You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 20, 2025

A Closer Look at Vietnam’s Decree 147 on Internet Services and Online Information

Vietnam’s Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (Decree 147) was issued on November 9, 2024, and came into effect on December 25, 2024. Decree 147 represents a more stringently regulated digital landscape in Vietnam, creating challenges not only for offshore service providers offering cross-border services but also for onshore providers. As these new regulations impose stricter requirements, particularly in areas like content control, user authentication, data storage, and service license/notification, companies will need to adapt quickly to maintain compliance and minimize legal risks.

The following are some of the key topics covered by Decree 147.

[Note: Shortly after the issuance of Decree 147, Vietnam began a government restructuring process, with the aim of streamlining the government by consolidating and eliminating various ministries and agencies. Thus, the decree’s references to authorities such as the Authority of Broadcasting and Electronic Information (ABEI) and the Ministry of Information and Communications (MIC) are subject to change.]

1. Cross-Border Information Provision

Cross-border information provision is defined broadly as the provision by overseas organizations and individuals of information and online information content services for service users in Vietnam to access or use. This wide-ranging definition encompasses various types of cross-border services, including social network services, online game services, and app store services. However, cross-border provision of online game services remains prohibited under Decree 147 (see further details below).

Offshore providers of services on a cross-border basis who lease data storage in Vietnam or meet a threshold of 100,000 or more total visits per month from Vietnam for six consecutive months (“regulated cross-border providers”) must adhere to stricter requirements. Specifically, they are required to, among other requirements:

  • Notify the relevant authority of their contact information, including the location of the main server providing the service, within 60 days of reaching the total visit threshold.
  • Inspect, monitor, prevent, and remove any content, services, and applications that violate the law within 24 hours from the time of a request from the relevant authority, and within 48 hours of receiving complaints from Vietnamese users regarding content, services, and applications that violate Article 8 of the Cybersecurity Law (which lists a wide range of prohibited acts in cyberspace, such as cyberterrorism, spreading malware, and advertising or trading in banned goods/services).
  • Store personal data of users from Vietnam, such as full name, date of birth, email, and Vietnamese mobile phone number (or ID number), and delete this data when the storage period expires.
  • Provide information of users from Vietnam to the relevant authority upon request for investigation and for law enforcement purposes.
  • Authenticate social network user accounts via users’ Vietnamese mobile phone numbers or ID numbers if they do not have Vietnamese mobile phone numbers, or if they use the livestream feature for commercial purposes; and ensuring that only verified accounts can post information (write posts or comments, livestream) and share content on social networks.
  • Classify and display warnings of content that is not suitable for children.
  • Receive and handle complaints from service users.
  • Provide tools for searching and scanning content as requested by the relevant authority.
  • Report annually to the relevant authority on their service provision to users from Vietnam and on an ad hoc basis regarding matters of national security, social order, and emergency upon the authority’s request.

Failure to comply with these obligations allows the relevant authority to enforce technical measures to block non-compliant content, services, and applications, as well as impose administrative penalties.

Only cross-border service providers who have notified the relevant authority of their contact information are allowed to provide livestream features or provide revenue-generating activities in any form.

2. Social Network Services

Regulated offshore social network service providers will be required to meet the obligations outlined above on cross-border information provision.

Onshore social network services, offered by organizations or enterprises with legal status in Vietnam, are categorized as either “high-visitor” or “low-visitor” based on the number of regular visitors. The high-visitor category includes social networks with total monthly visits of 10,000 or more (based on a monthly average over six consecutive months) or with more than 1,000 regular users in a month (“regular” is not further defined). High-visitor onshore social network service providers are required to obtain a license from the relevant authority to operate, while low-visitor providers must obtain a notification confirmation from the authority to provide social network services.

Only licensed onshore providers are permitted to provide livestream features or engage in revenue-generating activities of any kind. Therefore, if a low-visitor onshore provider intends to offer livestream features or revenue-generated services, it must apply for a social network service license.

Onshore social network service providers face stricter requirements than regulated offshore social network service providers as they must additionally meet obligations including having at least one server in Vietnam to serve investigations and information provision at the request of the relevant authority, connecting to the monitoring system of the relevant authority for statistics and user access monitoring, and being subject to inspections by the authority.

Within 90 days from the effective date of Decree 147 (i.e., by March 25, 2025), both onshore and regulated offshore social network service providers are required to authenticate the identities of their active users. Additionally, within this same timeline, licensed onshore social network service providers are required to review and report to the relevant authority the number of total visits per month from Vietnam for six consecutive months, as well as the number of regular users per month.

Both onshore and offshore social network service providers must temporarily or permanently block social network accounts, community pages, community groups, and content channels that frequently violate the law. Temporary blocking will be applied at the relevant authority’s request when these accounts, community pages/groups, or channels have been found to violate the law at least five times within a 30-day period or at least 10 times within a 90-day period. The temporary block must be implemented within 24 hours of the relevant authority’s request and will last from 7 to 30 days, depending on the number and severity of the violations. A permanent block will be enforced when such accounts, community pages/groups, or channels publish illegal content that impacts national security or have previously been temporarily blocked at least three times as per request from the relevant authority.

If onshore social network service providers do not comply with the request of the relevant authority, the authority will suspend the provision of social networking services or revoke the license.

3. Online Game Services

Decree 147 expressly provides that offshore entities providing online game services to users in Vietnam must establish an enterprise in compliance with the decree and with regulations on foreign investment to provide such services. As a result, the cross-border provision of online games remains prohibited.

Online games are still categorized into four types: G1 games have interaction among multiple players via the game server; G2 games only have interaction between players and the game server; G3 games have interaction among multiple players without interaction between players and the game server; and G4 games are downloaded from the internet without interaction among players or between players and the game server.

Enterprises may provide G1 games after obtaining a license to provide G1 game services and a decision on release of a G1 game. Meanwhile, to provide G2, G3, and G4 games, enterprises must obtain a certificate of game service provision and a notification confirmation of G2, G3, or G4 game release. The license to provide G1 game services and certificate of game service provision for G2, G3 and G4 game services have a 10-year maximum duration while the decision and notification confirmation of game release has a 5-year maximum duration.

Decree 147 explicitly introduces regulations that prohibit the release of online games that feature content and scenarios resembling prizewinning games in casinos or games using images of playing cards. This regulation is designed to prevent transformation of online games into gambling activities in the virtual realm.

The main responsibilities of online game service providers include:

  • Having at least one server in Vietnam to serve the purposes of investigations by the relevant authority and handling of user complaints.
  • Having a website that introduces and provides services, displaying required information such as age-based game classification, rules for handling complaints and disputes, and details about the service provider.
  • Implementing measures to mitigate the negative impacts of each game, including registering, storing, authenticating, and managing player content and information, and ensuring that only players who provide complete and accurate information can participate, and players are warned about the effects of excessive gameplay.
  • Implementing technical measures to manage forums, shared content, and interactions between players.
  • Not advertising online games without a decision on G1 game release or notification confirmation of G2, G3, or G4 game release.
  • Submitting service provision reports regularly every six months and on an ad hoc basis when requested by the relevant authority.
  • Being subject to inspections, examinations, and enforcement actions by the relevant authority.
  • Connecting to legitimate payment methods only.
  • Storing player information for the duration of service use and for six months after a player stops using the service. Providers must also establish a system to connect to the national population database to verify player information upon request by the relevant authority.

4. App Store Services

Regulated cross-border app store service providers will be required to meet the obligations outlined above for cross-border information provision. Additionally, they are required to remove any apps that violate the law within 24 hours of receiving a request from the relevant authority; comply with Vietnamese payment regulations; and ensure that any online game service providers offering services to users in Vietnam provide the decision on G1 game release or notification confirmation of G2, G3, G4 game release before uploading their games to the app store.

5. Telecom, Internet, Web Hosting, Data Center, and Telecom Application Services

Telecom, internet, web hosting, data center and telecom application service providers are required to report to the relevant authority within 24 hours of self-discovery or receipt of feedback or complaints from users about content, services, and applications that violate Article 8 of the Cybersecurity Law; remove infringing content within 24 hours of request from the relevant authority; and handle requests and complaints about intellectual property in accordance with intellectual property laws. Additionally, they are required to submit annual reports to the relevant authority on data storage rental services provided in Vietnam to foreign entities for providing cross-border information to Vietnamese users, as well as ad hoc reports when requested by the relevant authority.

Telecom and internet enterprises must also, among other obligations:

  • Implement necessary technical measures to block access to content, services, and applications that violate the law within 24 hours of receiving a request from the relevant authority, e.g., Department of Cybersecurity and High-Tech Crime Prevention (A05) of the Ministry of Public Security (MPS).
  • Implement measures to monitor, collect, and detect information that violates the law at the request of the relevant authority (for violations of copyright and intellectual property, in compliance with intellectual property law).
  • Provide information and data related to telecom and internet subscribers suspected of violations to enable accurate identification of offenders, upon request from the relevant authority, e.g., A05 under the MPS.
  • Refuse, suspend, or terminate connections to online games without proper licenses or certificates to provide game services or decisions/notification confirmations for game release.
  • Comply with the relevant authority’s requests to coordinate, report, and carry out other measures as requested by the authority.

6. Public Internet Access Points

Owners of public internet access points in hotels, restaurants, airports, coffee shops, and other public spaces who offer paid internet access services must register as internet agency businesses and sign internet agency contracts, while those offering the services for free are not required to do so.

Internet agents are required to display an “internet agent” sign with their registration number. If the location also serves as a public online gaming point or public internet access point, this information must also be clearly indicated on the sign. When providing online game services, internet agents also have the responsibilities of an owner of a public online gaming point. Additionally, they must not organize or allow internet users to use computer features at their business location to perform prohibited acts.

RELATED INSIGHTS​ 

August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public
August 10, 2026
Thailand has finalized its social media KYC (“know your customer”) rules under Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers (No. 2), which was published in the Government Gazette on May 5, 2026, and will take effect on November 1, 2026. While an early draft of the notification proposed requiring social media platforms to arrange identification of every user account, the final notification is significantly more targeted, focusing on paid online advertising and advertiser identity verification. Though the regulatory initiative primarily aims to combat online fraud and technology-related crimes, it also has important consequences for intellectual property enforcement, because the verified platform records that will be generated under the new requirements can help IP rights holders to identify anonymous online infringers. Key Regulatory Mandates The notification requires social media service providers to verify the identity of advertisers before their paid advertisements are published and disseminated in Thailand through social media, regardless of whether the advertising fees come from the advertisers or third parties. Verification of an advertiser is valid for one year, after which verification would have to be performed again before the platform could publish additional paid advertisements from the advertiser. Permitted verification methods are specified under the notification. A platform may verify an advertiser by checking identity evidence and confirming the connection between the advertiser and that identity evidence, with the notification giving facial comparison against certain government-issued identity documents as an example. Alternatively, platforms may verify advertisers through a digital identity verification and authentication system with an identity-proofing assurance level not lower than the level prescribed by Thailand’s Electronic Transactions Commission. The notification further requires platforms to retain only the advertiser’s information necessary to identify the advertiser, beginning from the start of the advertising activity and for
August 10, 2026
On July 31, 2026, Thailand’s Big Data Institute (BDI) launched a public consultation on the principles of a proposed new data-sharing law, with comments accepted until August 31, 2026. If enacted, the law would establish Thailand’s first comprehensive framework for government and private-sector data sharing, creating a systematic, secure, and transparent regime to support analytics, policymaking, research, and innovation. Central Data-Sharing Platform The draft law establishes a central system for data sharing, managed by the BDI. Government agencies would be required to connect to the BDI’s Data Integration and Intelligence Platform (also referred to as D2), in accordance with the BDI’s rules and procedures. Five Dimensions of Data Sharing The draft law covers five key types of data sharing between government (G), businesses (B), and consumers (C): G2B: Private organizations may request government data specifically for research and development purposes. The BDI will assess the applicant’s data governance, security, and privacy capabilities whether such measures meet prescribed standards before forwarding the request to the relevant government agency within 90 days. Any dispute may be escalated to a newly established Data-Sharing Promotion Committee for final determination. G2G: Government agencies may request data from other agencies through the central system. The data-holding agency must respond within 90 days, taking legality, necessity, proportionality, public interest, and personal data protection into account. Disputes may be referred to the Data-Sharing Promotion Committee for adjudication. B2G: In emergency situations involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society may require private entities to provide data through the central data-sharing system. Government agencies must specify the data requested, demonstrate its necessity and expected benefits, and request only data reasonably available to the data holder. Requests for personal data must be limited to the minimum amount necessary. B2C: Royal decrees may
August 10, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) recently released draft guidance on records of processing activities (ROPA) for personal data controllers and processors under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft guidance, which was presented to the public on July 7, 2026, addresses both controller records of collection, use, and disclosure of personal data and processor records of processing activities carried out on behalf of controllers. If implemented, the guidance will significantly expand organizational expectations for ROPA preparation, maintenance, and use across all sectors. Key Takeaways The draft guidance contains several important implications for organizations subject to the PDPA: ROPA reframed as a core accountability tool. The guidance elevates ROPA from an administrative record to a central accountability mechanism, connecting controller duties with recordkeeping obligations. ROPA as a source for privacy notices and governance documents. ROPA should serve as the primary source for privacy notices and align with consent management, retention schedules, DPIAs, incident response plans, and vendor contracts. Expanded scope across all activities. ROPA must cover all processing activities across the organization—including security, finance, HR, and external contractors—with correct controller or processor classification for each. Ongoing maintenance and auditability. ROPA must be updated for any change to systems, purposes, or processors, reviewed at least annually, and maintained with version control and a designated owner. Enhanced vendor, processor, and cross-border transfer requirements. Organizations must document all processors, external recipients, and cross-border transfers, specifying purposes, access scope, and destination countries. Linkage with risk assessment, DPIAs, and LIAs. ROPA should assign risk levels to each activity and identify when data protection impact assessments (DPIAs) or legitimate interests assessments (LIAs) are required, functioning as a risk-management tool. ROPA and data breach readiness. Incomplete ROPA can delay breach response and notification. Organizations should map data flows, vendors,