You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 9, 2024

Critical Updates to Vietnam’s Regulatory Framework for Intermediary Payment Services

As non-cash payments continue to surge in Vietnam, the requirement for strong security standards and a clear legislative framework for intermediary payment services (“IPS”) is becoming more and more critical. Recognizing this, the State Bank of Vietnam (“SBV”) has been working on a draft decree to supersede the outdated Decree No. 101/2012/ND-CP dated November 22, 2012, on non-cash payments (“Draft Non-Cash Payment Decree”), which will lay the groundwork for non-cash payments in general and the provision of IPS in particular.

Building upon this, the SBV recently issued a draft circular to replace Circular No. 39/2014/TT-NHNN dated December 11, 2014, on IPS (“Circular 39”) (“Draft IPS Circular”), which will offer more detailed guidance on the provision of IPS in Vietnam on top of the Draft Non-Cash Payment Decree. The Draft IPS Circular will be applicable to (i) IPS providers; (ii) foreign organizations providing IPS in Vietnam; and (iii) organizations and individuals involved in the provision of IPS.

Some key updates regarding the Draft IPS Circular are as follows:

Scope of Application

The Draft IPS Circular sets out further guidance for the provision of IPS as listed under the Draft Non-Cash Payment Decree, including: (i) electronic clearing services; (ii) electronic wallet (“e-wallet”) services; (iii) collection and payment support services; (iv) financial switching services; (v) international financial switching services; and (vi) electronic payment gateway services.

Notably, the Draft IPS Circular has explicitly excluded from its scope of application the provision of accounts by goods/service providers to their customers solely for the purpose of payment within the systems of such providers (e.g., cards/coupons or service/transaction accounts of online game service providers, transportation service providers, or securities companies, etc.).

Requirements on the Provision of IPS

Electronic Clearing Services: The Draft IPS Circular introduces regulations to cover certain elements of electronic clearing services that have not been explicitly outlined in Circular 39. This is done to ensure alignment with Circular No. 37/2016/TT-NHNN dated December 30, 2016, on the management, operation, and use of the national interbank electronic payment system, specifically:

  • Additional clarification is provided on the responsibilities of the “organization presiding over electronic clearing system,” which refers to an IPS provider licensed by the SBV to offer financial switching services and electronic clearing services. This organization is also permitted to directly participate in and connect with the interbank electronic payment system (“IEPS”) for the purpose of conducting electronic clearing settlements. To achieve this, the organization will have to construct and operate an Electronic Clearing System.
  • To send, receive, and process payment transactions, IPS providers need to be members of the Electronic Clearing System. This system consists of two types of memberships: settlement members and non-settlement members. Settlement members in the system have an established net debt limit within the system, maintain a payment account at the SBV Transaction Office, and are responsible for managing their own clearing settlements. Non-settlement members depend on settlement members to manage these tasks while still being able to send, receive, and process payment transactions within the system.
  • The conditions for becoming a settlement member include: (i) being a direct member of the IEPS; (ii) establishing, monitoring, and managing an electronic clearing limit; and (iii) having written commitments with the organization presiding over the Electronic Clearing System and the SBV Transaction Office regarding its payment ability.

E-Wallet Services: The Draft Non-Cash Payment Decree and the Draft IPS Circular tightly regulate e-wallet services in the same manner as other non-cash payment methods. Some notable requirements for the provision of e-wallet services include the following:

  • E-wallet customers: Pursuant to the Draft IPS Circular, e-wallet customers are individuals and organizations allowed to open and have payment accounts at banks and/or branches of foreign banks. E-wallet service providers are not allowed to open their own e-wallets.
  • E-wallet opening channels: E-wallet opening channels have been expanded, allowing customers to also register to open e-wallets directly at partnered banks or their online transaction channels according to the e-wallet service contracts/agreements between the e-wallet service providers and the partnered banks.
  • E-wallet transaction limit: The Draft IPS Circular prescribes the personal e-wallet limit at VND 100 million/month (about USD 400/month) for normal payment transactions (excluding transactions for goods and services serving the essential needs of consumers).
  • Linking e-wallets with owners’ payment accounts/debit cards: In order to maintain a strict management approach as reflected in the Draft Non-Cash Payment Decree as well as the SBV’s recent directions, the Draft IPS Circular does not allow e-wallet customers to use e-wallets in the absence of a connection with their payment accounts/debit cards.
  • E-wallet services payment capability assurance: The Draft IPS Circular requires that e-wallet service providers must maintain (i) a payment guarantee account specifically for e-wallet services; and (ii) segregation of account information, money flows, and the use of the payment guarantee account for e-wallet services, as well as for any collection and payment support services, if applicable.

Collection and Payment Support Services: The Draft IPS Circular sets forth several principles on the provision of collection and payment support services, including: (i) subjects allowed to use the services (i.e., customers having payment accounts or bank cards); (ii) requirements for an agreement or contract with the partnered banks, which are to contain regulations on payment guarantee measures for the provision of these services, including opening a payment guarantee account, maintaining deposits, or other guarantee measures.

IPS Containing International Elements: The Draft IPS Circular provides guidance on the provision of IPS containing international elements, specifically regarding (i) foreign IPS providers that offer IPS to customers who are non-residents and foreigners residing in Vietnam to perform payment transactions for goods and/or services in Vietnam; and (ii) Vietnamese IPS providers who allow customers to perform payment transactions for goods and/or services in foreign countries.

Electronic Payment Gateway Services: The Draft IPS Circular separates the obligations of financial switching service providers, international financial switching service providers, and electronic clearing service providers from those of electronic payment gateway service providers. This separation is made due to the distinct nature of the former services, which involve providing services to parties involved in the payment systems rather than directly to customers, as is the case with payment gateway services. The Draft IPS Circular also includes a section outlining the obligations of electronic payment gateway service providers, covering their responsibilities toward both their customers and their service provision partners, such as associated banks and merchants.

Short Transitional Period

The Draft IPS Circular is expected to take effect on July 1, 2024, with a transitional period until December 31, 2024, for IPS providers to review existing information, documents, procedures, etc., and implement necessary measures to ensure full compliance. Depending on the specific circumstances, failure to do so may subject the IPS providers to penalties such as enforced termination of service provision, termination of respective partnership contracts/agreements, or termination of partnership from January 1, 2025.

IPS-Related Issues Under Other Legal Instruments

In addition to the Draft Non-Cash Payment Decree and the Draft IPS Circular, several recently released and impending legal instruments also have the potential to reshape the legal landscape for the provision of IPS in Vietnam. These include the following:

  • Decision No. 2345/QD-NHNN of the SBV dated December 18, 2023, on the application of safety and security measures to online payment and card payment: Categorizes online transactions based on transaction value and imposes specific authentication measures on the respective transaction categories, especially including an authentication mechanism using biometric data for certain transactions. Also prescribes risk mitigation solutions in online payments applicable to IPS providers, including notably: (i) customer authentication for individual customers for their first transaction using mobile banking; (ii) notification of first log-in to internet banking/mobile banking applications; and (iii) storage of information about devices on which customers’ online transactions are carried out and transaction authentication logs.
  • Draft circular to replace Circular No. 46/2014/TT-NHNN of the SBV dated December 31, 2014, guiding non-cash payment services: Addresses the responsibilities of payment service providers when cooperating with IPS providers, including (i) the responsibility to have a written agreement that clearly stipulates the parties’ obligations regarding confidentiality of customer information, payment transactions, and liability for violations of this obligation; and (ii) the responsibility for coordinating with IPS providers in checking and comparing data, authenticating transactions, customer information, etc.
  • Draft circular to replace Circular No. 20/2018/TT-NHNN of the SBV dated August 30, 2018, on the supervision of payment systems: Regulates the supervision of activities related to the provision of IPS, including monitoring compliance with legal regulations and overseeing risk management activities. These activities encompass policy development, risk management processes, and implementation activities.
  • Draft circular to replace Circular 19/2016/TT-NHNN of the SBV dated June 30, 2016, on bank card operations: Addresses the cooperation between IPS providers and other parties in transactions related to bank cards, specifically in the electronic switching and clearing of these transactions.
  • Draft circular on payment agent services: Expands regulations to encompass certain activities that resemble those of IPS providers but are not legally considered IPS. These activities now may include the following on behalf of banks: (i) collecting and verifying documents to open accounts, (ii) receiving and verifying information for bank card issuance, and (iii) handling customer service, processing transactions, and receiving or paying cash for customers.

Conclusion

As part of a series of draft circulars under the regulatory development program of the SBV this year, the Draft IPS Circular encompasses a number of new and more stringent regulations on the provision of IPS. The Draft IPS Circular is expected to address the loopholes in the existing Circular 39 and usher in momentous changes to the legal framework governing IPS in Vietnam. Given the anticipated short transitional period for compliance, IPS providers should closely monitor the progress of this draft circular to ensure they are fully prepared to comply with its new requirements.

RELATED INSIGHTS​ 

July 27, 2026
Vietnam’s new E-Commerce Law, which took effect on 1 July 2026 along with its implementing Decree No. 248/2026/ND-CP (Decree 248), marks a significant development in the country’s approach to online intellectual property (IP) enforcement, reflecting a clear shift from a reactive model of intermediary liability to one that expects platforms to play a more active role in preventing infringement. From notice-and-takedown to platform responsibility The most significant change introduced by the E-Commerce Law is the transformation of the legal role of e-commerce platforms. The existing safe harbor provisions under the IP Law and the copyright notice-and-takedown regime established by Decree 17/2023/ND-CP (Decree 17) largely required intermediaries to act only after receiving notice of infringement. Once infringing content had been removed, the platform’s legal obligation was generally considered fulfilled. The new legislation adopts a fundamentally different approach. Article 17 of the E-Commerce Law requires intermediary platforms to screen information relating to goods and services before publication in order to prevent listings involving counterfeit or IP-infringing goods, and goods of unknown origin. Rather than relying exclusively on complaints from rights holders, platforms are now expected to implement preventive measures before infringing listings become publicly available. Decree 248 further requires platforms to update keyword filters based on recommendations issued by competent authorities. These filtering mechanisms are intended to prevent prohibited listings from appearing on the platform and represent a further move away from a purely complaint-driven enforcement model. The legislation also introduces Vietnam’s first statutory stay-down obligation. Under the E-Commerce Law and Decree 248, major digital platforms must maintain automated systems capable of reviewing, warning against, and removing unlawful listings while also implementing measures to prevent repeat violations, defined under Decree 248 as conduct that has previously been identified and handled by the platform, but continues to recur. This obligation addresses one
July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 21, 2026
Thailand’s Ministry of Digital Economy and Society (MDES) published a notification establishing an expedited court-ordered takedown mechanism for online content in cases of “urgent necessity.” The notification, which was issued on July 17, 2026, under the Computer Crime Act B.E. 2550 (2007), as amended, took effect the following day. It significantly expands the categories of content subject to rapid government-initiated removal. Content Categories Subject to Takedown The notification defines “urgent necessity” (section 20, paragraph 5, of the Computer Crime Act) as circumstances where any delay in suppressing computer data may impact national security, religion, the monarchy, good morals, social culture, or public order. In this regard, it establishes four broad categories of content: Computer Crime Act offenses. National security offenses. IP and other criminal offenses, where it is contrary to public order or good morals and a competent officer has requested its suppression. Content contrary to public order or good morals, a broad residual category encompassing 14 subcategories approved by the Computer Data Screening Committee. The fourth category is the most expansive. Its 14 subcategories include: Content defaming, mocking, satirizing, or devaluing the monarchy. Online gambling advertising or facilitation. Offering illegal firearms for sale. Offering baraku (hookah) products or e-cigarettes for sale. Offering cannabis inflorescences or processed cannabis products for sale. Advertising or soliciting prostitution. Content inciting violence, hatred, or social division. Unauthorized overseas employment advertising. Offering boiled kratom juice for sale. Online sale or advertising of alcoholic beverages. Content satirizing or degrading Buddhism. Money lending at interest rates exceeding legally prescribed limits. Advertising or disseminating information about surrogacy services. Forgery of documents, cards, or official documents. Enforcement Procedure In cases of urgent necessity, a competent official assigned by the MDES permanent secretary must file a petition with supporting evidence to the court with jurisdiction, requesting an order to
July 20, 2026
On July 16, 2026, Thailand’s Personal Data Protection Committee (PDPC) published a notification in the Government Gazette establishing detailed rules governing data subjects’ right of access under section 30 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notification will take effect 60 days after publication—mid-September 2026—giving data controllers a limited window to bring their processes into compliance. Scope The notification covers requests to access or obtain copies of personal data and requests for disclosure of the source of data collected without consent. Data subjects may exercise their rights directly or through authorized representatives. Key Requirements Important requirements set by the notification include the following: Required request channels. Controllers must provide at least two request channels: direct submission at the business location and registered mail. Electronic channels are optional but, if offered, may also be used for fulfilling requests. Request contents. Requests must be in writing or in electronic form and include the data subject’s name, the preferred access method, details of the data requested, and the requester’s signature. Controllers may request additional identifying information as needed. Identity and authority verification. Controllers may require official identity documents for verification. Authorized representatives must provide authorization documents and identity documents for both the data subject and the representative. Alternative verification methods (e.g., digital authentication) are permitted if they do not unreasonably obstruct data subjects’ rights. Review and response timelines. Controllers must review requests within 15 days. If the request is incomplete, the controller must notify the requester and allow at least 15 days to correct deficiencies. If not corrected, the request may be treated as abandoned. Once verified, controllers must fulfill requests within 30 days, extendable by another 30 days for large-volume or complex requests with notice to the requester. Methods for providing access or copies. Controllers may fulfill