You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 20, 2025

A Closer Look at Vietnam’s Decree 147 on Internet Services and Online Information

Vietnam’s Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (Decree 147) was issued on November 9, 2024, and came into effect on December 25, 2024. Decree 147 represents a more stringently regulated digital landscape in Vietnam, creating challenges not only for offshore service providers offering cross-border services but also for onshore providers. As these new regulations impose stricter requirements, particularly in areas like content control, user authentication, data storage, and service license/notification, companies will need to adapt quickly to maintain compliance and minimize legal risks.

The following are some of the key topics covered by Decree 147.

[Note: Shortly after the issuance of Decree 147, Vietnam began a government restructuring process, with the aim of streamlining the government by consolidating and eliminating various ministries and agencies. Thus, the decree’s references to authorities such as the Authority of Broadcasting and Electronic Information (ABEI) and the Ministry of Information and Communications (MIC) are subject to change.]

1. Cross-Border Information Provision

Cross-border information provision is defined broadly as the provision by overseas organizations and individuals of information and online information content services for service users in Vietnam to access or use. This wide-ranging definition encompasses various types of cross-border services, including social network services, online game services, and app store services. However, cross-border provision of online game services remains prohibited under Decree 147 (see further details below).

Offshore providers of services on a cross-border basis who lease data storage in Vietnam or meet a threshold of 100,000 or more total visits per month from Vietnam for six consecutive months (“regulated cross-border providers”) must adhere to stricter requirements. Specifically, they are required to, among other requirements:

  • Notify the relevant authority of their contact information, including the location of the main server providing the service, within 60 days of reaching the total visit threshold.
  • Inspect, monitor, prevent, and remove any content, services, and applications that violate the law within 24 hours from the time of a request from the relevant authority, and within 48 hours of receiving complaints from Vietnamese users regarding content, services, and applications that violate Article 8 of the Cybersecurity Law (which lists a wide range of prohibited acts in cyberspace, such as cyberterrorism, spreading malware, and advertising or trading in banned goods/services).
  • Store personal data of users from Vietnam, such as full name, date of birth, email, and Vietnamese mobile phone number (or ID number), and delete this data when the storage period expires.
  • Provide information of users from Vietnam to the relevant authority upon request for investigation and for law enforcement purposes.
  • Authenticate social network user accounts via users’ Vietnamese mobile phone numbers or ID numbers if they do not have Vietnamese mobile phone numbers, or if they use the livestream feature for commercial purposes; and ensuring that only verified accounts can post information (write posts or comments, livestream) and share content on social networks.
  • Classify and display warnings of content that is not suitable for children.
  • Receive and handle complaints from service users.
  • Provide tools for searching and scanning content as requested by the relevant authority.
  • Report annually to the relevant authority on their service provision to users from Vietnam and on an ad hoc basis regarding matters of national security, social order, and emergency upon the authority’s request.

Failure to comply with these obligations allows the relevant authority to enforce technical measures to block non-compliant content, services, and applications, as well as impose administrative penalties.

Only cross-border service providers who have notified the relevant authority of their contact information are allowed to provide livestream features or provide revenue-generating activities in any form.

2. Social Network Services

Regulated offshore social network service providers will be required to meet the obligations outlined above on cross-border information provision.

Onshore social network services, offered by organizations or enterprises with legal status in Vietnam, are categorized as either “high-visitor” or “low-visitor” based on the number of regular visitors. The high-visitor category includes social networks with total monthly visits of 10,000 or more (based on a monthly average over six consecutive months) or with more than 1,000 regular users in a month (“regular” is not further defined). High-visitor onshore social network service providers are required to obtain a license from the relevant authority to operate, while low-visitor providers must obtain a notification confirmation from the authority to provide social network services.

Only licensed onshore providers are permitted to provide livestream features or engage in revenue-generating activities of any kind. Therefore, if a low-visitor onshore provider intends to offer livestream features or revenue-generated services, it must apply for a social network service license.

Onshore social network service providers face stricter requirements than regulated offshore social network service providers as they must additionally meet obligations including having at least one server in Vietnam to serve investigations and information provision at the request of the relevant authority, connecting to the monitoring system of the relevant authority for statistics and user access monitoring, and being subject to inspections by the authority.

Within 90 days from the effective date of Decree 147 (i.e., by March 25, 2025), both onshore and regulated offshore social network service providers are required to authenticate the identities of their active users. Additionally, within this same timeline, licensed onshore social network service providers are required to review and report to the relevant authority the number of total visits per month from Vietnam for six consecutive months, as well as the number of regular users per month.

Both onshore and offshore social network service providers must temporarily or permanently block social network accounts, community pages, community groups, and content channels that frequently violate the law. Temporary blocking will be applied at the relevant authority’s request when these accounts, community pages/groups, or channels have been found to violate the law at least five times within a 30-day period or at least 10 times within a 90-day period. The temporary block must be implemented within 24 hours of the relevant authority’s request and will last from 7 to 30 days, depending on the number and severity of the violations. A permanent block will be enforced when such accounts, community pages/groups, or channels publish illegal content that impacts national security or have previously been temporarily blocked at least three times as per request from the relevant authority.

If onshore social network service providers do not comply with the request of the relevant authority, the authority will suspend the provision of social networking services or revoke the license.

3. Online Game Services

Decree 147 expressly provides that offshore entities providing online game services to users in Vietnam must establish an enterprise in compliance with the decree and with regulations on foreign investment to provide such services. As a result, the cross-border provision of online games remains prohibited.

Online games are still categorized into four types: G1 games have interaction among multiple players via the game server; G2 games only have interaction between players and the game server; G3 games have interaction among multiple players without interaction between players and the game server; and G4 games are downloaded from the internet without interaction among players or between players and the game server.

Enterprises may provide G1 games after obtaining a license to provide G1 game services and a decision on release of a G1 game. Meanwhile, to provide G2, G3, and G4 games, enterprises must obtain a certificate of game service provision and a notification confirmation of G2, G3, or G4 game release. The license to provide G1 game services and certificate of game service provision for G2, G3 and G4 game services have a 10-year maximum duration while the decision and notification confirmation of game release has a 5-year maximum duration.

Decree 147 explicitly introduces regulations that prohibit the release of online games that feature content and scenarios resembling prizewinning games in casinos or games using images of playing cards. This regulation is designed to prevent transformation of online games into gambling activities in the virtual realm.

The main responsibilities of online game service providers include:

  • Having at least one server in Vietnam to serve the purposes of investigations by the relevant authority and handling of user complaints.
  • Having a website that introduces and provides services, displaying required information such as age-based game classification, rules for handling complaints and disputes, and details about the service provider.
  • Implementing measures to mitigate the negative impacts of each game, including registering, storing, authenticating, and managing player content and information, and ensuring that only players who provide complete and accurate information can participate, and players are warned about the effects of excessive gameplay.
  • Implementing technical measures to manage forums, shared content, and interactions between players.
  • Not advertising online games without a decision on G1 game release or notification confirmation of G2, G3, or G4 game release.
  • Submitting service provision reports regularly every six months and on an ad hoc basis when requested by the relevant authority.
  • Being subject to inspections, examinations, and enforcement actions by the relevant authority.
  • Connecting to legitimate payment methods only.
  • Storing player information for the duration of service use and for six months after a player stops using the service. Providers must also establish a system to connect to the national population database to verify player information upon request by the relevant authority.

4. App Store Services

Regulated cross-border app store service providers will be required to meet the obligations outlined above for cross-border information provision. Additionally, they are required to remove any apps that violate the law within 24 hours of receiving a request from the relevant authority; comply with Vietnamese payment regulations; and ensure that any online game service providers offering services to users in Vietnam provide the decision on G1 game release or notification confirmation of G2, G3, G4 game release before uploading their games to the app store.

5. Telecom, Internet, Web Hosting, Data Center, and Telecom Application Services

Telecom, internet, web hosting, data center and telecom application service providers are required to report to the relevant authority within 24 hours of self-discovery or receipt of feedback or complaints from users about content, services, and applications that violate Article 8 of the Cybersecurity Law; remove infringing content within 24 hours of request from the relevant authority; and handle requests and complaints about intellectual property in accordance with intellectual property laws. Additionally, they are required to submit annual reports to the relevant authority on data storage rental services provided in Vietnam to foreign entities for providing cross-border information to Vietnamese users, as well as ad hoc reports when requested by the relevant authority.

Telecom and internet enterprises must also, among other obligations:

  • Implement necessary technical measures to block access to content, services, and applications that violate the law within 24 hours of receiving a request from the relevant authority, e.g., Department of Cybersecurity and High-Tech Crime Prevention (A05) of the Ministry of Public Security (MPS).
  • Implement measures to monitor, collect, and detect information that violates the law at the request of the relevant authority (for violations of copyright and intellectual property, in compliance with intellectual property law).
  • Provide information and data related to telecom and internet subscribers suspected of violations to enable accurate identification of offenders, upon request from the relevant authority, e.g., A05 under the MPS.
  • Refuse, suspend, or terminate connections to online games without proper licenses or certificates to provide game services or decisions/notification confirmations for game release.
  • Comply with the relevant authority’s requests to coordinate, report, and carry out other measures as requested by the authority.

6. Public Internet Access Points

Owners of public internet access points in hotels, restaurants, airports, coffee shops, and other public spaces who offer paid internet access services must register as internet agency businesses and sign internet agency contracts, while those offering the services for free are not required to do so.

Internet agents are required to display an “internet agent” sign with their registration number. If the location also serves as a public online gaming point or public internet access point, this information must also be clearly indicated on the sign. When providing online game services, internet agents also have the responsibilities of an owner of a public online gaming point. Additionally, they must not organize or allow internet users to use computer features at their business location to perform prohibited acts.

RELATED INSIGHTS​ 

July 14, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has published guidelines establishing a risk-based framework for the responsible use of artificial intelligence by telecom licensees. Released on July 2, 2026, the Guidelines on the Use of Artificial Intelligence for Telecommunications Services address governance structures, ethical principles, lifecycle management, and consumer protection obligations. Scope and Legal Context The nonbinding guidelines apply to holders of telecom business licenses under Thailand’s telecom licensing laws, but only with respect to the use of AI in providing licensed telecom services. Entities without such licenses are not directly subject to the guidelines, though they may be affected as third-party AI solution providers to licensees. The guidelines supplement and should be read alongside existing laws, including the Cybersecurity Act, the Personal Data Protection Act (PDPA), the Computer Crime Act, and the NBTC Notification regarding Measures to Protect Telecommunications Service Users’ Rights Regarding Personal Data, Privacy Rights, and Freedom of Telecommunications, as well as forthcoming AI governance legislation being drafted by the ETDA. AI Governance Structure Licensees are expected to establish committees, working groups, or designated officers at both policy and operational levels to set strategic direction for AI use, formulate governance policies and tools, and oversee risk management. Roles, responsibilities, and accountability should be clearly defined for all personnel across every stage of the AI lifecycle—including for third-party AI solution providers and outsourced service providers, whose obligations should be explicitly documented in service agreements. Core Principles The guidelines identify six core principles that licensees should adhere to when deploying AI: Compliance with laws, ethics, and international standards: AI should respect privacy, dignity, and human rights, and content filtering for inputs and outputs should be considered. For example, the AI should not be designed and developed to be used in generating false information, supporting illegal activities, or causing
July 10, 2026
Vietnam has taken a significant step in regulating its e-commerce sector with the issuance of a new decree guiding the country’s recently enacted Law on E-Commerce. Decree No. 248/2026/ND-CP, issued on June 30, 2026, and taking effect the following day, addresses mandatory platform policies, registration requirements for offshore platforms, additional obligations on platform operators, and market access conditions for foreign investors. Mandatory Policy Contents The decree sets out detailed guidance on the required contents of various platform policies, covering pricing, payment, display priority, livestream sales, delivery, returns, method of service provision, and service termination and refunds. Clarification of Obligations for Platform Operators The decree provides clarification of the obligations applicable to platform operators. Notably, intermediary e-commerce platform operators with online ordering functions must: Collect specific information to implement electronic identity verification of sellers; Cooperate with regulators by reporting online through the state e-commerce management system and by blocking, suspending, or removing content upon request of a competent authority; Maintain a mechanism to store contract data, including price, product or service information, and parties’ information, for at least three years from the date of contract conclusion; and If qualifying as a “large digital platform” under consumer protection law, maintain an online system for receiving and handling complaints and requests, and comply with enhanced content-removal requirements. Registration Requirements for Offshore Platforms Offshore e-commerce platforms, whether direct-sales, intermediary, social-network-based, or integrated, that conduct e-commerce activity in Vietnam must register with the Ministry of Industry and Trade if the platform: Allows Vietnamese-language selection; Uses a “.vn” domain; or Reaches 100,000 or more transactions with Vietnam-based buyers within a calendar year. Notably, the registration requirement now captures not only traditional intermediary platforms, but also direct-sales platforms. Foreign Investment Conditions Foreign investors holding a controlling interest in an intermediary e-commerce platform, a social media platform
July 8, 2026
On July 7, 2026, the Trade Competition Commission of Thailand (TCCT) issued a press release announcing the establishment of two new subcommittees designed to intensify oversight of digital platforms and modern trade businesses. The formation of the digital platform subcommittee marks a significant escalation in competition enforcement following the TCCT’s Guidelines on Multi-Sided Platforms and E-Commerce Businesses, which took effect on March 25, 2026. Platform operators, sellers, and related service providers should expect heightened regulatory scrutiny and potential investigations into practices already flagged under the March guidelines. Two Dedicated Enforcement Bodies The first new body is the digital platform subcommittee—formally the Subcommittee on Supervision, Monitoring, and Prevention of Trade Conduct in Digital Platform Business. It is tasked with driving intensive oversight of digital platform businesses. It will coordinate with government agencies, the private sector, business operators, and other relevant stakeholders to supervise and prevent trade conduct that may affect competition, and to promote free and fair competition in the digital platform sector. The subcommittee will be composed of TCCT members and representatives from the Department of Internal Trade. The second body—the Subcommittee on Determining Guidelines and Action Plans Concerning Competition Conditions in Modern Wholesale and Retail Business—will study, analyze, and monitor market structure in modern wholesale and retail businesses, compile databases to analyze retail business concentration, assess impacts on small-scale operators, and propose supervisory measures for the retail sector. TCCT members will serve on the subcommittee alongside experts from government and private organizations, including the Office of Industrial Economics, the Office of Small and Medium Enterprises Promotion, the Thai SME Federation, and the Thai SME Council. Operational Impact for Industry Participants These subcommittees provide the TCCT with a focused mechanism to investigate various trade practices deemed unfair, and the TCCT has authority under the Trade Competition Act to issue cease-and-desist
July 6, 2026
Vietnam has introduced an official list of high-risk AI systems, triggering more stringent compliance obligations for developers, suppliers, and deployers operating in the country. On June 30, 2026, the prime minister issued Decision No. 33/2026/QD-TTg (Decision 33), which establishes the List of High-Risk AI Systems under the Law on Artificial Intelligence (AI Law) and Decree No. 142/2026/ND-CP (Decree 142). Decision 33 takes effect on August 15, 2026. Decision 33 is significant because only AI systems included on the list will be subject to the heightened compliance obligations applicable to high-risk AI systems under the AI Law and Decree 142. These include, among others, local presence requirements for foreign providers, mandatory conformity assessment before deployment, comprehensive risk management and data quality documentation, and strict liability for damages even when the provider is fully compliant. Decision 33 also specifies the applicable conformity assessment pathway for each listed system, indicating whether the system must undergo mandatory third-party conformity certification before being placed into use, or whether the provider may self-assess conformity or voluntarily engage a registered or recognized conformity assessment body. Which AI Systems Are Covered? Decision 33 identifies high-risk AI systems across six sectors—the key attributes of which are summarized below. Education: AI systems used for automated assessment, learner ranking, behavioral monitoring, or generating educational content from uncontrolled data sources. Ethnic affairs and religion: AI systems used to automatically score, classify, or rank applications for government ethnic policies; approve or reject regulatory applications; suspend benefits on suspicion of fraud; allocate budgets; or infer and classify individuals by ethnicity or religion for administrative purposes. Healthcare: AI-assisted surgical systems and autonomous AI-powered surgical robots. Banking: AI systems that autonomously conduct electronic banking transactions or make credit approval decisions. Judicial proceedings: Certain large-scale biometric identification systems used in public-interest civil proceedings. Transport: Thirty-one categories