What should a Penetration Testing Agreement include under Thai law?
The Penetration Testing Agreement on this site is an English-language document drafted for use under Thai law. Its 21 clauses cover Definitions and Interpretation; Engagement and Authorisation; Rules of Engagement; Client Preparations; Conduct of the Testing; Stop Conditions and Emergency Contacts; Critical Findings and Prior Compromise; Data Encountered During Testing; Reports and Retesting; and 12 more. The notes below explain Before the first test packet is sent.
| Clauses in the template | 21 |
|---|---|
| Stamp duty | A penetration testing engagement is a hire of work (Instrument 4 of the Stamp Duty Schedule), and the Tester pays the duty (Clause 12.3): 1 THB for every 1,000 THB or part of 1,000 THB of the Contract Price. On the Contract Price you entered, the duty on the original is the amount the system calculates from the figures entered, and each counterpart carries the amount the system calculates from the figures entered.Because the price is in …, convert it to Thai Baht at the exchange rate on the date of signing and calculate the duty on the Baht amount. If the Agreement is signed electronically, pay through the Revenue Department's e-Stamp Duty system within 15 days after signing. An unstamped agreement cannot be used as evidence in a Thai civil court until the duty and a surcharge are paid. A Thai company paying a Thai tester normally withholds 3% of the fee and issues a certificate. If the Tester is abroad, Thai withholding tax on fees paid overseas and self-assessed VAT may apply; take accounting advice before paying, especially because you ticked gross-up. |
| Language of the form | English |
| Price of the form on this site | 990 THB |
What the template covers
- Definitions and Interpretation
- Engagement and Authorisation
- Rules of Engagement
- Client Preparations
- Conduct of the Testing
- Stop Conditions and Emergency Contacts
- Critical Findings and Prior Compromise
- Data Encountered During Testing
- Reports and Retesting
- AI and Automated Tools
- Fees and Payment
- Taxes
- Confidentiality of Findings
- Ownership of the Report
- Warranties and Limits of Testing
- Liability
- Force Majeure
- Termination
- Notices
- Governing Law and Disputes
- General
Before the first test packet is sent
- Sign this Agreement and the Letter of Authorisation in Schedule 2 before the Testing Window starts. Under the Computer Crime Act B.E. 2550 (2007), accessing a computer system protected by access controls without authorisation is an offence (section 5), and other offences under the same Act cover interference with systems and disclosure of access measures. The written authorisation, limited to the listed Targets, dates and source addresses, is what separates a lawful test from an attack (Clause 2.2).
- Check every Target yourself. An IP address or domain that belongs to someone else, such as a shared host or a customer's system, cannot be authorised by you. For systems on a cloud, hosting or managed-service platform, read the provider's testing policy and give any notice it requires, then send the Tester the confirmation (Clauses 2.3 and 2.4).
- Take and test backups of every Target (Clause 4.1). If the Testing is performed within the rules and a system still slows down or fails, the Tester is not liable unless it acted wilfully or with gross negligence (Clause 16.1).
- Tell your IT team, your security monitoring provider and, where relevant, your hosting provider about the Testing Window and the Tester's source addresses, unless you deliberately want an unannounced test. An unannounced test can trigger a real incident response.
- Keep the emergency contact reachable by telephone during all testing hours. The Tester must stop and call within 1 hour if something goes wrong (Clause 6.1).
- Social engineering is switched on. Decide how your staff will be informed and make sure the exercise follows your employment policies. Results are reported by group, not to shame individuals (Clause 3.4).
- Denial-of-service or load testing is switched on. Agree the exact times with your emergency contact and warn your hosting provider in advance, because such tests can break its terms of service (Clause 3.3).
Critical findings, prior compromise and personal data
- The Tester must report each Critical Finding within … hours (Clause 7.1). Act on it immediately; do not wait for the Report.
- If the Tester finds signs that someone has already broken in, or sees personal data exposed, you are the data controller and you decide whether to notify the Personal Data Protection Committee Office. Unless the breach poses no risk to individuals' rights and freedoms, the notice is due within 72 hours after you become aware of it (Personal Data Protection Act section 37(4)), and individuals must also be told where the risk is high. Engage an incident response team if needed; that work is outside this Agreement (Clause 7.2).
- The Tester processes personal data only as a data processor with the limited duties in Clause 8.2 and must delete working data within 30 days after the Report is accepted. If the Tester will handle large volumes of personal data, for example in a white-box test with database access, consider signing a separate, full Data Processing Agreement.
- After the Testing, change every password, key or token listed in the Report (Clause 8.3), and confirm that the Tester removed its tools and test accounts (Clause 5.5).
Report, retest and use of the results
- Comment on the draft Report within 10 Business Days (Clause 9.2). The Tester decides its findings in good faith; you can correct facts, not negotiate ratings away.
- Ask for the free retest within … days after the final Report (Clause 9.3). Fix the highest-severity findings first.
- A penetration test is a snapshot. A clean Report does not prove that the systems are secure, and it is not a certification (Clause 15.2). You may share the Report with auditors, insurers, regulators and customers under confidentiality, but they cannot rely on it against the Tester (Clause 9.4).
Stamp duty and tax
- A penetration testing engagement is a hire of work (Instrument 4 of the Stamp Duty Schedule), and the Tester pays the duty (Clause 12.3): 1 THB for every 1,000 THB or part of 1,000 THB of the Contract Price. On the Contract Price you entered, the duty on the original is the amount the system calculates from the figures entered, and each counterpart carries the amount the system calculates from the figures entered.Because the price is in …, convert it to Thai Baht at the exchange rate on the date of signing and calculate the duty on the Baht amount. If the Agreement is signed electronically, pay through the Revenue Department's e-Stamp Duty system within 15 days after signing. An unstamped agreement cannot be used as evidence in a Thai civil court until the duty and a surcharge are paid.
- A Thai company paying a Thai tester normally withholds 3% of the fee and issues a certificate. If the Tester is abroad, Thai withholding tax on fees paid overseas and self-assessed VAT may apply; take accounting advice before paying, especially because you ticked gross-up.
Signing and disputes
- The Client's signatory must have authority over every Target, because the same person signs the Letter of Authorisation. A company signs through the directors shown in its company affidavit, with the company seal if required.
- Electronic signatures and signed PDF copies are allowed (Clause 21.8). Keep the signed Agreement, the Letter of Authorisation, any third-party consents and the Tester's activity log together; together they prove that the Testing was authorised.
- A Thai court works in Thai, so a Party relying on this Agreement in court must file a certified Thai translation.
Author and sources
Compiled from the notes that accompany the English contract templates on this site, published by Phuwara Krobtaku (ภูวรา ครอบตะคุ), Thai attorney-at-law, licence no. 477/2558. The short answer and summary at the top of this page are put together by the site from the template's clause headings and notes. Statutes are quoted only in the official Thai text: Thai is the only official language of Thai legislation, and an unofficial translation can mislead. Article registry OKC-582424. If you reuse this content, please credit the author and link to the original.
Frequently asked questions
Does a Penetration Testing Agreement need stamp duty in Thailand?
A penetration testing engagement is a hire of work (Instrument 4 of the Stamp Duty Schedule), and the Tester pays the duty (Clause 12.3): 1 THB for every 1,000 THB or part of 1,000 THB of the Contract Price. On the Contract Price you entered, the duty on the original is the amount the system calculates from the figures entered, and each counterpart carries the amount the system calculates from the figures entered.Because the price is in …, convert it to Thai Baht at the exchange rate on the date of signing and calculate the duty on the Baht amount. If the Agreement is signed electronically, pay through the Revenue Department's e-Stamp Duty system within 15 days after signing. An unstamped agreement cannot be used as evidence in a Thai civil court until the duty and a surcharge are paid. A Thai company paying a Thai tester normally withholds 3% of the fee and issues a certificate. If the Tester is abroad, Thai withholding tax on fees paid overseas and self-assessed VAT may apply; take accounting advice before paying, especially because you ticked gross-up.
How should a Penetration Testing Agreement be signed?
The Client's signatory must have authority over every Target, because the same person signs the Letter of Authorisation. A company signs through the directors shown in its company affidavit, with the company seal if required. Electronic signatures and signed PDF copies are allowed (Clause 21.8). Keep the signed Agreement, the Letter of Authorisation, any third-party consents and the Tester's activity log together; together they prove that the Testing was authorised. A Thai court works in Thai, so a Party relying on this Agreement in court must file a certified Thai translation.
What happens if a Penetration Testing Agreement ends up in a dispute in Thailand?
The Client's signatory must have authority over every Target, because the same person signs the Letter of Authorisation. A company signs through the directors shown in its company affidavit, with the company seal if required. Electronic signatures and signed PDF copies are allowed (Clause 21.8). Keep the signed Agreement, the Letter of Authorisation, any third-party consents and the Tester's activity log together; together they prove that the Testing was authorised. A Thai court works in Thai, so a Party relying on this Agreement in court must file a certified Thai translation.
What clauses does a Penetration Testing Agreement on this site include?
Definitions and Interpretation; Engagement and Authorisation; Rules of Engagement; Client Preparations; Conduct of the Testing; Stop Conditions and Emergency Contacts; Critical Findings and Prior Compromise; Data Encountered During Testing; Reports and Retesting; AI and Automated Tools; Fees and Payment; Taxes; Confidentiality of Findings; Ownership of the Report; Warranties and Limits of Testing; Liability; Force Majeure; Termination; Notices; Governing Law and Disputes; General
Thai law cited (official Thai text)
The 13 sections below are quoted from the official Thai text, the only official language of Thai legislation. No translation is given, because an unofficial translation can mislead; check the Royal Gazette before relying on them in court.
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 224
หนี้เงินนั้น ให้คิดดอกเบี้ยในระหว่างเวลาผิดนัดในอัตราที่กำหนดตามมาตรา 7 บวกด้วยอัตราเพิ่มร้อยละสองต่อปี ถ้าเจ้าหนี้อาจจะเรียกดอกเบี้ยได้สูงกว่านั้นโดยอาศัยเหตุอย่างอื่นอันชอบด้วยกฎหมาย ก็ให้คงส่งดอกเบี้ยต่อไปตามนั้น
ส่วนที่ 1 การไม่ชำระหนี้
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 373
ความตกลงทำไว้ล่วงหน้าเป็นข้อความยกเว้นมิให้ลูกหนี้ต้องรับผิดเพื่อกลฉ้อฉล หรือความประมาทเลินเล่ออย่างร้ายแรงของตนนั้น ท่านว่าเป็นโมฆะ
หมวด 2 ผลแห่งสัญญา
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 383
ถ้าเบี้ยปรับที่ริบนั้นสูงเกินส่วน ศาลจะลดลงเป็นจำนวนพอสมควรก็ได้ ในการที่จะวินิจฉัยว่าสมควรเพียงใดนั้น ท่านให้พิเคราะห์ถึงทางได้เสียของเจ้าหนี้ทุกอย่างอันชอบด้วยกฎหมาย ไม่ใช่แต่เพียงทางได้เสียในเชิงทรัพย์สิน เมื่อได้ใช้เงินตามเบี้ยปรับแล้ว สิทธิเรียกร้องขอลดก็เป็นอันขาดไป
หมวด 3 มัดจำและกำหนดเบี้ยปรับ
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 386
ถ้าคู่สัญญาฝ่ายหนึ่งมีสิทธิเลิกสัญญาโดยข้อสัญญาหรือโดยบทบัญญัติแห่งกฎหมาย การเลิกสัญญาเช่นนั้นย่อมทำด้วยแสดงเจตนาแก่อีกฝ่ายหนึ่ง
หมวด 4 เลิกสัญญา
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 387
ถ้าคู่สัญญาฝ่ายหนึ่งไม่ชำระหนี้ อีกฝ่ายหนึ่งจะกำหนดระยะเวลาพอสมควร แล้วบอกกล่าวให้ฝ่ายนั้นชำระหนี้ภายในระยะเวลานั้นก็ได้ ถ้าและฝ่ายนั้นไม่ชำระหนี้ภายในระยะเวลาที่กำหนดให้ไซร้ อีกฝ่ายหนึ่งจะเลิกสัญญาเสียก็ได้
หมวด 4 เลิกสัญญา
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 391
เมื่อคู่สัญญาฝ่ายหนึ่งได้ใช้สิทธิเลิกสัญญาแล้ว คู่สัญญาแต่ละฝ่ายจำต้องให้อีกฝ่ายหนึ่งได้กลับคืนสู่ฐานะดังที่เป็นอยู่เดิม แต่ทั้งนี้จะให้เป็นที่เสื่อมเสียแก่สิทธิของบุคคลภายนอกหาได้ไม่
หมวด 4 เลิกสัญญา
ประมวลกฎหมายแพ่งและพาณิชย์ มาตรา 587
อันว่าจ้างทำของนั้น คือสัญญาซึ่งบุคคลคนหนึ่ง เรียกว่าผู้รับจ้าง ตกลงจะทำการงานสิ่งใดสิ่งหนึ่งจนสำเร็จให้แก่บุคคลอีกคนหนึ่ง เรียกว่าผู้ว่าจ้าง และผู้ว่าจ้างตกลงจะให้สินจ้างเพื่อผลสำเร็จแห่งการที่ทำนั้น
ลักษณะ 7 จ้างทำของ
พ.ร.บ.ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540 มาตรา 4
ข้อตกลงในสัญญาระหว่างผู้บริโภคกับผู้ประกอบธุรกิจการค้า หรือวิชาชีพ หรือในสัญญาสำเร็จรูป หรือในสัญญาขายฝากที่ทำให้ผู้ประกอบธุรกิจการค้า หรือวิชาชีพ หรือผู้กำหนดสัญญาสำเร็จรูป หรือผู้ซื้อฝากได้เปรียบคู่สัญญาอีกฝ่ายหนึ่งเกินสมควร เป็นข้อสัญญาที่ไม่เป็นธรรม และให้มีผลบังคับได้เพียงเท่าที่เป็นธรรมและพอสมควรแก่กรณีเท่านั้น
พระราชบัญญัติ ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540
พ.ร.บ.ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540 มาตรา 8
ข้อตกลง ประกาศ หรือคำแจ้งความที่ได้ทำไว้ล่วงหน้า เพื่อยกเว้นหรือจำกัดความรับผิดเพื่อละเมิดหรือผิดสัญญาในความเสียหายต่อชีวิต ร่างกาย หรืออนามัยของผู้อื่น อันเกิดจากการกระทำโดยจงใจหรือประมาทเลินเล่อของผู้ตกลง ผู้ประกาศ ผู้แจ้งความ หรือของบุคคลอื่นซึ่งผู้ตกลง ผู้ประกาศ หรือผู้แจ้งความต้องรับผิดด้วย จะนำมาอ้างเป็นข้อยกเว้นหรือจำกัดความรับผิดไม่ได้
พระราชบัญญัติ ว่าด้วยข้อสัญญาที่ไม่เป็นธรรม พ.ศ. 2540
พ.ร.บ.ว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. 2550 มาตรา 5
ผู้ใดเข้าถึงโดยมิชอบซึ่งระบบคอมพิวเตอร์ที่มีมาตรการป้องกันการเข้าถึงโดยเฉพาะและมาตรการนั้นมิได้มีไว้สำหรับตน ต้องระวางโทษจำคุกไม่เกินหกเดือน หรือปรับไม่เกินหนึ่งหมื่นบาท หรือทั้งจำทั้งปรับ
พระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. 2550 (เฉพาะมาตราที่ใช้ร่างสัญญา)
พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 มาตรา 37
ผู้ควบคุมข้อมูลส่วนบุคคลมีหน้าที่ ดังต่อไปนี้ (1) จัดให้มีมาตรการรักษาความมั่นคงปลอดภัยที่เหมาะสม เพื่อป้องกันการสูญหาย เข้าถึง ใช้ เปลี่ยนแปลง แก้ไข หรือเปิดเผยข้อมูลส่วนบุคคลโดยปราศจากอำนาจหรือโดยมิชอบ และต้องทบทวน มาตรการดังกล่าวเมื่อมีความจำเป็นหรือเมื่อเทคโนโลยีเปลี่ยนแปลงไปเพื่อให้มีประสิทธิภาพในการรักษา ความมั่นคงปลอดภัยที่เหมาะสม ทั้งนี้ ให้เป็นไปตามมาตรฐานขั้นต่ำที่คณะกรรมการประกาศกำหนด (2) ในกรณีที่ต้องให้ข้อมูลส่วนบุคคลแก่บุคคลหรือนิติบุคคลอื่นที่ไม่ใช่ผู้ควบคุมข้อมูลส่วนบุคคล ต้องดำเนินการเพื่อป้องกันมิให้ผู้นั้นใช้หรือเปิดเผยข้อมูลส่วนบุคคลโดยปราศจากอำนาจหรือโดยมิชอบ (3) จัดให้มีระบบการตรวจสอบเพื่อดำเนินการลบหรือทำลายข้อมูลส่วนบุคคลเมื่อพ้นกำหนด ระยะเวลาการเก็บรักษา หรือที่ไม่เกี่ยวข้องหรือเกินความจำเป็นตามวัตถุประสงค์ในการเก็บรวบรวม ข้อมูลส่วนบุคคลนั้น หรือตามที่เจ้าของข้อมูลส่วนบุคคลร้องขอ หรือที่เจ้าของข้อมูลส่วนบุคคล ได้ถอนความยินยอม เว้นแต่เก็บรักษาไว้เพื่อวัตถุประสงค์ในการใช้เสรีภาพในการแสดงความคิดเห็น การเก็บรักษาไว้เพื่อวัตถุประสงค์ตามมาตรา 24 (1) หรือ (4) หรือมาตรา 26 (5) (ก) หรือ (ข) การใช้เพื่อการก่อตั้งสิทธิเรียกร้องตามกฎหมาย การปฏิบัติตามหรือการใช้สิทธิเรียกร้องตามกฎหมาย หรือการยกขึ้นต่อสู้สิทธิเรียกร้องตามกฎหมาย หรือเพื่อการปฏิบัติตามกฎหมาย ทั้งนี้ ให้นำความใน
พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (เฉพาะส่วนที่ใช้ร่างสัญญา)
พ.ร.บ.ลิขสิทธิ์ พ.ศ. 2537 มาตรา 17
ลิขสิทธิ์นั้นย่อมโอนให้แก่กันได้ เจ้าของลิขสิทธิ์อาจโอนลิขสิทธิ์ของตนทั้งหมดหรือแต่บางส่วนให้แก่บุคคลอื่นได้ และจะโอน ให้โดยมีกำหนดเวลาหรือตลอดอายุแห่งการคุ้มครองลิขสิทธิ์ก็ได้ การโอนลิขสิทธิ์ตามวรรคสองซึ่งมิใช่ทางมรดกต้องทำเป็นหนังสือลงลายมือชื่อผู้โอน และผู้รับโอน ถ้าไม่ได้กำหนดระยะเวลาไว้ในสัญญาโอน ให้ถือว่าเป็นการโอนมีกำหนดระยะเวลาสิบปี
พระราชบัญญัติลิขสิทธิ์ พ.ศ. 2537 (เฉพาะมาตราที่ใช้ร่างสัญญา)
ประมวลรัษฎากร มาตรา 118
ตราสารใดไม่ปิดแสตมป์บริบูรณ์ จะใช้ต้นฉบับ คู่ฉบับ คู่ฉีก หรือสำเนาตราสารนั้นเป็นพยานหลักฐานในคดีแพ่งไม่ได้ จนกว่าจะได้เสียอากรโดยปิดแสตมป์ครบจำนวนตามอัตราในบัญชีท้ายหมวดนี้ และขีดฆ่าแล้ว แต่ทั้งนี้ ไม่เป็นการเสื่อมสิทธิที่จะเรียกเงินเพิ่มอากรตามมาตรา 113 และมาตรา 114
บทบัญญัติ (ถ้อยคำตามเว็บกรมสรรพากร)