You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 20, 2025

A Closer Look at Vietnam’s Decree 147 on Internet Services and Online Information

Vietnam’s Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (Decree 147) was issued on November 9, 2024, and came into effect on December 25, 2024. Decree 147 represents a more stringently regulated digital landscape in Vietnam, creating challenges not only for offshore service providers offering cross-border services but also for onshore providers. As these new regulations impose stricter requirements, particularly in areas like content control, user authentication, data storage, and service license/notification, companies will need to adapt quickly to maintain compliance and minimize legal risks.

The following are some of the key topics covered by Decree 147.

[Note: Shortly after the issuance of Decree 147, Vietnam began a government restructuring process, with the aim of streamlining the government by consolidating and eliminating various ministries and agencies. Thus, the decree’s references to authorities such as the Authority of Broadcasting and Electronic Information (ABEI) and the Ministry of Information and Communications (MIC) are subject to change.]

1. Cross-Border Information Provision

Cross-border information provision is defined broadly as the provision by overseas organizations and individuals of information and online information content services for service users in Vietnam to access or use. This wide-ranging definition encompasses various types of cross-border services, including social network services, online game services, and app store services. However, cross-border provision of online game services remains prohibited under Decree 147 (see further details below).

Offshore providers of services on a cross-border basis who lease data storage in Vietnam or meet a threshold of 100,000 or more total visits per month from Vietnam for six consecutive months (“regulated cross-border providers”) must adhere to stricter requirements. Specifically, they are required to, among other requirements:

  • Notify the relevant authority of their contact information, including the location of the main server providing the service, within 60 days of reaching the total visit threshold.
  • Inspect, monitor, prevent, and remove any content, services, and applications that violate the law within 24 hours from the time of a request from the relevant authority, and within 48 hours of receiving complaints from Vietnamese users regarding content, services, and applications that violate Article 8 of the Cybersecurity Law (which lists a wide range of prohibited acts in cyberspace, such as cyberterrorism, spreading malware, and advertising or trading in banned goods/services).
  • Store personal data of users from Vietnam, such as full name, date of birth, email, and Vietnamese mobile phone number (or ID number), and delete this data when the storage period expires.
  • Provide information of users from Vietnam to the relevant authority upon request for investigation and for law enforcement purposes.
  • Authenticate social network user accounts via users’ Vietnamese mobile phone numbers or ID numbers if they do not have Vietnamese mobile phone numbers, or if they use the livestream feature for commercial purposes; and ensuring that only verified accounts can post information (write posts or comments, livestream) and share content on social networks.
  • Classify and display warnings of content that is not suitable for children.
  • Receive and handle complaints from service users.
  • Provide tools for searching and scanning content as requested by the relevant authority.
  • Report annually to the relevant authority on their service provision to users from Vietnam and on an ad hoc basis regarding matters of national security, social order, and emergency upon the authority’s request.

Failure to comply with these obligations allows the relevant authority to enforce technical measures to block non-compliant content, services, and applications, as well as impose administrative penalties.

Only cross-border service providers who have notified the relevant authority of their contact information are allowed to provide livestream features or provide revenue-generating activities in any form.

2. Social Network Services

Regulated offshore social network service providers will be required to meet the obligations outlined above on cross-border information provision.

Onshore social network services, offered by organizations or enterprises with legal status in Vietnam, are categorized as either “high-visitor” or “low-visitor” based on the number of regular visitors. The high-visitor category includes social networks with total monthly visits of 10,000 or more (based on a monthly average over six consecutive months) or with more than 1,000 regular users in a month (“regular” is not further defined). High-visitor onshore social network service providers are required to obtain a license from the relevant authority to operate, while low-visitor providers must obtain a notification confirmation from the authority to provide social network services.

Only licensed onshore providers are permitted to provide livestream features or engage in revenue-generating activities of any kind. Therefore, if a low-visitor onshore provider intends to offer livestream features or revenue-generated services, it must apply for a social network service license.

Onshore social network service providers face stricter requirements than regulated offshore social network service providers as they must additionally meet obligations including having at least one server in Vietnam to serve investigations and information provision at the request of the relevant authority, connecting to the monitoring system of the relevant authority for statistics and user access monitoring, and being subject to inspections by the authority.

Within 90 days from the effective date of Decree 147 (i.e., by March 25, 2025), both onshore and regulated offshore social network service providers are required to authenticate the identities of their active users. Additionally, within this same timeline, licensed onshore social network service providers are required to review and report to the relevant authority the number of total visits per month from Vietnam for six consecutive months, as well as the number of regular users per month.

Both onshore and offshore social network service providers must temporarily or permanently block social network accounts, community pages, community groups, and content channels that frequently violate the law. Temporary blocking will be applied at the relevant authority’s request when these accounts, community pages/groups, or channels have been found to violate the law at least five times within a 30-day period or at least 10 times within a 90-day period. The temporary block must be implemented within 24 hours of the relevant authority’s request and will last from 7 to 30 days, depending on the number and severity of the violations. A permanent block will be enforced when such accounts, community pages/groups, or channels publish illegal content that impacts national security or have previously been temporarily blocked at least three times as per request from the relevant authority.

If onshore social network service providers do not comply with the request of the relevant authority, the authority will suspend the provision of social networking services or revoke the license.

3. Online Game Services

Decree 147 expressly provides that offshore entities providing online game services to users in Vietnam must establish an enterprise in compliance with the decree and with regulations on foreign investment to provide such services. As a result, the cross-border provision of online games remains prohibited.

Online games are still categorized into four types: G1 games have interaction among multiple players via the game server; G2 games only have interaction between players and the game server; G3 games have interaction among multiple players without interaction between players and the game server; and G4 games are downloaded from the internet without interaction among players or between players and the game server.

Enterprises may provide G1 games after obtaining a license to provide G1 game services and a decision on release of a G1 game. Meanwhile, to provide G2, G3, and G4 games, enterprises must obtain a certificate of game service provision and a notification confirmation of G2, G3, or G4 game release. The license to provide G1 game services and certificate of game service provision for G2, G3 and G4 game services have a 10-year maximum duration while the decision and notification confirmation of game release has a 5-year maximum duration.

Decree 147 explicitly introduces regulations that prohibit the release of online games that feature content and scenarios resembling prizewinning games in casinos or games using images of playing cards. This regulation is designed to prevent transformation of online games into gambling activities in the virtual realm.

The main responsibilities of online game service providers include:

  • Having at least one server in Vietnam to serve the purposes of investigations by the relevant authority and handling of user complaints.
  • Having a website that introduces and provides services, displaying required information such as age-based game classification, rules for handling complaints and disputes, and details about the service provider.
  • Implementing measures to mitigate the negative impacts of each game, including registering, storing, authenticating, and managing player content and information, and ensuring that only players who provide complete and accurate information can participate, and players are warned about the effects of excessive gameplay.
  • Implementing technical measures to manage forums, shared content, and interactions between players.
  • Not advertising online games without a decision on G1 game release or notification confirmation of G2, G3, or G4 game release.
  • Submitting service provision reports regularly every six months and on an ad hoc basis when requested by the relevant authority.
  • Being subject to inspections, examinations, and enforcement actions by the relevant authority.
  • Connecting to legitimate payment methods only.
  • Storing player information for the duration of service use and for six months after a player stops using the service. Providers must also establish a system to connect to the national population database to verify player information upon request by the relevant authority.

4. App Store Services

Regulated cross-border app store service providers will be required to meet the obligations outlined above for cross-border information provision. Additionally, they are required to remove any apps that violate the law within 24 hours of receiving a request from the relevant authority; comply with Vietnamese payment regulations; and ensure that any online game service providers offering services to users in Vietnam provide the decision on G1 game release or notification confirmation of G2, G3, G4 game release before uploading their games to the app store.

5. Telecom, Internet, Web Hosting, Data Center, and Telecom Application Services

Telecom, internet, web hosting, data center and telecom application service providers are required to report to the relevant authority within 24 hours of self-discovery or receipt of feedback or complaints from users about content, services, and applications that violate Article 8 of the Cybersecurity Law; remove infringing content within 24 hours of request from the relevant authority; and handle requests and complaints about intellectual property in accordance with intellectual property laws. Additionally, they are required to submit annual reports to the relevant authority on data storage rental services provided in Vietnam to foreign entities for providing cross-border information to Vietnamese users, as well as ad hoc reports when requested by the relevant authority.

Telecom and internet enterprises must also, among other obligations:

  • Implement necessary technical measures to block access to content, services, and applications that violate the law within 24 hours of receiving a request from the relevant authority, e.g., Department of Cybersecurity and High-Tech Crime Prevention (A05) of the Ministry of Public Security (MPS).
  • Implement measures to monitor, collect, and detect information that violates the law at the request of the relevant authority (for violations of copyright and intellectual property, in compliance with intellectual property law).
  • Provide information and data related to telecom and internet subscribers suspected of violations to enable accurate identification of offenders, upon request from the relevant authority, e.g., A05 under the MPS.
  • Refuse, suspend, or terminate connections to online games without proper licenses or certificates to provide game services or decisions/notification confirmations for game release.
  • Comply with the relevant authority’s requests to coordinate, report, and carry out other measures as requested by the authority.

6. Public Internet Access Points

Owners of public internet access points in hotels, restaurants, airports, coffee shops, and other public spaces who offer paid internet access services must register as internet agency businesses and sign internet agency contracts, while those offering the services for free are not required to do so.

Internet agents are required to display an “internet agent” sign with their registration number. If the location also serves as a public online gaming point or public internet access point, this information must also be clearly indicated on the sign. When providing online game services, internet agents also have the responsibilities of an owner of a public online gaming point. Additionally, they must not organize or allow internet users to use computer features at their business location to perform prohibited acts.

RELATED INSIGHTS​ 

January 22, 2026
On January 20, 2026, Vietnam’s Ministry of Finance (MOF) issued Decision No. 96/QD-BTC to formally launch pilot administrative procedures for licensing crypto asset trading market services in Vietnam. The decision took immediate effect and implements the government’s pilot crypto asset market program under Resolution No. 05/2025/NQ-CP. Notably, competent authorities have now begun accepting license applications, marking the first time Vietnam has operationalized a licensing pathway for crypto trading market operators. Administrative Procedures and Applications The decision stipulates procedures for (i) granting, (ii) adjusting, and (iii) revoking licenses to provide services for organizing crypto asset trading markets. It provides detailed, step-by-step guidance for each procedure, including dossier composition, internal review stages, coordination mechanisms, and statutory timelines. These procedures apply specifically to entities seeking to organize and operate crypto asset trading markets within Vietnam’s pilot regulatory framework. The MOF is the authority responsible for reviewing and deciding on the above procedures, with the State Securities Commission acting as the receiving, coordinating, and procedural focal point. For licensing applications, the MOF will coordinate with multiple authorities, including the State Bank of Vietnam and the Ministry of Public Security, particularly in relation to anti-money laundering, cybersecurity, system safety, and risk control requirements. Applications may be submitted in person, by post, or electronically via the National Public Service Portal or the administrative procedure information system, in line with applicable regulations. Statutory processing timelines vary depending on the specific procedure and stage involved. For applications to obtain a license to organize a crypto asset trading market, the process is conducted in multiple phases: The MOF will issue an initial written response within 20 working days from receipt of a complete and valid initial dossier, following which, upon submission of the full set of required documents, the MOF will complete substantive review and issue the license
January 21, 2026
On January 16, 2026, Thailand’s Electronic Transactions Committee released for public comment a draft notification that would require social media platforms operating in Thailand to implement identity verification for all user accounts and advertisers, with enhanced scrutiny for high-risk advertising activities. If finalized in its current form, the Notification on Measures to Prevent Technology Crime for Social Media Service Providers would take effect 180 days after publication in the Government Gazette, fundamentally changing how platforms verify users and monetize advertising services. The public comment period is open through February 2, 2026. Mandatory User and Advertiser Identity Verification The draft establishes a universal requirement that all social media service providers implement identity verification measures for every user account. The draft imposes stricter verification obligations for advertisers than for general users. Before publishing any advertisement, platforms must verify the advertiser’s identity at a level sufficient to identify the advertiser, unless the advertiser has previously completed verification. Risk-Based Advertisement Verification The identification requirements for advertisers will be more stringent in the following cases: The advertiser has a history of user complaints or has previously violated the platform’s terms of service. The advertisement involves finance, investment, loans, sensitive personal data, or content flagged as potentially involving cybercrime. The advertisement specifically targets vulnerable groups, such as the elderly or other at-risk demographics. In such cases, platforms must conduct identity verification using government-issued identification documents and must confirm the accuracy, authenticity, and currency of these documents with the issuing government agencies. Alternatively, platforms may verify identity through an eligible digital identity verification and authentication system provider. Information Retention Platforms must retain specific information for each advertiser, including the name of the individual or juristic person and any representatives, government-issued identification documents such as ID cards, passports, or certificates of incorporation, and reachable contact information including
January 21, 2026
Spurred by global geopolitics and Canada’s Indo-Pacific Strategy, which aims to forge deeper ties with ASEAN, Canadian companies have been showing growing interest in Thailand and Southeast Asia in recent years. To understand the opportunities offered by the region, we sat down with Andrew Stoutley, a Toronto native and the chief operating officer of Tilleke & Gibbins, a leading Southeast Asian regional law firm with over 130 years of history in Thailand. Q: Why are Canadian companies looking at Thailand and Southeast Asia right now? A: Two reasons stand out. First, diversification has moved up the agenda. Many Canadian companies want options outside North America due to tariff volatility and policy uncertainty in the United States, as well as questions around the next Canada–United States–Mexico Agreement mandatory joint review. At the same time, the shift of global production from China to Southeast Asia is accelerating, driven by rising costs, geopolitics, and the need to avoid overreliance on a single market. As a result, Canadian companies are looking for a second production base or a regional hub, and Thailand and its neighbors are natural choices given their manufacturing depth, location, and established supply chains. Second, Canada’s own efforts in the region are gaining traction. The Indo-Pacific Strategy has led to more on-the-ground support, including larger trade missions, upgraded diplomatic posts, and new financing options. Export Development Canada (EDC) now has a presence in Bangkok, giving Canadian companies a direct line to financing and insurance in Thailand. There’s also steady progress on trade frameworks like the recently signed Canada–Indonesia Comprehensive Economic Partnership Agreement (which will come into effect pending domestic procedures), ongoing negotiations of a Canada–ASEAN FTA, and the exciting announcement about the launch of negotiations of a Canada–Thailand FTA. Together, these developments have the potential to make it much easier
January 13, 2026
On January 9, 2026, Thailand’s Securities and Exchange Commission (SEC) filed a criminal complaint with the Economic Crime Suppression Division (ECD) against five individuals for unauthorized operation of a digital-asset dealer business under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This precedent-setting case signals that the regulator is willing to pursue crypto enforcement against natural persons even in the absence of a licensed platform entity. Background and Implications The case follows the SEC’s October 2025 public warning about the use of iris-scanning technology in exchange for certain digital tokens. In its warning, the SEC cautioned that exchanging or trading these specific tokens with unlicensed service providers exposes users to heightened fraud, scam, and money laundering risks. Unlike prior regulatory enforcement matters, which involved platform-level administrative fines for operational or compliance failures, this case targets misconduct by individuals who may not be professional traders but openly advertised their willingness to buy these tokens from the public, opened individual over-the-counter (OTC) trade channels for these tokens, and facilitated off-exchange transactions in a manner resembling ordinary commercial dealing. This enforcement action establishes a clear precedent that natural persons engaging in public-facing digital-asset dealing may face criminal liability under Thai law, even without operating through a corporate or licensed platform structure. Outlook The alleged offenders may not settle this crime by payment of fines. Following the SEC’s referral, the ECD will undertake further investigation, after which prosecutors may review the case and proceed to court. The SEC has stated that it will cooperate fully with enforcement agencies throughout the criminal enforcement process.