or approved by the NBTC to the NBTC for inspection and approval prior to obtaining the certificate required for its business operation. This will require some extra time (approximately ten working days) and effort from the applicant, especially for brand-new devices with new technology that is unknown to the NBTC. After the consideration, the NBTC will notify the result to the applicant within seven days.
In addition to the NBTC inspection and approval, operators who wish to manufacture, sell or import certain telecommunication devices that have obtained certain international inspections/approvals (such as certain ISO marks) may file documentation relating to the international approval (such as the ISO certificate) to the NBTC for its consideration rather than submitting product samples for the NBTC’s inspection/approval. The goal is to shorten the process to obtain the relevant certificate required (whether manufacture, sell or import) prior to operating such telecommunication business in Thailand.
There are no specific laws and regulations that apply to technology agreements, and there is currently no particular law or regulation that requires data to be stored locally in Thailand. Nevertheless, industry-specific regulations mandate that some data is to be available or processed within Thailand. The banking industry, for example, requires banks to process debit card transaction data and make electronic payment system data available in Thailand.
As there is no direct legal requirement for the terms and conditions in a technology agreement, the challenge is to establish an agreement with terms and conditions that cover all the necessary elements. The provisions stated therein shall be based on the intention of the parties and the work for hire concept under the CCC. Except for the specific commercial and technical terms prescribed in the service agreement, the following terms should be noted and stated therein:
Banking and Insurance
The BOT and the OIC) have notified the terms that should be stated in the business partner (ie, outsourcing) agreement, as follows:
The Royal Decree on Security Procedures regarding Electronic Transactions B.E. 2553 (2001) (SPET) is prescribed under the Electronic Transactions Act B.E. 2544 (2001) (ETA) and mainly indicates the criteria of a reliable electronic transaction and divides the security procedure into three levels: strict, intermediate and basic. These three levels are categorised under the notification regarding the standard for maintaining information security, which mainly focuses on the establishment of administrative security, information security in respect of personnel, physical security and the environment, etc.
The Royal Decree regarding the supervision of services related to licensed digital authentication B.E. 2565 (2022) (“Digital Authentication Decree”) was promulgated on 22 December 2022 under the ETA, and will become effective 180 days after the promulgation date. Digital authentication service providers are subject to be approved for a licence by the Electronic Transactions Development Agency (ETDA). Services deemed to fall within the scope of such a licence are authentication services, issuing and managing authentication services and information exchange services for the authentication and verification of digital identity. However, the authentication of electronic signature service providers under the ETA does not fall within the scope of a licence under the Digital Authentication Decree.
Therefore, digital authentication service providers are obliged to comply with the regulations under the Digital Authentication Decree, including the duty to report and comply with notifications notified by the ETDA regarding authentication data outsourcing, change of corporate structures, cessation of service, lawsuits against the service provider, director or manager qualifications, minimum company limited or public company limited registered capital, business and authentication system assessments, etc.
Regarding the use of electronic signatures, the ETA prescribes that the method of electronic signature must be:
Therefore, electronic signatures are legally effective and enforceable in Thailand, except in those transactions prescribed by a Royal Decree to exclude electronic signatures under the ETA (ie, transactions relating to family and succession).
Regarding digital identity, the Royal Decree regarding Digital platform service business that must notify B.E. 2565 (2022) (“Digital Platform Decree”) was promulgated on 22 December 2022 under the ETA and will become effective 240 days after the promulgation date.
The Digital Platform Decree prescribes that any digital platform that provides a service in Thailand and has an annual income of more than THB1.8 million (~USD53,000) for a natural person operator or THB50 million (~USD1.5 million) for a juristic person operator, or any platform that provides to more than 5,000 users per month, must provide the ETDA with information concerning the operator, digital platform, users, co-ordinator (if a digital platform operates overseas), etc. The definition of digital platform service is wide, so most digital platform services in Thailand are deemed to fall under the Digital Platform Decree.
Furthermore, the co-ordinator must not be a foreign business operator, and a digital platform entity establishment is not required. In addition, the ETDA is empowered to restrict the digital platform in the event of non-compliance with Thai laws and regulations. The digital platform must inform the terms and conditions of use and provide mitigation and compensation measures to compensate those who have been damaged through the digital platform operation. In order to cease operation, the co-ordinator must notify the ETDA under the regulation prescribed by the ETDA. However, any digital platform that needs to notify the ETDA and operated before the effective date of the Digital Platform Decree is able to notify the ETDA within 90 days after the effective date.
399, Interchange 21 Building
23rd Fl., Unit 3, Sukhumvit Road
Klongtoey-Nua
Wattana
Bangkok 10110
Thailand
+66 2 107 1882
info@fosrlaw.com www.fosrlaw.comOverview of the Telecom Market in Thailand
In October 2022, the National Broadcasting and Telecommunications Commission (NBTC) approved a proposed merger between TRUE and DTAC, two of the biggest telco operators in Thailand. The two companies are now in the process of preparing the merger plan.
This merger may have a tremendous impact on Thailand’s telecommunications market, as there were previously three big competitors in the market and soon there will be two. As a controversial topic in Thailand, there were concerns and criticisms that the service fee will rise considerably and that the telecommunications market will be monopolised.
Nonetheless, the NBTC indicated that certain measures would be implemented, such as pricing control, supporting smaller-scale operators to compete in the market, regulating the quality of service, spectrum utilisation and infrastructure sharing, and a digital divide. Moreover, the NBTC specifically stated that TRUE and DTAC must keep the brands separate for three years, in order to maintain consumers’ freedom of choice.
The consequences of this merger between two big telco operators are yet to be seen. According to the Securities and Exchange Commission (SEC), the new company's name will be TRUE Corporation and the registered capital will be THB138,208,403,204, which is equivalent to the registered capital of TRUE and DTAC combined. In addition, 34,552,100,801 common shares will be allocated to the shareholders of TRUE and DTAC on the book closing date.
Personal Data Protection Act
The Personal Data Protection Act B.E. 2562 (2019) (PDPA) has been fully enforced since 1 June 2022; all business sectors are required to comply with the PDPA. This compliance was a controversial issue after the PDPA become fully enforced, as it requires major changes to business operations, especially customer engagement. The PDPA’s provisions are somewhat similar to those of the GDPR and other data privacy laws in various jurisdictions. Nonetheless, some of the provisions in the PDPA remain unclarified, awaiting for notifications to be prescribed by the Personal Data Protection Commission (PDPC).
The criteria and method by which to notify a data breach have recently been notified under the PDPA. The notification mainly prescribes the procedure and list of details that must be included in the data breach notice, along with the timeframe in which it must be submitted to the Office of the PDPC. However, several notifications have not yet been notified under the PDPA, such as the criteria and method to transfer personal data to foreign countries, which may cause difficulties and issues in the practice of data transferring. More ancillary laws for the PDPA are expected to be issued in 2023 to address remaining and new issues that may arise with the new technologies.
Recent update to space law
Nowadays, space-related technology is increasingly applied to daily life, benefiting both the public and the private sectors, with more than 35,600 enterprises operating space-related businesses in Thailand, generating an income of approximately THB56.122 billion. The technology that these companies produce helps to mitigate and prevent national disasters, including floods, drought and other climate crises. The technology has also been applied to issues brought about by the COVID-19 pandemic, and has helped to identify different locations for commercial and medical activities.
As space businesses and activities involve cross-border operators and international organisations, Thailand requires transparent, up-to-date and adequate space laws to enable proper, legal operation of space activities and to gain trust from all operators.
A draft Space Affairs Act (“Draft Act”) has been proposed by the Geo-Informatics and Space Technology Development Agency (GISTDA), and was approved by the Cabinet on 13 July 2021. It is now undergoing the legislation process and will be sent to the Office of the Council of State and Parliament for consideration and approval before becoming effective.
The Draft Act mainly focuses on regulating a natural or juristic person who is involved in space affairs to apply for a direct space activity licence or space-related activity licence. This will also be applied to space affairs carried out before the Draft Act becomes effective. In this event, the natural or juristic person must apply for a licence within 60 days of the Draft Act becoming effective. Furthermore, space objects must be registered under the Draft Act.
The Draft Act also prescribes that the Thai government is responsible for damages that occur outside Thailand related to space activities, space objects or space-related activities by a Thai individual or a Thai juristic person to a third party, regardless of whether the activity or object is licensed or registered. If the government has settled a dispute and paid compensation to a third party, it will have the right of recourse to the individual or the juristic person who caused the damage. More updates from the government regarding the Draft Act are expected in 2023.
Over-the-top (OTT) service in Thailand
OTT contents have been a rising trend all around the world, especially in the widespread pandemic period. More than one-third of Thailand’s population selected to utilise OTT platform, with approximately 1.4 billion hours per month spent on the platforms. Accordingly, Thailand’s OTT market is considered one of the biggest in Southeast Asia.
However, OTT service platform remains unregulated by a specific broadcasting and television law like the traditional media of radio, films, television and advertisement. Therefore, only existing laws and regulations in other relevant laws will be applicable in regards to OTT service.
The NBTC's attempt to regulate OTT platforms by requesting the operators to register themselves under the NBTC was heavily criticised by the public and OTT platform operators, as well as technology-related NGOs. In consequence, the NBTC withdrew its requests to OTT operators.
Therefore, OTT operators who operate in Thailand must be aware of regulatory risk. On a case-by-case basis, the operators should be active and ensure that the content is in compliance with the relevant laws and regulations in forces in Thailand.
Illegal contents, such as pornography, lèse-majesté and fake news are regulated under the Computer Crimes Act; operators who allow such illegal contents on their platforms may be blocked, banned and penalised by the Thai authority. No major changes to the existing laws are expected in 2023, but it is likely there will be some changes to the related laws in the future.
Thailand National AI Strategy and Action Plan (2022–2027)
According to the Government Artificial Intelligence Readiness Index 2020, Thailand was ranked in 60th due to the lack of policy and action plan relating to AI. In consequence, the Cabinet approved the (Draft) Thailand National AI Strategy and Action Plan (2022–2027) (“AI Plan”) on 26 July 2022, under the vision “Thailand has an effective ecosystem to promote AI development and application to enhance the economy and quality of life within 2027”.
The AI plan is aimed to build human capacity and technology, economic growth, and social and environmental impact. The AI Plan will be implemented under the following five strategies:
Focusing on laws proposed by the AI plan, the intention of the law is to create guidelines and regulations in order to promote AI as being socially beneficial, ethical, trustworthy, secure and private, fair, and emphasising human well-being. Moreover, the laws will be enacted to be in compliance with the PDPA, with consideration of data subject rights.
The intention is to create policy regulations and standards, and to enact laws that are relevant to AI. The laws will be by design, and can be divided into the following seven topics:
After the enforcement of the aforementioned laws, the AI plan states that ethics in utilising AI technology and the development and effects of AI utilisation should be addressed in the primary stage of Thai education. Furthermore, the capabilities of AI entrepreneurs should be enhanced by setting standards for data storage, data verification, robotics or medical devices related to AI, in order to be in compliance with AI laws, ethics and international standards.
The AI-related laws and regulations in Thailand are clearly in the primary stages. However, AI is becoming a controversial topic. Thailand’s government and business sectors are pushing to regulate this cutting-edge technology for the benefit of Thailand’s economic and society. Only the insurance and finance sectors regulate and put out criteria and measures for utilising AI tools as an IT outsourcing service to mitigate unexpected scenarios that technology may cause.
Trading Forex in Thailand
Forex was a hot issue in Thailand in 2022, as it was involved in one of the biggest scandals in Thailand, Forex 3D. According to official reports, the damage in this case is up to THB2.5 billion, with more than 80,000 investors. It is nearly clear that fraud has been committed, with the suggestion that investors would receive 10–15% monthly from the invested capital and 5% from capital invested by invitees.
Looking into Forex regulation in Thailand, there are no laws and regulations that indicate Forex is illegal Thailand. Nonetheless, no licences have been granted for non-banks to be Forex brokers in Thailand, even though there are laws regulating this issue. Therefore, Thai investors are capable of opening an account with foreign Forex brokers.
As there is no Forex broker regulation under Thai law, Forex investors in Thailand are not protected under Thai law. It is beyond Thailand’s jurisdiction to file a lawsuit against the broker if damages occur with a foreign broker. An individual investor is responsible for pursuing damages by themselves.
According to the Bank of Thailand, a ministerial regulation was recently issued under the Exchange Control Act B.E. 2485 (1942) to amend the regulation covering transaction business relating to foreign means of payment, to enhance the regulation and reliability in the international aspect, but this does not directly affect Forex brokers.
Notice and takedown policy
As technology changes and evolves rapidly, various illegal contents are published on the internet. Thailand recently issued a notification in regard to the notice and takedown policy (“Notification”) under the Computer-related Crime Act B.E. 2550 (2007) and its amendment (CCA). The purpose of this Notification is to amend the notice and takedown policy, so that it is stricter and up to date.
The main characteristics of the Notification are as follows:
These main characteristics differ from the previous notice and takedown notification, especially the final point, as the competent officer was previously not authorised to directly instruct operators to take content down. Nonetheless, the Notification has been criticised as being contrary to the presumption of innocence (until proven guilty), which is assured by the Constitution of Thailand. However, the Notification will be enforced in mid-2023.
399, Interchange 21 Building
23rd Fl., Unit 3, Sukhumvit Road
Klongtoey-Nua
Wattana
Bangkok 10110
Thailand
+66 2 107 1882
info@fosrlaw.com www.fosrlaw.com