You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 3, 2019

Cryptocurrency Regulations in Mainland Southeast Asia

Informed Counsel

Introduction

The rapid global proliferation of cryptocurrencies—digital currencies using advanced cryptography (typically blockchain) to verify and secure transactions and maintain supply—has seen governments scrambling to regulate what some see as an opportunity and others see as a threat. The digital nature of cryptocurrencies has meant that investors faced with new regulations can quickly seek new jurisdictions to act as a safe harbor for their assets, while developing countries that have a varied history with fiat currency have responded to this high-risk capital inflow in a number of different ways.

In this article, we compare the cryptocurrency regulations (or lack thereof) in mainland Southeast Asia—an area of increasing interest to investors following restrictive policies in China, India, and elsewhere.

Country Overviews

Cambodia – Jay Cohen, Partner and Director, Cambodia

While there is no clear regulatory scheme in Cambodia for cryptocurrencies and cryptocurrency-related activities, a joint statement on cryptocurrencies was released on May 11, 2018, by the National Bank of Cambodia (NBC), the Securities and Exchange Commission of Cambodia (SECC), and the General-Commissariat of the National Police. The release of this statement likely indicates that these ministries would be involved in the regulation of cryptocurrencies in the future, should Cambodia choose to regulate them.  

The statement makes it clear that unlicensed operations related to cryptocurrencies (e.g., propagation, buying, selling, trading, and settlement) are illegal. To date, however, neither the NBC nor the SECC have given guidance on how to apply for such a license. This could indicate that a licensing scheme for cryptocurrencies is being considered, but overall the NBC and SECC have shown reluctance to adopt cryptocurrencies in recent public statements.   

The statement also indicates that those who participate in cryptocurrency-related activities without obtaining a license from competent authorities would be subject to penalties in accordance with applicable laws. However, it is unclear what laws apply in this case, so the scope of punishments could range greatly in severity.

Laos – Dino Santaniello, Head, Laos

There is also no regulatory framework yet in place in Laos, but the Bank of the Lao P.D.R. (BOL) has issued two notifications and a warning regarding cryptocurrency.   

The first, Notification No. 314/BOL, dated August 29, 2018, encourages the Lao population to be more knowledgeable about cryptocurrency. To combat questionable or potentially misleading advertisements on social media and elsewhere promoting the use of cryptocurrencies, the BOL warned that cryptocurrency is not money and cannot be used to pay debts, while expressly identifying that there are no attendant regulations in Laos. The notification also explains the risks, lack of transparency, and potential negative ramifications of using cryptocurrencies for payment.

The BOL again addressed cryptocurrencies in Notification No. 382/BOL, dated October 30, 2018, which prohibits financial institutions in Laos from engaging in cryptocurrency-related activities or helping their clients to participate in various activities. However, no penalties for violating these prohibitions were clearly indicated. The positions of both notifications were subsequently reiterated in a BOL warning.

Some have interpreted this response as the BOL waiting to learn more about cryptocurrency before deciding upon its approach—merely urging caution rather than taking steps toward providing a clear legal framework. However, although cryptocurrency has not been declared illegal per se, the BOL’s position lays the groundwork for a potentially negative response.

Myanmar – Ross Taylor, Counsel   

In Myanmar, the only official statement on cryptocurrencies has been an announcement issued by the Central Bank of Myanmar (CBM) on May 3, 2019, which affirms that the CBM is the sole legal issuer and manager of domestic currency; that the CBM does not recognize any cryptocurrency as legal tender in Myanmar; and that the CBM has not given approval to any financial institutions to buy, sell, or exchange cryptocurrencies. Any financial institutions (bank and non-bank) that do not abide by the announcement’s provisions may face a variety of administrative sanctions up to and including the revocation of licenses under the Financial Institutions Law (2016), and consumers who buy, sell, or exchange cryptocurrencies do so at their own risk.   

Some other regulations are also pertinent here. For example, if buying and selling cryptocurrencies were used to avoid the foreign exchange regime, the party doing so could arguably be prosecuted for conducting a foreign exchange business without a license under the Foreign Exchange Management Law (2012). Similarly, if any such activity was deemed to involve money laundering, the act could be punishable by up to 10 years’ imprisonment. As for tax obligations, any profits made from cryptocurrency trading would be taxable in Myanmar as income upon examination by a tax officer.

Thailand – Praew Annez, Consultant       

Thailand leads the way as the only country in mainland Southeast Asia to have a regulatory regime for cryptocurrency. The Securities and Exchange Commission (SEC) supervises cryptocurrency-related activities, which are regulated by the 2018 Emergency Decree on Digital Asset Businesses (the “ICO Decree”). This regulates the offering and dealing of “digital assets,” including cryptocurrencies and digital tokens.    

The ICO Decree also sets requirements for ICO portals and digital asset businesses. An ICO portal is defined as an electronic system provider with the offering of newly issued digital tokens, while digital asset businesses include digital asset exchanges, digital asset brokers, and digital asset dealers. Under the ICO Decree, issuers of digital tokens must register with the SEC and obtain the appropriate approvals. This process includes the submission of a draft prospectus to the SEC.    

Additional requirements are set for issuers offering digital tokens to the public. When applying for approval, issuers must submit a registration statement and a draft prospectus, and must issue tokens according to the categories specified under the SEC approval.   

The ICO Decree sets a comprehensive structure of offenses subject to criminal sanctions and civil sanctions, which could include civil penalties, financial damages, prohibitions of involvement in cryptocurrency-related activities, and reimbursement of expenses incurred in investigating the offense.

Capital gains from the sale of digital assets are subject to income tax. For VAT purposes, digital assets are regarded as “goods,” which are subject to 7% VAT.

Vietnam  – Thao Thu Bui, Trainee Lawyer

In Vietnam, cryptocurrencies are commonly referred to as “virtual assets.” There are no legal definitions, and a regulatory framework is still lacking. However, cryptocurrencies are strictly prohibited from use as payment instruments in Vietnam.

On August 21, 2017, the prime minister issued Decision 1255 directing the Ministry of Justice, the State Bank, the Ministry of Finance, and the Ministry of Public Security to prepare reports explaining the legal status of “virtual assets” and “virtual currencies” and to recommend the amendment or issuance of relevant legislation. Almost two years later, the reports have either not yet been completed or have not been announced publicly. This delay may indicate that the government has not been able to adopt a clear stand on how to regulate cryptocurrencies in Vietnam.

In the meantime, the prime minister issued Directive 101 on April 11, 2018, after a series of cryptocurrency-related fraudulent activities. This directive ordered:

  1. the State Bank to direct credit institutions and intermediate payment providers not to carry out transactions associated with “virtual currencies”;
  2. the Ministry of Finance to direct securities firms not to engage in issuance, brokerage, and trading of “virtual currencies”; and
  3. the Ministry of Public Security to intensify its investigations into acts of mobilizing funds, multi-level marketing, and fraud in relation to “virtual currencies.”

Following this directive, the State Bank and the State Securities Commission issued warnings to lower-level banks, securities firms, and public companies not to engage in cryptocurrency-related transactions.   

Issuance, provision, or use of illegal payment instruments is subject to an administrative fine of up to VND 400 million (approx. USD 17,094) or imprisonment for 6 to 36 months.

Summary   

Although cryptocurrency regulations remain scant across mainland Southeast Asia, a quick comparison of the provisions that are in place shows that the region is not a uniformly welcoming environment for them either. Indeed, the only jurisdiction with a clear regulatory framework—Thailand—is the most expressly hospitable, with other countries issuing tentative warnings and cautionary prohibitions, rather than full regulatory frameworks.

RELATED INSIGHTS​ 

July 27, 2026
Vietnam’s new E-Commerce Law, which took effect on 1 July 2026 along with its implementing Decree No. 248/2026/ND-CP (Decree 248), marks a significant development in the country’s approach to online intellectual property (IP) enforcement, reflecting a clear shift from a reactive model of intermediary liability to one that expects platforms to play a more active role in preventing infringement. From notice-and-takedown to platform responsibility The most significant change introduced by the E-Commerce Law is the transformation of the legal role of e-commerce platforms. The existing safe harbor provisions under the IP Law and the copyright notice-and-takedown regime established by Decree 17/2023/ND-CP (Decree 17) largely required intermediaries to act only after receiving notice of infringement. Once infringing content had been removed, the platform’s legal obligation was generally considered fulfilled. The new legislation adopts a fundamentally different approach. Article 17 of the E-Commerce Law requires intermediary platforms to screen information relating to goods and services before publication in order to prevent listings involving counterfeit or IP-infringing goods, and goods of unknown origin. Rather than relying exclusively on complaints from rights holders, platforms are now expected to implement preventive measures before infringing listings become publicly available. Decree 248 further requires platforms to update keyword filters based on recommendations issued by competent authorities. These filtering mechanisms are intended to prevent prohibited listings from appearing on the platform and represent a further move away from a purely complaint-driven enforcement model. The legislation also introduces Vietnam’s first statutory stay-down obligation. Under the E-Commerce Law and Decree 248, major digital platforms must maintain automated systems capable of reviewing, warning against, and removing unlawful listings while also implementing measures to prevent repeat violations, defined under Decree 248 as conduct that has previously been identified and handled by the platform, but continues to recur. This obligation addresses one
July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 21, 2026
Thailand’s Ministry of Digital Economy and Society (MDES) published a notification establishing an expedited court-ordered takedown mechanism for online content in cases of “urgent necessity.” The notification, which was issued on July 17, 2026, under the Computer Crime Act B.E. 2550 (2007), as amended, took effect the following day. It significantly expands the categories of content subject to rapid government-initiated removal. Content Categories Subject to Takedown The notification defines “urgent necessity” (section 20, paragraph 5, of the Computer Crime Act) as circumstances where any delay in suppressing computer data may impact national security, religion, the monarchy, good morals, social culture, or public order. In this regard, it establishes four broad categories of content: Computer Crime Act offenses. National security offenses. IP and other criminal offenses, where it is contrary to public order or good morals and a competent officer has requested its suppression. Content contrary to public order or good morals, a broad residual category encompassing 14 subcategories approved by the Computer Data Screening Committee. The fourth category is the most expansive. Its 14 subcategories include: Content defaming, mocking, satirizing, or devaluing the monarchy. Online gambling advertising or facilitation. Offering illegal firearms for sale. Offering baraku (hookah) products or e-cigarettes for sale. Offering cannabis inflorescences or processed cannabis products for sale. Advertising or soliciting prostitution. Content inciting violence, hatred, or social division. Unauthorized overseas employment advertising. Offering boiled kratom juice for sale. Online sale or advertising of alcoholic beverages. Content satirizing or degrading Buddhism. Money lending at interest rates exceeding legally prescribed limits. Advertising or disseminating information about surrogacy services. Forgery of documents, cards, or official documents. Enforcement Procedure In cases of urgent necessity, a competent official assigned by the MDES permanent secretary must file a petition with supporting evidence to the court with jurisdiction, requesting an order to
July 20, 2026
On July 16, 2026, Thailand’s Personal Data Protection Committee (PDPC) published a notification in the Government Gazette establishing detailed rules governing data subjects’ right of access under section 30 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notification will take effect 60 days after publication—mid-September 2026—giving data controllers a limited window to bring their processes into compliance. Scope The notification covers requests to access or obtain copies of personal data and requests for disclosure of the source of data collected without consent. Data subjects may exercise their rights directly or through authorized representatives. Key Requirements Important requirements set by the notification include the following: Required request channels. Controllers must provide at least two request channels: direct submission at the business location and registered mail. Electronic channels are optional but, if offered, may also be used for fulfilling requests. Request contents. Requests must be in writing or in electronic form and include the data subject’s name, the preferred access method, details of the data requested, and the requester’s signature. Controllers may request additional identifying information as needed. Identity and authority verification. Controllers may require official identity documents for verification. Authorized representatives must provide authorization documents and identity documents for both the data subject and the representative. Alternative verification methods (e.g., digital authentication) are permitted if they do not unreasonably obstruct data subjects’ rights. Review and response timelines. Controllers must review requests within 15 days. If the request is incomplete, the controller must notify the requester and allow at least 15 days to correct deficiencies. If not corrected, the request may be treated as abandoned. Once verified, controllers must fulfill requests within 30 days, extendable by another 30 days for large-volume or complex requests with notice to the requester. Methods for providing access or copies. Controllers may fulfill