You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 21, 2025

AI Regulations Come into Focus in Vietnam’s Draft Law on Digital Technology Industry

Vietnam’s Ministry of Information and Communications has released the latest version of its draft Law on the Digital Technology Industry (DTI Law), marking a significant step toward comprehensive regulation of digital technologies and notably addressing artificial intelligence (AI). The draft law was deliberated in the National Assembly on January 6, 2025, and is expected to be adopted in May 2025. Once in effect, the law will modernize Vietnam’s existing information technology regulatory framework.

Background

Vietnam has been steadily building its regulatory framework for AI since January 2021, when the prime minister issued Decision No. 127/QD-TTg on the National Strategy for Research, Development, and Application of Artificial Intelligence until 2030. While various ministries have been tasked with issuing guidance documents and technical standards, Vietnam still lacks a comprehensive legal framework specifically addressing AI and digital technologies. The draft DTI Law aims to fill this gap by providing a structured approach to regulating the digital technology industry.

Scope and Definitions

The draft DTI Law establishes a broad framework governing digital technology industry activities, initiatives for developing the digital technology sector, and rights and obligations of organizations and individuals in the industry. The draft law also proposes the creation of various incentives, primarily in the form of tax benefits, for encouraging foreign direct investment, talent acquisition and development, and industry growth.

The draft law introduces several important definitions, particularly around AI, which is defined as digital technology that simulates human intelligence to generate content, forecasts, suggestions, and decisions based on human-determined goals. The draft distinguishes between different categories of AI systems:

  • High-risk AI systems: Those posing risks to health, safety, rights, and legitimate interests.
  • High-impact AI systems: Distinguished by their broad scope, large user base, and significant computational resources for training.
  • Standard AI systems: Basic systems that apply AI for automated analysis and decision-making. The draft DTI Law notably contains a “whitelist” of AI systems that are not considered high-risk if they are (1) designed to perform a task within a narrow scope, (2) intended to improve the outcomes of previously completed human activities, and (3) aimed at detecting and recommending deviations from previous results.

Requirements and Restrictions

The draft law implements several requirements for AI deployment, such as:

  • Principles for AI development, provision, implementation, and use, which must:
    • Serve human prosperity and happiness, be human-centered, and enhance productivity and work efficiency; ensure inclusive, fair, and nondiscriminatory access; respect ethical values, human rights, and interests; and protect privacy;
    • Ensure transparency, explainability, accountability, and control over AI algorithms and models, and not replace or surpass human control;
    • Ensure security and confidentiality;
    • Manage risks throughout the AI lifecycle;
    • Promote responsible innovation and encourage international cooperation; and
    • Apply environmentally friendly and energy-saving measures in the development, provision, and use of AI.
  • Mandatory labeling: All digital technology products created by AI systems must be clearly labeled for identification purposes.
  • Prohibited activities: The draft law explicitly prohibits the provision, implementation, or use of AI systems for:
    • Manipulation and fraud;
    • Discriminatory applications;
    • Invasion of privacy;
    • Human rights violations; and
    • Activities infringing on organizational or individual interests.

Next Steps

Although the final version of the DTI Law may differ from this draft, organizations operating or planning to operate in Vietnam’s digital technology sector should review their AI systems, prepare for compliance, and assess potential opportunities for receiving investment incentives.

For AI research and development, attention should be paid to the regulatory developments led by the Ministry of Science and Technology (MOST), which has also issued guiding principles for research and development of AI systems as well as standards on AI lifecycle processes, quality requirements, and sustainability. MOST is also revamping the Law on Science, Technology, and Innovation—the latest draft of which was released in December 2024 and includes guidance on research and development of AI systems.

RELATED INSIGHTS​ 

December 27, 2022
Thailand has issued the Royal Decree on Digital Platforms, which was published in the Government Gazette on December 22, 2022. The royal decree provides a grace period of 240 days from its publication for digital platform providers to take the actions necessary to ensure compliance. The key requirements are outlined below. Definitions After going through various amendments in its draft stages, the published royal decree’s definition of “digital platform” refers to the provision of an electronic intermediary platform that manages information to create connections between “merchants,” “consumers,” and “users” via a computer network in order to create electronic transactions—regardless of whether payment is actually made. However, this does not include digital platforms that offer goods or services of the digital platform operator or an affiliated company acting as its representative, regardless of whether the goods or services are offered to third parties or to affiliated companies. Notification Exemption Under the royal decree, a digital platform provider under the supervision of other authorities, such as the Bank of Thailand and the Securities and Exchange Commission, or falling under the Electronic Transactions Commission’s list of exempted digital platform providers is exempted from the requirement to notify the Electronic Transactions Development Agency (ETDA) of the operation of its digital platform. The commission may also exempt any other digital platform service as it sees fit. Extraterritorial Effect Certain digital platforms located outside Thailand are subject to the royal decree and must appoint a coordinating person in Thailand. This requirement to appoint a local coordinator does not mean that overseas digital platforms have to establish their business in Thailand. Digital Platform Certification Mark The royal decree introduces an ETDA certification mark for digital platforms. Display of the mark appears not to be mandatory, but more specific rules, procedures, and other details will be prescribed
December 23, 2022
On December 15, 2022, Thailand’s Personal Data Protection Committee (PDPC) issued the Notification on the Criteria and Procedures for Handling Personal Data Breaches. What Constitutes a “Data Breach”? A “personal data breach” refers to a breach of security measures that causes unlawful or unauthorized loss, access, use, modification, or disclosure of personal data, resulting from an intentional, willful, negligent, accidental, unauthorized, or unlawful act, or an act related to computer crimes, cyber threats, mistakes or accidents, or any other act. The notification also classifies personal data breaches into three categories: confidentiality breach, integrity breach, and availability breach. Upon being informed of an actual or suspected personal data breach, a data controller must take the following actions: To the extent possible, assess the reliability of the information and investigate the facts related to the personal data breach, including all aspects concerning security measures, such as organizational measures, technical measures, and physical measures; Conduct a data breach assessment to consider whether the personal data breach is likely to result in a risk to an individual’s rights and freedom; Notify the Office of the PDPC, any affected data subjects, or both as required; and Take necessary and appropriate action to prevent further consequences resulting from the personal data breach. Breach Assessment When conducting a data breach assessment, the following factors must be taken into account if there is a risk to an individual’s rights and freedom. Nature and the type of data breach; Nature, type, and volume of personal data involved; Nature, type, and status of the affected data subject; Severity of the consequences of the personal data breach for any affected data subjects, and the effectiveness of the measures taken to prevent the data breach; Impact of the data breach on the operation of the business or on the public; Storage
December 2, 2022
On November 11, 2022, Myanmar’s Ministry of Commerce (MOC) announced a pilot period for importing electric vehicles into Myanmar, which came into force with MOC Order No. 62/2022, issued under the Import and Export Law. A separate order (No. 61/2022) issued on the same day specifies rules for importation of motorcycles by companies that do not have a certificate to open a showroom, as well as rules for opening motorcycle showrooms. Electric Vehicle Importation According to the order, which takes effect January 1, 2023, “electric vehicles” includes only battery electric vehicles (BEVs) for both personal use and passenger use. In order to import electric vehicles into Myanmar without having a certificate to open a showroom, companies must: Be registered as a company, either wholly owned by nationals or a joint venture, at the Directorate of Investment and Company Administration (DICA); Be able to present the purchase and sales agreement for each brand of imported electric vehicles; Receive approval from the National Steering Committee for Development of Electric Vehicles and Associated Businesses, and import according to the quality and quantity of electric vehicles permitted by the committee; Arrange the necessary warranty, spare parts availability, and after-sales service for the imported electric vehicles; Deposit a bank guarantee of MMK 50 million at a bank recognized by the Central Bank of Myanmar; and Apply for a purchase permit at the MOC, for the purpose of registering the imported vehicles with the Road Transport Administration Department. BEV Tax Exemption Following MOC Order No. 62/2022, BEVs and their batteries are now exempted from commercial tax and special goods tax, which came into force with the Law Amending the Union Tax Law 2022 (State Administrative Council Law No. 48/2022) dated November 17, 2022. These tax exemptions will be effective from October 1, 2022, to March
November 4, 2022
Lawyers from Tilleke & Gibbins in Cambodia, Laos, Myanmar, Thailand, and Vietnam have contributed to the new Multilaw Global Checklist for Monitoring Staff Data, which compiles essential information on regulations related to collection of data on employees. Such collection of data is an increasingly important concern for employers and entrepreneurs as the world pays closer attention to diversity, equality, and antidiscrimination in the workplace. The checklist contains fundamental information for each jurisdiction on legal considerations pertaining to employment diversity surveys and what can and cannot be asked. The table-style list is global in scope, with a separate line for each jurisdiction. The jurisdictional entries are grouped by region, allowing the reader to quickly compare how various countries treat different issues in each part of the world. In each column is a common question about how employers can monitor staff data in full compliance with the law, covering issues such as: Requesting data from employees; Type and format of data captured; Data storage and access; Retention of data; Intra-group cross-border data transfers; and Specific considerations for each jurisdiction. Multilaw, of which Tilleke & Gibbins is a member, is a global network of carefully selected, independent law firms consisting of over 10,000 commercial lawyers in more than 100 countries, able to provide expert legal advice in complex environments around the globe. The full checklist is available for free on the Multilaw website.