134
Dictating the Internet:
to determine or designate any organization as CII, and also to determine
fundamentally what amounts to a “threat” in the first place.518 The Act also
allows for State bodies to implement the law against individuals and entities
even without requiring the bodies to furnish sufficient evidence to prove a
material risk of harm519 and in certain cases do not allow for judicial review
of decisions by the authorities520 – in violation of the principles of legitimacy,
necessity and proportionality.521
The extent of executive discretionary authority is particularly
concerning with respect to actions that the State can take where “it appears”
that a threat may be “critical” or “crisis” level.522 At the “critical” level, the
CRC can order any legal person for investigation, enter premises, search
and seize electronic data and equipment from any private entity, make
copies of such data, test electronic equipment or systems.523 Officials are
also empowered to request “real-time” access to information held by private
entities.524 While judicial oversight is present with respect to “non-critical”
and certain “critical” threats525, where a “cyber threat” is deemed to be at
“crisis” level, the Secretary-General of the NCSC is authorized to undertake
all these actions without obtaining a court warrant, and these decisions
are not subject to appeal before the courts.526 Failure to comply with such
orders is punishable with up to three years’ imprisonment and beyond tens
of thousands of baht (which can accumulate to thousands in USD).527
Severe limitations in the Cybersecurity Act allow for potentially
egregious violations of the rights to privacy and freedom of expression
and information by military-led State authorities under the law. It allows
518 [Thai] Cybersecurity Act, sections 3, 49; See also Manushya Foundation 2019 report, pp. 14 to 15,
18.
See Manushya Foundation 2019 report, pp. 19, 20.
[Thai] Cybersecurity Act, section 69.
[Thai] Cybersecurity Act, sections 61 to 68.
[Thai] Cybersecurity Act, sections 61, 64 to 66 apply where it “appears to the CRC that there exist
or may exist a ‘critical’ risk’”, the CRC can order the NCSC Office to take relevant action. Section
62 provides for the power of the Secretary-General of the NCSC “in order to analyse and evaluate
the damage from (any) cyber threats” to make relevant orders to authorities. For threats at
“crisis” level, section 67 allows the NSC to deal with the matter, or in cases of emergency, section
68 allows the Secretary-General to proceed without a court order.
523 [Thai] Cybersecurity Act, sections 66 to 69.
524 [Thai] Cybersecurity Act, section 68(2).
525 Judicial oversight is not extended to some “critical” threats, see [Thai] Cybersecurity Act, section
66, particularly section 66(1)(2).
526 [Thai] Cybersecurity Act, section 68(1). Appeal is only available for “non-critical” threats, see
section 69.
527 [Thai] Cybersecurity Act, sections 75, 76; Section 75 imposes a fine of up to THB 300,000 and an
increased fine of THB 10,000 per day until an individual or legal person complies with an order,
and imposes up to 1 year’s imprisonment or a fine of up to THB 20,000 for non-compliance.
Section 76 imposes up to three years’ imprisonment and a fine of up to THB 60,000 for noncompliance.
519
520
521
522