You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 2, 2021

Decree on Consumer Protection in the Financial Sector in Laos

Informed Counsel

Background

On May 8, 2020, the Lao Ministry of Justice published the Decree on Consumer Protection regarding Financial Services No. 225/GOV, dated April 6, 2020, in its online Official Gazette. The decree was drafted by the Bank of the Lao PDR (BOL), which is the central bank in Laos. In addition to supplementing the country’s guidelines on commercial banks’ obligations to their customers, the new decree bolsters the country’s consumer protection regulatory regime under its primary relevant piece of legislation, the Law on Consumer Protection No. 02/NA, dated June 30, 2010.

Scope of Application

The decree was drafted to elaborate on Article 57 of the Law on Commercial Banks No. 56/NA, dated December 7, 2018, which requires commercial banks to devise clear procedures for receiving and resolving consumer complaints. Besides its application to commercial banks as defined by the law, the decree also applies to a wide range of service providers, including microfinance institutions (deposit-taking or otherwise), deposit and savings cooperatives, leasing companies, pawnshops, and providers proposing other types of financial services under the supervision of the BOL (referred to collectively as “service providers”). Likewise, the decree addresses a spectrum of financial services, including:

  • Monetary deposits and issuance of deposit certificates;
  • Provision of credit;
  • Card services;
  • Hire-purchase and leasing;
  • Mortgages;
  • Payment services;
  • Buying and selling currencies; and,
  • Other services authorized by the BOL, which covers all types of banking services in Laos.

Fee Restrictions and Disclosure Requirements for Financial Services

The decree requires service providers to set a written policy determining the appropriateness of the selected product, official fee, service fee, representation fee, interests rate, and other fees, in accordance with the relevant law and regulations (if any), and to document the justification for the price of each product.

Service providers are also required to advise consumers on financial services through supporting documents and materials. Though the decree provides specific requirements for different types of financial services, it notes that all service providers must provide consumers with information on the following:

  • Fees or service fees, representation fees (if any), interest and other fees—to be summarized in the relevant section of the material;
  • Impact of a change of interest rate, exchange rate, or other factors that affect the price, remuneration, or other conditions relating to the financial service;
  • The expected return of the product;
  • Duration of the contract and payment plan;
  • Conditions for termination of contracts with consumers if the consumers cannot fulfill their obligations;
  • Risks to the financial service;
  • Other similar products (if any); and,
  • How the consumer’s confidential information will be kept private.

The supporting documents and materials, which must be written primarily in the Lao language, are to use terms that are easily understood and should be in an easily readable font size and color (especially the section on the consumer’s rights and obligations under the contract). Moreover, financial service advertisements should not mislead consumers. For instance, service providers cannot claim that they guarantee a return on investment for financial services that are deemed risky.

Consumer Data Maintenance and Other Requirements for Service Providers

The decree is also attentive to the manipulation of personal information, financial information, and card passwords. Service providers must not disclose the information of consumers, and if any information is leaked, the service provider must inform the relevant consumer and document the leak. If the leak affects a large number of consumers, the service provider must also report the situation to the BOL.

The decree also requires service providers to:

  • Provide the financial services without discrimination concerning nationality, ethnicity, gender, or religion;
  • Explain the financial services;
  • When applicable, propose options that may be most appropriate for the selected consumer, so that the consumer can make an informed decision (e.g., by discussing the pros and cons of selected financial services);
  • Not retain information that may harm the consumer for the benefit of the service provider;
  • Provide services based on the disclosed or advertised information of the selected product, and not charge undisclosed fees;
  • Provide consumers with all necessary documents, such as the unsigned draft contract, the original copy of the contract after being signed, and any accompanying documentation, and specify when the consumer has the right to terminate the contract; and,
  • Set a reasonable time for the consumer to review a contract before signing or to cancel the contract (in which case the service provider may charge the consumer for the actual expenses incurred).

The decree also requires service providers to assist non-literate or visually impaired consumers, either by explaining or reading the relevant contract and other relevant documents before their signing, or by having the consumers’ respective representatives sign the contract on their behalf.

Contracts for Financial Services

All contracts related to financial services must include the following information:

  • Names and addresses of the contracting parties;
  • Terms and conditions of using the financial service;
  • Rights and obligations of the consumer;
  • Fees, service charges, and penalties (if any);
  • Information on the confidentiality of the consumer’s information;
  • Dispute resolution requirements;
  • Rights, conditions, and methods for terminating the contract; and
  • Consequences of terminating the contract.

The required content may also differ according to the type of financial service. For example, card services contracts must include information on withdrawal fees, using the card in Laos and internationally, and the credit granted and minimum monthly repayments, while contracts to provide credit must include interest rates and consequences of default.

Dispute Resolution and Penalties

In setting up a new unit or hiring an employee, service providers are required to set up communication channels to receive comments from and propose solutions to consumers’ feedback. The decree permits the service providers to administer these channels in writing, verbally, or electronically.

Upon establishing these communication channels, service providers must indicate the contact details of the unit or employee, and the relevant consumer protection department of the BOL, in every contract of services proposed. Service providers must also explain contact details and processes to the public by clearly displaying this information in their offices, branches, units, or websites.

The decree requires service providers to pay special attention to consumer complaints by recording them and, upon receiving the complete information of the source of the complaints, resolving them promptly. If the service provider cannot propose a solution to the relevant consumer immediately and requires further information on the corresponding issue, they must provide updates to the consumer every 15 days.

If the service provider’s solution is not satisfactory, the service provider and customer may then refer the dispute to the BOL (including cases involving multiple consumers). If the parties still cannot reach an agreement, the decree stipulates that they may then consult the Economic Dispute Resolution Center (a domestic arbitration center), the Lao People’s Courts, or both.

The decree provides only a broad outline of the penalties that may be triggered if its provisions are violated. It indicates that the particular sanctions will depend on the violation and may include disciplinary measures and civil compensation, but a sliding scale of the proposed fines is not given. As a result, the sanctions under the current decree may be difficult to implement, though future regulations may elaborate further.

Conclusion

By addressing financial services and their providers in Laos, this decree is an innovative regulation that is notable for its dedication to filling out the country’s consumer protection regulatory regime, as well as its transparent counsel and recommendations for service providers and their consumers. In particular, its obligations imposed on service providers, and its elaboration of the expected content of contracts for financial services, are significant steps. By clarifying the requirements of the contracts, the decree conveys its recognition of the surge of financial leasing services, which have become common for the purchase of various goods, such as cars, throughout the country in recent years, but which many had considered somewhat unregulated to date.

Overall, although the relevant sanctions have yet to be to clarified, this decree is another positive signal that the Lao authorities are expanding consumer protection in Laos after their publication earlier this year of other consumer protection-related decisions (including on the establishment of consumer protection associations, and consumer protection considerations for telecommunications and internet service providers). Moreover, the decree fulfills, in large part, its objective to elaborate on parts of the Law on Consumer Protection and the Law on Commercial Banks. Consequently, although the decree is not exhaustive, it has clearly made a positive contribution to Laos’ efforts to enhance the relationship between consumers, service providers, and financial services, both domestically and internationally.

RELATED INSIGHTS​ 

August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must
July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 17, 2026
On July 11, 2026, media reports conveyed key messages from Bank of Thailand (BOT) Governor Vitai Ratanakorn’s announcement of a sweeping regulatory crackdown on grey capital activities. The measures target high-value cash transactions, gold trading, and stablecoin flows, with new requirements set to take effect in the fourth quarter of 2026. The initiative aims to prevent financial institutions from facilitating shadow economy activity, money laundering—particularly through stablecoins—and capital flight, through enhanced compliance obligations on commercial banks across multiple transaction channels. Expanded Cash Controls Close the Deposit–Withdrawal Circuit New fourth-quarter guidelines will require individuals depositing THB 5 million or more in cash to formally verify the source of their funds. This builds on restrictions introduced in April 2026, which required anyone withdrawing 5 million baht or more in cash to provide their bank with verified commercial justification for why electronic transfers or checks could not be used. That initial measure caused high-value physical cash withdrawals to drop by 35 percent nationwide. The upcoming deposit-side requirement closes the circuit on large cash movements. The BOT is also assessing tracking mechanisms for high-value banknote swaps, specifically targeting individuals seeking to exchange large volumes of THB 1,000 notes into smaller THB 100 or THB 500 denominations without clear business justification. Governor Vitai emphasized that these measures require continuous deployment of multiple parallel strategies rather than short-term fixes. Tightened Bullion Reporting Frameworks Restrict Money Laundering Channels The BOT has also tightened reporting frameworks for gold trading to close money laundering loopholes and shield the Thai baht from speculative bullion volatility. Regulators identified a recurring pattern in which buyers purchased large quantities of gold through digital applications in the morning and then made same-day physical withdrawals from retail gold shops in the afternoon. Gold shops are reminded of their duties to flag and report cash
June 23, 2026
On May 14, 2026, Thailand published a ministerial regulation in the Government Gazette to prescribe measures for prevention and suppression of technology crimes. The regulation creates a comprehensive procedural framework for returning money and digital assets to victims of technology crimes. It will take effect 90 days after publication (in mid-August 2026), giving affected entities a limited window to prepare. Mandatory Reporting Obligations for Financial Institutions When a deposit account, e-money account, or digital asset wallet is frozen in connection with a technology crime, the relevant financial institution or business operator must report transaction data to the Anti-Money Laundering Office (AMLO) via AMLO’s designated electronic system. Required data elements include account numbers (sender and receiver), names, identification or passport numbers, legal entity registration numbers, phone numbers, remaining balance, damage amount, transaction reference numbers, and the bank case ID. Institutions that already share data through the information-sharing system under the emergency decree are deemed to have satisfied this reporting obligation, creating an incentive for platform participation. When the Royal Thai Police or the Department of Special Investigation seize or freeze assets related to technology crimes, they must provide AMLO with investigation reports, complaint evidence, money-trail data, and account statements. Notification and Claims Process Once the AMLO secretary-general approves verified reports of a technology crime, the account information of persons connected to the crime will be published in the Government Gazette, triggering a 90-day window for victims to file claims and for related persons to file objections. Officers will also publish details on AMLO’s electronic media and send registered mail to identified victims, which will be deemed received after 7 days domestically or 15 days internationally. Victims have 90 days from the date the crime is published in the Government Gazette to file claims through AMLO’s electronic system. Claims must include