You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 21, 2025

AI Regulations Come into Focus in Vietnam’s Draft Law on Digital Technology Industry

Vietnam’s Ministry of Information and Communications has released the latest version of its draft Law on the Digital Technology Industry (DTI Law), marking a significant step toward comprehensive regulation of digital technologies and notably addressing artificial intelligence (AI). The draft law was deliberated in the National Assembly on January 6, 2025, and is expected to be adopted in May 2025. Once in effect, the law will modernize Vietnam’s existing information technology regulatory framework.

Background

Vietnam has been steadily building its regulatory framework for AI since January 2021, when the prime minister issued Decision No. 127/QD-TTg on the National Strategy for Research, Development, and Application of Artificial Intelligence until 2030. While various ministries have been tasked with issuing guidance documents and technical standards, Vietnam still lacks a comprehensive legal framework specifically addressing AI and digital technologies. The draft DTI Law aims to fill this gap by providing a structured approach to regulating the digital technology industry.

Scope and Definitions

The draft DTI Law establishes a broad framework governing digital technology industry activities, initiatives for developing the digital technology sector, and rights and obligations of organizations and individuals in the industry. The draft law also proposes the creation of various incentives, primarily in the form of tax benefits, for encouraging foreign direct investment, talent acquisition and development, and industry growth.

The draft law introduces several important definitions, particularly around AI, which is defined as digital technology that simulates human intelligence to generate content, forecasts, suggestions, and decisions based on human-determined goals. The draft distinguishes between different categories of AI systems:

  • High-risk AI systems: Those posing risks to health, safety, rights, and legitimate interests.
  • High-impact AI systems: Distinguished by their broad scope, large user base, and significant computational resources for training.
  • Standard AI systems: Basic systems that apply AI for automated analysis and decision-making. The draft DTI Law notably contains a “whitelist” of AI systems that are not considered high-risk if they are (1) designed to perform a task within a narrow scope, (2) intended to improve the outcomes of previously completed human activities, and (3) aimed at detecting and recommending deviations from previous results.

Requirements and Restrictions

The draft law implements several requirements for AI deployment, such as:

  • Principles for AI development, provision, implementation, and use, which must:
    • Serve human prosperity and happiness, be human-centered, and enhance productivity and work efficiency; ensure inclusive, fair, and nondiscriminatory access; respect ethical values, human rights, and interests; and protect privacy;
    • Ensure transparency, explainability, accountability, and control over AI algorithms and models, and not replace or surpass human control;
    • Ensure security and confidentiality;
    • Manage risks throughout the AI lifecycle;
    • Promote responsible innovation and encourage international cooperation; and
    • Apply environmentally friendly and energy-saving measures in the development, provision, and use of AI.
  • Mandatory labeling: All digital technology products created by AI systems must be clearly labeled for identification purposes.
  • Prohibited activities: The draft law explicitly prohibits the provision, implementation, or use of AI systems for:
    • Manipulation and fraud;
    • Discriminatory applications;
    • Invasion of privacy;
    • Human rights violations; and
    • Activities infringing on organizational or individual interests.

Next Steps

Although the final version of the DTI Law may differ from this draft, organizations operating or planning to operate in Vietnam’s digital technology sector should review their AI systems, prepare for compliance, and assess potential opportunities for receiving investment incentives.

For AI research and development, attention should be paid to the regulatory developments led by the Ministry of Science and Technology (MOST), which has also issued guiding principles for research and development of AI systems as well as standards on AI lifecycle processes, quality requirements, and sustainability. MOST is also revamping the Law on Science, Technology, and Innovation—the latest draft of which was released in December 2024 and includes guidance on research and development of AI systems.

RELATED INSIGHTS​ 

November 8, 2024
On October 31, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) opened a public consultation period on its draft notifications—one directed at data controllers and another at data processors—regarding exemptions from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft notification for data controllers aims to amend and revoke certain aspects of the first ROPA exemption notification issued in June 2022 and outlines the criteria for data controllers to be exempted from the obligation to prepare and maintain such records. Although it is officially titled “Notification of the Personal Data Protection Committee on Exemption from Record-Keeping Requirements for Small Business Data Controllers,” this draft notification applies to all types of exempted data controllers (see list below), and not only small businesses. The draft notification for data processors is new and does not replace any prior notification. The criteria under both draft notifications exempt certain data controllers and data processors from the obligation to maintain ROPAs, but exempted data controllers are not free from the obligation to retain information on the rejection of data subjects’ requests to exercise certain rights under the PDPA. While these criteria remain consistent with the June 2022 ROPA exemption notification, there are a few key takeaways from the notifications, as detailed below. Types of Exempted Parties The draft notification on data controllers adds condominium and housing estate juristic persons, as well as individuals, to the list of parties eligible for an exemption, while removing internet cafes from the list. The new draft notification for data processors mirrors the corresponding list in the draft notification for data controllers. The complete list of parties eligible for ROPA exemptions under the draft notifications is as follows: SMEs according to the law on
October 8, 2024
On October 1, 2024, the Thai cabinet acknowledged the recommendations proposed by the National Anti-Corruption Commission (NACC) to prevent corruption related to online gambling. The Ministry of Digital Economy and Society (MDES) has been assigned as the lead agency to collaborate with various relevant agencies to reach a consensus on the necessary amendments and updates to laws related to online gambling. In assigning the MDES this role, the cabinet emphasized the importance of the following key items: Establishment of a national committee. The national committee will be chaired by a minister and will comprise relevant agencies, including policymaking bodies, technology agencies, frequency management agencies, law enforcement agencies, and other experts. The committee’s primary responsibility will be to consider amending and updating laws related to online gambling. Urgent action on online gambling. As online gambling has been deemed a serious issue requiring urgent action, joint policies will be developed among relevant agencies such as the Royal Thai Police, the Bank of Thailand, and the Anti-Money Laundering Office to elevate the importance of online gambling issues. Public awareness and law enforcement. Public awareness campaigns are to be conducted to educate the public about the risks and legal consequences of online gambling, and laws against online gambling and related financial crimes are to be strictly enforced. Compliance with the Cybersecurity Act. It is necessary to ensure strict compliance with the Cybersecurity Act B.E. 2562 (2019). At the same time, government data systems are to be moved to cloud computing for enhanced data security. Next Steps The MDES is tasked with summarizing the results of the related discussions, actions taken, and overall opinions and submitting the summary to the cabinet secretariat for further presentation to the cabinet. These measures aim to address and mitigate the risks associated with online gambling and related corruption.
October 8, 2024
Thailand’s Electronic Transactions Development Agency (ETDA) issued guidelines for managing advertisements on digital platform services (DPSs) earlier this year. These guidelines aim to prevent fraud, illegal product or service offerings, and inducements to commit illegal acts, and are likely to provide a basis for greater regulation of this issue in the future. Key obligations for DPS business operators under the guidelines are detailed below. Advertiser Screening and Data Collection Verification and collection: Business operators must establish processes for verifying and collecting advertiser data. This includes steps, methods, and required information for advertiser registration. Identity verification: Business operators should follow identity verification requirements for advertiser registration. This may include using identity verification results from other identity providers or conducting their own identity verification processes with a minimum identity assurance level (IAL) of IAL2. Data storage: Advertiser data must be stored in a machine-readable format. Business operators must maintain records for watchlists, blacklists, and whitelists. Prepublication Advertisement Review Review process: Business operators should review advertisements before publication. This review should consider factors such as prohibited or restricted advertisements, required permissions, and avoiding sensitive user data. Postpublication Monitoring Advertisement monitoring: Business operators must monitor published advertisements using automated systems, staff, or contracted personnel. Criteria for prioritizing reviews should be established. Reporting channels: Business operators must provide channels for users to report illegal or inappropriate advertisements. Reports must be promptly addressed, prioritizing cases involving intellectual property owners or multiple credible reports. Advertiser account monitoring: Business operators must monitor advertiser accounts. This includes considering factors such as the number of reports/flags received and compliance with service agreements and community standards. For more information on this initiative from the ETDA, or on any aspect related to Thailand’s regulations for DPSs, please contact Athistha (Nop) Chitranukroh at [email protected], Thammapas Chanpanich at [email protected], Pornpan Wichawut at [email protected],
October 2, 2024
The first draft of Vietnam’s new Personal Data Protection Law (“Draft PDPL”) was released for public consultation on September 24, 2024, and is open for comments until November 24, 2024. (See further details here.) It is expected that the draft will be presented to the National Assembly before the end of 2024 and will be submitted for adoption in May 2025, with a tentative entry into force on January 1, 2026. As the Draft PDPL incorporates most of the provisions of Decree No. 13/2023/ND-CP on Personal Data Protection (“PDPD”), which has been the primary legal instrument on personal data protection since it took effect on July 1, 2023, it is likely that it will supersede the PDPD when it takes effect. [Please contact our Vietnam data protection team to request a detailed comparison of the Draft PDPL to the PDPD.] Noting that there might be further changes to the draft once the public consultation period closes, the Draft PDPL proposes new specific requirements for a number of services. Some highlights of the current version include the following: Marketing services: Although marketing services are already regulated under the PDPD, the Draft PDPL now recognizes that the use of personal data for marketing must comply with anti-spam regulations. The current draft does not clarify whether organizations are exempted from the consent requirement for the purpose of the initial call or message under the anti-spam regime. Marketing service providers are not allowed to outsource the services to another organization to perform or support the implementation of marketing business, which may prevent the sharing of personal data. Behavioral advertising: Behavioral advertising (targeted personalized advertising based on a user’s activity or personal data) requires the consent of the data subject in a modifiable manner that allows the data subject to refuse to share data