You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 3, 2026

Draft Decree Has New Measures to Address Online IP Infringement in Vietnam

On March 16, 2026, Vietnam’s Ministry of Public Security released a draft version of a new Decree on the Prevention and Combating of Cybercrime and High-Tech Crime to replace the currently effective Decree 25/2014/ND-CP. In the draft, the ministry has proposed a comprehensive regulatory framework aimed at addressing violations occurring within the cybersecurity domain, including measures related to intellectual property.

Acts of Online IP Infringement

Article 9 of the draft decree notably introduces specific provisions addressing online intellectual property infringement, with detailed lists of acts considered to constitute infringement in the online environment.

Copyright and related rights infringement includes:

  • Uploading or sharing works, performances, sound recordings, video recordings, broadcasts, computer programs, software, research, documents, theses, or other intellectual creations on digital platforms without the consent of the rights holder.
  • Unauthorized livestreaming of copyrighted television programs, sporting events, or artistic performances.
  • Uploading, sharing, storing, transmitting, or providing links to infringing works or digital content via websites, social networks, applications, or digital platforms.
  • Providing or using software, tools, devices, or access codes to circumvent technological protection measures or evade lawful control mechanisms implemented by rights holders.
  • Using artificial intelligence (AI) tools to replicate the ideas or structure of another person’s work without significant new creativity or without proper attribution, thereby causing damage to the original author.

Industrial property infringement includes:

  • Manufacturing, trading, advertising, or distributing counterfeit goods bearing counterfeit trademarks, geographical indications, or industrial designs, as well as goods infringing industrial property rights through online platforms.
  • Unauthorized registration, appropriation, or use of domain names, account names, or digital identifiers that create confusion regarding the rights holder or the origin of goods or services.
  • Producing, using, or offering for sale products containing all or part of a patented invention via online platforms.
  • Advertising or introducing products with technical features or characteristics identical to those of protected inventions.

In addition to direct infringement, the draft decree also targets supporting and facilitating activities, including:

  • Failing to comply with takedown procedures or intentionally maintaining infringing content after receiving valid notification from rights holders or competent authorities.
  • Facilitating infringement by providing advertising services or payment gateway services to websites hosting infringing content.
  • Establishing or operating websites, applications, e-commerce platforms, online storefronts, channels, groups, or intermediary accounts that organize, support, or facilitate IP infringement.
  • Gaining unlawful profits from infringing activities through advertising, subscriptions, digital payments, payment intermediaries, or other monetization methods in cyberspace.
  • Concealing or legitimizing the origin of infringing goods or digital content, or obstructing the detection, removal, or handling of infringing acts.
  • Other acts conducted via cyberspace that infringe IP rights.

Notable Implications

Several aspects of the draft decree merit particular attention.

  • Expanded enforcement authority for police authorities: The police are granted enforcement authority to take action against infringements involving patents, industrial designs, domain names, and other areas. Such authority has not been clearly provided under existing regulations.
  • Introduction of AI-related copyright provisions: New provisions addressing the use of AI to generate works that may infringe copyright reflect growing regulatory attention to emerging risks associated with generative technologies.
  • New definitions related to industrial property infringement: Some new concepts are introduced, including “counterfeit industrial design goods,” “products containing all or part of a patented invention,” and “products having technical features identical to a protected invention.” These definitions could significantly affect enforcement practices involving industrial property rights.
  • Regulation of contributory infringement: The draft decree explicitly targets supporting or facilitating activities, such as providing advertising services or payment systems to infringing platforms—areas that previously lacked clear regulatory provisions.

Outlook

Although some provisions remain broad and may require further clarification through implementing guidelines, the draft decree represents a significant advancement in Vietnam’s regulatory approach to addressing online IP infringement, and signals a major policy shift by authorities toward strengthening enforcement mechanisms against IP infringement in the digital environment.

If adopted in its current or similar form, the regulation is likely to expand enforcement exposure, particularly for online platforms, intermediaries, and service providers involved in digital ecosystems.

RELATED INSIGHTS​ 

February 28, 2025
Vietnam’s Decree No. 163/2024/ND-CP (Decree 163), which has been in full effect since January 1, 2025, provides crucial guidance on the implementation of Vietnam’s 2023 Telecom Law. Decree 163 replaced Decree No. 25/2011/ND-CP dated April 6, 2011 (Decree 25), which guided the implementation of the previous 2009 Telecom Law, and introduces many notable changes to the regulations on telecom service provision. Some key changes that will impact businesses engaged in the telecom sector in Vietnam are detailed below. 1. Classification of Telecom Services The classification of telecom services into “basic telecom services” and “value-added telecom services” has been retained, in alignment with Vietnam’s WTO commitments in the telecom sector. However, Decree 163 expands the scope of both categories, as follows: Basic telecom services: “Transmission services for machine-to-machine (M2M) communication” and “leasing services of all or part of the telecom network” are added. “Image transmission services” is changed to “transmission services for radio and television.” Value-added telecom services: “Data center services,” “cloud computing services,” and “basic telecom services over the internet” (also known as over-the-top (OTT) telecom services) are added. 2. M2M Communication Services Since M2M communication services are classified as basic telecom services, without exception, they are subject to the same regulatory framework. Specifically: Cross-border provision: M2M communication services provided across borders must be conducted through a commercial agreement with a Vietnamese telecom enterprise licensed to provide telecom services with an international communication scope. Onshore provision: Onshore M2M communication services will require a telecom license. 3. New Telecom Services (Data Center, Cloud, and OTT Telecom Services) The 2023 Telecom Law adopted a light-touch management approach for data center, cloud, and OTT telecom services by not requiring the same licensing as previously regulated value-added telecom services, but instead mandating registration or notification before service provision. Decree 163 offers clearer guidance
February 26, 2025
Tilleke & Gibbins has contributed the Vietnam chapter to Data Protection 2025, a comprehensive comparative guide in the Law Over Borders series from Global Legal Post. This Q&A-style resource offers detailed insights into data protection regulations across multiple jurisdictions, serving as an essential reference for organizations managing personal data in today’s global business environment. The Vietnam chapter examines the evolving data protection landscape in Vietnam, including analysis of relevant provisions in the Cybersecurity Law, the Law on Information Technology, and the upcoming Personal Data Protection Decree. The chapter addresses key aspects of data protection through the following topics: Regulatory framework: Analysis of national laws regulating personal data, jurisdictional scope, application to different entities, and regulated data processing activities. Data categories and processing: Overview of regulated personal data types, special categories requiring enhanced protection, and lawful processing requirements. Compliance requirements: Explanation of controller and processor obligations, technical and organizational measures, and data subject rights. Commercial communications and international transfers: Rules governing direct marketing and cross-border data flows. Regulatory oversight: Details on enforcement powers, investigation procedures, sanctions, and remedies for noncompliance. Tilleke & Gibbins also contributed the Thailand chapter to Data Protection 2025. Readers can access the complete Data Protection 2025 guide through Global Legal Post’s Law Over Borders platform.
February 26, 2025
Tilleke & Gibbins has contributed the Thailand chapter to Data Protection 2025, a newly published comparative guide from Global Legal Post’s Law Over Borders series. This comprehensive Q&A-style resource provides insights into data protection regulations across multiple jurisdictions worldwide, offering valuable guidance for businesses navigating the complex landscape of global data privacy requirements. The Thailand chapter offers a detailed analysis of the country’s data protection framework, with particular focus on the Personal Data Protection Act (PDPA) that came into full effect in 2022. The chapter addresses key aspects of data protection in Thailand through the following topics: Regulatory framework: National laws governing personal data, scope of application, territorial reach, and regulated operations. Data categories and protection: Types of personal data covered, special categories subject to enhanced protection, and processing requirements. Compliance obligations: Requirements for lawful processing, organizational responsibilities, and data subject rights. Marketing and cross-border considerations: Rules for commercial communications and international data transfers. Enforcement mechanisms: Regulatory powers, investigation procedures, sanctions, and remedies for noncompliance. Tilleke & Gibbins also contributed the Vietnam chapter to Data Protection 2025. Readers can access the complete Data Protection 2025 guide through Global Legal Post’s Law Over Borders platform.
February 20, 2025
Vietnam’s Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (Decree 147) was issued on November 9, 2024, and came into effect on December 25, 2024. Decree 147 represents a more stringently regulated digital landscape in Vietnam, creating challenges not only for offshore service providers offering cross-border services but also for onshore providers. As these new regulations impose stricter requirements, particularly in areas like content control, user authentication, data storage, and service license/notification, companies will need to adapt quickly to maintain compliance and minimize legal risks. The following are some of the key topics covered by Decree 147. [Note: Shortly after the issuance of Decree 147, Vietnam began a government restructuring process, with the aim of streamlining the government by consolidating and eliminating various ministries and agencies. Thus, the decree’s references to authorities such as the Authority of Broadcasting and Electronic Information (ABEI) and the Ministry of Information and Communications (MIC) are subject to change.] 1. Cross-Border Information Provision Cross-border information provision is defined broadly as the provision by overseas organizations and individuals of information and online information content services for service users in Vietnam to access or use. This wide-ranging definition encompasses various types of cross-border services, including social network services, online game services, and app store services. However, cross-border provision of online game services remains prohibited under Decree 147 (see further details below). Offshore providers of services on a cross-border basis who lease data storage in Vietnam or meet a threshold of 100,000 or more total visits per month from Vietnam for six consecutive months (“regulated cross-border providers”) must adhere to stricter requirements. Specifically, they are required to, among other requirements: Notify the relevant authority of their contact information, including the location of the main server providing the service, within 60