In an effort to curb cybercrime and enhance investor protection, Thailand’s Securities and Exchange Commission (SEC) has introduced significant amendments to two key pieces of legislation – the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018) (the “Digital Asset Business Law”) and the Emergency Decree on Measures for the Prevention and Suppression of Cybercrime B.E. 2566 (2023) (the “Cybercrime Law”). The primary features of these pieces of regulation include Thai regulators’ oversight on foreign crypto operators as well as their expanded enforcement powers.
These amendments, now in effect following their publication in the Royal Gazette, aim to strengthen Thailand’s regulatory framework around digital asset activities, particularly those conducted by foreign entities targeting Thai users.
Thailand’s Regulatory Scope Now Includes Foreign Crypto Operators
A central feature of the amended Digital Asset Business Law is the broadened definition of what constitutes providing services in Thailand. Under the new Section 26/1, foreign digital asset business operators are considered to be operating within the Kingdom if any of the following conditions apply:
- Their platform displays content, wholly or partially, in the Thai language.
- They operate under a Thai domain name (e.g., “.th”, “.ไทย”) or any domain referencing Thailand.
- They accept payments in Thai baht or through local bank, e-wallet accounts, or other infrastructure.
- They specify Thai law as the governing law or designate Thai courts for dispute resolution.
- They pay search engines to target Thai users specifically.
- They maintain a local office, agency, or personnel supporting users in Thailand.
- They fall under any additional criteria prescribed by the SEC.
Through these expanded parameters, regulators aim to ensure clarity among all digital asset platforms and place foreign operators within the scope of Thai law if they actively engage Thai users, regardless of where their operations are based.
Expanded Enforcement and Blocking Measures
Supplementing the Digital Asset Business Law, the Cybercrime Law has also been updated to authorize the Ministry of Digital Economy and Society (MDES) to swiftly block access to unlicensed digital asset platforms that solicit Thai users. This streamlined process is expected to reduce regulatory delays in responding to illegal or harmful activities linked to scam call centers, fraud, or crypto-based schemes.
Regulators are now also permitted to take legal action against individuals who knowingly permit their digital asset accounts to be used as “mule accounts” for illicit transactions. Penalties for such offenses include imprisonment of up to three years, fines of up to THB 300,000, or both. The central focus behind this is to prevent the misuse of foreign digital asset exchanges as conduits for money laundering.
Complementing this, the SEC has also introduced comprehensive measures to combat the rise of digital asset mule account wallets used to facilitate cybercrimes and financial fraud. The updated regulations will now require licensed digital asset business operators to implement security measures comparable to those used in the banking sector, including:
- Screening and suspending suspicious transactions or accounts.
- Establishing a blacklist of individuals or wallet addresses linked to cybercrimes.
- Enforcing refund mechanisms to expedite compensation to fraud victims.
- Sharing information with relevant government agencies to facilitate investigations.
Furthermore, digital asset operators may be held jointly liable-alongside banks, telecom companies, and social media platforms for damages caused by cybercrimes if they fail to comply with regulatory standards.
Foreign Crypto Operators Need to Comply
Given the regulatory changes, digital asset platforms that engage with Thai users must take active steps to assess whether their operations fall within the regulatory scope defined by the SEC. Factors such as local language content, payment channels in Thai baht, Thai legal references, and targeted marketing can all trigger compliance obligations under Thai law.
To avoid potential penalties, reputational damage, or service disruption, it is strongly recommended for digital asset businesses to review their platforms and user acquisition strategies. Those intending to serve users in Thailand must seek appropriate licenses and implement the necessary risk and compliance frameworks.
Disclaimer: This article is intended solely for informational purposes and does not constitute legal advice. As digital asset regulations continue to evolve in Thailand, we recommend consulting legal professionals for specific guidance on digital asset activities in Thailand. For further assistance, please contact Silk Legal at [email protected].
