Curtailing Free Expression, Opinion and Information Online in Southeast Asia Brought into force to combat “cyber threats” or “hacking attacks”, the Cybersecurity Act provides sweeping powers to government authorities to monitor online information, and search and seize electronic data and equipment under an overarching framework of protecting “national security”, through protecting against “threats” to the country’s “Critical Information Infrastructure” (CII), where “national security” and CII are left vaguely defined.512 Section 3 of the Act broadly includes as CII “any computer or computer system that the Government Agency or private organization uses in their operations which relate to maintaining national security, public security, national economic security, or infrastructures in the public interest”.513 This allows for arbitrary interpretation by State bodies in implementing the Act including nearly any organization or individual under its remit, and for any purpose deemed to be in the interest of national or public security. This expanded authority is particularly concerning as the powers extended to State bodies tasked with interpreting and executing the law are not subject to independent monitoring mechanisms or authorities. The Act creates the National Cybersecurity Committee (‘NCSC’) which sets policy standards for the implementation of the CSA, headed by Prime Minister Prayuth Chan-o-cha and including ministers of the Ministry of Defence, the Ministry of Digital Economy and Society (MDES), the Ministry of Justice and the Ministry of Finance, the Commissioner-General of the Royal Thai Police (RTP) and the Secretary-General of the National Security Council (NSC).514 It also sets up the Cybersecurity Regulation Committee (‘CRC’) which – supported by the Office of the National Cybersecurity Committee (‘NCSC Office’) – implements these standards, led by the MDES and including the Royal Thai Armed Forces and the RTP.515 The NCSC possesses, among other powers, the authority to determine three levels of “cyber threats” – “non-critical”, “critical” or “crisis” – which pose significant risks and broadly compromise the country’s CII.516 A threat is deemed to be at “critical” or “crisis” levels where it “affects national defence, public safety or order”.517 The NCSC is provided with broad powers 512 [Thai] Cybersecurity Act B.E. 2562 (2019)(‘Cybersecurity Act’), section 3, Available at: http:// www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/069/T_0020.PDF; For reference of English translation of the Act, and related concerns, refer to Manushya Foundation 2019 report. 513 [Thai] Cybersecurity Act, section 3; See also Manushya Foundation 2019 report, p. 17. 514 [Thai] Cybersecurity Act, sections 5, 9, 41 to 43; See also Manushya Foundation 2019 report, pp. 28 to 31. 515 [Thai] Cybersecurity Act, sections 12, 13, 22, 61 to 66; See also Manushya Foundation 2019 report, pp. 28 to 31. 516 [Thai] Cybersecurity Act, section 60(3)(a). 517 [Thai] Cybersecurity Act, section 60; See also Manushya Foundation 2019 report, pp. 22 to 23. 133

Select target paragraph3