Telemedicine Practices and Data Protection Compliance in Thailand: Legal Brief

I. Introduction to Telemedicine in Thailand:

Telemedicine has emerged as one of the most transformative innovations in healthcare. By leveraging modern communication technologies, telemedicine enables the delivery of medical services regardless of geographic barriers. As the global demand for accessible, efficient, and cost-effective healthcare increases, many countries have embraced telemedicine to overcome traditional challenges such as distance, cost, and limited access to medical expertise.

Thailand, with its rapidly developing digital infrastructure and progressive approach to healthcare, is becoming a prominent destination for telemedicine providers. However, alongside its tremendous growth potential, Thailand presents unique challenges, particularly in the realm of data protection and privacy. For both local and international telemedicine platforms, understanding and complying with the local legal environment is critical. The country’s evolving legal landscape, especially concerning data protection, patient privacy, and healthcare standards, requires providers to implement robust compliance measures. Doing so not only safeguards sensitive patient information but also builds trust with users, ensuring sustainable business growth in a competitive market.

In this guide, we delve into the key considerations for data compliance, discuss the relevant regulatory frameworks under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), and outline practical steps for telemedicine platforms to navigate these regulations. By doing so, telemedicine providers can effectively mitigate risks, secure patient data, and maintain a competitive edge in the Thai market.


II. Health Information Protection Before the Enforcement of the Personal Data Protection Law:

  1. The National Health Act and Ministerial Regulation:

Thailand’s regulatory framework for data protection has undergone significant evolution over recent years. Prior to the enactment of the PDPA in 2019, Thailand relied on a combination of the Thai Constitution, the Thai Civil and Commercial Code, and sector-specific regulations like the National Health Act B.E. 2550 (2007) (“National Health Act”). The National Health Act mandated that personal health information be kept confidential. Specifically, Section 7 of the National Health Act required that such information not be disclosed in a manner that could harm the data subject, except when authorized by the individual or required by law.

The Ministerial Regulation on the Protection and Management of Personal Health Information B.E. 2561 (2018) (“MR”) provided further details on the scope and nature of personal health information. Clause 4 of the MR defined personal health information as encompassing a variety of documents, case files, reports, and other materials capable of identifying an individual’s health status. Clause 11 offered an exhaustive list of items considered personal health information, such as:

  1. Health History: Such as height, weight, blood type, and body shape.
    1. Medical Records: Such as nursing records, laboratory examinations, and x-ray films.
    1. Related Documents: Any documents or objects that relate to the above data.
    1. Photographic Evidence: Images of medical personnel or actions during treatment.
    1. Additional Information: Any further information as specified by the Personal Health Data Protection and Management Committee.
  2. Penalties for Non-Compliance:

Before the PDPA’s enactment, violations regarding the unlawful or unauthorized disclosure of personal health information were met with penalties prescribed under the NHA. Under Section 49 of the National Health Act, such violations could result in imprisonment of up to six months, fines of up to 10,000 THB, or both. Moreover, wrongful use of personal data was addressed under Section 420 of the Civil and Commercial Code, which provided for civil liability in cases where data misuse resulted in harm to the data subject.

  • Transition to the PDPA:

In 2019, the PDPA was published in the Royal Gazette, marking a significant shift in Thailand’s data protection landscape. With its comprehensive framework, the PDPA rendered the earlier MR obsolete. The Medical Council of Thailand subsequently issued a new Ministerial Regulation on the Revocation of the MR B.E. 2565 (2022). This evolution represents Thailand’s commitment to aligning its data protection standards with international best practices.


III. What Is Health Information?

As a result of the MR revocation, Thailand no longer has a statutory definition of health information, which is crucial in terms of personal data protection and compliance with obligations under the PDPA. Telemedicine platforms need to understand the personal data in their possession and handle such data according to the PDPA.

In the absence of subordinate regulations, directives, or guidelines to clarify the extent and scope of health information under the PDPA, it is worth exploring the definition given under the European Union General Data Protection Regulations (2016/679) (“EU GDPR”), which was a core foundation of the Thai PDPA, containing many similar provisions tailored to Thailand’s contexts.

Article 4 (15) of the EU GDPR defines ‘data concerning health’ as personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status. Additionally, the European Parliament and the Council of the European Union opined that ‘personal data concerning health’ should include all data pertaining to the health status of a data subject, including information collected during registration or provision of health care services, testing results, disease history, clinical treatments, or physiological states.

By this principle, personal data that may not obviously qualify as health information could still be considered health information depending on the context of personal data processing activities.


IV. Overview of PDPA Compliance for Telemedicine Platforms:

The PDPA extends its reach not only to local businesses but also to international data controllers who process the personal data of Thai residents. This extraterritorial effect means that even telemedicine platforms headquartered outside Thailand must comply with the PDPA if they process the personal data of individuals located in the country.

  1. Extraterritorial Applicability:

According to Section 5, Paragraph 2 of the PDPA, foreign data controllers are subject to the PDPA if any of the following criteria are met:

  1. The offering of goods or services to the data subjects who are in the Kingdom of Thailand, irrespective of whether the payment is made by the data subject, or
    1. The monitoring of the data subject’s behavior, where the behavior takes place in the Kingdom of Thailand.
  • Obligations for Telemedicine Providers:

Once the PDPA applies, telemedicine providers (whether local or international) must adhere to various obligations under the PDPA, some of which include:

  1. Data Collection and Processing: Ensure that personal data is collected, used, and disclosed with legal bases supporting each processing activity.
    1. Privacy Notices: Clearly communicate to data subjects how their personal data will be used.
    1. Security Measures: Implement appropriate technical and organizational measures to safeguard personal data.
    1. Data Subject Rights: Provide mechanisms for data subjects to exercise their rights (e.g., access, correction, deletion).
    1. Breach Notification: Establish procedures to notify both the regulatory authority and affected data subjects in the event of a data breach.
    1. Record-Keeping: Maintain a Record of Processing Activities (ROPA) to document data processing practices.

V. Privacy Notice / Privacy Policy Under the PDPA:

One of the foundational requirements under the PDPA is the preparation and dissemination of a comprehensive privacy notice or privacy policy. This document serves to inform data subjects about how their personal data is collected, processed, stored, and shared.

  1. Content of Privacy Policy:

Under Section 23 of the PDPA, data controllers must notify data subjects of the purposes of data collection prior to or at the time of collection. Common practices include written notices, electronic pop-ups on websites or applications, or verbal communications as applicable.

  • Best Practices for Drafting a Privacy Policy:

For telemedicine platforms, drafting a privacy policy involves a deep understanding of the personal data flows within the organization. Understanding the customer journey is vital for telemedicine platforms in preparing the privacy policy, as each touchpoint involves the collection and processing of personal data.

  1. Sign-Up / Registration:

During the initial sign-up process, users are generally required to provide basic personal data such as their name, age, contact details, and, in some cases, initial health information, such as their height, weight, medical history, passport or national identification card, contact information, and information relating to personal allergies. This stage sets the foundation for subsequent interactions and must be handled with the highest level of security and clarity regarding data usage.

  • Know Your Customer (KYC) and Confirming the Identity of the Data Subject: To ensure compliance with Thailand’s PDPA and safeguard sensitive personal data, telemedicine platforms must implement robust KYC procedures during the sign-up phase. These procedures are designed to verify the identity of the data subject and establish trust between the platform and its users.
  • Verification of Identity: Platforms should require users to provide a valid
    • identification documents, such as a national ID card, passport, or other government-issued IDs, to confirm their identity.
    • The verification process may involve uploading scanned copies of these documents or using digital identity verification tools that comply with Thai legal standards.
  • Biometric Verification (Optional):

For enhanced security, telemedicine platforms may opt to incorporate biometric verification methods, such as facial recognition or fingerprint scanning, where applicable and permitted by law.

  • Data Matching:

Once the user submits their identification details, the platform should cross-check this information against official databases (e.g., government records) to ensure accuracy and prevent fraud.

  • Explicit Consent:

During the registration process, explicit consent must be obtained from the user for the collection, use, and disclosure of both general personal data and sensitive personal data. This includes clear explanations of how their data will be processed, stored, and shared.

If the user is under 20 years of age, additional consent from their legal representative, guardian, or curator may be required under Section 20 of the PDPA.

  • Booking / Appointment Scheduling:

Once registered, users schedule appointments with healthcare providers. The booking process may involve selecting a healthcare professional based on specialty, availability, or patient reviews. Additional forms might be used to capture medical history or current health conditions.

  • Consultation:

Consultations are the core of telemedicine services. Whether conducted via video calls, chat sessions, or telephone, these interactions involve real-time exchange of sensitive health information. Data from these sessions may include verbal communications, visual data, and records of diagnosis and treatment.

  1. Post-Consultation Services:

After the consultation, several processes may occur:

  • Payments: Patients make payments through integrated or third-party payment gateways. This process generally involves third-party service providers.
  • Insurance Claims: In some cases, patients may file insurance claims. Telemedicine platforms might assist in this process by forwarding relevant health information to insurers.
  • Medicine Delivery: If medication is prescribed, delivery logistics come into play. This may involve sharing personal data (such as address and contact information) with third-party courier services.
  • Follow-up Appointments: Follow-up consultations or treatment plans may be scheduled, requiring further data collection.
  • Feedback and Reviews: Post-consultation feedback is often solicited to improve service quality. While this may involve general data, any health-related feedback is treated with heightened sensitivity

n)


VI. Legal Bases for Each Activity:

Different stages of the customer journey require distinct legal bases under the PDPA. For example:

ActivityGeneral Personal DataSensitive Personal Data
Sign-up / RegistrationNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Booking / AppointmentNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
ConsultationNecessary to enter into / Performance of a contract
(Section 24 (3))
Necessary for compliance with a law with respect to the provision of health or social care / Explicit Consent (Section 26 (5)(a) / Section 26)
Payment and BillingNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Insurance ClaimsLegitimate interest
(Section 24 (5))
Explicit Consent
(Section 26)
Medicine DeliveryNecessary to enter into / Performance of a contract
(Section 24 (3))
Explicit Consent
(Section 26)
Feedback / ReviewsLegitimate interest
(Section 24 (5))
Explicit Consent
(Section 26)

Important Remark: Please note that the table above shall only be used as a reference. The actual legal basis for each activity may differ based on the specific facts and circumstances.


VII. Processing Personal Data of Minors, Quasi-Incompetent Persons, or Incompetent Persons:

Where a patient is under 20 years of age or is a quasi-incompetent person or incompetent person, Section 20 of the PDPA requires their consent to be accompanied by consent from their respective legal representatives, guardians, or curators. However, if the patient is under 10 years of age, sole consent from the legal representative is sufficient.

Section 24 of the Thai Civil and Commercial Code provides an exemption for acts deemed suitable for a minor’s reasonable needs. Therefore, a minor (between 10 and 20 years of age) may give sole consent for telemedicine consultation purposes, as it deems suitable and actually required for their reasonable needs.


VIII. Data Subject Rights and Request Compliance Under the PDPA:

The PDPA enshrines several rights for data subjects. Telemedicine platforms must have robust processes to facilitate these rights.

A. Overview of Data Subject Rights:

The PDPA grants data subjects the following rights:

  1. Right to Access: Data subjects may request copies of their personal data.
  2. Right to Data Portability: Individuals can obtain their personal data in a structured, commonly used format.
  3. Right to Object: Data subjects may object to certain personal data processing activities.
  4. Right to Delete: Also known as the “right to be forgotten,” this allows data subjects to request deletion or anonymization of their personal data.
  5. Right to Restrict Processing: In certain circumstances, processing may be limited or suspended.
  6. Right to Rectification: Data subjects can have inaccurate or incomplete personal data corrected.
  7. Right to Lodge a Complaint: Data subjects can lodge complaints with regulatory authorities.
  8. Right to Withdraw Consent: Where processing is based on consent, data subjects may withdraw that consent at any time.

B. Procedures for Data Subject Rights Requests (DSRR):

Upon receiving a data subject request, telemedicine platforms should follow a set of protocols:

  1. Verification: Confirm the identity of the data subject or their representative.
  • Clarification: Request additional information if the request is ambiguous.
  • Documentation: Record all details of the request.
  • Data Retrieval: Locate and compile the relevant data.
  • Review for Exemptions: Determine if any exemptions apply.
  • Response: Communicate a clear response—either fulfilling the request, rejecting it, or outlining why an exception applies.
  • Record-Keeping: Maintain records of the requests and responses for regulatory audits.

IX. Record of Processing Activities (ROPA):

Maintaining a detailed ROPA is a regulatory requirement under Section 39 of the PDPA.

A comprehensive ROPA should include,

  1. the collected personal data;
    1. the purpose of the collection of personal data in each category;
    1. details of the data controller;
    1. the retention period of personal data;
    1. rights and methods for accessing personal data, including conditions for exercising these rights;
    1. the use or disclosure of personal data;
    1. rejection or objection to the data subject’s rights request; and
    1. explanation of the appropriate security measures.

However, SMEs may be exempt from maintaining a full ROPA if they employ fewer than 100 people and have an annual revenue of no more than 300,000,000 THB. Nevertheless, telemedicine platforms handling sensitive personal data must maintain a full ROPA due to the risks involved.


X. Appropriate Security Measures for Telemedicine Platforms:

Prescribed under Section 37 (1) of the PDPA, where a data controller is required to provide appropriate security measures to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data. In this regard, the appropriate security measures for the telemedicine platforms shall focus on the maintenance of personal data’s confidentiality, integrity, and availability.

According to the PDPC’s Announcement on Security Measures for Personal Data,  the security measures should contain at least the following mechanism: (1) access controls, allowing access to personal data only on a need-to-know basis provided that there shall also be an identity proofing, authentication, and authorization procedure; (2) user access management including registration and de-registration of access provision; (3) user responsibilities shall be prescribed; (4) implement an audit trail to enable the reviewing of access, change, alteration, or deletion of personal data.

The duty to implement appropriate security measures shall be extended to the imposition of obligations on the data processor of the telemedicine platforms (such as medicine delivery service providers), to prevent unauthorized or unlawful loss, access to, use, alteration, correction, or disclosure of personal data.


XI. Personal Data Breach and Breach Notification Procedures:

Despite security measures, data breaches can occur. The PDPA requires prompt action in response to breaches.

A. Definition:

A personal data breach is defined as a breach of security measures resulting in the loss, access, use, alteration, modification, or disclosure of personal data without authorization or unlawfully.

B. Procedures:

Assess the reliability of the breach report and investigate the facts.

Notify the PDPC within 72 hours if the breach affects the rights and freedoms of data subjects.

Notify affected data subjects without delay if the breach poses a high risk.

Mitigate the situation and review security measures to prevent future breaches.


XII. Processing of Sensitive Personal Data by Data Processors:

Throughout the customer journey, a data processor may be involved in processes such as medicine delivery. A data controller must prepare a Data Processing Agreement (DPA) to control the activities of the data processor. Key provisions of a DPA include:

Restriction on use or disclosure of personal data.

Implementation of appropriate security measures.

Recording of personal data processing activities.

Notification of personal data breaches.


XIII. Designating a Representative and a Data Protection Officer (DPO) in Thailand:

A. Designating a Representative for Foreign Providers:

Foreign telemedicine providers offering services to Thai residents must designate a representative in Thailand under Section 5, Paragraph 2 of the PDPA.

B. Appointment of a Data Protection Officer (DPO):

Telemedicine platforms are obligated to designate a DPO if their core activities involve processing sensitive personal data. External or outsourced DPOs may be appointed for SMEs.


XIV. Use of Sensitive Personal Data (Health Information) for Telemarketing Purposes:

Sensitive personal data cannot be used for marketing purposes without explicit consent. Instead, telemedicine platforms may rely on general personal data (e.g., email addresses) for mass communications, provided an opt-out mechanism is available.


XV. Frequently Asked Questions (FAQs)

Q1: Does Weight and Height Qualify as Health Information?

Weight and height information may qualify as either general personal data or sensitive personal data, depending on the context. For example, in telemedicine services, weight and height may play a vital role in medical analysis and thus could be considered sensitive personal data.

Q2: Can a Patient Request Deletion of Their Health Information?

Patients have the right to request deletion of their personal data under certain conditions. However, telemedicine platforms are required to retain medical records for at least 5 years in accordance with the National Health Act.


XVI. Conclusion

As telemedicine continues to revolutionize the healthcare industry, ensuring robust compliance with data protection laws like the PDPA is critical. Health information, being sensitive personal data, demands the highest level of security and compliance to protect patient privacy and maintain trust in digital healthcare services.

For telemedicine platforms operating in Thailand, navigating the interplay between local regulations and international frameworks necessitates a meticulous approach to data processing. Failure to comply can lead to reputational damage, regulatory penalties, and legal liabilities. By adopting best practices such as transparent privacy policies, strong security measures, and compliance with data subject rights, telemedicine providers can create a safe and legally compliant environment.

In conclusion, the landscape of health information regulation is complex and continuously evolving. Telemedicine platform providers must proactively update their policies and compliance strategies to align with changing regulations, ensuring that patient rights remain protected while fostering innovation in digital healthcare solutions. By doing so, they can contribute to a more secure, efficient, and globally compliant telemedicine ecosystem.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Integrating Cybersecurity, Fraud Response, and PDPA Compliance: Practical Implications of the Proposed Digital Channel Security Framework

The Bank of Thailand (BOT) has released a proposed Digital Channel Security framework that would strengthen expectations for authentication, fraud prevention, incident response, and the governance of digital financial services. While the proposal focuses primarily on enhancing the security and resilience of digital channels, financial institutions should not view these requirements in isolation.

In practice, a single cybersecurity incident frequently triggers multiple legal and regulatory obligations simultaneously. For example, an account takeover resulting from a phishing attack may require an institution to activate its cybersecurity incident response procedures, implement fraud mitigation measures, assess whether a personal data breach has occurred under the Personal Data Protection Act (PDPA), evaluate outsourcing or third-party service provider involvement, and make appropriate internal and regulatory notifications.

Although these obligations arise from different legal and regulatory sources, organizations may benefit from managing them through a coordinated incident response framework. This article examines the practical implications of the proposed BOT framework alongside existing obligations under the PDPA and broader operational governance practices.

From cybersecurity to operational resilience:

The proposed framework reflects an increasing regulatory emphasis on operational resilience rather than viewing cybersecurity solely as an information technology function. It places greater focus on preventing, detecting, responding to, and recovering from threats affecting digital financial services while maintaining the continuity and integrity of critical operations.

At the same time, financial institutions should recognize that cybersecurity incidents rarely occur in isolation. A single event may involve operational disruption, attempted fraud, compromise of customer credentials, unauthorized disclosure of personal data, and third-party service providers. As a practical matter, organizations may therefore benefit from adopting governance arrangements capable of addressing these interconnected risks through a unified response process.

Governance beyond information technology:

The proposed framework emphasizes that responsibility for digital channel security extends beyond information security teams.

Boards of directors and senior management are expected to establish appropriate governance, oversee digital risks, allocate adequate resources, monitor security performance, and ensure that significant incidents are escalated appropriately.

From a broader governance perspective, institutions should also consider ensuring that legal, compliance, privacy, operational risk, business continuity, and customer service functions are integrated into incident management processes. This cross-functional approach can help organizations address multiple regulatory obligations efficiently when significant incidents occur.

Fraud prevention as part of digital channel security:

The BOT proposal places significant emphasis on fraud prevention through enhanced digital channel security. Proposed measures include stronger customer authentication, monitoring of suspicious activities, behavioral analysis, device identification, protection against phishing and social engineering attacks, and mechanisms for responding to suspicious transactions.

These expectations primarily seek to reduce fraud risks affecting digital financial services. However, successful fraud attacks frequently have wider legal implications. Unauthorized access to customer accounts may also involve compromised personal data, contractual issues with service providers, customer remediation, and regulatory reporting obligations. Institutions should therefore consider integrating fraud response procedures into broader cybersecurity governance rather than treating fraud management as a separate operational function.

Incident response across multiple regulatory frameworks:

The proposed framework expects institutions to establish formal incident response procedures covering detection, escalation, containment, investigation, recovery, and post-incident review.

In practice, these procedures should also enable organizations to identify other legal and regulatory obligations that may arise from the same incident. Depending on the circumstances, an incident may require parallel consideration of fraud management, operational resilience measures, contractual obligations, outsourcing arrangements, and personal data protection requirements.

Developing coordinated response procedures may help reduce duplication of effort, improve decision-making, and ensure that regulatory obligations are addressed consistently across different functions.

Interaction with the Personal Data Protection Act:

The proposed BOT framework does not replace or modify existing obligations under the PDPA. Rather, the two regimes operate alongside one another.

Where a cybersecurity incident involves unauthorized access to, disclosure of, alteration of, or loss of personal data, organizations should assess their obligations under the PDPA independently of the BOT framework. This may include determining whether a personal data breach has occurred, evaluating notification obligations, preserving relevant evidence, documenting response measures, and implementing appropriate remediation.

Accordingly, organizations may wish to ensure that privacy officers, legal counsel, and cybersecurity teams participate jointly in incident response planning and tabletop exercises so that both operational and data protection considerations are addressed from the outset.

Third-party risk management:

Digital financial services increasingly depend on cloud service providers, payment processors, managed service providers, software vendors, and other external partners.

The proposed framework reinforces expectations regarding oversight of third-party service providers throughout the outsourcing lifecycle. Institutions should conduct appropriate due diligence, establish contractual security requirements, monitor vendor performance, and ensure that incident reporting and business continuity arrangements are clearly defined.

Because cybersecurity incidents involving third parties may also raise fraud and personal data protection issues, organizations should consider aligning vendor management processes with their broader incident response and compliance frameworks.

Documentation and evidence of compliance:

The proposed framework places considerable emphasis on governance, accountability, and demonstrating that appropriate controls are in place.

Organizations should maintain comprehensive records of cybersecurity governance, risk assessments, incident response activities, testing, training, vendor oversight, and business continuity exercises. From a broader compliance perspective, documentation should also support obligations arising under other applicable legal frameworks, including the PDPA and contractual commitments relating to outsourced services.

Maintaining complete records may facilitate regulatory engagement, internal investigations, and post-incident reviews while demonstrating that reasonable organizational and technical measures have been implemented.

Practical considerations:

As organizations prepare for the proposed framework, they may wish to assess not only technical cybersecurity controls but also how different compliance functions interact during a significant incident.

Areas for review may include:

  • governance and board oversight;
  • coordination among cybersecurity, legal, compliance, privacy, and operational teams;
  • fraud detection and response procedures;
  • customer authentication controls;
  • third-party risk management;
  • incident reporting and escalation processes;
  • documentation and recordkeeping; and
  • operational resilience testing and tabletop exercises.

An integrated approach may improve organizational readiness while reducing the risk that separate regulatory obligations are managed through disconnected processes.

Key takeaways:

  • The proposed BOT Digital Channel Security framework primarily addresses digital channel security, fraud prevention, governance, and operational resilience.
  • Existing obligations under the PDPA continue to apply independently where cybersecurity incidents involve personal data.
  • A single cyber incident may simultaneously trigger cybersecurity, fraud management, personal data protection, outsourcing, and operational governance obligations.
  • Although these obligations arise under different legal and regulatory frameworks, organizations may benefit from managing them through an integrated incident response framework.
  • Financial institutions should consider reviewing governance structures, cross-functional coordination, and documentation practices to improve operational resilience and regulatory compliance.

Author: Panisa Suwanmatajarn, Managing Partner

Other Articles

Billing Software Requirements vs. Electronic Invoicing Requirements

Executive Summary:

As governments continue to digitalize tax administration, businesses are increasingly expected to adopt electronic invoicing solutions that comply with evolving regulatory requirements. Although the terms billing software and electronic invoicing are often used interchangeably, they represent distinct concepts that serve different commercial and legal functions.

In Thailand, billing software is not subject to a dedicated statutory or regulatory framework. Businesses are generally free to select accounting, billing, or enterprise resource planning (ERP) systems that best support their commercial operations, provided they comply with the Revenue Code and other applicable laws. Electronic invoicing, by contrast, is governed by the Revenue Department’s e-Tax Invoice & e-Receipt framework, which establishes the legal and technical requirements for issuing electronic tax invoices recognized for VAT purposes.

Understanding the distinction between these concepts is important for businesses implementing digital invoicing solutions. A billing system that efficiently generates commercial invoices does not necessarily satisfy the legal requirements for issuing electronic tax invoices. Businesses should therefore evaluate their invoicing systems not only from an operational perspective but also from a tax compliance standpoint.

Introduction:

Digital transformation has fundamentally changed the way businesses prepare invoices, maintain accounting records, and comply with tax obligations. Around the world, tax authorities have introduced electronic invoicing regimes to improve tax compliance, enhance transparency, and reduce administrative burdens for both taxpayers and regulators.

Although electronic invoicing has become an increasingly common feature of modern tax systems, countries have adopted different regulatory approaches. Some jurisdictions regulate the software used to generate invoices, while others focus on the legal validity and technical characteristics of the electronic tax documents themselves.

Thailand follows the latter approach. Rather than regulating billing software as a separate category of software, Thai law establishes a framework governing the issuance of electronic tax invoices through the Revenue Department’s e-Tax Invoice & e-Receipt system. Consequently, businesses remain free to use their preferred accounting or ERP software, provided that the electronic tax documents generated by those systems comply with the applicable legal and technical requirements.

For businesses operating in Thailand, particularly multinational enterprises implementing global ERP platforms, understanding the distinction between billing software and electronic invoicing is essential. While both are integral components of modern financial management, they perform different functions and are subject to different legal considerations.

Billing Software:

Billing software generally refers to applications used by businesses to prepare invoices, calculate taxes, record payments, manage customer accounts, and maintain accounting records. These functions support day-to-day commercial operations and are commonly integrated into accounting software or ERP systems.

Unlike some jurisdictions that regulate invoicing software, Thailand does not currently impose a dedicated legal or regulatory regime governing billing software itself. There is no statutory requirement for billing software to be licensed, certified, or approved by the Revenue Department before it can be used by businesses. Instead, Thai law focuses on the legal sufficiency of the invoices and accounting records generated by the software.

This does not mean that businesses have complete discretion in how billing systems are used. Regardless of the software selected, businesses remain responsible for ensuring that invoices comply with the Revenue Code, VAT is correctly calculated where applicable, accounting records are properly maintained, and supporting documentation is available for inspection by the tax authorities.

Accordingly, compliance under Thai law depends not on the software itself, but on whether the business uses that software in a manner that satisfies its statutory obligations. A business may therefore choose from a wide range of commercial accounting platforms, cloud-based invoicing applications, or ERP systems without obtaining prior approval from the Revenue Department.

Electronic Invoicing:

Electronic invoicing serves a different purpose. Rather than facilitating internal billing processes, it establishes the legal framework under which electronic tax invoices are recognized for VAT purposes.

Thailand’s electronic invoicing regime is principally governed by the Revenue Code, supplemented by the Electronic Transactions Act, Ministerial Regulation No. 384, and Revenue Department notifications prescribing the technical standards for electronic tax documents. Collectively, these instruments enable tax invoices and receipts to be created, transmitted, and retained electronically while ensuring their authenticity, integrity, and reliability.

Businesses wishing to issue electronic tax invoices under the Revenue Department’s e-Tax Invoice & e-Receipt framework must comply with prescribed legal and technical requirements. These include registration with the Revenue Department, generation of electronic tax documents in the prescribed format, use of appropriate electronic authentication mechanisms, transmission through approved channels where applicable, and maintenance of electronic records in accordance with the Revenue Department’s requirements.

An important characteristic of the Thai framework is that it regulates the electronic tax document rather than the accounting software used to produce it. Consequently, businesses may continue using their existing accounting or ERP systems, provided those systems are capable of generating electronic tax invoices that comply with the Revenue Department’s technical specifications. In practice, many businesses achieve this through system localization or integration with specialized e-Tax solutions or authorized service providers.

Thailand currently provides two principal electronic invoicing models. The e-Tax Invoice & e-Receipt system is designed for businesses requiring full electronic integration, while the e-Tax Invoice by Email system provides a simplified alternative for eligible businesses. Although both systems enable businesses to issue legally recognized electronic tax invoices, they differ in their technical implementation and authentication methods.

Key Takeaways:

  • Thailand does not regulate billing software as a separate legal category or require billing software to be certified or approved by the Revenue Department.
  • The Revenue Department’s e-Tax Invoice & e-Receipt framework governs the issuance of legally recognized electronic tax invoices and establishes the applicable technical and procedural requirements.
  • A commercial invoice generated by billing software does not automatically constitute an electronic tax invoice for VAT purposes.
  • Businesses implementing accounting or ERP systems should evaluate both operational functionality and compliance with Thailand’s e-Tax requirements.
  • Early coordination among finance, tax, legal, and information technology functions can help ensure a successful implementation of electronic invoicing while supporting long-term digital tax compliance.

Source: International Comparison July 2026: Global Legal Market Analysis

Read Full Article

Consumer Enforcement Intensifies for EV Businesses as Complaint Cases Rise and Labeling Expectations Increase

Thailand’s consumer protection regulator has signaled a more assertive enforcement approach toward the electric vehicle (EV) sector through two related developments. First, it has indicated its readiness to initiate legal proceedings on behalf of consumers in appropriate EV dispute cases. Second, it has issued new guidance consolidating labeling requirements for automobiles, electric vehicles, and used cars.

Although neither development introduces new legislation, together they demonstrate heightened regulatory scrutiny of the automotive industry and provide valuable insight into the regulator’s current enforcement priorities. Manufacturers, importers, distributors, dealers, service centers, and online vehicle marketplaces should treat these developments as an opportunity to reassess their compliance and dispute management frameworks.

Increased Enforcement Risk from EV Consumer Complaints:

The Office of the Consumer Protection Board (OCPB) has reported a significant number of consumer complaints relating to electric vehicles, with a substantial portion already progressing through legal procedures. The agency has confirmed that it has begun issuing formal demand letters in cases supported by sufficient documentation and has reiterated its statutory authority to commence legal proceedings on behalf of consumers where the legal requirements are satisfied.

This represents an important enforcement signal. Rather than merely facilitating mediation between consumers and businesses, the regulator has indicated its willingness to escalate suitable cases into formal litigation.

The risk is particularly significant where multiple complaints arise from the same product model, manufacturing issue, software defect, battery performance concern, warranty practice, or recurring after-sales service problem. A pattern of similar complaints may increase regulatory attention and expose businesses to coordinated enforcement actions, representative litigation, or broader product liability claims.

Businesses operating within the EV supply chain should therefore review whether existing complaint-handling mechanisms are capable of identifying systemic issues before they evolve into regulatory investigations or court proceedings.

Strengthened Expectations for Vehicle Label Compliance:

Separately, the OCPB has published an electronic handbook consolidating labeling requirements applicable to automobiles, electric vehicles, and used vehicles.

The publication emphasizes information that consumers commonly rely upon when making purchasing decisions, including battery specifications, driving range, testing standards, pricing information, warranty coverage, and the disclosure of material vehicle history for used vehicles.

Although the handbook itself is not legally binding, it provides a clear indication of the regulator’s compliance expectations. It reinforces that automobiles and electric vehicles remain controlled labeling products under consumer protection law and that incomplete, inaccurate, or misleading information may expose businesses to regulatory enforcement.

The guidance also illustrates that compliance extends beyond physical labels. Regulators are increasingly likely to examine whether information presented across all customer-facing channels remains accurate and consistent.

Businesses should therefore review:

  • labels displayed at dealerships and points of sale;
  • information published on corporate websites and online marketplaces;
  • brochures and sales presentations used by sales personnel;
  • representations concerning driving range and the testing methodology used, such as WLTP or NEDC;
  • battery capacity, expected degradation, warranty scope, and warranty exclusions;
  • disclosures relating to collision history, flood damage, major repairs, and battery replacement for used vehicles; and
  • consistency between information published by manufacturers, importers, dealers, and affiliated sales channels.

Claims relating to vehicle performance, battery longevity, operating costs, sustainability, resale value, or environmental benefits should be supported by appropriate technical evidence and internal documentation before publication.

Litigation Readiness and Document Preservation:

These developments also highlight the importance of litigation preparedness.

Businesses should consider establishing a centralized process for collecting and analyzing customer complaints to determine whether recurring issues indicate broader product or service risks.

At the same time, organizations should preserve relevant evidence, including:

  • sales documentation;
  • warranty records;
  • repair histories;
  • technical diagnostic reports;
  • replacement part records;
  • communications with customers;
  • call center recordings;
  • email correspondence;
  • mobile application records; and
  • connected vehicle diagnostic data.

Where disputes may reasonably be anticipated, organizations should consider implementing litigation hold procedures to reduce the risk of inadvertent deletion of potentially relevant evidence.

Companies should also review contractual risk allocation among overseas manufacturers, importers, dealers, distributors, and service centers, including indemnity provisions and responsibilities for handling product defects, recalls, warranty claims, and consumer litigation.

Data Protection Considerations:

Responding to consumer complaints frequently requires the collection and sharing of customer information, vehicle service histories, location information, and connected vehicle diagnostic data. Much of this information may constitute personal data under the Personal Data Protection Act.

Organizations should ensure that internal investigations and litigation response procedures incorporate appropriate data governance measures, including clearly defined access controls, documented processing purposes, retention periods, and secure mechanisms for sharing information with external counsel, technical experts, and other authorized parties.

Integrating consumer protection compliance with data governance can reduce both regulatory and litigation risks while supporting more effective dispute management.

Key Takeaways:

  • Organizations should strengthen complaint management, evidence preservation, document retention, contractual risk allocation, and data governance processes to prepare for increased regulatory scrutiny and potential consumer litigation.
  • The OCPB’s indication that it is prepared to commence litigation on behalf of consumers represents a significant escalation in consumer protection enforcement affecting the EV industry.
  • Businesses should not view repeated consumer complaints as isolated customer service matters but as potential regulatory and litigation risks requiring centralized oversight.
  • The newly published vehicle labeling handbook, although not legally binding, demonstrates higher regulatory expectations regarding the accuracy, completeness, and consistency of vehicle-related information across all sales channels.
  • Automotive businesses should review advertising claims, warranty disclosures, battery-related representations, and used vehicle disclosures to ensure they are fully substantiated.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Revises Visa Exemption Scheme: Shorter Stay Periods and a New Country-Based Category System

Introduction

On 14 July 2026, the Thai Cabinet approved a revision of Thailand’s visa exemption scheme. Under the revised framework, the current uniform 60-day visa exemption will be abolished and replaced with a country-based system that classifies eligible countries according to Thailand’s diplomatic relations and immigration risk assessment. Depending on the category assigned, eligible foreign nationals will be permitted to enter Thailand visa-free for stays of up to 30 or 15 days, or will remain eligible for a Visa on Arrival.

Background

In 2024, Thailand introduced a 60-day visa exemption for nationals of 93 countries and territories to stimulate tourism and support the country’s economic recovery following the COVID-19 pandemic. Since implementation, however, the government has identified several concerns associated with the scheme, including visa runs, illegal employment, nominee business arrangements, transnational crime, and visa overstays. In response, the government resolved to review and revise the existing visa exemption policy.

Key Changes

1. Introduction of a Tiered Visa Exemption Framework

30-Day Visa Exemption (59 Countries and Territories)

Nationals of 59 countries and territories will be eligible for visa-free entry for tourism purposes for stays of up to 30 days. The revised scheme extends this 30-day entitlement to six countries that were not previously covered:

  • India
  • Croatia
  • Bulgaria
  • Cyprus
  • Malta
  • Maldives

With these additions, all 27 European Union Member States will receive the same 30-day visa exemption entitlement, promoting greater consistency across Thailand’s visa policy. The government expects this measure to strengthen diplomatic relations, support future discussions on Schengen visa exemptions for Thai nationals, and facilitate continued economic and trade cooperation with partner countries.

15-Day Visa Exemption (2 Countries)                                                                                                                                                                            

Nationals of Mauritius and Seychelles will be eligible for visa-free entry for stays of up to 15 days. The government intends to periodically review this entitlement based on tourism statistics and visitor spending patterns.

Visa on Arrival (3 Countries)

Nationals of the following three countries will remain eligible to obtain a Visa on Arrival at Thailand’s immigration checkpoints:

  • Azerbaijan
  • Belarus
  • Serbia

2. Implementation of the “One Country, One Entitlement” Policy

Under the revised framework, each country will be eligible for only one immigration privilege, and overlapping schemes will be eliminated. For example, India will no longer be eligible for a Visa on Arrival, as it has instead been granted 30-day visa exemption status.

3. Enhanced Border Screening

The government will strengthen the Thailand Digital Arrival Card (TDAC) system by integrating it with relevant government databases, improving immigration risk assessment, border screening, and monitoring of visa exemption usage.

The Cabinet resolution provides for a revised visa framework covering a reported total of 65 countries and territories across the categories described above. The complete list of eligible countries and territories in each category has not yet been officially published; further detail is expected in forthcoming Ministry of Interior notifications and related subordinate legislation.

Effective Date

The revised measures have not yet entered into force. They will take effect 15 days after the relevant Ministry of Interior notifications are published in the Royal Gazette. Until that time, the existing immigration rules remain in effect, and foreign nationals who enter Thailand before the change takes effect will be permitted to remain for the duration of their existing permitted stay.

Key Takeaways

  • The revised measures are pending implementation and will take effect 15 days after publication in the Royal Gazette.
  • Thailand will replace its uniform 60-day visa exemption scheme with a tiered, country-based system.
  • The revised scheme aims to balance tourism promotion and ease of international travel against the prevention of visa abuse and the strengthening of immigration control and national security.
  • Eligible countries will receive 30-day or 15-day visa-free entry, while three countries retain Visa on Arrival status; overlapping privileges are removed under the “one country, one entitlement” policy.
  • The TDAC system will be enhanced to strengthen immigration screening and monitoring.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand signals a shift toward expenditure-based management of universal healthcare

Thailand’s universal healthcare system has long been regarded as one of the country’s most successful public policy achievements. However, increasing healthcare utilization, an aging population, rising treatment costs, and fiscal constraints are prompting policymakers to reconsider how the system should be financed over the long term.

Recent policy discussions within the Ministry of Public Health indicate that the focus is no longer solely on expanding healthcare benefits. Instead, the government appears to be moving toward a framework that emphasizes expenditure management, efficiency, and value-based healthcare while maintaining universal access to essential medical services.

Shift from expanding benefits to managing sustainability:

Thailand’s public healthcare system is primarily delivered through three government-funded schemes:

  • the Universal Coverage Scheme (UCS);
  • the Social Security Scheme (SSS); and
  • the Civil Servant Medical Benefit Scheme (CSMBS).

Although annual government appropriations for these schemes have continued to increase, healthcare expenditure has grown at an even faster pace due to demographic changes, increasing prevalence of chronic diseases, advances in medical technology, and greater public expectations regarding access to treatment. Policymakers have therefore expressed concern that healthcare expenditure may outpace long-term fiscal capacity unless structural reforms are implemented.

Proposed expenditure management measures:

Current policy discussions suggest that future reforms may include greater reliance on expenditure controls rather than across-the-board budget increases.

Measures under consideration reportedly include:

  • expenditure ceilings for public hospitals;
  • tighter monitoring of hospital operating costs, pharmaceuticals, and medical supplies;
  • wider use of digital technologies and data analytics to improve financial oversight;
  • periodic review of healthcare benefit packages to prioritize clinically effective and cost-effective services; and
  • broader adoption of value-based healthcare models that reward providers based on patient outcomes rather than service volume.

These initiatives reflect an effort to improve efficiency without fundamentally changing the principle of universal healthcare coverage.

Potential implications for healthcare providers:

Public hospitals may face increasing pressure to operate within fixed budgetary allocations while maintaining service quality. More sophisticated financial management, procurement practices, and clinical governance are therefore likely to become increasingly important.

Healthcare providers may also experience:

  • greater scrutiny of prescribing practices;
  • stronger emphasis on evidence-based treatment pathways;
  • expanded use of health technology assessment in reimbursement decisions; and
  • increased reporting and compliance obligations relating to cost management.

Private healthcare providers participating in government reimbursement programs may likewise experience closer oversight of reimbursement methodologies and service delivery standards.

Regulatory considerations:

While no legislative amendments have fundamentally altered Thailand’s universal healthcare framework, any future implementation of expenditure caps or revised reimbursement mechanisms will require careful alignment with existing legislation governing public health financing and healthcare entitlements.

Future regulatory developments may include:

  • revised payment methodologies;
  • updated reimbursement criteria;
  • enhanced procurement controls;
  • expanded digital monitoring of healthcare expenditure; and
  • revised administrative guidelines governing public healthcare providers.

Businesses operating in the healthcare, pharmaceutical, medical device, and digital health sectors should therefore continue to monitor policy developments, as changes in reimbursement and procurement practices may influence market access and commercial strategies.

Key takeaways:

  • Thailand is shifting its healthcare policy emphasis from expanding benefits toward improving financial sustainability.
  • Expenditure management and value-based healthcare are emerging as central policy themes.
  • Public hospitals are likely to face tighter budgetary controls and enhanced financial oversight.
  • Healthcare suppliers should anticipate increasing scrutiny of reimbursement, procurement, and cost-effectiveness.
  • Although universal healthcare remains intact, future reforms are expected to focus on preserving the system through more disciplined allocation of healthcare resources rather than unlimited expenditure growth.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

New Apostille Rules Simplify Thailand Working and Retirement Visa Renewal Documents Requirement

The Immigration Bureau has issued Immigration Bureau Order No. 122/2026 (the “Order”), amending certain documentary requirements under Immigration Bureau Order No. 12/2025 for applications for renewal of visa. The Order came into effect on 28 May 2026.

Previously, where certain prescribed documents were unavailable, applicants were generally required to authenticate them through notarization by a notary public, legalization by a Royal Thai Embassy or Royal Thai Consulate-General, and super-legalization by Thailand’s Ministry of Foreign Affairs. The new Order introduces Apostille certification as an alternative method of authentication for specified documents.

Key Amendments

The amendments primarily benefit foreign nationals applying for the renewal of Non-Immigrant “B” (Business) and Non-Immigrant “O-A” (Retirement) categories. In particular, the changes are expected to benefit foreign nationals working for foreign companies operating in Thailand through their representative offices, regional offices, and branch offices set up in Thailand requiring renewal of their visa, for which the affidavits or certificates of incorporation relating to those offices are required to be submitted. The amendment also benefits foreign retirees required to submit health insurance documents or evidence of state welfare benefits issued or granted overseas.

Previously, such documents were generally required to be certified by the issuing authority and/or notarized, followed by legalization by a Royal Thai Embassy or Royal Thai Consulate-General and super-legalization by Thailand’s Ministry of Foreign Affairs. The amendment streamlines this process by reducing the number of authentication steps required for eligible documents.

The amendments also address practical difficulties faced by representative offices, regional offices, and branch offices of foreign companies in obtaining certain corporate registration documents. In practice, the Department of Business Development (DBD) may not issue particular certificates in certain circumstances The revised requirements therefore provide greater flexibility where equivalent DBD-issued documents are unavailable.

Conclusion

The Order represents a practical modernization of Thailand’s immigration procedures by introducing Apostille certification as an alternative method of authenticating documents for certain business and retirement-based applications.

Although the amendments do not alter the substantive eligibility requirements of renewal of visa, they simplify documentary compliance, reduce reliance on multiple layers of consular legalization, and offer practical solutions for foreign business entities that may encounter difficulties obtaining certain certifications in Thailand. Overall, the changes are expected to make the immigration process more efficient for both foreign businesses and foreign retirees.

Key Takeaways

The changes reflect Thailand’s continuing movement toward

Apostille certification is now recognized as an alternative to traditional embassy legalization for certain business and retirement-based extension of stay applications.

The amendments simplify document authentication and reduce administrative burdens for eligible applicants.

Foreign nationals working with representative offices, regional offices, and branch offices in Thailand may benefit from greater flexibility where equivalent DBD-issued certifications are unavailable.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Billing Software and Electronic Invoicing: Understanding Thailand’s Digital Tax Compliance Framework

Executive Summary:

As governments continue to digitalize tax administration, businesses are increasingly expected to adopt electronic invoicing solutions that comply with evolving regulatory requirements. Although the terms billing software and electronic invoicing are often used interchangeably, they represent distinct concepts that serve different commercial and legal functions.

In Thailand, billing software is not subject to a dedicated statutory or regulatory framework. Businesses are generally free to select accounting, billing, or enterprise resource planning (ERP) systems that best support their commercial operations, provided they comply with the Revenue Code and other applicable laws. Electronic invoicing, by contrast, is governed by the Revenue Department’s e-Tax Invoice & e-Receipt framework, which establishes the legal and technical requirements for issuing electronic tax invoices recognized for VAT purposes.

Understanding the distinction between these concepts is important for businesses implementing digital invoicing solutions. A billing system that efficiently generates commercial invoices does not necessarily satisfy the legal requirements for issuing electronic tax invoices. Businesses should therefore evaluate their invoicing systems not only from an operational perspective but also from a tax compliance standpoint.

Introduction:

Digital transformation has fundamentally changed the way businesses prepare invoices, maintain accounting records, and comply with tax obligations. Around the world, tax authorities have introduced electronic invoicing regimes to improve tax compliance, enhance transparency, and reduce administrative burdens for both taxpayers and regulators.

Although electronic invoicing has become an increasingly common feature of modern tax systems, countries have adopted different regulatory approaches. Some jurisdictions regulate the software used to generate invoices, while others focus on the legal validity and technical characteristics of the electronic tax documents themselves.

Thailand follows the latter approach. Rather than regulating billing software as a separate category of software, Thai law establishes a framework governing the issuance of electronic tax invoices through the Revenue Department’s e-Tax Invoice & e-Receipt system. Consequently, businesses remain free to use their preferred accounting or ERP software, provided that the electronic tax documents generated by those systems comply with the applicable legal and technical requirements.

For businesses operating in Thailand, particularly multinational enterprises implementing global ERP platforms, understanding the distinction between billing software and electronic invoicing is essential. While both are integral components of modern financial management, they perform different functions and are subject to different legal considerations.

Billing Software:

Billing software generally refers to applications used by businesses to prepare invoices, calculate taxes, record payments, manage customer accounts, and maintain accounting records. These functions support day-to-day commercial operations and are commonly integrated into accounting software or ERP systems.

Unlike some jurisdictions that regulate invoicing software, Thailand does not currently impose a dedicated legal or regulatory regime governing billing software itself. There is no statutory requirement for billing software to be licensed, certified, or approved by the Revenue Department before it can be used by businesses. Instead, Thai law focuses on the legal sufficiency of the invoices and accounting records generated by the software.

This does not mean that businesses have complete discretion in how billing systems are used. Regardless of the software selected, businesses remain responsible for ensuring that invoices comply with the Revenue Code, VAT is correctly calculated where applicable, accounting records are properly maintained, and supporting documentation is available for inspection by the tax authorities.

Accordingly, compliance under Thai law depends not on the software itself, but on whether the business uses that software in a manner that satisfies its statutory obligations. A business may therefore choose from a wide range of commercial accounting platforms, cloud-based invoicing applications, or ERP systems without obtaining prior approval from the Revenue Department.

Electronic Invoicing:

Electronic invoicing serves a different purpose. Rather than facilitating internal billing processes, it establishes the legal framework under which electronic tax invoices are recognized for VAT purposes.

Thailand’s electronic invoicing regime is principally governed by the Revenue Code, supplemented by the Electronic Transactions Act, Ministerial Regulation No. 384, and Revenue Department notifications prescribing the technical standards for electronic tax documents. Collectively, these instruments enable tax invoices and receipts to be created, transmitted, and retained electronically while ensuring their authenticity, integrity, and reliability.

Businesses wishing to issue electronic tax invoices under the Revenue Department’s e-Tax Invoice & e-Receipt framework must comply with prescribed legal and technical requirements. These include registration with the Revenue Department, generation of electronic tax documents in the prescribed format, use of appropriate electronic authentication mechanisms, transmission through approved channels where applicable, and maintenance of electronic records in accordance with the Revenue Department’s requirements.

An important characteristic of the Thai framework is that it regulates the electronic tax document rather than the accounting software used to produce it. Consequently, businesses may continue using their existing accounting or ERP systems, provided those systems are capable of generating electronic tax invoices that comply with the Revenue Department’s technical specifications. In practice, many businesses achieve this through system localization or integration with specialized e-Tax solutions or authorized service providers.

Thailand currently provides two principal electronic invoicing models. The e-Tax Invoice & e-Receipt system is designed for businesses requiring full electronic integration, while the e-Tax Invoice by Email system provides a simplified alternative for eligible businesses. Although both systems enable businesses to issue legally recognized electronic tax invoices, they differ in their technical implementation and authentication methods.

Key Takeaways:

  • Thailand does not regulate billing software as a separate legal category or require billing software to be certified or approved by the Revenue Department.
  • The Revenue Department’s e-Tax Invoice & e-Receipt framework governs the issuance of legally recognized electronic tax invoices and establishes the applicable technical and procedural requirements.
  • A commercial invoice generated by billing software does not automatically constitute an electronic tax invoice for VAT purposes.
  • Businesses implementing accounting or ERP systems should evaluate both operational functionality and compliance with Thailand’s e-Tax requirements.
  • Early coordination among finance, tax, legal, and information technology functions can help ensure a successful implementation of electronic invoicing while supporting long-term digital tax compliance.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

ETDA’s Proposed AI Sandbox Signals a New Phase of AI Governance

The Electronic Transactions Development Agency (ETDA) has opened a public consultation on a draft notification establishing an Artificial Intelligence (AI) Sandbox. Although the notification has not yet been adopted, it represents one of the clearest regulatory signals that Thailand is moving toward a structured governance framework for AI systems through a controlled testing environment.

For businesses developing or deploying AI solutions, the proposed AI Sandbox is more than a pilot initiative. It is likely to establish regulatory expectations that may influence future AI compliance standards across multiple sectors.

Why the AI Sandbox matters                                              

Regulatory sandboxes have long been used in the financial sector to facilitate innovation while allowing regulators to observe risks under controlled conditions. The proposed AI Sandbox extends this concept to AI technologies by providing an environment where AI systems can be tested before wider deployment.

Unlike traditional compliance regimes that focus primarily on post-deployment enforcement, an AI Sandbox emphasizes governance during the development and testing stages. This reflects an international regulatory trend toward proactive AI risk management.

Although participation in the Sandbox may initially be voluntary, organizations should not view it merely as an experimental program. Regulatory sandboxes frequently become the foundation for future best practices and may ultimately shape industry standards and supervisory expectations.

A shift toward risk-based AI governance

While the draft notification remains subject to consultation, it suggests that AI governance in Thailand is moving toward a risk-based model.

Businesses should expect greater emphasis on governance measures such as:

  • AI risk identification and assessment;
  • testing and validation before deployment;
  • documentation of AI models, datasets, and development processes;
  • human oversight over significant AI-assisted decisions;
  • ongoing monitoring throughout the AI lifecycle; and
  • governance mechanisms for accountability and incident management.

These principles are broadly consistent with international AI governance developments and demonstrate a growing expectation that organizations should be able to explain not only what an AI system does, but also how risks have been identified and managed.

Implications for businesses

The proposed framework has implications across numerous industries, particularly where AI systems influence commercial or operational decision-making.

  • Technology companies and SaaS providers
  • Software developers offering AI-enabled products may need to implement more formal governance processes throughout the product lifecycle. Technical documentation, testing records, model validation, and change management procedures could become increasingly important in demonstrating responsible AI practices.
  • Organizations that currently rely on informal development processes may eventually need governance structures comparable to those already used for cybersecurity and information security compliance.
  • Financial services and fintech
  • Financial institutions already operate within a highly regulated environment. AI governance requirements may become an additional layer of compliance where AI is used for credit scoring, fraud detection, investment services, customer onboarding, or automated decision-making.
  • Existing risk management frameworks may therefore need to expand to include AI-specific controls.
  • Healthcare and health technology
  • Healthcare providers and health technology companies using AI for diagnostics, treatment recommendations, clinical decision support, or patient management are likely to face heightened expectations regarding accuracy, validation, human supervision, and patient safety.
  • Testing within a controlled environment could become an important mechanism for demonstrating reliability before deployment.
  • HR technology
  • Organizations using AI in recruitment, employee evaluation, workforce management, or performance assessment should anticipate closer scrutiny of automated decision-making processes.
  • Transparent governance, human review, and measures to reduce discriminatory outcomes are likely to become increasingly significant compliance considerations.
  • Digital platforms
  • Platform operators deploying generative AI, recommendation algorithms, content moderation systems, or AI-powered customer services may also need stronger governance over system performance, monitoring, and accountability.
  • The ability to document how AI systems operate and respond to identified risks may become an important aspect of regulatory compliance.

Interaction with existing legal frameworks

Although the AI Sandbox is intended to facilitate innovation, participation is unlikely to exempt organizations from existing legal obligations.

Organizations testing AI systems would still be expected to comply with applicable laws, including those governing:

  • personal data protection under the Personal Data Protection Act;
  • electronic transactions;
  • cybersecurity obligations;
  • consumer protection;
  • intellectual property rights; and
  • sector-specific regulatory requirements.

For example, organizations using personal data for AI model training or testing should ensure that appropriate legal bases, transparency obligations, data security measures, and data subject rights continue to be observed.

Similarly, businesses developing generative AI applications should continue to assess potential intellectual property risks relating to training data, generated outputs, and ownership of AI-assisted content.

Preparing for future regulatory expectations

Although the draft notification has not yet entered into force, organizations should consider using the consultation period to evaluate their existing AI governance practices.

Practical steps may include:

  • identifying AI systems currently in operation;
  • classifying AI use cases according to potential risk;
  • documenting AI development and deployment processes;
  • establishing internal AI governance policies;
  • implementing human oversight for significant AI-assisted decisions;
  • reviewing contractual allocation of AI-related responsibilities with vendors and customers; and
  • ensuring that AI governance aligns with existing data protection and cybersecurity compliance programs.

Organizations that begin implementing these governance measures now are likely to be better positioned if the AI Sandbox becomes operational and if similar requirements are incorporated into future regulatory frameworks.

Looking ahead

The draft AI Sandbox notification demonstrates that Thai regulators are moving beyond high-level discussions about artificial intelligence and toward practical governance mechanisms.

Even if participation remains voluntary during its initial stages, the Sandbox is likely to influence regulatory expectations regarding responsible AI development and deployment. Businesses should therefore view the proposal not simply as a testing initiative, but as an indication of the governance standards that may shape future AI regulation.

Key takeaways

Businesses that prepare early are likely to be better positioned as AI governance requirements continue to evolve.

The proposed AI Sandbox represents a significant step toward a structured AI governance framework.

The initiative reflects a broader shift toward risk-based regulation and responsible AI development.

Organizations developing or deploying AI should begin strengthening governance, documentation, testing, and oversight processes.

Existing obligations under data protection, cybersecurity, consumer protection, and intellectual property laws will continue to apply during AI development and testing.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Super License Reform Moves to Final Stage Before Becoming Law

In our previous article, “Super License: The Draft Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public,” we discussed the proposed overhaul of the administrative licensing regime and its potential to fundamentally modernize public services and regulatory approvals.

Super License: The Draft Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public – The Legal Co., Ltd.

The legislative process has now reached a significant milestone. The Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public B.E. 2569 has been approved by Parliament and is currently awaiting publication in the Government Gazette before coming into force. Once effective, the new legislation will repeal the Facilitation of Licensing by Government Agencies Act B.E. 2558 (2015) and introduce a substantially broader and more integrated framework for government licensing and public services.

A Shift from Licensing Control to Public Service Facilitation:

The new legislation reflects a significant policy shift in the administration of regulatory approvals. Rather than focusing solely on licensing procedures, it establishes a broader framework designed to improve the overall delivery of government services by emphasizing efficiency, transparency, digital integration, and reduced administrative burdens.

The scope of the law extends beyond traditional licensing procedures to cover registrations, notifications, approvals, and various public services provided by government agencies. This broader application aims to establish consistent administrative standards across the public sector while making interactions with government agencies more predictable and user-friendly.

Greater Transparency Through Mandatory Public Handbooks:

One of the most significant reforms is the enhanced requirement for government agencies to prepare comprehensive public handbooks.

These handbooks must clearly specify:

  • application procedures;
  • required documents;
  • statutory processing periods;
  • applicable fees;
  • approval criteria;
  • conditions imposed on applicants; and
  • written guidelines governing the exercise of official discretion.

Requiring agencies to disclose how discretion will be exercised represents an important development. It is intended to reduce inconsistent decision-making, improve legal certainty, and minimize opportunities for arbitrary administrative actions.

Digital Government and “Once-Only” Documentation:

The legislation further advances the government’s digital transformation policy by requiring agencies to utilize electronic information already available within government systems.

Where government agencies already possess information through interconnected databases, applicants generally should not be required to submit the same documents repeatedly. This “once-only” principle is expected to reduce paperwork significantly and improve the overall efficiency of administrative procedures.

The legislation also supports greater use of electronic application systems and centralized digital service platforms.

The Super License Mechanism:

Perhaps the most anticipated feature is the introduction of the Super License mechanism.

For business activities designated by the Cabinet, applicants will be able to obtain a principal license that automatically covers related subsidiary approvals normally issued by multiple government agencies. Instead of pursuing numerous sequential approvals, businesses will be able to complete much of the licensing process through a single application.

Although the categories of businesses eligible for the Super License mechanism will be determined through subsequent implementing measures, the reform is expected to benefit sectors that traditionally require multiple regulatory approvals, including manufacturing, hospitality, energy, and certain service industries.

The practical effectiveness of this mechanism will ultimately depend upon the implementing regulations and the level of coordination among participating agencies.

Faster Licensing Procedures:

The legislation introduces several measures intended to shorten administrative timelines.

Government agencies will be required to review applications promptly upon receipt, notify applicants immediately if documents are incomplete, and adhere to published processing periods. Where delays become unavoidable, agencies must notify applicants and explain the reasons for any extension.

In addition, the legislation provides for:

  • centralized application centers;
  • electronic submission and tracking systems;
  • expedited processing channels for eligible matters;
  • simplified renewal procedures for certain licenses; and
  • multilingual services where appropriate.

Collectively, these measures are designed to reduce procedural uncertainty while improving the overall applicant experience.

Deemed Approval for Certain Applications:

One of the most closely watched reforms is the introduction of a form of deemed approval.

For specified categories of lower-risk activities, where the responsible agency fails to complete consideration within the prescribed timeframe and does not properly extend the review period, the application may be treated as approved by operation of law.

This mechanism is intended to encourage administrative efficiency while providing greater certainty for businesses. However, it is not expected to apply universally, particularly where public safety, environmental protection, national security, or other significant public interests require substantive regulatory review.

Provisional Operations for Low-Risk Activities:

The legislation also introduces mechanisms allowing certain low-risk businesses to commence operations through notification or registration before obtaining full approval.

This represents a notable departure from the traditional approach, under which businesses generally must wait until all approvals have been formally issued before commencing operations. The reform seeks to facilitate earlier economic activity while maintaining appropriate regulatory oversight.

Increased Accountability for Government Agencies:

The legislation imposes stronger obligations on public officials responsible for licensing and service delivery.

Failure to comply with statutory procedures—such as requesting unnecessary documents, failing to meet prescribed timelines without justification, or otherwise violating procedural requirements—may constitute disciplinary misconduct.

These accountability measures reinforce the legislation’s broader objective of improving public confidence in administrative decision-making.

What Businesses Should Do Next:

Although the legislation has completed the parliamentary process, businesses should recognize that it will not become effective until publication in the Government Gazette.

In the meantime, companies that regularly interact with licensing authorities should begin assessing how the new framework may affect their operations. Particular attention should be paid to businesses that currently require approvals from multiple agencies, as they may eventually benefit from the Super License mechanism once implementing regulations identify eligible sectors.

Businesses should also monitor forthcoming subordinate legislation, ministerial regulations, and administrative guidelines, which will determine many of the practical details governing implementation.

Key Takeaways:

  • Businesses should begin reviewing their regulatory compliance strategies and monitor the issuance of subordinate legislation that will govern implementation of the new regime.
  • Parliament has approved the new Act, which is now awaiting publication in the Government Gazette before becoming effective.
  • The legislation replaces the existing licensing facilitation framework with a broader law covering licensing, registrations, notifications, approvals, and public services.
  • The new framework emphasizes transparency, digital government, reduced administrative burdens, and standardized procedures.
  • The Super License mechanism has the potential to significantly simplify regulatory approvals for businesses requiring multiple licenses, although further implementing regulations will determine its practical scope.

Author: Panisa Suwanmatajarn, Managing Partner.

Related Articles: Super License: The Draft Act on Facilitation in the Consideration of Licenses and Provision of Services to the Public – The Legal Co., Ltd.

Other Articles