Curtailing Free Expression, Opinion and Information Online in Southeast Asia
Brought into force to combat “cyber threats” or “hacking attacks”,
the Cybersecurity Act provides sweeping powers to government authorities
to monitor online information, and search and seize electronic data and
equipment under an overarching framework of protecting “national security”,
through protecting against “threats” to the country’s “Critical Information
Infrastructure” (CII), where “national security” and CII are left vaguely
defined.512 Section 3 of the Act broadly includes as CII “any computer or
computer system that the Government Agency or private organization uses in
their operations which relate to maintaining national security, public security,
national economic security, or infrastructures in the public interest”.513 This
allows for arbitrary interpretation by State bodies in implementing the Act
including nearly any organization or individual under its remit, and for any
purpose deemed to be in the interest of national or public security.
This expanded authority is particularly concerning as the powers
extended to State bodies tasked with interpreting and executing the law are
not subject to independent monitoring mechanisms or authorities. The Act
creates the National Cybersecurity Committee (‘NCSC’) which sets policy
standards for the implementation of the CSA, headed by Prime Minister
Prayuth Chan-o-cha and including ministers of the Ministry of Defence, the
Ministry of Digital Economy and Society (MDES), the Ministry of Justice and
the Ministry of Finance, the Commissioner-General of the Royal Thai Police
(RTP) and the Secretary-General of the National Security Council (NSC).514
It also sets up the Cybersecurity Regulation Committee (‘CRC’) which –
supported by the Office of the National Cybersecurity Committee (‘NCSC
Office’) – implements these standards, led by the MDES and including the
Royal Thai Armed Forces and the RTP.515
The NCSC possesses, among other powers, the authority to determine
three levels of “cyber threats” – “non-critical”, “critical” or “crisis” – which
pose significant risks and broadly compromise the country’s CII.516 A threat
is deemed to be at “critical” or “crisis” levels where it “affects national
defence, public safety or order”.517 The NCSC is provided with broad powers
512 [Thai] Cybersecurity Act B.E. 2562 (2019)(‘Cybersecurity Act’), section 3, Available at: http://
www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/069/T_0020.PDF; For reference of English
translation of the Act, and related concerns, refer to Manushya Foundation 2019 report.
513 [Thai] Cybersecurity Act, section 3; See also Manushya Foundation 2019 report, p. 17.
514 [Thai] Cybersecurity Act, sections 5, 9, 41 to 43; See also Manushya Foundation 2019 report, pp.
28 to 31.
515 [Thai] Cybersecurity Act, sections 12, 13, 22, 61 to 66; See also Manushya Foundation 2019
report, pp. 28 to 31.
516 [Thai] Cybersecurity Act, section 60(3)(a).
517 [Thai] Cybersecurity Act, section 60; See also Manushya Foundation 2019 report, pp. 22 to 23.
133