top of page
搜尋

The Proposal of Thai Data Sharing Law 關於泰國資料共享法的提案

  • 18小时前
  • 讀畢需時 4 分鐘
IBC 法律金融會計事務所製作之《泰國資料共享法》草案解析資訊圖表,展示 D2 中央平台、公私部門資料互通、五大資料流向面向(G2B、G2G、B2G、B2C)、PDPA 協同效應與企業合規建議。

On 31 July 2026, Thailand’s Big Data Institute (BDI) officially published the draft Data Sharing Law and launched a public consultation, which will end on 31 August 2026. This legislative milestone accelerates the implementation of Thailand's National Big Data Strategy, designed to bridge existing regulatory gaps, and enhance public-private data interoperability.

泰國大數據研究所(BDI)在2026年7月31日正式發布《資料共享法》草案,並啟動公眾諮詢,將於2026年8月31日結束。這項立法里程碑加速泰國《國家大數據戰略》的落實,旨在填補現有的法規缺口以及強化公私部門間的資料互通性。

The following are key highlights of the Draft Data Sharing Law

以下是《資料共享法》草案的要點。

 

1.         Central Data-Sharing Platform: Establishes a central system, known as the Data Integration and Intelligence Platform (D2), managed by the BDI for government and private-sector data sharing.

中央資料共享平台: 建立一個名為資料整合與情報平台(D2)的中央系統,由 BDI 管理,用於政府與私營部門的資料共享。

 

2.         Public-Private Data Interoperability: Establishes standard frameworks for seamless and secure data exchange between public sector entities and private corporations.

公私部門資料互通性: 建立標準化架構,以實現公部門實體與私營企業之間順暢且安全的資料交換。

3.         Unified Data Governance Standards: Introduces guidelines on data categorization, security baselines, and open-data formatting to streamline cross-sector collaboration.

統一的資料治理標準:引入有關資料分類、安全基線與開放資料格式的指引,以簡化跨領域的合作。

4.         Synergy with Thailand’s Personal Data Protection Act (PDPA): Reinforces data protection alignment, ensuring that expanded data sharing complies with personal data rights under the PDPA.

與《泰國個人資料保護法》(PDPA)的協同效應:強化資料保護的一致性,確保擴大後的資料共享符合PDPA的個人資料權利。

 

Key dimensions from the Five Dimensions of data flows outlined in Thailand's Draft

Framework for Data Sharing are:

泰國《資料共享草案架構》所概述的五個主要資料流向面向為:

 

Ø  Government-to-Business (G2B): Businesses can request access to government datasets for research and development once the BDI verifies their compliance with data governance and security standards. Qualifying requests are forwarded to agencies within 90 days, providing a key opportunity for enhanced market analysis and product innovation. The data-holding agency must respond within 90 days, taking legality and PDPA into account. 

政府對企業(G2B): 一旦BDI核實企業符合資料治理與安全標準,企業即可申請存取政府資料集以進行研究與開發。符合資格的申請會在 90 天內轉交給相關主管機關,為提升市場分析與產品創新提供關鍵契機。資料持有機關必須在 90 天內做出回應,並將合法性與 PDPA 納入考量。

Ø  Government-to-Government (G2G): Facilitates faster inter-agency data exchanges within 90-day response windows. While internal to the state, this process streamlines business-facing administrative operations such as licensing, tax filing, and regulatory reviews. 

政府對政府(G2G): 促進政府機關之間在 90 天回應期限內進行更快速的資料交換。雖然這屬於國家內部事務,但該流程簡化面向企業的行政作業,例如執照核發、稅務申報與法規審查。

Ø  Business-to-Government (B2G): Grants the Minister of Digital Economy and Society the power to compel private entities to disclose data during emergencies (e.g., public safety, economic security, or disaster response). Although legal safeguards mandate minimum necessary disclosure and proof of necessity, it creates significant compliance obligations for foreign investors. Requests for personal data must be limited to the minimum amount necessary. 

企業對政府(B2G): 賦予數位經濟與社會部部長在緊急狀況時(例如公共安全、經濟安全或災難應變),強制私營實體公開資料的權力。儘管法律保障措施規定僅能進行最低限度的必要公開並須證明其必要性,但這仍為外國投資者帶來重大的合規義務。對個人資料的請求必須限制在最低必要範圍內。

Ø  Business-to-Consumer (B2C): Signals a policy shift toward greater consumer data portability and individual control—aligning with existing PDPA trends. Royal decrees may require businesses in designated sectors—such as banking, insurance, e-commerce, or telecommunications—to share customer data and business data, comparable to “smart data” schemes in the UK.

企業對消費者(B2C): 釋放出政策轉向的訊號,朝向給予消費者更多資料可攜權與個人控制權發展—這與現行的PDPA趨勢一致。皇家法令可能要求指定領域的企業(如銀行、保險、電子商務或電信)共享客戶與業務商業資料,這與英國的「智慧資料(smart data)」計畫相似。

 

Additional Key Provisions for Businesses:

企業應注意的其他關鍵條款: 

 

Data-Sharing Promotion Committee: A newly formed committee that will resolve disputes, issue regulations, and monitor the implementation of the data-sharing regime.

資料共享促進委員會: 一個新成立的委員會,將負責解決爭議、發布法規並監督資料共享機制的落實執行。 

Voluntary Certification (Trust Mark): The draft introduces a voluntary certification regime for data-sharing service providers. Certified providers may display a recognized trust mark indicating compliance with prescribed standards.

自願性認證(信任標誌): 該草案為資料共享服務提供者引入自願性認證制度。獲得認證的提供者可以展示經認可的信任標誌,表明其符合規定標準。

 

Investors can adopt the following measures to comply with the new regulations

投資者可採取以下作法以便因應新的法規

 

Ø  Conduct a Data Inventory Audit: Review company’s data architecture and localized data flows in Thailand to assess readiness under the new sharing standards.

進行資料盤點審計: 檢視公司在泰國的資料架構與在地化資料流向,以評估在全新共享標準的準備狀況。

Ø  Strengthen Integrated Compliance (PDPA + Data Sharing): Align internal data protection policies with both PDPA requirements and the newly proposed data-sharing protocols.

強化整合性合規(PDPA + 資料共享): 將內部資料保護政策與PDPA的要求以及新提議的資料共享協定保持一致。


 
 
 

留言


© 2025 by International Business Consultancy Co., Ltd.

  • Facebook Social Icon
bottom of page