You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 12, 2023

Circular 06 Sets Out Guidance for VOD Content Providers in Vietnam

On June 30, 2023, Vietnam’s Ministry of Information and Communications (MIC) issued Circular No. 06/2003/TT-BTTTT to provide implementing guidelines for Decree 71 on editing, ratings, and warnings for video on demand (VOD) sports and entertainment content provided over radio and TV services. Circular 06 will take effect on August 15, 2023.

Because Decree 71 allows VOD providers to self-edit and self-rate this type of content, it is important for them to know how the process is regulated in order to fully comply before providing VOD sports and entertainment programs to Vietnamese users.

Under Circular 06, radio and TV service providers are required to display ratings and warnings on their programs, following the principles set out in the circular. These service providers must also compile dossiers in a stipulated form on the editing, ratings, and warnings of their programs for reporting to the authority and inspection.

The main contents of Circular 06 are as follows.

1. Content Editing

The main principles for editing VOD sports and entertainment programs include:

  • Protection of children and other vulnerable people from inappropriate or potentially harmful content.
  • Removal of all illegal/prohibited content, as well as content related to controversial issues or issues not recognized by Vietnamese law.
  • Removal of content or dialogue that disparages the origins of others or makes fun of others’ physical weaknesses, and content that is contrary to Vietnamese culture, morality and fine customs and traditions;
  • Removal of programs if it is discovered during the editing process that in the program or at the venue of the event, there are images or activities violating the prohibitions of the law, violating Vietnamese fine customs and traditions, or containing sensitive political elements.

In addition to compliance with the above-mentioned principles, sports and entertainment programs related to health, education, and online gaming must additionally meet the requirements of relevant specialized laws.

 

2. Content Ratings

Under Circular 06, the principles for rating of programs are based on the manner of expression; specific situations and contexts; interactivity; frequency; duration; level of detail of images, sound, lighting, and dialogue; and the level of impact of the program on the audience, in which the importance of the context and the level of impact on the audience are priority factors in rating of the programs.

The factors for rating programs include topic and content; violence; nudity and sex; drugs, stimulants and addictive substances; horror; vulgar images, sounds, and language; and dangerous behavior that is easy to imitate.

Programs are rated at a lower level when:

  • The program content is depicted verbally rather than visually; or
  • The images and words of the program have a low impact on the audience.

Programs are rated at a more stringent level when the program content:

  • Contains more details, including close-ups and slow motion;
  • Uses highlighting techniques such as lighting, perspective, and resolution;
  • Uses special effects such as light, sound, noise, resolution, color, image size, characteristics, and tones;
  • Is realistic instead of stylized; and
  • Encourages interaction.

There are six categories of program rating, based on the age range of the audience the program is eligible to be disseminated to:

  • P rated: All ages
  • K rated: Under 13 years old, provided that they are with their parents or guardians
  • T13 rated (13+): From 13 years old or older
  • T16 rated (16+): From 16 years old or older
  • T18 rated (18+): From 18 years old or older
  • C rated: Prohibited from dissemination on TV services

For programs at the borderline between levels, if the program has a way of handling situation and results which sends a message of education, humanity, praise of moral and social values, and/or has a positive impact on the audience, it will be considered to be rated at a lower level.

Further details on the program ratings are provided in an appendix to the circular.

Rating descriptors of programs are to be displayed according to the following principles:

  • The rating must be displayed clearly and prominently in the program introduction/display folder on the device’s screen interface so that the audience can make a decision to listen to or watch the program provided on the service.
  • For TV programs and audiovisual programs: The rating must continuously appear in the upper left or right corner of the screen during the program broadcast, ensuring that it does not overlap with the service icons or other icons.
  • For radio programs and audio-only programs: There is no need to display the rating during the program broadcast.

 

3. Content Warnings

Circular 06 provides the following principles for content warnings:

  • For programs rated from K to T18: Warnings must be displayed.
  • For entertainment programs that are reality TV shows; art performances; TV talent contests; exhibitions of risky and dangerous acts, with the risk of causing injury; or fictional TV shows, shows based on real-life events; sports programs in extreme sports, combat sports, and martial arts with violent or/and dangerous nature: A warning text must appear at least three seconds before the time of the act or content subject to the warning, and the text must be maintained throughout the act so that viewers do not imitate and follow the acts in these programs. The warning is to be displayed at the bottom of the screen of the device during broadcast, ensuring that it does not overlap with the service icons or other icons.

The display of warning text must be done immediately at the start of the broadcast and during the broadcast of the program using one or more appropriate methods, including but not limited to verbal or written warnings.

For TV programs and audiovisual programs, a written or verbal warning must be displayed/played no later than three seconds after the start of the broadcast; and display at least one more warning text during the broadcast for programs with a duration of less than 30 minutes, display the warning text at least two more times for programs with a duration of 30 minutes or more. The display position of the warning text is right below the rating icon of the programs.

For radio programs and audio-only programs, a verbal warning must be played immediately at the start of the broadcast.

 

4. Technical Measures

Radio and TV service providers must implement technical and technological measures to manage their content to comply with requirements. In particular, they are required to:

  • Control on the playout server programs that have been edited, rated, and had warnings attached and monitor viewers and listeners by mandatory login of personal information before listening to or viewing programs; allow listeners and viewers to control access by setting the right to restrict listening and viewing according to their needs.
  • Fully archive the provided programs on the storage device system for a period of 30 days to serve the purpose of authorities’ inspection.
  • Edit programs through a delayed server for entertainment programs that are broadcast at the same time as the original program.

RELATED INSIGHTS​ 

June 19, 2024
On June 14, 2024, the Personal Data Protection Committee (PDPC) released a draft notification under the Personal Data Protection Act 2019 (PDPA), setting out criteria for how data controllers must delete, destroy, and de-identify personal data. According to the PDPA, a data subject can request that a data controller delete, destroy, or de-identify their personal data in any of the following circumstances: The personal data is no longer necessary for the purposes for which it was collected, used, or disclosed. The data subject has withdrawn their consent for the processing of the personal data, and no other lawful basis for processing remains. The data subject has objected to the processing of their personal data on grounds of legitimate interests or official tasks, the data controller has no other compelling grounds to refuse the request, and the data is not needed for legal claims. The data subject objects to the processing of their personal data for direct marketing purposes. The processing of personal data is unlawful. The draft stipulates that data controllers respond to a data subject’s request to delete, destroy, or de-identify personal data immediately, and within 60 days of receiving the request. If the data controller cannot fulfill the request immediately, they must take interim measures to ensure that the personal data is made difficult to collect, use, or disclose. This includes implementing measures such as preventing access to the data and applying appropriate security measures to protect the data from unauthorized use or disclosure. De-identification or Anonymization of Personal Data In certain circumstances, a data controller may opt to de-identify or anonymize personal data, rather than delete or destroy it. If doing so, the data controller must satisfy the following criteria: There must be a structured process to remove or eliminate all direct identifiers linked to the
May 15, 2024
On May 1, 2024, Thailand’s National Cyber Security Committee (NCSC) published the draft NCSC Notification Re: Cloud Cybersecurity Standards for a public hearing period, which was open until May 14, 2024. These standards have been drafted to drive the country’s cloud-first policy with the aim of minimizing risks from cyber threats to cloud services utilized by government agencies, supervising or regulating organizations, and critical information infrastructure (CII) organizations. The key points of the draft Cloud Cybersecurity Standards are below. Scope The standards apply to government agencies, supervising or regulating organizations, and CII organizations under the Cybersecurity Act B.E. 2562 (2019), as well as cloud service providers (defined below). The standards prescribe cloud system cybersecurity measures for cloud service customers (defined below) and providers only to the extent that the service is provided to the in-scope organizations outlined above. Definitions Cloud service customers (CSCs): In-scope organizations that have a formal contractual agreement to use cloud services provided by a cloud service provider. Cloud service providers (CSPs): Persons who enable cloud services to be used by a cloud service customer, responsible for maintaining infrastructure, platforms, and software that enable provision of the cloud services and for managing these resources to ensure their accessibility, security, and scalability for their cloud service customers. Application In-scope organizations that will use or have been using cloud services must comply with the Cloud Cybersecurity Standards by taking into account their data or technology information systems’ level of impact, as specified in the previously issued Notification of the NCSC Re: Standards for Defining the Security Category for Data and Information Systems B.E. 2566 (2023). The impact level related to personal data is to be rated as being at least at the medium level, and the minimum standards for that level specified in the draft Cloud Cybersecurity Standards
May 13, 2024
On May 2, 2024, Vietnam’s Ministry of Justice published on its online platform the most recent version of the draft decree on administrative sanctions for violations in the field of cybersecurity (“Draft Sanction Decree”) to gather feedback and contributions from the community and stakeholders. After receiving the Ministry of Justice’s assessment, the Ministry of Public Security (“MPS”), in charge of drafting the Draft Sanction Decree, may make further revisions before submitting it to the government for review and final decision on enactment. The decree is expected to have an effective date of June 1, 2024. The stringent penalties for infringements involving personal data of the previous draft version remain in this Draft Sanction Decree—a sign of the proactive stance of the MPS in enforcing the Personal Data Protection Decree (“PDPD”). Effective Date and Transitional Provisions It is important to note that the Draft Sanction Decree does not impose any new obligations on organizations or individuals, and only sets out the administrative sanctions that could be imposed on violators as soon as June 1, 2024, which is indicated as the effective date in Article 49. This signals the MPS’s eagerness to begin taking enforcement actions against recalcitrant organizations and individuals that have not complied with the various obligations imposed on them under the Law on Network Information Security (enacted in 2015), the Law on Cybersecurity (enacted in 2018) and its guiding decree (Decree 53 – enacted in 2022), and the most recent PDPD (enacted in 2023). Article 50.1 of the Draft Sanction Decree outlines the transitional provisions regarding administrative violations in the cybersecurity field. It clarifies that the decree does not have retroactive effect, by stating that violations occurring before its effective date, but discovered or under review after such effective date will be subject to the regulations on administrative
May 9, 2024
As non-cash payments continue to surge in Vietnam, the requirement for strong security standards and a clear legislative framework for intermediary payment services (“IPS”) is becoming more and more critical. Recognizing this, the State Bank of Vietnam (“SBV”) has been working on a draft decree to supersede the outdated Decree No. 101/2012/ND-CP dated November 22, 2012, on non-cash payments (“Draft Non-Cash Payment Decree”), which will lay the groundwork for non-cash payments in general and the provision of IPS in particular. Building upon this, the SBV recently issued a draft circular to replace Circular No. 39/2014/TT-NHNN dated December 11, 2014, on IPS (“Circular 39”) (“Draft IPS Circular”), which will offer more detailed guidance on the provision of IPS in Vietnam on top of the Draft Non-Cash Payment Decree. The Draft IPS Circular will be applicable to (i) IPS providers; (ii) foreign organizations providing IPS in Vietnam; and (iii) organizations and individuals involved in the provision of IPS. Some key updates regarding the Draft IPS Circular are as follows: Scope of Application The Draft IPS Circular sets out further guidance for the provision of IPS as listed under the Draft Non-Cash Payment Decree, including: (i) electronic clearing services; (ii) electronic wallet (“e-wallet”) services; (iii) collection and payment support services; (iv) financial switching services; (v) international financial switching services; and (vi) electronic payment gateway services. Notably, the Draft IPS Circular has explicitly excluded from its scope of application the provision of accounts by goods/service providers to their customers solely for the purpose of payment within the systems of such providers (e.g., cards/coupons or service/transaction accounts of online game service providers, transportation service providers, or securities companies, etc.). Requirements on the Provision of IPS Electronic Clearing Services: The Draft IPS Circular introduces regulations to cover certain elements of electronic clearing services that have