You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 3, 2026

Draft Decree Has New Measures to Address Online IP Infringement in Vietnam

On March 16, 2026, Vietnam’s Ministry of Public Security released a draft version of a new Decree on the Prevention and Combating of Cybercrime and High-Tech Crime to replace the currently effective Decree 25/2014/ND-CP. In the draft, the ministry has proposed a comprehensive regulatory framework aimed at addressing violations occurring within the cybersecurity domain, including measures related to intellectual property.

Acts of Online IP Infringement

Article 9 of the draft decree notably introduces specific provisions addressing online intellectual property infringement, with detailed lists of acts considered to constitute infringement in the online environment.

Copyright and related rights infringement includes:

  • Uploading or sharing works, performances, sound recordings, video recordings, broadcasts, computer programs, software, research, documents, theses, or other intellectual creations on digital platforms without the consent of the rights holder.
  • Unauthorized livestreaming of copyrighted television programs, sporting events, or artistic performances.
  • Uploading, sharing, storing, transmitting, or providing links to infringing works or digital content via websites, social networks, applications, or digital platforms.
  • Providing or using software, tools, devices, or access codes to circumvent technological protection measures or evade lawful control mechanisms implemented by rights holders.
  • Using artificial intelligence (AI) tools to replicate the ideas or structure of another person’s work without significant new creativity or without proper attribution, thereby causing damage to the original author.

Industrial property infringement includes:

  • Manufacturing, trading, advertising, or distributing counterfeit goods bearing counterfeit trademarks, geographical indications, or industrial designs, as well as goods infringing industrial property rights through online platforms.
  • Unauthorized registration, appropriation, or use of domain names, account names, or digital identifiers that create confusion regarding the rights holder or the origin of goods or services.
  • Producing, using, or offering for sale products containing all or part of a patented invention via online platforms.
  • Advertising or introducing products with technical features or characteristics identical to those of protected inventions.

In addition to direct infringement, the draft decree also targets supporting and facilitating activities, including:

  • Failing to comply with takedown procedures or intentionally maintaining infringing content after receiving valid notification from rights holders or competent authorities.
  • Facilitating infringement by providing advertising services or payment gateway services to websites hosting infringing content.
  • Establishing or operating websites, applications, e-commerce platforms, online storefronts, channels, groups, or intermediary accounts that organize, support, or facilitate IP infringement.
  • Gaining unlawful profits from infringing activities through advertising, subscriptions, digital payments, payment intermediaries, or other monetization methods in cyberspace.
  • Concealing or legitimizing the origin of infringing goods or digital content, or obstructing the detection, removal, or handling of infringing acts.
  • Other acts conducted via cyberspace that infringe IP rights.

Notable Implications

Several aspects of the draft decree merit particular attention.

  • Expanded enforcement authority for police authorities: The police are granted enforcement authority to take action against infringements involving patents, industrial designs, domain names, and other areas. Such authority has not been clearly provided under existing regulations.
  • Introduction of AI-related copyright provisions: New provisions addressing the use of AI to generate works that may infringe copyright reflect growing regulatory attention to emerging risks associated with generative technologies.
  • New definitions related to industrial property infringement: Some new concepts are introduced, including “counterfeit industrial design goods,” “products containing all or part of a patented invention,” and “products having technical features identical to a protected invention.” These definitions could significantly affect enforcement practices involving industrial property rights.
  • Regulation of contributory infringement: The draft decree explicitly targets supporting or facilitating activities, such as providing advertising services or payment systems to infringing platforms—areas that previously lacked clear regulatory provisions.

Outlook

Although some provisions remain broad and may require further clarification through implementing guidelines, the draft decree represents a significant advancement in Vietnam’s regulatory approach to addressing online IP infringement, and signals a major policy shift by authorities toward strengthening enforcement mechanisms against IP infringement in the digital environment.

If adopted in its current or similar form, the regulation is likely to expand enforcement exposure, particularly for online platforms, intermediaries, and service providers involved in digital ecosystems.

RELATED INSIGHTS​ 

January 9, 2026
Thailand continues to advance its legal and regulatory framework for the technology sector, with several key laws undergoing review and proposed amendments. These developments reflect Thailand’s broader efforts to ensure that its regulatory landscape keeps pace with rapid technological change and aligns more closely with international standards and best practices. The following are key legal developments and proposed legislative reforms in 2026 that are expected to impact businesses operating in the technology sector and the broader Thai business landscape. Data Privacy and Cybersecurity Personal Data Protection Act B.E. 2562 (2019) Following the full enforcement of Thailand’s Personal Data Protection Act (PDPA) in June 2022, businesses and practitioners have identified practical implementation challenges and interpretative issues. These challenges were reflected in an effectiveness assessment conducted by the Personal Data Protection Committee (PDPC) in late 2024. The PDPC published a set of principles for public consultation to identify issues and directions for potential amendments to the PDPA. Key issues: Emerging issues include clarifying the definitions of “data controller,” “data processor,” and “criminal record”; revisiting the scope of sensitive personal data to better reflect Thailand’s context; proposing amendments to the hierarchy of legal bases to avoid misconceptions of consent as the default legal basis; and clarifying the required level of expressiveness for explicit consent, as well as rules for collecting personal data from other sources. Current status: The first round of public consultation has concluded. Next steps: The proposed amendments are proceeding to a revised draft following the consultation outcomes. Cybersecurity Act B.E. 2562 (2019) Thailand is moving forward with proposed amendments to enhance the effectiveness of its national cybersecurity framework, as evolving digital technologies bring new risks such as misinformation, system intrusions, and attacks on critical infrastructure, making cybersecurity a national priority. Key issues: The amendments aim to clarify and strengthen
January 8, 2026
Thailand’s Digital Government Development Agency (DGA) has proposed new standards that would require government agencies to select cloud services exclusively from a preapproved shortlist of providers. The draft Digital Government Standards re: Cloud Service Provider Standards aims to strengthen procurement confidence and reduce risks associated with selecting cloud service providers that do not meet the required standards. A public hearing period on these standards concluded on December 27, 2025. The DGA will now review submitted comments and consider revising the standards accordingly. Shortlisted Cloud Service Provider Tiers The draft standards establish three tiers of cloud service providers based on their assessed service capability levels, core qualifications, and certifications. The DGA sets qualification requirements for each tier, and it is at the discretion of each agency to select the tier of cloud service provider that best suits its operational needs, as follows: Tier 1 cloud service providers are suitable for providing services involving disclosable official data. Tier 2 cloud service providers are suitable for handling official data and protected data, such as personal data, which requires a high-security public cloud (e.g., virtual private cloud). Tier 3 cloud service providers are suitable for providing services to agencies with specific regulatory and security requirements that handle highly protected data, such as the national security system. These providers must offer sovereign or hybrid cloud as stipulated by the Ministry of Digital Economy and Society. All tiers of cloud service providers must be legal entities incorporated under Thai law and can be authorized distributors of offshore cloud service providers. However, each tier will be subject to different requirements, including infrastructure obligations. Government agencies are encouraged to select a cloud service provider appropriate for their intended use. For example, if a government agency intends to procure cloud services for operating applications that process personal data,
January 8, 2026
Thailand has enacted comprehensive sexual harassment legislation that significantly expands criminal penalties and creates new compliance obligations for online platform operators. The Act Amending the Penal Code (No. 30) B.E. 2568 (2025), enacted on December 29, 2025, and taking effect the following day, introduces a comprehensive definition of sexual harassment, establishes new criminal offenses with graduated penalties, and imposes content removal obligations on social media platforms and computer system service providers. The amendment, which establishes a comprehensive framework for addressing sexual harassment in both physical and digital environments, significantly expands legal exposure for online service operators. It also grants courts authority to order takedowns of violating data accessible to the public. Definition of Sexual Harassment The law introduces “sexual harassment” as a distinct statutory concept covering physical conduct, verbal conduct, sounds, gestures, expressions, postures, communications, surveillance, stalking, and acts committed through computer systems or electronic devices. Conduct qualifies as sexual harassment when it is sexual in nature and likely to cause the victim distress, annoyance, embarrassment, humiliation, fear, or a sense of sexual insecurity. Criminal Offenses and Penalties The amended Penal Code establishes graduated penalties based on the severity and context of the harassment—including enhanced penalties for public or online conduct. For instance: Basic sexual harassment is punishable by imprisonment for up to one year, a fine of up to THB 20,000, or both. Continuous or repeated harassment that prevents normal life escalates penalties to imprisonment for up to two years, a fine of up to THB 40,000, or both. Critically for online operators, harassment committed in public places, in the presence of the public, or through computer systems accessible to the general public triggers imprisonment for up to three years, a fine of up to THB 60,000, or both. Acts of harassment committed by supervisors, employers, or others
January 6, 2026
On December 30, 2025, Thailand’s Electronic Transactions Development Agency (ETDA) notified digital marketplace operators of a consolidated list of “high‑risk products” that are subject to strict monitoring on digital platforms. The list was jointly prepared by the Thai Industrial Standards Institute (TISI) and the Food and Drug Administration (FDA) to guide platform compliance in the initial phase of implementation of the Electronic Transaction Committee’s Notification on Other Measures for Marketplace for Goods with Specific Characteristics under Section 18(2) of the 2022 Royal Decree on Digital Platform Businesses Requiring Notification B.E.2568 (2025). The notice is addressed to operators of digital platform services that function as product marketplaces with specific characteristics laid out in the notification. The ETDA states that the TISI and the FDA are closely monitoring the high‑risk product categories on digital platforms, and the published list serves as the baseline reference for platform screening during the initial phase of the notification’s implementation. High‑Risk Product List The list aggregates categories of products that are illegal to sell online or are otherwise tightly regulated under Thai law, with an emphasis on health-related products, controlled substances, medical devices, and a wide range of industrial products that require certification or compliance with specified Thai Industrial Standards, as detailed below. Prohibited and tightly controlled health products. This includes all categories of modern medicines subject to control other than general household remedies; all categories of controlled herbal products except for over-the-counter herbal products; narcotics; psychotropic substances; and medical devices requiring use in medical facilities or a physician’s prescription. Selected industrial products requiring heightened controls. The list highlights dozens of TISI-regulated items commonly sold online. Examples include pacifiers, rice cookers, electrical wire, food wrap film, crayons, washing machines and dryers, air conditioners, electric cookers and air fryers, water heaters, microwave ovens, LED luminaires, hair dryers