Emergency Decree on the Prevention and Suppression of Technological Crimes (No. 2), B.E. 2568 (2025)
Thailand has significantly tightened its regulatory regime for cybercrime prevention with the enactment of the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes (No. 2), B.E. 2568 (2025). Published in the Royal Gazette on 1 August 2025, the decree marks a pivotal shift in the country’s approach to digital fraud, personal data protection, and platform accountability—particularly for financial service providers, telecom operators, digital platforms, and social media companies.
This new legal framework introduces a multi-faceted set of obligations for both domestic and foreign business operators, strengthens enforcement powers for government agencies, and reinforces victims’ rights to restitution. Its extraterritorial effect will be of particular interest to foreign digital asset platforms and fintech firms targeting Thai consumers.
Expanded Scope and Covered Entities
The decree applies to a wide range of entities, including banks, payment service providers, digital asset businesses, telecommunications operators, and social media platforms. Notably, its jurisdiction extends to foreign platforms that serve users in Thailand—whether through local agents, Thai-language interfaces, acceptance of Thai baht, or use of .th domains. As such, even companies without a physical presence in Thailand may fall within the scope of enforcement if they engage Thai users.
Mandatory Data Disclosure and Transaction Monitoring
One of the central features of the decree is the requirement for regulated businesses to transmit customer and transaction data to a centralized government platform in cases involving suspected cybercrime. This applies to financial institutions, payment service providers, and digital asset platforms, among others.
In tandem, businesses are expected to invest in real-time fraud detection infrastructure and ensure internal systems are capable of flagging and blocking suspicious transactions. Non-compliance could result in regulatory penalties, including blacklisting or suspension of operations, potentially without prior notice.
Shared Liability for Scam-Related Losses
Another significant development is the imposition of shared liability on regulated entities for financial losses arising from scams—even when committed by third parties. Unless a company can demonstrate full compliance with government-mandated preventive measures, it may face legal claims, administrative fines, or civil suits filed by affected customers.
This effectively raises the bar for due diligence and compliance, compelling businesses to document internal protocols, update risk management frameworks, and ensure continuous coordination with regulators.
Victim Restitution Through Administrative Channels
The decree enhances protection for victims of cybercrime, granting them the right to seek financial restitution through administrative agencies such as the Anti-Money Laundering Office (AMLO). Institutions may be required to compensate victims, even if they were not directly involved in the fraudulent activity.
In response, businesses are advised to establish or enhance their claims handling procedures, ensure prompt internal investigations, and consider allocating insurance coverage or reserve funds to address potential liabilities arising from restitution demands.
Criminal Penalties and Executive Liability
Violations of the decree—such as the unauthorized sale of personal data or failure to comply with data handling requirements—carry criminal penalties, including fines and imprisonment. Importantly, corporate officers and executives may also face personal liability where non-compliance is attributable to managerial failure.
To mitigate risk, companies should undertake comprehensive legal audits, reinforce employee and vendor screening processes, and ensure staff are trained on lawful data processing and reporting obligations.
Broadened Governmental Enforcement Powers
The decree grants significant new powers to the Anti-Online Scam Operation Center (AOC) and enforcement officers under the Computer Crime Act. Authorities are now empowered to:
✓ Block access to unlicensed or non-compliant digital platforms;
✓ Freeze suspicious financial transactions;
✓ Compel disclosure of information and suspend telecom services.
These powers may be exercised without prior notice, raising operational risk for businesses unprepared for rapid intervention. Proactive compliance, ongoing regulatory engagement, and emergency legal response protocols are now essential.
Implications for Foreign Platforms and the Digital Asset Sector
Of particular note is the decree’s extraterritorial application. Foreign digital platforms that target Thai users must now ensure full compliance with Thai law, including licensing requirements imposed by the Securities and Exchange Commission (SEC) and other relevant authorities. Failure to comply may result in IP blocks, service takedowns, or enforcement actions.
Further, the decree places peer-to-peer (P2P) business models under regulatory watch. While not currently banned, regulators such as the SEC are expected to issue subordinate legislation that could limit or reshape the operation of P2P platforms. Businesses operating such models are encouraged to initiate legal reviews, evaluate alternative structures, and monitor legislative developments closely.
Conclusion
This new cybercrime law reflects Thailand’s intent to adopt a more aggressive and coordinated approach to combatting online fraud and protecting digital consumers. For regulated entities—particularly those in the fintech and digital asset space—the decree introduces significant compliance obligations, operational challenges, and legal exposure.
Businesses should act swiftly to review their compliance programs, reassess legal risks, and update operational procedures in light of the decree’s broad scope and severe penalties. Foreign platforms should also take immediate steps to evaluate their exposure to the Thai market and seek local legal representation if necessary.
How MPG Can Assist
Mahanakorn Partners Group (MPG) offers legal and regulatory advisory services to financial institutions, digital platforms, and multinational businesses affected by the new decree. Our team provides:
✓ Licensing and compliance support;
✓ Data governance audits;
✓ Legal risk assessments and enforcement preparedness;
✓ Liaison with Thai regulators and administrative bodies;
✓ Multilingual assistance for internal training and client communication.
For tailored legal support or to schedule a consultation, please contact us at [email protected]