You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 12, 2023

Circular 06 Sets Out Guidance for VOD Content Providers in Vietnam

On June 30, 2023, Vietnam’s Ministry of Information and Communications (MIC) issued Circular No. 06/2003/TT-BTTTT to provide implementing guidelines for Decree 71 on editing, ratings, and warnings for video on demand (VOD) sports and entertainment content provided over radio and TV services. Circular 06 will take effect on August 15, 2023.

Because Decree 71 allows VOD providers to self-edit and self-rate this type of content, it is important for them to know how the process is regulated in order to fully comply before providing VOD sports and entertainment programs to Vietnamese users.

Under Circular 06, radio and TV service providers are required to display ratings and warnings on their programs, following the principles set out in the circular. These service providers must also compile dossiers in a stipulated form on the editing, ratings, and warnings of their programs for reporting to the authority and inspection.

The main contents of Circular 06 are as follows.

1. Content Editing

The main principles for editing VOD sports and entertainment programs include:

  • Protection of children and other vulnerable people from inappropriate or potentially harmful content.
  • Removal of all illegal/prohibited content, as well as content related to controversial issues or issues not recognized by Vietnamese law.
  • Removal of content or dialogue that disparages the origins of others or makes fun of others’ physical weaknesses, and content that is contrary to Vietnamese culture, morality and fine customs and traditions;
  • Removal of programs if it is discovered during the editing process that in the program or at the venue of the event, there are images or activities violating the prohibitions of the law, violating Vietnamese fine customs and traditions, or containing sensitive political elements.

In addition to compliance with the above-mentioned principles, sports and entertainment programs related to health, education, and online gaming must additionally meet the requirements of relevant specialized laws.

 

2. Content Ratings

Under Circular 06, the principles for rating of programs are based on the manner of expression; specific situations and contexts; interactivity; frequency; duration; level of detail of images, sound, lighting, and dialogue; and the level of impact of the program on the audience, in which the importance of the context and the level of impact on the audience are priority factors in rating of the programs.

The factors for rating programs include topic and content; violence; nudity and sex; drugs, stimulants and addictive substances; horror; vulgar images, sounds, and language; and dangerous behavior that is easy to imitate.

Programs are rated at a lower level when:

  • The program content is depicted verbally rather than visually; or
  • The images and words of the program have a low impact on the audience.

Programs are rated at a more stringent level when the program content:

  • Contains more details, including close-ups and slow motion;
  • Uses highlighting techniques such as lighting, perspective, and resolution;
  • Uses special effects such as light, sound, noise, resolution, color, image size, characteristics, and tones;
  • Is realistic instead of stylized; and
  • Encourages interaction.

There are six categories of program rating, based on the age range of the audience the program is eligible to be disseminated to:

  • P rated: All ages
  • K rated: Under 13 years old, provided that they are with their parents or guardians
  • T13 rated (13+): From 13 years old or older
  • T16 rated (16+): From 16 years old or older
  • T18 rated (18+): From 18 years old or older
  • C rated: Prohibited from dissemination on TV services

For programs at the borderline between levels, if the program has a way of handling situation and results which sends a message of education, humanity, praise of moral and social values, and/or has a positive impact on the audience, it will be considered to be rated at a lower level.

Further details on the program ratings are provided in an appendix to the circular.

Rating descriptors of programs are to be displayed according to the following principles:

  • The rating must be displayed clearly and prominently in the program introduction/display folder on the device’s screen interface so that the audience can make a decision to listen to or watch the program provided on the service.
  • For TV programs and audiovisual programs: The rating must continuously appear in the upper left or right corner of the screen during the program broadcast, ensuring that it does not overlap with the service icons or other icons.
  • For radio programs and audio-only programs: There is no need to display the rating during the program broadcast.

 

3. Content Warnings

Circular 06 provides the following principles for content warnings:

  • For programs rated from K to T18: Warnings must be displayed.
  • For entertainment programs that are reality TV shows; art performances; TV talent contests; exhibitions of risky and dangerous acts, with the risk of causing injury; or fictional TV shows, shows based on real-life events; sports programs in extreme sports, combat sports, and martial arts with violent or/and dangerous nature: A warning text must appear at least three seconds before the time of the act or content subject to the warning, and the text must be maintained throughout the act so that viewers do not imitate and follow the acts in these programs. The warning is to be displayed at the bottom of the screen of the device during broadcast, ensuring that it does not overlap with the service icons or other icons.

The display of warning text must be done immediately at the start of the broadcast and during the broadcast of the program using one or more appropriate methods, including but not limited to verbal or written warnings.

For TV programs and audiovisual programs, a written or verbal warning must be displayed/played no later than three seconds after the start of the broadcast; and display at least one more warning text during the broadcast for programs with a duration of less than 30 minutes, display the warning text at least two more times for programs with a duration of 30 minutes or more. The display position of the warning text is right below the rating icon of the programs.

For radio programs and audio-only programs, a verbal warning must be played immediately at the start of the broadcast.

 

4. Technical Measures

Radio and TV service providers must implement technical and technological measures to manage their content to comply with requirements. In particular, they are required to:

  • Control on the playout server programs that have been edited, rated, and had warnings attached and monitor viewers and listeners by mandatory login of personal information before listening to or viewing programs; allow listeners and viewers to control access by setting the right to restrict listening and viewing according to their needs.
  • Fully archive the provided programs on the storage device system for a period of 30 days to serve the purpose of authorities’ inspection.
  • Edit programs through a delayed server for entertainment programs that are broadcast at the same time as the original program.

RELATED INSIGHTS​ 

September 8, 2022
While much attention has been paid to the data localization requirements for foreign enterprises under Vietnam’s 2018 Cybersecurity Law (“CSL”) and the recently issued Decree 53 guiding its implementation, the corresponding requirements for domestic enterprises are often overlooked, despite being potentially more troublesome. Under Decree 53, “domestic enterprises” are defined to mean enterprises established or registered for establishment under Vietnamese law and having their head offices in Vietnam (Article 2.11), so this designation includes not only Vietnamese companies, but foreign-invested enterprises as well. Background Before analyzing the stipulations in Articles 26 and 27 of Decree 53 further guiding the data localization/storage requirements, it is worth restating the very problematic Article 26.3 of the CSL, which reads: “Domestic and foreign enterprises providing services on telecommunication networks or the internet or value-added services in cyberspace in Vietnam with activities of collecting, exploiting, analyzing, and/or* processing personal information data, data on the relationships of service users, or data generated by service users in Vietnam must store such data in Vietnam for the period prescribed by the government. Foreign enterprises mentioned in this clause must open branches or representative offices in Vietnam.” [* Note: The Vietnamese text simply uses a comma here, without specifying whether this should be “and” or “or,” leading to additional problems in interpretation.] Because of this very broad and ambiguous wording, Article 26.3 of the CSL required further guidance from the government and remained unenforced for more than three years after the CSL took effect on January 1, 2019. Decree 53 guiding the implementation of the CSL was finally issued on August 15, 2022, and provides additional clarity on this matter. But does Decree 53 provide sufficient guidelines for implementation with regard to domestic enterprises? Scope of Application With regard to foreign enterprises, although there remains some ambiguity, Decree
September 6, 2022
The Thai National Cybersecurity Committee (NCSC), as required by the Cybersecurity Act, reported to the cabinet in mid-August on trends and developments regarding cyber incidents in Thailand. According to the NCSC, the top five most common cyber incidents involve website phishing, website defacement, data leakage, data security vulnerabilities, and ransomware. Reported incidents of cyberattacks have increased in recent years. The report stated that affected organizations primarily responded to cyber incidents and attacks by notifying the NCSC about the incident and the remedial actions planned or taken, and conducting internal training to increase awareness of cyber threats. Only two organizations chose to conduct IT risk assessments and vulnerability tests as preventive measures against future cyber threats. The NCSC report also showed that aside from telecom infrastructure, energy and utilities, and education operators falling victim to cyberattacks, healthcare, webhosting, and data center operators have also become “more common victims” of cyber incidents. The NCSC recommended that all organizations prepare for inevitable future cyber incidents. This includes ensuring that businesses and organizations comply with international standards, which includes measures that are recognized and incorporated in Thailand’s Personal Data Protection Act (PDPA) and Cybersecurity Act. Conducting internal training for employees as well as directors and officers is also recommended by the NCSC, as this can help prevent cyber incidents and ensure that businesses comply with the minimum required security standards issued by the Personal Data Protection Committee (PDPC) in their Notification Re: Security Measures of the Data Controller B.E. 2565 (2022), which came into effect on June 21, 2022. Industry-specific minimum required security standards (e.g., those regulated by the Bank of Thailand, Office of Insurance Commission, etc.) should also be considered in conjunction with those in this PDPC notification—particularly when sectoral requirements are more stringent than the PDPC’s recommended measures. PDPA statutory penalties
August 19, 2022
Vietnam’s Cybersecurity Law was promulgated on June 12, 2018, and came into effect on January 1, 2019, with a majority of its provisions enforceable from the effective date. However, certain provisions of the law, including the very concerning data localization requirements, still awaited further guidance from implementing regulations. After more than three years of being drafted and submitted back and forth to the government for consideration and approval, Decree No. 53/2022/ND-CP to implement certain articles of the Cybersecurity Law (Decree 53) was finally promulgated on August 15, 2022, with an effective date of October 1, 2022. Key provisions of Decree 53 include the following. 1. Data localization requirements (Articles 26 & 27) Decree 53 retains most of the data localization requirements of the last accessible version of the draft decree dated August 21, 2019 (Draft Decree), clearly extends the scope of requirements to cover both domestic and foreign enterprises, adds regulations on force majeure events, and amends the timeline to implement data localization requirements for business facilitation. (i) Data subject to data localization: Data (information in the form of symbols, writing, numbers, images, sounds, or similar forms) which must be stored in Vietnam (“regulated data”) includes: Data on personal information of service users in Vietnam: Data used to identify an individual. Data generated by service users in Vietnam: Data reflecting the process of participating in, operating and/or using cyberspace by service users and information about network equipment and services used in order to connect with cyberspace in the territory of Vietnam. This includes the account name for use of services, duration of use of services, credit card information, email address, IP addresses for the latest login and logout, and registered telephone number attached to the account or data. Data on the relationships of service users in Vietnam: Data reflecting
August 11, 2022
In July 2022, the Thai cabinet approved in principle a royal decree exempting some businesses and other entities from parts of the Personal Data Protection Act B.E. 2562 (PDPA). The draft royal decree proposes to exempt certain business operators and activities from the requirements of the following portions of the PDPA: Chapter II: Personal Data Protection – Consent, notification, cross-border transfer of the personal data requirements, etc. Chapter III: Rights of the Data Subject – Requirements and criteria on data subject rights. Chapter V: Complaints – Requirements on the submission of complaints to the Office of the Personal Data Protection Commission. Chapter VI: Civil Liability – Conditions in relation to the civil liability of a data controller or data processor. Chapter VII: Penalties – Administrative and criminal penalties. The proposed exemptions would apply to three main categories of business operators and activities: 1. Data controllers acting on government requests in adherence with specific laws for the following purposes: State security and public safety. Exempted operations include activities intended to safeguard state security, intelligence, and information relating to national security, as well as efforts to maintain fiscal and economic security and public security. Also exempt are prevention and suppression of certain criminal activities, such as money laundering, drug trafficking, transnational threats and terrorism, transnational crime, and human trafficking; activities to bolster anticorruption or cybersecurity efforts; and actions relating to public health, sanitation to prevent epidemics, and protection of public life, health, and property. Taxation. Exempted activities include those related to tax collection under laws that are the responsibility of the Revenue Department, Customs Department, or Excise Department. This also extends to any action relating to the enforcement of taxation fees or duties, and actions related to social security, the performance of obligations, or international cooperation. Risk mitigation, monitoring, and surveillance.