You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 12, 2023

Vietnam 2022 ICT Legislation Year in Review

The year 2022 witnessed a dynamic environment in the development of information and communications technology (ICT) policy in Vietnam. The following are some highlights of remarkable legislative developments in the ICT space from the past year, and some notes on key draft laws and regulations that are in the pipeline for 2023.

1. Telecommunications

Although it has helped Vietnam develop modern telecommunications network infrastructure and a diversified and competitive telecom market with a variety of services, Vietnam’s Telecom Law, which has been in effect since 2010, has posed problems and inadequacies in meeting today’s more complex evolution of new service types and new business models as well as the trend of convergence of telecom, information technology, and automation.

Accordingly, the Ministry of Information and Communications (MIC) has been working to replace the existing Telecom Law, with a Draft Telecom Law made available for public consultation from October 27 to December 27, 2022 (the Vietnamese version can be accessed here).

The primary amendment of the Telecom Law focuses on widening the scope of application to regulate data center and cloud computing services. Data center services include data center space rental services, server rental services, and data storage space rental services. Cloud computing services include services providing server resources, storage capacity, and networks (IaaS services); services that provide the ability to create, develop, manage, and operate software, including applications (PaaS services); and software delivery services, including applications (SaaS services).

According to the Draft Telecom Law, it could be interpreted that all providers of data center services and IaaS cloud computing services, whether onshore or offshore, must obtain a permit to provide the services by registration with the MIC via its online portal; while PaaS and SaaS cloud computing services are exempted from this requirement.

In addition, the Draft Telecom Law adds new content related to the management of OTT telecom services, or “information communication service without using telecom number storage” according to the language of the Draft Telecom Law (for example, WhatsApp, Zalo, Viber, Line, etc.). These services have not been regulated before and for a long time the MIC has attempted to regulate these services via a draft Circular on OTT telecom services, without success. This content is now put into the Draft Telecom Law but with much lighter requirements compared to the previous draft Circular. The Draft Telecom Law allows cross-border provision of OTT telecom services to Vietnam with regulations on service providers’ responsibilities in service provision as well as requirements for notification to the MIC. The content for notification includes representative name and contact information (phone, email). Forms and procedures for notification must comply with the government’s regulations.

Another new area contemplated in the Draft Telecom Law which is worthy of mention is telecom wholesale and retail services. The Draft Telecom Law supplements obligations of telecom companies with a dominant position in the market for important retail services that require state management of competition, as well as obligations of telecom enterprises providing telecom wholesale services with the aim of creating favorable conditions for enterprises to negotiate and buy telecom traffic, and to promote the wholesale market and contribute to promoting competition in the retail market through the wholesale market.

The Draft Telecom Law is scheduled to be discussed by the National Assembly in May 2023 and submitted for approval in October 2023.

2. Cybersecurity

The long-awaited Decree 53 on the implementation of the Cybersecurity Law (which took effect in 2019) was issued on August 15, 2022, with an effective date of October 1, 2022. Decree 53 provides further guidance on a number of key issues, including:

  • Data localization requirements which may create potential troubles for not only overseas enterprises but also domestic enterprises;
  • Takedown of illegal online content with corresponding responsibilities of the Ministry of Public Security (MPS), the Ministry of Defense, and the MIC;
  • Collection of electronic data relating to illegal activities in cyberspace to serve the purposes of investigation and handling of such activities according to stipulated conditions and procedures;
  • Suspension or stoppage of information system operation, and/or revocation of domain names when the operation of the information system violates the laws on national security and cybersecurity, or when the information system is being used for the purpose of infringing upon national security or social order and safety; and
  • Responsibilities of relevant stakeholders in coordinating and assisting the authorities in preventing and handling the violations, including cross-border violations.

Regarding the controversial issue of data localization requirements, it is worth noting that domestic enterprises may be impacted more than overseas enterprises.

For overseas enterprises, only those fulfilling all the following conditions are subject to the MPS’s decision to store regulated data and establish a branch or representative office in Vietnam within a grace period of 12 months:

  1. Providing services falling within 10 enumerated types of regulated services;
  2. Collecting, exploiting, analyzing, and/or processing regulated data; and
  3. Have received a warning from the Department for Cybersecurity and Prevention of High-Tech Crime (A05) under the MPS but have not taken any measures for avoiding, dealing with, fighting against, or preventing the breach mentioned in the notification, or have resisted, obstructed, or ignored requests from the relevant authorities.

For domestic enterprises, the requirements are more stringent. Without further clarification of the MPS, nearly all online domestic service providers which collect, use, analyze, and/or process regulated data are required to store the regulated data in Vietnam without triggering conditions and without a grace period. For more information of the Decree 53, please refer to our previous articles here and here.

3. Data Privacy

The government recently released Resolution 156/NQ-CP on December 6, 2022, which requires the MPS to quickly finalize the draft Decree on Personal Data Protection (draft PDPD) and submit it to the government for submission to the National Assembly Standing Committee for comments before the government promulgates it. Therefore, it is expected that the PDPD could be issued in 2023. Within 2022, there was no official updated version of the draft PDPD available for public assessment of the major changes from the previous publicly accessible version. For more information of the main content of the draft PDPD, please see our previous articles here, here, and here.

4. OTT TV Services & VOD Films

Decree 71 was issued on October 1, 2022, with an effective date of January 1, 2023, to amend the prior Decree 06 on the Management, Provision, and Use of Radio and Television Services. The new decree will have a major impact on over-the-top (OTT) television services and on-demand content (VOD) in Vietnam. Although there are still ambiguities in the wording of Decree 71, the government has expressed a clear intention to regulate the cross-border provision of foreign OTT TV services, including provision via Internet applications. Accordingly, overseas companies might no longer be eligible to provide OTT pay TV services to users in Vietnam on a cross-border basis as they are currently doing with regard to OTT VOD, but may now have to establish a company in Vietnam or cooperate with a licensed Vietnamese pay TV service provider to provide such services.

The MIC has recently taken their first moves to enforce the new requirements under Decree 71. The Authority of Broadcasting and Electronic Information (ABEI) under the MIC has announced the enforcement actions via two official letters on their website, whose main points are summarized as follows:

  • On January 5, 2023, the MIC sent an official letter to a number of foreign OTT service enterprises, requesting a report by January 15, 2023, on the plan to carry out the procedures for applying for a license to provide pay radio and television services The official letter clearly states that if the enterprises continue to maintain the current service provision and do not comply with the provisions of Decree 71 (i.e., do not establish an enterprise in Vietnam to apply for the pay TV license or do not comply with other obligations of local service providers), they will be administratively sanctioned according to the provisions of Decree No. 119/2020/ND-CP dated October 7, 2020.
  • Via official letter No. 6272/BTTTT-PTTH&TTDT dated December 31, 2022, the ABEI has also requested businesses importing, manufacturing, and distributing smart TVs in Vietnam to review the legality of pre-installing unlicensed OTT apps in smart TVs and/or including shortcut buttons on remote controls of smart TVs allowing users to easily access to unlicensed OTT apps, to ensure that they do not violate the provisions of Decree 71.

Interestingly, Decree 71 does not differentiate between provision of film-only VOD from the provision of other types of VOD, which leads to a potential inconsistency between the state management of film-only versus other types of VOD, i.e., more specifically, there may be a potential inconsistency between Decree 71 and the Cinema Law and its guiding decree, Decree No. 131/2022/ND-CP promulgated by the government on December 31, 2022 (“Cinema Decree”). We discuss the new Cinema Decree in more detail in this article.

According to Decree 71, films are specified as a type of “on-demand radio and television content,” and the provision of “on-demand radio and television content” via the internet/internet applications falls within the definition of “TV services,” which are subject to the same requirements imposed on other types of TV services, including local establishment and licensing requirements.

Under the Cinema Law and the Cinema Decree, however, there is no such requirement for foreign providers of VOD films. According to the Cinema Decree, offshore enterprises are allowed to disseminate their films in Vietnam’s cyberspace without having to establish a company in Vietnam and to obtain a license. The film disseminators must only comply with the obligation to self-rate their films according to the government’s guidance.

Given the foregoing potential inconsistency in application of Decree 71 and the Cinema Law, it is strongly recommended that the government should clearly exempt the provision of films on demand in cyberspace from the governing scope of Decree 71 and clarify that such provision is subject to the requirements under the Cinema Law and the management of Ministry of Culture, Sports and Tourism. For further information on Decree 71, please refer to our previous article here.

5. E-Commerce

The government has entrusted the MIC to draft a new Law on E-Transactions, because after 17-years, the existing law has shown shortcomings in the new era of rapid technology and e-commerce development. The Minister of the MIC emphasized that the Law on E-Transactions should be amended to reflect and fully govern current industry technologies, including those relating to the digital environment’s traditional transactions, but with varying degrees of reliability, different costs, and different complexity. The revised law must ensure a wide scope of application and lower costs and less complexity of e-transactions compared to traditional transactions.

Accordingly, the Draft Law on E-Transactions (version 4 of which is publicly accessible) widens the scope of application to attempt to cover all areas of transactions. It retains key principles of the current law, but also provides more comprehensive regulations relating to e-contracts, e-signatures/digital signatures, and data messages. Furthermore, it provides new regulations on e-certificates, trust services and information systems serving e-transactions (digital platforms). For more information, please refer to our previous article here.

The Draft Law on E-Transactions was reviewed for the first reading by the National Assembly in November 2022; however, later draft versions are not available for public access. This draft law is scheduled for approval on the second reading by the National Assembly in May 2023.

RELATED INSIGHTS​ 

August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public
August 10, 2026
Thailand has finalized its social media KYC (“know your customer”) rules under Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers (No. 2), which was published in the Government Gazette on May 5, 2026, and will take effect on November 1, 2026. While an early draft of the notification proposed requiring social media platforms to arrange identification of every user account, the final notification is significantly more targeted, focusing on paid online advertising and advertiser identity verification. Though the regulatory initiative primarily aims to combat online fraud and technology-related crimes, it also has important consequences for intellectual property enforcement, because the verified platform records that will be generated under the new requirements can help IP rights holders to identify anonymous online infringers. Key Regulatory Mandates The notification requires social media service providers to verify the identity of advertisers before their paid advertisements are published and disseminated in Thailand through social media, regardless of whether the advertising fees come from the advertisers or third parties. Verification of an advertiser is valid for one year, after which verification would have to be performed again before the platform could publish additional paid advertisements from the advertiser. Permitted verification methods are specified under the notification. A platform may verify an advertiser by checking identity evidence and confirming the connection between the advertiser and that identity evidence, with the notification giving facial comparison against certain government-issued identity documents as an example. Alternatively, platforms may verify advertisers through a digital identity verification and authentication system with an identity-proofing assurance level not lower than the level prescribed by Thailand’s Electronic Transactions Commission. The notification further requires platforms to retain only the advertiser’s information necessary to identify the advertiser, beginning from the start of the advertising activity and for
August 10, 2026
On July 31, 2026, Thailand’s Big Data Institute (BDI) launched a public consultation on the principles of a proposed new data-sharing law, with comments accepted until August 31, 2026. If enacted, the law would establish Thailand’s first comprehensive framework for government and private-sector data sharing, creating a systematic, secure, and transparent regime to support analytics, policymaking, research, and innovation. Central Data-Sharing Platform The draft law establishes a central system for data sharing, managed by the BDI. Government agencies would be required to connect to the BDI’s Data Integration and Intelligence Platform (also referred to as D2), in accordance with the BDI’s rules and procedures. Five Dimensions of Data Sharing The draft law covers five key types of data sharing between government (G), businesses (B), and consumers (C): G2B: Private organizations may request government data specifically for research and development purposes. The BDI will assess the applicant’s data governance, security, and privacy capabilities whether such measures meet prescribed standards before forwarding the request to the relevant government agency within 90 days. Any dispute may be escalated to a newly established Data-Sharing Promotion Committee for final determination. G2G: Government agencies may request data from other agencies through the central system. The data-holding agency must respond within 90 days, taking legality, necessity, proportionality, public interest, and personal data protection into account. Disputes may be referred to the Data-Sharing Promotion Committee for adjudication. B2G: In emergency situations involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society may require private entities to provide data through the central data-sharing system. Government agencies must specify the data requested, demonstrate its necessity and expected benefits, and request only data reasonably available to the data holder. Requests for personal data must be limited to the minimum amount necessary. B2C: Royal decrees may
August 10, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) recently released draft guidance on records of processing activities (ROPA) for personal data controllers and processors under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft guidance, which was presented to the public on July 7, 2026, addresses both controller records of collection, use, and disclosure of personal data and processor records of processing activities carried out on behalf of controllers. If implemented, the guidance will significantly expand organizational expectations for ROPA preparation, maintenance, and use across all sectors. Key Takeaways The draft guidance contains several important implications for organizations subject to the PDPA: ROPA reframed as a core accountability tool. The guidance elevates ROPA from an administrative record to a central accountability mechanism, connecting controller duties with recordkeeping obligations. ROPA as a source for privacy notices and governance documents. ROPA should serve as the primary source for privacy notices and align with consent management, retention schedules, DPIAs, incident response plans, and vendor contracts. Expanded scope across all activities. ROPA must cover all processing activities across the organization—including security, finance, HR, and external contractors—with correct controller or processor classification for each. Ongoing maintenance and auditability. ROPA must be updated for any change to systems, purposes, or processors, reviewed at least annually, and maintained with version control and a designated owner. Enhanced vendor, processor, and cross-border transfer requirements. Organizations must document all processors, external recipients, and cross-border transfers, specifying purposes, access scope, and destination countries. Linkage with risk assessment, DPIAs, and LIAs. ROPA should assign risk levels to each activity and identify when data protection impact assessments (DPIAs) or legitimate interests assessments (LIAs) are required, functioning as a risk-management tool. ROPA and data breach readiness. Incomplete ROPA can delay breach response and notification. Organizations should map data flows, vendors,