You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 21, 2025

AI Regulations Come into Focus in Vietnam’s Draft Law on Digital Technology Industry

Vietnam’s Ministry of Information and Communications has released the latest version of its draft Law on the Digital Technology Industry (DTI Law), marking a significant step toward comprehensive regulation of digital technologies and notably addressing artificial intelligence (AI). The draft law was deliberated in the National Assembly on January 6, 2025, and is expected to be adopted in May 2025. Once in effect, the law will modernize Vietnam’s existing information technology regulatory framework.

Background

Vietnam has been steadily building its regulatory framework for AI since January 2021, when the prime minister issued Decision No. 127/QD-TTg on the National Strategy for Research, Development, and Application of Artificial Intelligence until 2030. While various ministries have been tasked with issuing guidance documents and technical standards, Vietnam still lacks a comprehensive legal framework specifically addressing AI and digital technologies. The draft DTI Law aims to fill this gap by providing a structured approach to regulating the digital technology industry.

Scope and Definitions

The draft DTI Law establishes a broad framework governing digital technology industry activities, initiatives for developing the digital technology sector, and rights and obligations of organizations and individuals in the industry. The draft law also proposes the creation of various incentives, primarily in the form of tax benefits, for encouraging foreign direct investment, talent acquisition and development, and industry growth.

The draft law introduces several important definitions, particularly around AI, which is defined as digital technology that simulates human intelligence to generate content, forecasts, suggestions, and decisions based on human-determined goals. The draft distinguishes between different categories of AI systems:

  • High-risk AI systems: Those posing risks to health, safety, rights, and legitimate interests.
  • High-impact AI systems: Distinguished by their broad scope, large user base, and significant computational resources for training.
  • Standard AI systems: Basic systems that apply AI for automated analysis and decision-making. The draft DTI Law notably contains a “whitelist” of AI systems that are not considered high-risk if they are (1) designed to perform a task within a narrow scope, (2) intended to improve the outcomes of previously completed human activities, and (3) aimed at detecting and recommending deviations from previous results.

Requirements and Restrictions

The draft law implements several requirements for AI deployment, such as:

  • Principles for AI development, provision, implementation, and use, which must:
    • Serve human prosperity and happiness, be human-centered, and enhance productivity and work efficiency; ensure inclusive, fair, and nondiscriminatory access; respect ethical values, human rights, and interests; and protect privacy;
    • Ensure transparency, explainability, accountability, and control over AI algorithms and models, and not replace or surpass human control;
    • Ensure security and confidentiality;
    • Manage risks throughout the AI lifecycle;
    • Promote responsible innovation and encourage international cooperation; and
    • Apply environmentally friendly and energy-saving measures in the development, provision, and use of AI.
  • Mandatory labeling: All digital technology products created by AI systems must be clearly labeled for identification purposes.
  • Prohibited activities: The draft law explicitly prohibits the provision, implementation, or use of AI systems for:
    • Manipulation and fraud;
    • Discriminatory applications;
    • Invasion of privacy;
    • Human rights violations; and
    • Activities infringing on organizational or individual interests.

Next Steps

Although the final version of the DTI Law may differ from this draft, organizations operating or planning to operate in Vietnam’s digital technology sector should review their AI systems, prepare for compliance, and assess potential opportunities for receiving investment incentives.

For AI research and development, attention should be paid to the regulatory developments led by the Ministry of Science and Technology (MOST), which has also issued guiding principles for research and development of AI systems as well as standards on AI lifecycle processes, quality requirements, and sustainability. MOST is also revamping the Law on Science, Technology, and Innovation—the latest draft of which was released in December 2024 and includes guidance on research and development of AI systems.

RELATED INSIGHTS​ 

September 6, 2022
The Thai National Cybersecurity Committee (NCSC), as required by the Cybersecurity Act, reported to the cabinet in mid-August on trends and developments regarding cyber incidents in Thailand. According to the NCSC, the top five most common cyber incidents involve website phishing, website defacement, data leakage, data security vulnerabilities, and ransomware. Reported incidents of cyberattacks have increased in recent years. The report stated that affected organizations primarily responded to cyber incidents and attacks by notifying the NCSC about the incident and the remedial actions planned or taken, and conducting internal training to increase awareness of cyber threats. Only two organizations chose to conduct IT risk assessments and vulnerability tests as preventive measures against future cyber threats. The NCSC report also showed that aside from telecom infrastructure, energy and utilities, and education operators falling victim to cyberattacks, healthcare, webhosting, and data center operators have also become “more common victims” of cyber incidents. The NCSC recommended that all organizations prepare for inevitable future cyber incidents. This includes ensuring that businesses and organizations comply with international standards, which includes measures that are recognized and incorporated in Thailand’s Personal Data Protection Act (PDPA) and Cybersecurity Act. Conducting internal training for employees as well as directors and officers is also recommended by the NCSC, as this can help prevent cyber incidents and ensure that businesses comply with the minimum required security standards issued by the Personal Data Protection Committee (PDPC) in their Notification Re: Security Measures of the Data Controller B.E. 2565 (2022), which came into effect on June 21, 2022. Industry-specific minimum required security standards (e.g., those regulated by the Bank of Thailand, Office of Insurance Commission, etc.) should also be considered in conjunction with those in this PDPC notification—particularly when sectoral requirements are more stringent than the PDPC’s recommended measures. PDPA statutory penalties
August 19, 2022
Vietnam’s Cybersecurity Law was promulgated on June 12, 2018, and came into effect on January 1, 2019, with a majority of its provisions enforceable from the effective date. However, certain provisions of the law, including the very concerning data localization requirements, still awaited further guidance from implementing regulations. After more than three years of being drafted and submitted back and forth to the government for consideration and approval, Decree No. 53/2022/ND-CP to implement certain articles of the Cybersecurity Law (Decree 53) was finally promulgated on August 15, 2022, with an effective date of October 1, 2022. Key provisions of Decree 53 include the following. 1. Data localization requirements (Articles 26 & 27) Decree 53 retains most of the data localization requirements of the last accessible version of the draft decree dated August 21, 2019 (Draft Decree), clearly extends the scope of requirements to cover both domestic and foreign enterprises, adds regulations on force majeure events, and amends the timeline to implement data localization requirements for business facilitation. (i) Data subject to data localization: Data (information in the form of symbols, writing, numbers, images, sounds, or similar forms) which must be stored in Vietnam (“regulated data”) includes: Data on personal information of service users in Vietnam: Data used to identify an individual. Data generated by service users in Vietnam: Data reflecting the process of participating in, operating and/or using cyberspace by service users and information about network equipment and services used in order to connect with cyberspace in the territory of Vietnam. This includes the account name for use of services, duration of use of services, credit card information, email address, IP addresses for the latest login and logout, and registered telephone number attached to the account or data. Data on the relationships of service users in Vietnam: Data reflecting
August 11, 2022
In July 2022, the Thai cabinet approved in principle a royal decree exempting some businesses and other entities from parts of the Personal Data Protection Act B.E. 2562 (PDPA). The draft royal decree proposes to exempt certain business operators and activities from the requirements of the following portions of the PDPA: Chapter II: Personal Data Protection – Consent, notification, cross-border transfer of the personal data requirements, etc. Chapter III: Rights of the Data Subject – Requirements and criteria on data subject rights. Chapter V: Complaints – Requirements on the submission of complaints to the Office of the Personal Data Protection Commission. Chapter VI: Civil Liability – Conditions in relation to the civil liability of a data controller or data processor. Chapter VII: Penalties – Administrative and criminal penalties. The proposed exemptions would apply to three main categories of business operators and activities: 1. Data controllers acting on government requests in adherence with specific laws for the following purposes: State security and public safety. Exempted operations include activities intended to safeguard state security, intelligence, and information relating to national security, as well as efforts to maintain fiscal and economic security and public security. Also exempt are prevention and suppression of certain criminal activities, such as money laundering, drug trafficking, transnational threats and terrorism, transnational crime, and human trafficking; activities to bolster anticorruption or cybersecurity efforts; and actions relating to public health, sanitation to prevent epidemics, and protection of public life, health, and property. Taxation. Exempted activities include those related to tax collection under laws that are the responsibility of the Revenue Department, Customs Department, or Excise Department. This also extends to any action relating to the enforcement of taxation fees or duties, and actions related to social security, the performance of obligations, or international cooperation. Risk mitigation, monitoring, and surveillance.
July 31, 2022
Thailand’s Securities and Exchange Commission (SEC) has announced three new regulatory requirements, which primarily require digital asset business operators to provide investors with training or a knowledge test on cryptocurrencies and to disclose information about the quality of their service and IT usage capacity. The amended SEC notification detailing these new obligations was promulgated on July 1, 2022; however, the measures come into effect separately, as detailed below. Training or Testing on Cryptocurrency From August 30, 2022, cryptocurrency exchanges, brokers, and dealers must provide guidance and education to their clients on basic asset allocation suitable to their capacity. These types of digital asset business operators must also provide for training or a knowledge test on cryptocurrency. The content should at least cover cryptocurrency, blockchain technology, digital wallets, and an overview of the market and investments. The following types of clients are exempted from these requirements: Existing clients of the digital asset business operators before July 1, 2022; New clients of the operator who already have experience investing in cryptocurrency before using the service of the business operator; and Institutional investors, ultra-high-net-worth investors, and high-net-worth investors. If the clients are legal entities other than those mentioned above, their representatives or appointed persons are required to undergo training or testing. The training or knowledge test is a prerequisite to using a digital asset business operator’s services. Operators are not allowed to provide their services to clients who do not undergo training or testing. Disclosure of Service Quality and IT Usage Capacity From January 1, 2023, cryptocurrency/digital token exchanges, brokers, and dealers are required to disclose to the SEC information about the quality of their services (including any technological errors and complaints from clients), and their IT usage capacity. For more information about the latest SEC rules and regulations for digital assets,