Drone Association Thailand

สมัครสมาชิก☰

Governance & Authorisation

English version of this page. อ่านฉบับภาษาไทย · Services: Security Services

Drone Association Thailand (DAT) operates under the oversight of Thai state regulators and positions itself as an intermediary between unmanned aircraft operators and government agencies, per the objectives registered at its incorporation on 16 December 2022. This page sets out how we work with regulators, where the boundaries of our work sit, and the principles governing how we publish security content.

The regulatory framework we operate under

Unmanned aircraft operations in Thailand are regulated by the Civil Aviation Authority of Thailand (CAAT), covering aircraft registration, remote pilot registration, and no-fly zone declarations. The association holds no regulatory authority of its own. Our role is to track announcements, explain them to operators, gather operational impact from the field, and present it back to the regulator through formal channels.

Tracking and publishing regulatory announcements

Since September 2025 we have tracked and published explanatory coverage of eleven CAAT announcements controlling unmanned aircraft operations, so operators understand their legal position before flying.

We also maintain a no-fly zone map and a restricted airspace summary so operators can verify a location before flying.

Participation in regulatory processes

We engage in policy formation through formal channels rather than acting unilaterally.

Board and advisers

The association’s advisory board includes senior figures from the security and legal professions, who set direction and review the boundaries of the association’s work. Full listing on our board and advisers page.

Member verification and accountability

Members complete identity verification before receiving full privileges. The membership system records document verification status and NFC card verification, which allows the association to identify users connected to an incident when lawfully requested by an authority with jurisdiction.

Scope and authorisation

The following principles apply to all work touching security or safety.

  • We act only on assignment. Any analysis or assessment involving another party’s systems or property is carried out at the request of, or under assignment from, the system owner or an authority with jurisdiction, with scope agreed in writing before work begins.
  • A human is accountable at every stage. Automated tooling and AI systems are used to accelerate analysis, but decisions, verification of results, and reporting are made by a named responsible person.
  • We do not act outside scope. We do not test, scan, or access systems outside the agreed list. If something anomalous is found outside scope during an engagement, we stop and notify the client before proceeding.
  • Data handling and destruction. Data obtained during an engagement is treated as the client’s confidential information and handled under terms agreed in advance.
  • No political involvement, per the association’s registered constitution.

Security publishing principles

We publish vulnerability and threat analysis under Cybersecurity. The following principles apply to every article without exception.

  • No payloads or attack procedures. Articles explain vulnerability mechanics at the level a system owner needs to assess risk and plan a response, but do not supply commands or code that are directly weaponisable.
  • Primary sources cited. Every article cites the vendor advisory, NVD entry, or a named research team’s report, with direct links so readers can verify independently.
  • Fact separated from interpretation. Where circulating figures are inaccurate — for instance the count of systems merely exposed being reported as confirmed victims — the article states the distinction explicitly.
  • No compromise claimed without evidence. Finding a vulnerable version means exposure exists; it is not evidence of a breach.
  • Corrections are dated. When a vendor or agency revises information, the article is amended and the review date recorded.

Privacy and data use

Collection and use of personal data from members and site visitors is governed by the association’s privacy policy.

Contact and reporting

To report an error in our content, disclose a vulnerability affecting association systems, or discuss the scope of a possible collaboration, use our contact page. Formal complaints can be filed through our complaints page.

Scroll to Top