134 Dictating the Internet: to determine or designate any organization as CII, and also to determine fundamentally what amounts to a “threat” in the first place.518 The Act also allows for State bodies to implement the law against individuals and entities even without requiring the bodies to furnish sufficient evidence to prove a material risk of harm519 and in certain cases do not allow for judicial review of decisions by the authorities520 – in violation of the principles of legitimacy, necessity and proportionality.521 The extent of executive discretionary authority is particularly concerning with respect to actions that the State can take where “it appears” that a threat may be “critical” or “crisis” level.522 At the “critical” level, the CRC can order any legal person for investigation, enter premises, search and seize electronic data and equipment from any private entity, make copies of such data, test electronic equipment or systems.523 Officials are also empowered to request “real-time” access to information held by private entities.524 While judicial oversight is present with respect to “non-critical” and certain “critical” threats525, where a “cyber threat” is deemed to be at “crisis” level, the Secretary-General of the NCSC is authorized to undertake all these actions without obtaining a court warrant, and these decisions are not subject to appeal before the courts.526 Failure to comply with such orders is punishable with up to three years’ imprisonment and beyond tens of thousands of baht (which can accumulate to thousands in USD).527 Severe limitations in the Cybersecurity Act allow for potentially egregious violations of the rights to privacy and freedom of expression and information by military-led State authorities under the law. It allows 518 [Thai] Cybersecurity Act, sections 3, 49; See also Manushya Foundation 2019 report, pp. 14 to 15, 18. See Manushya Foundation 2019 report, pp. 19, 20. [Thai] Cybersecurity Act, section 69. [Thai] Cybersecurity Act, sections 61 to 68. [Thai] Cybersecurity Act, sections 61, 64 to 66 apply where it “appears to the CRC that there exist or may exist a ‘critical’ risk’”, the CRC can order the NCSC Office to take relevant action. Section 62 provides for the power of the Secretary-General of the NCSC “in order to analyse and evaluate the damage from (any) cyber threats” to make relevant orders to authorities. For threats at “crisis” level, section 67 allows the NSC to deal with the matter, or in cases of emergency, section 68 allows the Secretary-General to proceed without a court order. 523 [Thai] Cybersecurity Act, sections 66 to 69. 524 [Thai] Cybersecurity Act, section 68(2). 525 Judicial oversight is not extended to some “critical” threats, see [Thai] Cybersecurity Act, section 66, particularly section 66(1)(2). 526 [Thai] Cybersecurity Act, section 68(1). Appeal is only available for “non-critical” threats, see section 69. 527 [Thai] Cybersecurity Act, sections 75, 76; Section 75 imposes a fine of up to THB 300,000 and an increased fine of THB 10,000 per day until an individual or legal person complies with an order, and imposes up to 1 year’s imprisonment or a fine of up to THB 20,000 for non-compliance. Section 76 imposes up to three years’ imprisonment and a fine of up to THB 60,000 for noncompliance. 519 520 521 522

Select target paragraph3