What should a Penetration Testing Agreement include under Thai law?

Short answer

The Penetration Testing Agreement on this site is an English-language document drafted for use under Thai law. Its 21 clauses cover Definitions and Interpretation; Engagement and Authorisation; Rules of Engagement; Client Preparations; Conduct of the Testing; Stop Conditions and Emergency Contacts; Critical Findings and Prior Compromise; Data Encountered During Testing; Reports and Retesting; and 12 more. The notes below explain Before the first test packet is sent.

Key facts
Clauses in the template21
Stamp dutyA penetration testing engagement is a hire of work (Instrument 4 of the Stamp Duty Schedule), and the Tester pays the duty (Clause 12.3): 1 THB for every 1,000 THB or part of 1,000 THB of the Contract Price. On the Contract Price you entered, the duty on the original is the amount the system calculates from the figures entered, and each counterpart carries the amount the system calculates from the figures entered.Because the price is in …, convert it to Thai Baht at the exchange rate on the date of signing and calculate the duty on the Baht amount. If the Agreement is signed electronically, pay through the Revenue Department's e-Stamp Duty system within 15 days after signing. An unstamped agreement cannot be used as evidence in a Thai civil court until the duty and a surcharge are paid. A Thai company paying a Thai tester normally withholds 3% of the fee and issues a certificate. If the Tester is abroad, Thai withholding tax on fees paid overseas and self-assessed VAT may apply; take accounting advice before paying, especially because you ticked gross-up.
Language of the formEnglish
Price of the form on this site990 THB

What the template covers

  1. Definitions and Interpretation
  2. Engagement and Authorisation
  3. Rules of Engagement
  4. Client Preparations
  5. Conduct of the Testing
  6. Stop Conditions and Emergency Contacts
  7. Critical Findings and Prior Compromise
  8. Data Encountered During Testing
  9. Reports and Retesting
  10. AI and Automated Tools
  11. Fees and Payment
  12. Taxes
  13. Confidentiality of Findings
  14. Ownership of the Report
  15. Warranties and Limits of Testing
  16. Liability
  17. Force Majeure
  18. Termination
  19. Notices
  20. Governing Law and Disputes
  21. General

Before the first test packet is sent

  • Sign this Agreement and the Letter of Authorisation in Schedule 2 before the Testing Window starts. Under the Computer Crime Act B.E. 2550 (2007), accessing a computer system protected by access controls without authorisation is an offence (section 5), and other offences under the same Act cover interference with systems and disclosure of access measures. The written authorisation, limited to the listed Targets, dates and source addresses, is what separates a lawful test from an attack (Clause 2.2).
  • Check every Target yourself. An IP address or domain that belongs to someone else, such as a shared host or a customer's system, cannot be authorised by you. For systems on a cloud, hosting or managed-service platform, read the provider's testing policy and give any notice it requires, then send the Tester the confirmation (Clauses 2.3 and 2.4).
  • Take and test backups of every Target (Clause 4.1). If the Testing is performed within the rules and a system still slows down or fails, the Tester is not liable unless it acted wilfully or with gross negligence (Clause 16.1).
  • Tell your IT team, your security monitoring provider and, where relevant, your hosting provider about the Testing Window and the Tester's source addresses, unless you deliberately want an unannounced test. An unannounced test can trigger a real incident response.
  • Keep the emergency contact reachable by telephone during all testing hours. The Tester must stop and call within 1 hour if something goes wrong (Clause 6.1).
  • Social engineering is switched on. Decide how your staff will be informed and make sure the exercise follows your employment policies. Results are reported by group, not to shame individuals (Clause 3.4).
  • Denial-of-service or load testing is switched on. Agree the exact times with your emergency contact and warn your hosting provider in advance, because such tests can break its terms of service (Clause 3.3).

Critical findings, prior compromise and personal data

  • The Tester must report each Critical Finding within … hours (Clause 7.1). Act on it immediately; do not wait for the Report.
  • If the Tester finds signs that someone has already broken in, or sees personal data exposed, you are the data controller and you decide whether to notify the Personal Data Protection Committee Office. Unless the breach poses no risk to individuals' rights and freedoms, the notice is due within 72 hours after you become aware of it (Personal Data Protection Act section 37(4)), and individuals must also be told where the risk is high. Engage an incident response team if needed; that work is outside this Agreement (Clause 7.2).
  • The Tester processes personal data only as a data processor with the limited duties in Clause 8.2 and must delete working data within 30 days after the Report is accepted. If the Tester will handle large volumes of personal data, for example in a white-box test with database access, consider signing a separate, full Data Processing Agreement.
  • After the Testing, change every password, key or token listed in the Report (Clause 8.3), and confirm that the Tester removed its tools and test accounts (Clause 5.5).

Report, retest and use of the results

  • Comment on the draft Report within 10 Business Days (Clause 9.2). The Tester decides its findings in good faith; you can correct facts, not negotiate ratings away.
  • Ask for the free retest within … days after the final Report (Clause 9.3). Fix the highest-severity findings first.
  • A penetration test is a snapshot. A clean Report does not prove that the systems are secure, and it is not a certification (Clause 15.2). You may share the Report with auditors, insurers, regulators and customers under confidentiality, but they cannot rely on it against the Tester (Clause 9.4).

Stamp duty and tax

  • A penetration testing engagement is a hire of work (Instrument 4 of the Stamp Duty Schedule), and the Tester pays the duty (Clause 12.3): 1 THB for every 1,000 THB or part of 1,000 THB of the Contract Price. On the Contract Price you entered, the duty on the original is the amount the system calculates from the figures entered, and each counterpart carries the amount the system calculates from the figures entered.Because the price is in …, convert it to Thai Baht at the exchange rate on the date of signing and calculate the duty on the Baht amount. If the Agreement is signed electronically, pay through the Revenue Department's e-Stamp Duty system within 15 days after signing. An unstamped agreement cannot be used as evidence in a Thai civil court until the duty and a surcharge are paid.
  • A Thai company paying a Thai tester normally withholds 3% of the fee and issues a certificate. If the Tester is abroad, Thai withholding tax on fees paid overseas and self-assessed VAT may apply; take accounting advice before paying, especially because you ticked gross-up.

Signing and disputes

  • The Client's signatory must have authority over every Target, because the same person signs the Letter of Authorisation. A company signs through the directors shown in its company affidavit, with the company seal if required.
  • Electronic signatures and signed PDF copies are allowed (Clause 21.8). Keep the signed Agreement, the Letter of Authorisation, any third-party consents and the Tester's activity log together; together they prove that the Testing was authorised.
  • A Thai court works in Thai, so a Party relying on this Agreement in court must file a certified Thai translation.

Author and sources

Compiled from the notes that accompany the English contract templates on this site, published by Phuwara Krobtaku (ภูวรา ครอบตะคุ), Thai attorney-at-law, licence no. 477/2558. The short answer and summary at the top of this page are put together by the site from the template's clause headings and notes. Statutes are quoted only in the official Thai text: Thai is the only official language of Thai legislation, and an unofficial translation can mislead. Article registry OKC-582424. If you reuse this content, please credit the author and link to the original.

This contract is ready to fill in onlineFill it in within minutes, preview the full contract before you pay, and download a print-ready PDF.
Open the form · 990 THB

Frequently asked questions

Does a Penetration Testing Agreement need stamp duty in Thailand?

A penetration testing engagement is a hire of work (Instrument 4 of the Stamp Duty Schedule), and the Tester pays the duty (Clause 12.3): 1 THB for every 1,000 THB or part of 1,000 THB of the Contract Price. On the Contract Price you entered, the duty on the original is the amount the system calculates from the figures entered, and each counterpart carries the amount the system calculates from the figures entered.Because the price is in …, convert it to Thai Baht at the exchange rate on the date of signing and calculate the duty on the Baht amount. If the Agreement is signed electronically, pay through the Revenue Department's e-Stamp Duty system within 15 days after signing. An unstamped agreement cannot be used as evidence in a Thai civil court until the duty and a surcharge are paid. A Thai company paying a Thai tester normally withholds 3% of the fee and issues a certificate. If the Tester is abroad, Thai withholding tax on fees paid overseas and self-assessed VAT may apply; take accounting advice before paying, especially because you ticked gross-up.

How should a Penetration Testing Agreement be signed?

The Client's signatory must have authority over every Target, because the same person signs the Letter of Authorisation. A company signs through the directors shown in its company affidavit, with the company seal if required. Electronic signatures and signed PDF copies are allowed (Clause 21.8). Keep the signed Agreement, the Letter of Authorisation, any third-party consents and the Tester's activity log together; together they prove that the Testing was authorised. A Thai court works in Thai, so a Party relying on this Agreement in court must file a certified Thai translation.

What happens if a Penetration Testing Agreement ends up in a dispute in Thailand?

The Client's signatory must have authority over every Target, because the same person signs the Letter of Authorisation. A company signs through the directors shown in its company affidavit, with the company seal if required. Electronic signatures and signed PDF copies are allowed (Clause 21.8). Keep the signed Agreement, the Letter of Authorisation, any third-party consents and the Tester's activity log together; together they prove that the Testing was authorised. A Thai court works in Thai, so a Party relying on this Agreement in court must file a certified Thai translation.

What clauses does a Penetration Testing Agreement on this site include?

Definitions and Interpretation; Engagement and Authorisation; Rules of Engagement; Client Preparations; Conduct of the Testing; Stop Conditions and Emergency Contacts; Critical Findings and Prior Compromise; Data Encountered During Testing; Reports and Retesting; AI and Automated Tools; Fees and Payment; Taxes; Confidentiality of Findings; Ownership of the Report; Warranties and Limits of Testing; Liability; Force Majeure; Termination; Notices; Governing Law and Disputes; General

Thai law cited (official Thai text)

The 13 sections below are quoted from the official Thai text, the only official language of Thai legislation. No translation is given, because an unofficial translation can mislead; check the Royal Gazette before relying on them in court.

Official Thai text

ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 224

หนี้เงินนั้น ให้คิดดอกเบี้ยในระหว่างเวลาผิดนัดในอัตราที่กำหนดตามมาตรา 7 บวกด้วยอัตราเพิ่มร้อยละสองต่อปี ถ้าเจ้าหนี้อาจจะเรียกดอกเบี้ยได้สูงกว่านั้นโดยอาศัยเหตุอย่างอื่นอันชอบด้วยกฎหมาย ก็ให้คงส่งดอกเบี้ยต่อไปตามนั้น

ส่วนที่ 1 การไม่ชำระหนี้

Official Thai text

ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 373

ความตกลงทำไว้ล่วงหน้าเป็นข้อความยกเว้นมิให้ลูกหนี้ต้องรับผิดเพื่อกลฉ้อฉล หรือความประมาทเลินเล่ออย่างร้ายแรงของตนนั้น ท่านว่าเป็นโมฆะ

หมวด 2 ผลแห่งสัญญา

Official Thai text

ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 383

ถ้าเบี้ยปรับที่ริบนั้นสูงเกินส่วน ศาลจะลดลงเป็นจำนวนพอสมควรก็ได้ ในการที่จะวินิจฉัยว่าสมควรเพียงใดนั้น ท่านให้พิเคราะห์ถึงทางได้เสียของเจ้าหนี้ทุกอย่างอันชอบด้วยกฎหมาย ไม่ใช่แต่เพียงทางได้เสียในเชิงทรัพย์สิน เมื่อได้ใช้เงินตามเบี้ยปรับแล้ว สิทธิเรียกร้องขอลดก็เป็นอันขาดไป

หมวด 3 มัดจำและกำหนดเบี้ยปรับ

Official Thai text

ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 386

ถ้าคู่สัญญาฝ่ายหนึ่งมีสิทธิเลิกสัญญาโดยข้อสัญญาหรือโดยบทบัญญัติแห่งกฎหมาย การเลิกสัญญาเช่นนั้นย่อมทำด้วยแสดงเจตนาแก่อีกฝ่ายหนึ่ง

หมวด 4 เลิกสัญญา

Official Thai text

ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 387

ถ้าคู่สัญญาฝ่ายหนึ่งไม่ชำระหนี้ อีกฝ่ายหนึ่งจะกำหนดระยะเวลาพอสมควร แล้วบอกกล่าวให้ฝ่ายนั้นชำระหนี้ภายในระยะเวลานั้นก็ได้ ถ้าและฝ่ายนั้นไม่ชำระหนี้ภายในระยะเวลาที่กำหนดให้ไซร้ อีกฝ่ายหนึ่งจะเลิกสัญญาเสียก็ได้

หมวด 4 เลิกสัญญา

Official Thai text

ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 391

เมื่อคู่สัญญาฝ่ายหนึ่งได้ใช้สิทธิเลิกสัญญาแล้ว คู่สัญญาแต่ละฝ่ายจำต้องให้อีกฝ่ายหนึ่งได้กลับคืนสู่ฐานะดังที่เป็นอยู่เดิม แต่ทั้งนี้จะให้เป็นที่เสื่อมเสียแก่สิทธิของบุคคลภายนอกหาได้ไม่

หมวด 4 เลิกสัญญา

Official Thai text

ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 587

อันว่าจ้างทำของนั้น คือสัญญาซึ่งบุคคลคนหนึ่ง เรียกว่าผู้รับจ้าง ตกลงจะทำการงานสิ่งใดสิ่งหนึ่งจนสำเร็จให้แก่บุคคลอีกคนหนึ่ง เรียกว่าผู้ว่าจ้าง และผู้ว่าจ้างตกลงจะให้สินจ้างเพื่อผลสำเร็จแห่งการที่ทำนั้น

ลักษณะ 7 จ้างทำของ

Official Thai text

พ.ร.บ.ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540 มาตรา 4

ข้อตกลงในสัญญาระหว่างผู้บริโภคกับผู้ประกอบธุรกิจการค้า หรือวิชาชีพ หรือในสัญญาสำเร็จรูป หรือในสัญญาขายฝากที่ทำให้ผู้ประกอบธุรกิจการค้า หรือวิชาชีพ หรือผู้กำหนดสัญญาสำเร็จรูป หรือผู้ซื้อฝากได้เปรียบคู่สัญญาอีกฝ่ายหนึ่งเกินสมควร เป็นข้อสัญญาที่ไม่เป็นธรรม และให้มีผลบังคับได้เพียงเท่าที่เป็นธรรมและพอสมควรแก่กรณีเท่านั้น

พระราชบัญญัติ ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540

Official Thai text

พ.ร.บ.ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540 มาตรา 8

ข้อตกลง ประกาศ หรือคำแจ้งความที่ได้ทำไว้ล่วงหน้า เพื่อยกเว้นหรือจำกัดความรับผิดเพื่อละเมิดหรือผิดสัญญาในความเสียหายต่อชีวิต ร่างกาย หรืออนามัยของผู้อื่น อันเกิดจากการกระทำโดยจงใจหรือประมาทเลินเล่อของผู้ตกลง ผู้ประกาศ ผู้แจ้งความ หรือของบุคคลอื่นซึ่งผู้ตกลง ผู้ประกาศ หรือผู้แจ้งความต้องรับผิดด้วย จะนำมาอ้างเป็นข้อยกเว้นหรือจำกัดความรับผิดไม่ได้

พระราชบัญญัติ ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540

Official Thai text

พ.ร.บ.ว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. 2550 มาตรา 5

ผู้ใดเข้าถึงโดยมิชอบซึ่งระบบคอมพิวเตอร์ที่มีมาตรการป้องกันการเข้าถึงโดยเฉพาะและมาตรการนั้นมิได้มีไว้สำหรับตน ต้องระวางโทษจำคุกไม่เกินหกเดือน หรือปรับไม่เกินหนึ่งหมื่นบาท หรือทั้งจำทั้งปรับ

พระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. 2550 (เฉพาะมาตราที่ใช้ร่างสัญญา)

Official Thai text

พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 มาตรา 37

ผู้ควบคุมข้อมูลส่วนบุคคลมีหน้าที่ ดังต่อไปนี้ (1) จัดให้มีมาตรการรักษาความมั่นคงปลอดภัยที่เหมาะสม เพื่อป้องกันการสูญหาย เข้าถึง ใช้ เปลี่ยนแปลง แก้ไข หรือเปิดเผยข้อมูลส่วนบุคคลโดยปราศจากอำนาจหรือโดยมิชอบ และต้องทบทวน มาตรการดังกล่าวเมื่อมีความจำเป็นหรือเมื่อเทคโนโลยีเปลี่ยนแปลงไปเพื่อให้มีประสิทธิภาพในการรักษา ความมั่นคงปลอดภัยที่เหมาะสม ทั้งนี้ ให้เป็นไปตามมาตรฐานขั้นต่ำที่คณะกรรมการประกาศกำหนด (2) ในกรณีที่ต้องให้ข้อมูลส่วนบุคคลแก่บุคคลหรือนิติบุคคลอื่นที่ไม่ใช่ผู้ควบคุมข้อมูลส่วนบุคคล ต้องดำเนินการเพื่อป้องกันมิให้ผู้นั้นใช้หรือเปิดเผยข้อมูลส่วนบุคคลโดยปราศจากอำนาจหรือโดยมิชอบ (3) จัดให้มีระบบการตรวจสอบเพื่อดำเนินการลบหรือทำลายข้อมูลส่วนบุคคลเมื่อพ้นกำหนด ระยะเวลาการเก็บรักษา หรือที่ไม่เกี่ยวข้องหรือเกินความจำเป็นตามวัตถุประสงค์ในการเก็บรวบรวม ข้อมูลส่วนบุคคลนั้น หรือตามที่เจ้าของข้อมูลส่วนบุคคลร้องขอ หรือที่เจ้าของข้อมูลส่วนบุคคล ได้ถอนความยินยอม เว้นแต่เก็บรักษาไว้เพื่อวัตถุประสงค์ในการใช้เสรีภาพในการแสดงความคิดเห็น การเก็บรักษาไว้เพื่อวัตถุประสงค์ตามมาตรา 24 (1) หรือ (4) หรือมาตรา 26 (5) (ก) หรือ (ข) การใช้เพื่อการก่อตั้งสิทธิเรียกร้องตามกฎหมาย การปฏิบัติตามหรือการใช้สิทธิเรียกร้องตามกฎหมาย หรือการยกขึ้นต่อสู้สิทธิเรียกร้องตามกฎหมาย หรือเพื่อการปฏิบัติตามกฎหมาย ทั้งนี้ ให้นำความใน

พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (เฉพาะส่วนที่ใช้ร่างสัญญา)

Official Thai text

ประมวลรัษฎากร มาตรา 118

ตราสารใดไม่ปิดแสตมป์บริบูรณ์ จะใช้ต้นฉบับ คู่ฉบับ คู่ฉีก หรือสำเนาตราสารนั้นเป็นพยานหลักฐานในคดีแพ่งไม่ได้ จนกว่าจะได้เสียอากรโดยปิดแสตมป์ครบจำนวนตามอัตราในบัญชีท้ายหมวดนี้ และขีดฆ่าแล้ว แต่ทั้งนี้ ไม่เป็นการเสื่อมสิทธิที่จะเรียกเงินเพิ่มอากรตามมาตรา 113 และมาตรา 114

บทบัญญัติ (ถ้อยคำตามเว็บกรมสรรพากร)

More in Work & services

What should a Diving and Adventure Activity Agreement include under Thai law?Practical notes on the Diving and Adventure Activity Agreement under Thai law: Before the Activity; About waivers; Weather, cancellations and refunds; Emergencies; Photographs and personal data; Stamp duty and tax; and 1 more.What should an AI Governance Assessment Agreement include under Thai law?Practical notes on the AI Governance Assessment Agreement under Thai law: Stamp duty; Tax; What the frameworks are – and are not; Before fieldwork; Reading and using the Report; Signing and evidence; and 1 more.What should an AI Implementation and Automation Agreement include under Thai law?Practical notes on the AI Implementation and Automation Agreement under Thai law: Stamp duty; Tax; Before Go-Live – the Authority Matrix; Testing and acceptance; Accounts and costs; Personal data; New AI laws; and 2 more.What should an AI Model Development and Fine-Tuning Agreement include under Thai law?Practical notes on the AI Model Development and Fine-Tuning Agreement under Thai law: Stamp duty; Tax; Before any data leaves your hands; Evaluation; Delivery, security and deletion; Signing and evidence; and 1 more.What should an AI Model Evaluation Services Agreement include under Thai law?Practical notes on the AI Model Evaluation Services Agreement under Thai law: Stamp duty; Tax; Before testing starts – authorisation; During testing; Using the Report; Signing and evidence; and If the case goes to a Thai court.What should an Architectural Services Agreement include under Thai law?Practical notes on the Architectural Services Agreement under Thai law: Before the Services start; Approvals and changes; Fees, tax and stamp duty; Building Permit and construction; Copyright and files; and Signing.