Thailand’s Data-Center Boom Enters a Second Regulatory Phase

Cloud, Connectivity, Energy Readiness, and the Limits of Investment Promotion

Thailand is no longer merely trying to attract data-center investment. That phase has already arrived.

In recent years, Thailand has seen major commitments and approvals across cloud regions, hyperscale facilities, data hosting, and AI-related digital infrastructure. Major international technology companies have announced investments in Thailand’s cloud and data-center infrastructure, while the Board of Investment (“BOI”) has approved significant projects spanning data centers, cloud services, data hosting, and advanced digital infrastructure.

The legal question is therefore changing.

The issue is no longer whether Thailand wants data centers. It does. The more difficult question is how Thailand intends to regulate data centers, cloud services, AI infrastructure, connectivity, foreign ownership, government access, power demand, water use, cybersecurity, and data governance as these facilities become part of the country’s critical digital infrastructure.

Thailand’s data-center market has entered a second regulatory phase. The first phase was investment attraction. The second phase is regulatory calibration.

Thailand is not simply liberalizing its data-center sector. It is selectively institutionalizing it.

The deeper issue is one of regulatory sovereignty. Thailand is trying to attract large-scale, often foreign-controlled digital infrastructure while retaining meaningful oversight over data, connectivity, power, water, cybersecurity, public-sector reliance, and national infrastructure resilience. Few jurisdictions have solved that balance cleanly. Thailand’s current approach is not to impose a single comprehensive data-center code, but to regulate through intersecting gateways: BOI promotion, energy readiness, telecommunications characterization, foreign ownership, data protection, cybersecurity, and customer-contract risk.

Phase One: Investment Attraction

Thailand’s first data-center policy phase focused on investment promotion.

Data centers and cloud services have long been eligible for BOI promotion under Thailand’s digital-industry framework. Earlier BOI frameworks treated data centers and cloud services as priority digital infrastructure, subject to technical and operational conditions such as minimum facility capacity, telecommunications connectivity, redundancy, backup power, cooling, fire protection, 24-hour security, and information-security certification.

That framework was important. It signaled Thailand’s intention to compete for regional cloud and data-center investment. It also allowed qualifying projects to access valuable investment incentives, including tax privileges, import-duty benefits, land ownership rights in certain cases, and work permit facilitation. FOSR’s BOI Companies practice addresses these investment-promotion issues across the sectors it promotes.

But investment promotion was never the same as deregulation.

Even in the first phase, data centers were not treated as ordinary real estate. A data center may look like a building, but its legal character depends on what it does. It may involve hosting, cloud services, colocation, telecommunications connectivity, cybersecurity, government customers, personal data, critical systems, foreign-owned infrastructure, high-capacity power demand, and environmental considerations.

BOI promotion could make a project more investable. It did not make the project legally self-contained.

The Limits of Investment Promotion

BOI promotion is powerful, but it does not replace other legal regimes.

A promoted data center or cloud project may still require separate analysis under Thailand’s telecommunications laws, the Foreign Business Act, the cybersecurity framework, the Personal Data Protection Act, the Computer Crime Act, energy and environmental regulations, building control requirements, land-use restrictions, and public-sector procurement or cloud policies.

This point is central to the current market.

Many data-center sponsors, hyperscale cloud providers, infrastructure funds, and foreign investors begin with the BOI question: can the project be promoted, and what incentives are available? That is a necessary question, but it is no longer sufficient.

The more important question is whether the project’s legal architecture matches its actual operating model.

A project promoted as a data center may also provide managed connectivity. A cloud platform may bundle network functions. A colocation facility may offer interconnection services. A data-hosting project may involve GPU-intensive AI workloads. A public-sector cloud project may raise concerns about government access, cybersecurity, and data governance. A foreign-owned platform may need to separate promoted activities from non-promoted services.

In each case, the legal analysis extends beyond BOI approval.

This is why data-center projects should be understood as part of Thailand’s wider digital-infrastructure regulatory environment. FOSR’s TMT / Telecommunications, Media and Technology practice page describes the firm’s work across telecommunications, cloud, data centers, satellite and network infrastructure, data privacy, cybersecurity, and related regulatory matters.

Phase Two: Regulatory Calibration

Thailand’s second phase is visible in the way investment-promotion conditions are becoming more selective.

The BOI framework has moved beyond general encouragement of digital infrastructure. Current data-center and cloud-related promotion conditions increasingly focus on energy efficiency, computing capability, water management, electricity readiness, local capability development, and contribution to Thailand.

For data-center projects, this is now concrete. BOI Notification Sor. 5/2568 introduced a higher-efficiency data-center category tied to a PUE threshold not exceeding 1.3. BOI Notification Sor. 9/2568 further confirmed and refined the relevant conditions, including water-management planning, Thailand-benefit planning, information-security certification, and Thai personnel requirements for executive and/or expert positions within a specified period. BOI Notification Sor. 2/2569 then added an important power-readiness gate: for certain data-center activities, the applicant must obtain a confirmation letter from the Office of the Energy Regulatory Commission before submitting the BOI application.

The BOI’s Investment Promotion Guide also reflects the increasing specificity of digital infrastructure requirements, including requirements for data centers, cloud services, international high-speed marine communication circuits, and data hosting services.

Thailand continues to encourage data-center investment, but under stricter conditions. The country seeks digital infrastructure while managing power demand, water use, grid stability, local benefits, cybersecurity, data governance, and the regulatory consequences of foreign-controlled infrastructure.

This shift aligns with the public conversation now underway about data centers in Thailand and across the region. The discussion is no longer limited to investment size, hyperscaler commitments, cloud adoption, or tax incentives. It increasingly addresses electricity supply, water use, cooling, emissions, pressure on local infrastructure, and the question of whether host countries have the physical capacity to support AI-era digital infrastructure.

That broader public discussion matters because data centers are not only digital projects. They are also energy, water, land, and environmental projects.

The Sovereignty Question Behind the Compliance Questions

The individual legal issues can look technical: BOI category selection, PUE thresholds, ERC confirmation, foreign business restrictions, telecom characterization, PDPA transfers, cybersecurity obligations, government access, and customer-contract allocation.

Collectively, they point to a larger policy question.

Thailand is trying to build a digital infrastructure economy without surrendering practical control over the infrastructure on which that economy will depend. Data centers and cloud regions may be privately owned and foreign-invested, but their effects are public and systemic. They support financial services, public administration, communications, healthcare, education, commerce, AI deployment, government data exchange, and regulated-sector operations.

This is why the second regulatory phase matters.

The state does not need to own the infrastructure to regulate the conditions under which it operates. It can use investment-promotion conditions, energy-readiness gates, telecommunications licensing boundaries, cybersecurity obligations, data-protection rules, public-sector procurement standards, and contractually enforced customer expectations to retain influence over critical points of control.

This does not mean Thailand is closing the market. The policy direction remains investment-positive. But data centers are increasingly being treated less as passive facilities and more as strategic infrastructure.

For investors, that distinction matters. A passive facility can be assessed primarily by land, construction, lease, and tax assumptions. Strategic infrastructure must also be assessed against regulatory resilience, state access, grid integration, water use, alignment with national policy, customer trust, and the ability to operate within a changing public-interest framework.

Legal Characterization Still Comes First

In the second phase, legal characterization remains the first question.

“Data center” is not a complete legal category. The label may cover very different operating models, including:

  • hyperscale data-center campuses;
  • colocation facilities;
  • cloud regions;
  • data-hosting services;
  • GPU or AI compute facilities;
  • customer-premises hosting;
  • managed edge infrastructure;
  • interconnection facilities;
  • passive infrastructure;
  • active network infrastructure;
  • cloud services bundled with connectivity; and
  • public-sector cloud environments.

Each model may raise different legal consequences.

A facility that provides space, power, cooling, and physical security may be analyzed differently from a platform that provides managed network services, interconnection, cloud workloads, AI compute, or bundled telecommunications connectivity.

This distinction is not academic. It affects BOI category selection, telecommunications analysis, foreign ownership structuring, contracting, customer responsibility, data-processing allocation, power planning, environmental review, and project finance risk.

A data-center project cannot be correctly promoted, financed, licensed, or contracted until its service layers are understood.

Connectivity Remains a Regulatory Boundary

Connectivity remains one of the important regulatory constraints in data-center structuring.

Cloud services are not automatically telecommunications services. Data hosting is not automatically telecommunications. Colocation is not automatically telecommunications. A data-center operator may use telecommunications services without becoming a telecommunications service provider.

But the analysis changes if the operator begins to provide or control telecommunications functionality.

Issues may arise when a data-center, cloud, or infrastructure operator provides or controls leased lines, internet access, interconnection, managed network services, cross-border transmission, gateway functions, traffic routing, or other connectivity functions for customers.

The key question is not whether the project uses fiber. Almost every data center does. The question is whether the operator is merely consuming connectivity from licensed telecommunications providers or is itself providing or controlling regulated telecommunications services.

This is why cloud, data center, and connectivity functions should be mapped out early. A pure colocation or hosting model may raise a different regulatory profile from a platform that bundles compute, storage, connectivity, interconnection, and managed network functions into a single customer-facing service.

Investors should therefore avoid two mistakes.

The first mistake is assuming that every data-center activity is a telecommunications business.

The second mistake is assuming that no data-center activity can ever raise telecommunications issues.

The correct approach is to map the operating model.

Foreign Ownership and the BOI Boundary

Foreign ownership is another area where BOI promotion helps but does not end the analysis.

For many promoted activities, BOI promotion may allow foreign-majority ownership and may support a Foreign Business Certificate route rather than an ordinary Foreign Business License. That can be highly valuable for foreign data-center and cloud investors.

Strictly speaking, BOI promotion is not itself a blanket exemption from the Foreign Business Act. Where a foreigner has been granted BOI promotion privileges, the Department of Business Development must issue a Foreign Business Certificate under section 12 of the Foreign Business Act for the promoted business activity.

But BOI promotion is activity-specific. If a company performs services outside the promoted scope, or if the actual business model includes non-promoted services, the Foreign Business Act analysis may reappear.

This is particularly important for service businesses. Thailand’s Foreign Business Act includes broad service-business restrictions, including the List Three “other service businesses” category. Data-center, cloud, platform, managed-services, and customer-support activities may need careful characterization where they fall outside a promoted activity or are not clearly covered by an exemption. If the company generates revenue from activities outside the BOI-promoted scope and outside the Foreign Business Certificate coverage, those activities may require a separate Foreign Business License. Operating outside the authorized scope is not merely an administrative issue; it may expose the company and responsible persons to Foreign Business Act penalties.

Sector-specific rules also remain relevant. BOI promotion does not override telecommunications licensing rules, radiocommunication requirements, cybersecurity obligations, PDPA requirements, energy regulation, environmental restrictions, or other laws that apply to the business.

FOSR has addressed the relationship between foreign ownership, telecommunications infrastructure, and sector-specific regulation in FBA Reform and Telecommunications Infrastructure: The Limits of Liberalization in Thailand. The same analytical caution applies to data-center and cloud projects: general investment liberalization should not be confused with sector-specific regulatory clearance.

For foreign investors, the practical point is straightforward: BOI promotion may be part of the ownership solution, but it should not be treated as the whole solution.

Energy, Water, and the Physical Limits of Digital Infrastructure

The most important shift in Thailand’s data-center discussion may not be legal in the narrow sense. It may be physical.

Data centers are digital infrastructure, but their constraints are physical: power, water, cooling, grid access, land, backup generation, and environmental acceptability.

As data-center and AI-infrastructure demand grows, these physical constraints increasingly become legal and regulatory issues. A data-center project may have customers, capital, technology partners, land, and BOI eligibility. But if it cannot secure sufficient power, demonstrate water-management planning, meet cooling requirements, or satisfy infrastructure-readiness conditions, the project may face delays, reduced incentives, financing difficulties, or reputational risk.

Thailand does not currently appear to have a standalone national “green data center” law or a mandatory certification scheme equivalent to a dedicated green data-center code. Instead, sustainability and environmental requirements are increasingly embedded in the BOI investment-promotion framework.

For promoted data-center projects, environmental performance is therefore becoming part of the investment-approval and tax-incentive framework, not merely an ESG narrative.

Recent BOI criteria distinguish between higher-efficiency and standard data-center projects. The higher-efficiency category is tied to measurable energy performance, including a PUE threshold. BOI conditions increasingly address water management planning, electricity readiness, local capability development, information security certification, redundancy, cooling, fire protection, and operational resilience.

The practical consequence is that sustainability commitments must be operational, not merely promotional. A data-center sponsor cannot simply state that a project will be efficient or green. It must be able to support the claim through design, equipment selection, cooling strategy, metering, operational controls, certification planning, and evidence that the project can satisfy the relevant BOI and utility requirements.

FOSR’s Energy practice page reflects how energy regulation, infrastructure development, and telecommunications increasingly intersect in areas such as dedicated power supply, renewable integration, and data-center development.

Electricity Readiness as a Legal Gate

Power availability is now a front-end legal and regulatory issue.

For data-center projects, electricity can no longer be treated as a post-approval engineering matter. Where BOI filing requires confirmation from the Office of the Energy Regulatory Commission, electricity readiness becomes part of the legal entry analysis. The project must be able to demonstrate that its intended load can be supported within Thailand’s power system and utility framework.

This is one of the clearest examples of Thailand’s second regulatory phase. The first phase asked whether Thailand wanted to invest in data centers. The second phase asks whether the grid can support the investment, whether the project’s load is realistic, and whether the proposed facility can be integrated into Thailand’s electricity system without undermining reliability or creating unplanned infrastructure pressure.

For sponsors, lenders, and customers, this changes the timing of diligence.

Power availability should be reviewed before site-selection assumptions harden. Utility discussions should not be deferred until after investment-promotion strategy is settled. ERC confirmation, grid capacity, connection timing, backup generation, tariff assumptions, and renewable-energy options should be treated as core structuring issues.

A project that cannot support its power case may not be bankable, regardless of its commercial demand.

Water Management and Cooling Strategy

Water is also moving from a technical concern to a legal and bankability concern.

Data centers require cooling. Cooling strategy affects water consumption, heat discharge, drainage, stormwater management, environmental acceptability, and community impact. In Thailand’s climate, cooling is not a minor design issue. It is central to efficiency, operating cost, environmental performance, and customer perception.

Water-management planning is therefore not simply an engineering appendix. It can affect BOI treatment, site selection, financing assumptions, public acceptance, and customer sustainability commitments.

The issue is especially important in areas where industrial growth, water supply, climate variability, and competing uses may create pressure on local resources. A data-center project that appears attractive from a land and connectivity perspective may be more difficult if the water and cooling strategy is weak.

For operators, this means that water use, cooling technology, redundancy, drainage, and environmental controls should be reviewed alongside land, power, and telecom connectivity. For customers, it means that sustainability due diligence should extend beyond carbon claims and include water strategy, cooling design, and local resource impact.

PUE, Efficiency, and the Limits of Design Claims

Energy efficiency is now a central regulatory and commercial issue.

Power Usage Effectiveness, or PUE, has become a key benchmark in data-center design and operations. A low PUE indicates that more of the facility’s electricity is used by IT equipment rather than by cooling, power conversion, lighting, or other overhead.

For Thailand, the important point is that PUE should not be treated merely as a marketing metric. While BOI incentives distinguish higher-efficiency data centers, the project must be able to demonstrate performance in practice. A design-stage efficiency claim may not be enough if operational performance cannot support the relevant threshold.

This creates legal and contractual consequences.

EPC contracts, equipment procurement, cooling design, service-level agreements, facility-management arrangements, and customer sustainability commitments should align with the efficiency position used for BOI and financing purposes.

If a project is structured around a high-efficiency incentive case, then the legal documents should support that case. The project company should be able to show who is responsible for efficiency performance, what happens if performance is not achieved, how metering and verification will occur, and whether customers can rely on any sustainability representation made during sales.

In Thailand’s second phase, efficiency claims should be evidence-based and contractually substantiated.

Renewable Energy and Customer Expectations

Thailand’s BOI framework does not yet appear to impose a universal renewable-energy percentage requirement on data centers. However, access to renewable energy is becoming increasingly important.

Large cloud, AI, and data-center customers often have internal sustainability commitments. Hyperscalers, multinational enterprises, regulated-sector customers, and public-sector customers may ask whether the facility can support renewable-energy claims, renewable-energy certificates, green tariffs, or other mechanisms to reduce the carbon profile of their workloads.

This creates another layer of legal analysis.

Renewable-energy claims must align with the project’s actual power procurement structure. Operators should avoid overclaiming. If a facility relies on renewable-energy certificates, green tariffs, corporate power arrangements, or other instruments, the contractual documentation should accurately describe the arrangement.

The same point applies to customer contracts. If customers are told that workloads are hosted in a “green” or “low-carbon” facility, the operator should be able to support that claim through procurement records, certificates, tariff documentation, or other evidence.

In the data-center sector, sustainability claims are becoming commercial commitments. Commercial commitments should be drafted with the same care as service-level commitments.

AI Infrastructure Increases the Physical Pressure

AI infrastructure adds another layer to the analysis.

Traditional data-center projects were often discussed in terms of storage, hosting, cloud services, and colocation. AI infrastructure is more power-, compute-, and cooling-intensive. GPU clusters, AI training workloads, model inference, high-density racks, advanced cooling, and cross-border platform management can change a project’s legal, technical, and environmental profile.

This is why the environmental discussion is becoming more important. AI-era data centers are not merely larger versions of earlier facilities. They may have different requirements for density, cooling, power, and resilience. They may also face greater scrutiny from customers, regulators, lenders, and local communities because their physical resource demands are more visible.

BOI’s recognition of data-hosting services that involve advanced processing capacity, including GPU-based systems, is an important sign of this shift. Thailand is not only seeking ordinary storage capacity. It is positioning itself for AI-related compute infrastructure.

For project sponsors, the relevant questions are practical. Does the project fit a BOI data-center category, cloud-service category, data-hosting category, or a combination? Is the facility designed for AI-density workloads? Are cooling and water assumptions realistic? Can the grid support the proposed IT load? Are energy-efficiency claims supported by measurable performance? Is renewable-energy access part of the customer proposition? Are AI workloads processed for one enterprise or multiple third-party customers? Are customers in regulated sectors? Does the customer contract address data use, cybersecurity, government access, sustainability claims, and service responsibility clearly?

AI infrastructure makes legal characterization more important. It also makes power, water, and environmental readiness more important.

Public-Sector Cloud and Customer Trust

Data centers and cloud services are not only infrastructure projects. They are trust projects.

Enterprise customers, regulated-sector customers, and public-sector customers increasingly ask legal questions that go beyond uptime, service levels, and cybersecurity certification. They ask where data is stored, who can access it, which law applies, how government requests are handled, who controls encryption keys, where support personnel are located, what logs are retained, how incidents are reported, and whether sustainability claims are reliable.

These questions are especially important for public-sector cloud adoption.

Thailand’s digital-government framework includes not only digital-service policy, but also government data exchange, public-sector connectivity, digital standards, and cybersecurity response architecture. Public-sector customers are therefore likely to view cloud and data-center arrangements through the lens of government data governance, resilience, security, lawful access, and institutional trust.

For international cloud and data-center operators, this creates a market-access issue. Customer trust depends not only on technical controls but also on predictable contractual and legal treatment of government access, customer notification, cross-border legal conflicts, encryption, incident response, transparency, data-control allocation, and sustainability reporting.

This is one reason local cloud regions and Thai data center capacity are commercially important, even where local hosting is not universally required by law.

PDPA and Data Residency: Where Risk Actually Concentrates

Thailand does not currently impose a universal private-sector data-localization rule.

That point matters. It would be wrong to suggest that all private-sector data must be stored in Thailand. Many Thai businesses may use offshore cloud services, subject to applicable contractual, regulatory, and data-protection requirements.

But local hosting is not legally irrelevant. The risk is more specific.

First, risk concentrates in public-sector and regulated-sector use cases. Even where the PDPA does not impose universal localization, government agencies, state-linked entities, financial institutions, healthcare operators, critical-infrastructure operators, and other regulated customers may impose stricter contractual, procurement, cybersecurity, or internal governance requirements.

Second, risk concentrates in offshore access. Data may be hosted in Thailand, but if offshore affiliates, vendors, support teams, administrators, or subcontractors can access personal data, logs, customer environments, or operational systems from outside Thailand, the legal analysis may still involve cross-border transfer, processor-controller allocation, security safeguards, and customer notification.

Third, risk concentrates in backups, replicas, logs, telemetry, and disaster-recovery environments. A customer may believe that a workload is hosted in Thailand while backups, logs, monitoring data, support records, or failover copies are stored or accessed elsewhere. For data residency, the legal map may differ from the commercial description.

Fourth, risk concentrates in conflicting legal obligations and government access. Cloud and data-center providers may be incorporated, controlled, hosted, or supported across multiple jurisdictions. Customers may therefore ask how the provider will handle lawful access requests, secrecy obligations, requests from foreign parent companies, encryption key control, and notification restrictions.

Fifth, risk concentrates in customer-facing commitments. Contractual promises about “Thailand hosting,” “local data residency,” “sovereign cloud,” “no offshore access,” or “regulated-sector compliance” may create obligations that are stricter than Thai law itself. A weakly drafted sales commitment can become a stronger legal obligation than the underlying statute.

This is where the PDPA, cybersecurity, procurement, and contract analysis converge.

Thailand’s Personal Data Protection Act and cross-border transfer rules require careful analysis where personal data is transferred or made accessible outside Thailand. Under the PDPA, cross-border transfers may require an adequacy basis, appropriate safeguards, binding corporate rules, contractual protections, consent, or another available legal basis depending on the circumstances.

For data-center and cloud projects, the practical question is not simply whether data is “in Thailand.” It is who can access it, from where, for what purpose, under which contract, subject to which security controls, and with what customer notice.

FOSR has discussed related PDPA operational issues in From Awareness to Accountability: Breach Notification Under Thailand’s PDPA. For data-center and cloud operators, breach response, customer notification, controller-processor allocation, and incident governance should be addressed as part of the project architecture, not only after an incident occurs.

What Investors and Operators Should Take From This

The practical lesson for investors is not to avoid Thailand. Thailand remains one of the region’s most active and strategically important digital-infrastructure markets.

The lesson is that data-center projects should be structured as regulated infrastructure from the outset.

The relevant diligence is not a linear checklist. It is an integrated architecture in which land, power, water, cooling, BOI promotion, telecommunications characterization, foreign ownership, data protection, cybersecurity, public-sector trust, environmental acceptability, and customer-contract commitments interact with each other.

This interaction is where many of the real risks emerge. A weak power case may affect BOI timing or financing assumptions. A hosting model that includes managed connectivity may change the telecommunications analysis. A foreign ownership structure that depends on BOI promotion may be vulnerable if the project also carries out non-promoted service lines. A “Thailand-hosted” customer promise may be undermined by offshore support, logging, backup, or disaster-recovery arrangements. A high-efficiency incentive case may depend not only on facility design, but also on EPC obligations, cooling performance, metering, verification, and facility-management controls.

For serious investors, the key question is not whether Thailand has a single data-center law. It does not. The more important question is whether the project can withstand scrutiny across the regulatory gateways Thailand is actually using: BOI, ERC, NBTC, PDPC, cybersecurity authorities, energy regulators, local authorities, customers, lenders, and public-sector counterparties.

This is why the legal architecture should be built before financial close, not after.

FOSR has also discussed continuing BOI compliance in The BOI’s New Quarterly Reporting Rule: What Every Promoted Company Needs to Know Before 31 May. For data-center operators, ongoing compliance is particularly important where incentives depend on technical, operational, local-benefit, or sustainability commitments.

Conclusion: Legal Coherence Is Now Part of Bankability

Thailand’s first data-center phase was about attraction. The second phase is about calibration.

The country is still seeking major investment in cloud, data center, and AI infrastructure. BOI remains a powerful investment-promotion tool, and Thailand’s digital-economy strategy continues to support cloud adoption, AI development, public-sector modernization, and regional infrastructure positioning. But the legal environment around these projects is becoming more structured.

BOI promotion now intersects with power readiness, energy efficiency, water management, local capability development, and increasingly precise digital infrastructure categories. Telecommunications characterization remains important where data-center, cloud, or AI infrastructure touches connectivity or network functions. Foreign ownership still requires analysis under the Foreign Business Act and any sector-specific overlays. Public-sector cloud adoption depends on trust architecture. PDPA and cybersecurity requirements shape customer confidence. Energy and water constraints affect project timing, finance ability, and public acceptance.

The conclusion is not that Thailand has become hostile to data centers. The opposite is true. Thailand is taking them more seriously, and that seriousness has legal consequences.

Thailand’s second regulatory phase is an attempt to balance investment openness with infrastructure control. That balance is not yet fully settled. BOI incentives, ERC electricity-readiness requirements, water-management obligations, telecom characterization, PDPA compliance, cybersecurity expectations, and public-sector cloud trust all point in the same direction: data centers are being treated less as passive facilities and more as strategic infrastructure.

The projects that succeed will be those that understand this shift before financial close, not after. Thailand is not simply opening the door to data centers. It is deciding what kind of digital infrastructure to build.


Disclaimer

This article is provided for general informational purposes only and does not constitute legal advice. The information contained in this article may not reflect the most current legal, regulatory, or policy developments and should not be relied upon as a substitute for specific legal advice. The application of Thai investment-promotion, telecommunications, foreign investment, data-protection, cybersecurity, energy, environmental, public-sector cloud, and regulatory requirements depends on the specific facts, technical configuration, ownership structure, operating model, customer base, contracts, and regulatory status of the parties involved. Readers should seek specific legal advice before acting on any matter discussed in this article.


Authors

  • John Formichella

    John Formichella heads our Telecommunication, Media, Technology, Data Privacy Practice, and is past Chair of the Information and Communications Technology Committee of the American Chamber of Commerce in Bangkok. He is rated as Leading Individual by Legal 500 and ranked as a Band 1 individual by Chambers and Partners.

  • Naytiwut Jamallsawat is a partner at Formichella & Sritawat and a recognized legal advisor in Thailand’s telecommunications, media, and energy sectors. He represents leading multinational and Thai companies in complex legal and regulatory matters, with a focus on high-compliance industries, including telecommunications licensing, satellite operations, media platforms, and data privacy.

    In the energy sector, Naytiwut has advised on numerous greenfield and brownfield generation projects—both conventional and renewable—providing legal guidance on project development, transactional structuring, and compliance with Thai regulatory frameworks.

    He leads the firm’s specialized group of lawyers focused on telecommunications, media, technology (TMT), and data privacy. In this role, he ensures the delivery of practical, business-focused legal solutions across regulated and fast-evolving sectors. Naytiwut also works closely with founding partner John Formichella on TMT and energy mandates, providing integrated legal support on transactions and compliance matters involving international and domestic stakeholders.

  • Onnicha Khongthon (Ging) is a Senior Associate with over seven years of experience in corporate law, the technology, media, and telecoms sector (TMT), data privacy, cyber-security, and space law, including corporate and commercial matters. Onnicha began practicing after receiving an LL.B. at Chulalongkorn University.

  • Supitchaya Akeyati is an associate attorney at Formichella & Sritawat Attorneys at Law (FOSR Law) in Bangkok, Thailand. She specializes in corporate law, commercial law, personal data protection law, and litigation. Her current practice primarily focuses on corporate matters and personal data protection. Additionally, she assists senior lawyers and partners in providing legal advice related to technology, media, and telecommunications (TMT).