You need more information?
Let us find the right lawyers for you
Last Updated: Feb 26, 2025
The rise of digital payments in Thailand reflects the nation’s broader embrace of digital transformation and financial inclusion. From mobile wallets to QR code transactions, digital payment platforms have reshaped how individuals and businesses handle financial transactions. However, these developments also bring about a host of legal and regulatory challenges.
This article explores the legal framework, key issues, and compliance obligations associated with digital payments in Thailand, offering an in-depth guide for lawyers and business professionals navigating this dynamic landscape.
As many of the companies operating in this space are startups, we would like to share our comprehensive resource for startups in Thailand, which includes matters such as how to register a company, the different business structures available, tax, visas, work permits and more.
Thailand's digital payment sector has experienced exponential growth due to advancements in financial technology (fintech), government initiatives like the National e-Payment Plan, and a rising preference for cashless transactions. Platforms like PromptPay, mobile banking apps, and e-wallets such as TrueMoney and Rabbit LINE Pay dominate the market.
Government Support: Initiatives like PromptPay, under the Bank of Thailand's guidance, promote seamless peer-to-peer and business transactions.
Consumer Adoption: Rising smartphone penetration and internet accessibility have fueled adoption.
Pandemic Influence: COVID-19 accelerated cashless payment adoption due to hygiene concerns.
Thailand's legal framework for digital payments encompasses financial, cybersecurity, and data privacy regulations.
Payment Systems Act B.E. 2560 (2017)
Anti-Money Laundering Act B.E. 2542 (1999)
Data Privacy Regulations
The Personal Data Protection Act (PDPA) B.E. 2562 (2019) applies to digital payment providers handling user data.
Cybersecurity Laws
The Cybersecurity Act B.E. 2562 (2019) outlines requirements for digital payment providers to address cyber threats and protect critical infrastructure.
Note: The Personal Data Protection Act (PDPA) B.E. 2562 (2019) and the Cybersecurity Act B.E. 2562 (2019) were enacted in the same year, meaning they came into effect at the same time; however, they address different aspects of data protection, with the PDPA focusing on individual privacy and the Cybersecurity Act focusing on broader cyber security measures within the country.
Operators offering payment services must obtain business licenses or register with the Bank of Thailand (BOT). Key categories include:
E-Money License: Required for issuing prepaid e-wallets.
Payment Gateway License: For platforms facilitating online transactions.
Clearing and Settlement System Registration: For intermediaries handling interbank transactions.
Thailand’s digital payments industry is regulated by the Bank of Thailand (BOT), which issues specific licenses based on the nature of services offered. These include:
Businesses offering prepaid digital wallets or stored-value accounts must obtain an e-money license. For example, platforms like TrueMoney and Rabbit LINE Pay fall under this category. These services allow users to preload funds and make cashless transactions seamlessly, often integrated into retail, transport, and e-commerce ecosystems. To comply, providers must ensure the real-time availability of funds and implement robust anti-money laundering (AML) checks.
Companies like 2C2P, Stripe and OPN Payments, which facilitate online payment processing for merchants, are required to secure a payment gateway license. These platforms handle complex financial transactions, ensuring secure connections between buyers, merchants, and banks. Compliance requires meeting transaction thresholds, maintaining data encryption protocols, and reporting suspicious activities promptly to the authorities.
Risk Management: Providers must implement systems to mitigate financial and cybersecurity risks.
Reporting Requirements: Periodic reporting to the BOT on operational metrics and incident reports.
KYC and AML Measures: Adherence to customer verification and anti-money laundering protocols.
The rise of cross-border e-commerce presents challenges related to currency conversion, taxation, and compliance with multiple jurisdictions' regulations. Thailand’s regulations on foreign exchange transactions can complicate these processes.
Digital payment systems are vulnerable to fraud, phishing, and unauthorized transactions. Legal recourse often hinges on proving negligence by the provider or the user.
Refund Mechanisms: Disputes over unauthorized transactions or service failures often require clarity in refund policies.
Transparency: Providers must clearly communicate fees, terms, and conditions to users to avoid litigation.
Fintech Innovation
Thailand encourages fintech startups to innovate through regulatory sandboxes managed by the BOT. These frameworks allow businesses to test digital payment solutions in controlled environments.
International Trade Facilitation
Digital payments simplify cross-border trade, but businesses must understand the legal nuances of foreign exchange controls and tax reporting requirements in Thailand.
Taxation is a critical aspect of operating digital payment services in Thailand. Providers must navigate regulations concerning Value-Added Tax (VAT), corporate income tax, and withholding tax for specific cross-border transactions.
Value-Added Tax (VAT)
Digital payment platforms are obligated to charge VAT on service fees collected from merchants. For instance, if a payment gateway charges a 3% fee per transaction, VAT must be calculated and reported to the Thai Revenue Department.
Double Taxation Concerns
Cross-border payment providers may face issues related to double taxation. Companies like PayPal or Stripe, which process international payments, need to ensure compliance with Thailand’s tax treaties to avoid paying taxes in both the country of origin and Thailand.
Corporate Income Tax
Platforms domiciled in Thailand are taxed on worldwide income, while foreign platforms operating in Thailand may only be taxed on income earned within the country. This distinction often necessitates expert legal advice to minimize liabilities while staying compliant.
Lawyers in Thailand specializing in digital payments can assist in:
Harmonization with Global Standards
Aligning Thai regulations with international frameworks like GDPR or PSD2 can enhance cross-border operability and investor confidence.
Enhanced Consumer Awareness
Public education campaigns on digital payment safety and rights can reduce fraud.
Stronger Penalties for Non-Compliance
Imposing stringent penalties for breaches of financial, data privacy, or cybersecurity regulations can deter violations.
Role of Regulatory Sandboxes in Thailand
The Bank of Thailand’s regulatory sandbox provides a safe environment for fintech companies to test innovative digital payment solutions. This initiative allows businesses to experiment with new technologies under close regulatory oversight, ensuring consumer protection and market stability.
Notable Digital Payments Case Studies:
GrabPay: Successfully piloted a peer-to-peer transfer service, addressing operational challenges before full-scale deployment.
SCB Easy: Tested blockchain technology for faster cross-border remittances, leading to more secure and efficient international transfers.
Benefits of Participation:
Businesses operating in the sandbox are exempt from certain licensing requirements during the trial period, providing them with the flexibility to refine their services. This encourages innovation while maintaining compliance with evolving legal standards.
Disputes are inevitable in the digital payments ecosystem, ranging from unauthorized transactions to service delays. Thailand has established mechanisms to address these concerns effectively:
Mediation by the Bank of Thailand (BOT)
The BOT serves as a mediator for disputes between users and providers. For instance, if a consumer disputes an unauthorized transaction, the BOT reviews the case and ensures fair resolution.
Legal Recourse for Consumers
Users can escalate unresolved disputes by filing a formal complaint with the Consumer Protection Board or relevant judicial bodies. Required documentation includes transaction records, communication logs, and proof of financial loss.
Expected Timelines
Thai law mandates that providers acknowledge complaints within 7 days and resolve them within 30 days. Failure to adhere to these timelines can result in penalties and reputational damage.
Environmental, Social, and Governance (ESG) considerations are gaining prominence in Thailand’s regulatory framework for digital payments.
Sustainability in Operations
Regulators encourage payment platforms to adopt energy-efficient data centers and green technologies. For example, companies integrating blockchain technologies must ensure their operations minimize carbon emissions.
Social Inclusion
Digital payment platforms are pivotal in extending financial services to underbanked populations. Initiatives such as QR payment systems in rural areas have improved financial accessibility, reducing economic disparities.
Governance Practices
Platforms are required to maintain transparent reporting mechanisms and robust internal controls to prevent fraud and misuse. Compliance with ESG standards not only fulfills legal requirements but also enhances brand reputation among socially conscious consumers.
Consumer protection is a cornerstone of Thailand’s digital payment regulations. The following rights ensure users are safeguarded against exploitation:
Right to Information
Users are entitled to clear, upfront details about transaction fees, data usage policies, and terms of service. Digital payment providers must ensure this information is readily accessible and understandable.
Right to Refunds
Refund policies are strictly regulated to protect consumers. For example, in cases of double charges or technical errors, platforms must process refunds within 14 business days.
Right to Security
Providers must adhere to stringent security standards, including two-factor authentication and real-time fraud monitoring. Non-compliance can lead to significant penalties and loss of operating licenses.
Blockchain Technology: The adoption of blockchain for secure and transparent payment systems.
Central Bank Digital Currency (CBDC): The Bank of Thailand is exploring a digital baht to streamline financial transactions.
Smart Contracts: Automated payments using smart contracts may require new legal frameworks.
Artificial Intelligence: AI-powered fraud detection tools could prompt updates to existing cybersecurity laws.
Thailand's digital payment landscape is a whirlwind of innovation. This guide should come in handy for a range of audiences, whether that be supporting businesses and legal experts. We hope that this resource helps you navigate the ever-shifting currents of regulations in this exciting sector. Be sure to also reach out to one of the leading fintech lawyers in Thailand, which can be found on our platform.
Let us find the right lawyers for you