You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 17, 2012

E-Commerce in AEC: Vietnam’s Regulatory Framework

Informed Counsel

In 2010, more than 50 percent of surveyed businesses in Vietnam used electronic means, such as e-mail or websites, to carry out their trading activities. Over the past six years, Vietnam has developed a legal framework that aims to facilitate online transactions, provide confidence in their legal validity, and at the same time protect the interest of consumers. Behind this development was the commitment made by Vietnam and other ASEAN member countries to implement a harmonized legal infrastructure for e-commerce in the ASEAN Economic Community by 2015.

Background

The first e-ASEAN Reference Framework for Electronic Commerce Legal Infrastructure signed in 2001, among other things, aimed to help ASEAN members without e-commerce laws to accelerate the drafting of their own laws. These countries were advised to apply the UNCITRAL Model Law on Electronic Commerce (1996) when drafting their e-commerce laws. In 2005, Vietnam passed the Law on Electronic Transactions, which largely reflected the ideologies of the UNCITRAL Model Law.

The next step was to harmonize laws among member countries in order to facilitate free flow of goods and services. Consequently, the member states have created a Roadmap for an ASEAN Community for 2008–2015, in which member states were required to facilitate mutual recognition of foreign digital signatures in ASEAN by 2011 and to build a fully harmonized legal infrastructure for ASEAN e-commerce by 2015.

Electronic Signatures

The main vision behind the UNCITRAL Model Law on Electronic Commerce was to provide a set of laws that (1) ensured that paper documents and electronic transactions were treated equally by the law, and (2) did not discriminate between different forms of technology.

The current assessment of how well these principles have been applied in Vietnam is problematic. On the one hand, Article 11 of the Law on Electronic Transactions provides that any information in data messages cannot be disclaimed of legal validity only because such information is in the form of a data message.

On the other hand, when assessing Article 11 against provisions on e-signatures and further implementing regulations, it is questionable whether electronic transactions are treated equally with traditional transactions and whether the laws are neutral in terms of technology. Article 21 provides a broad definition of electronic signature as “created in the form of words, script, numerals, symbols, sounds or in other forms by electronic means, logically attached or associated with a data message and shall be capable of certifying the person who has signed the data message and certifying the approval by such person with respect to the content of the signed data message.” In different jurisdictions, electronic signatures are interpreted broadly and may even include a simple facsimiled signature or typed name in the e-mail. This broad definition allows foreign jurisdictions to hold various e-transactions as legally binding.

In Vietnam, Decree 26/2007/ND-CP stipulates that where the law requires a document to be signed or affixed with a seal of a body or institution, the requirement is satisfied if such a data message is signed by a digital signature. A digital signature should be distinguished from an electronic signature. Digital signatures are also called cryptographic signatures, as they use asymmetric cryptography to generate the signature. Therefore, when the law requires a seal or a signature, this requirement can only be met by a data message containing a specific technology—a digital signature, which is provided by a certified organization providing digital signature certification services in Vietnam.

However, Decree 56/2006/ND-CP on e-commerce stipulates that an e-document is regarded as having a signature of a party if the method used to identify the signatory and indicate the signatory’s approval of the signed e-document is sufficiently reliable for creating and interchanging e-documents. When reviewing the above with the implementing Circular 09/2008/TT-BCT, the interpretation follows that a consumer entering into a contract via a commercial website is not required to have a digital signature, if other methods were used to identify the consumer.

Mutual Recognition of Foreign Digital Signatures

According to Decree 26 and implementing regulations, in order for foreign signatures to be recognized as legally valid in Vietnam, the foreign digital signature certification service providers must obtain a certificate from the Ministry of Information and Communications, Obtaining this certificate is subject to conditions relating to international treaties, certification in the home country, digital signature reliability, and representative office presence in Vietnam to resolve issues.

A new regulation, Decree 106/2011, has been implemented recently to amend several provisions of Decree 26. The above requirements, however, have not been amended.

Consumer Protection

By 2011, Vietnam completed the implementation of a legal framework on consumer protection. The Law on Protection of Consumers’ Rights was passed in 2010 and implementing Decree 99/2011/ND-CP passed in late 2011. The regulations provide basic protection to consumers engaging in electronic transactions by requiring suppliers to provide certain information about the transaction to the consumer. Consumers are also given the default right to unilaterally terminate the contract if the supplier does not provide the information. The law allows disputes between consumers and organizations to be resolved by arbitration.

Conclusion

Although drastic steps have been taken to create a legal framework to regulate e-commerce in Vietnam, the implementing regulations are not always consistent with best practices. A more effective system for implementing mutual recognition of digital signatures is necessary for Vietnam to prepare for harmonization of e-commerce legal infrastructure in the AEC by 2015.

RELATED INSIGHTS​ 

June 5, 2026
Vietnam’s AI regulatory framework has reached an important milestone. While the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law) established the foundation for AI governance, many practical compliance requirements were left to implementing regulations. On April 30, 2026, the government issued Decree No. 142/2026/ND-CP (Decree 142), which took effect on May 1, 2026, and provides the first detailed guidance on the implementation of the AI Law. Although an official list of high-risk AI systems is still pending from the prime minister, Decree 142 provides valuable insight into how Vietnam’s risk-based AI regulatory framework will operate in practice. Risk Classification Framework The AI Law adopts a risk-based approach under which AI systems are classified as high-risk, medium-risk, or low-risk. Decree 142 builds on this framework by providing detailed guidance on how these classifications are determined. High-risk AI systems are determined based on factors such as (i) their potential impact on life, health, property, human rights, public interests, or national security; (ii) the sector in which they are deployed; and (iii) the scale of affected users or integration with critical infrastructure. The latest draft list of high-risk AI systems appears to follow these same principles. Medium-risk AI systems generally include systems that may mislead, influence, or manipulate users, particularly where users may not realize they are interacting with AI or AI-generated content. The focus is therefore on transparency and authenticity risks rather than broader societal or safety concerns. Low-risk AI systems are those that do not meet the criteria for either high-risk or medium-risk classification. Importantly, Decree 142 seeks to avoid over-classification. Certain systems may fall outside the high-risk or medium-risk regimes, including internal-use systems, office-support tools, technical editing applications, certain back-end processing systems, and AI systems used in artistic, gaming, cinematic, or other creative contexts. Providers must also review and
June 5, 2026
On May 11, 2026, Thailand’s Ministry of Social Development and Human Security released a draft Child Protection Act (“CPA”) for public review. The draft CPA would completely repeal and replace the current Child Protection Act B.E. 2546 (2003). This represents the most comprehensive overhaul of Thailand’s child protection framework in over two decades, reflecting the government’s stated objective of modernizing the law to address evolving social challenges—including those arising from digital technology—and to promote greater coordination among government agencies, local authorities, and civil society. The public review period closes on June 9, 2026. Key changes introduced by the draft CPA that could have significant implications for businesses, particularly online platform providers, media companies, and entities operating child-related services in Thailand, are set out below. Expanded Definition of “Child” Under the current CPA, a “child” is defined as a person under the age of 18, excluding those who have attained legal majority through marriage. The draft CPA removes the marriage exception entirely, broadening the scope of the law’s protections to include all individuals under 18 without exception. Replacement of “Abuse” with Broader Concept of “Violence” The current CPA uses the term “abuse/cruelty,” which covers acts causing harm to a child’s liberty, body, or mind; sexual offenses against children; and using children in harmful or immoral activities. The draft CPA replaces this with the broader concept of “violence,” which encompasses any act or omission causing harm to a child’s body, mind, or development; abandonment or neglect; improper exploitation; and sexual abuse. Notably, the new definition adds developmental harm as a recognized category of injury and captures all forms of misconduct regardless of the child’s consent. New Standalone Definition of Sexual Abuse, Including Online Conduct One of the most significant additions in the draft CPA is the introduction of a standalone definition
May 25, 2026
After several years of policy discussion and continued efforts led by the Ministry of Commerce (MOC) to relax the list of reserved businesses under the Foreign Business Act B.E. 2542 (1999) (FBA), the reform process has now reached a significant milestone. On May 12, 2026, the Thai cabinet approved in principle two draft subordinate legislative instruments aimed at delisting certain reserved business activities under the FBA and reducing licensing requirements for foreign business operators. These developments signal a renewed and concrete effort by the government to modernize Thailand’s business regulatory framework in order to attract foreign investment and boost Thailand’s competitiveness in the global market. Nine Businesses Set for FBA Delisting Below is a list of the nine businesses that are being targeted for delisting from the FBA’s restrictions. A draft ministerial regulation would delist the first eight reserved businesses, while a royal decree has been drafted to delist the ninth business: Telecommunications services (Type 1 license only, covering operators without their own telecommunications infrastructure), under the supervision of the Office of the National Broadcasting and Telecommunications Commission. Treasury center services subject to the Foreign Exchange Control Act B.E. 2485 and under the supervision of the Bank of Thailand. Securities-collateralized lending, pursuant to the laws governing securities and exchange and derivatives regulated by the Securities and Exchange Commission. Agency, dealer, advisory, or fund management services relating to derivatives where the underlying assets fall outside the scope of the Derivatives Act B.E. 2546 (2003) Intra-group shared services, including administrative, human resources, and IT functions Intra-group domestic debt guarantee services Leasing of partial space for installation of financial service machines and automatic vending machines for employee use Petroleum drilling services Trading of agricultural product derivatives through a futures exchange, with physical delivery or receipt of agricultural products at a futures exchange–designated
May 25, 2026
Thailand published new rules on May 1, 2026, establishing clear procedures for how the Anti-Money Laundering Office (AMLO) handles digital assets seized during criminal and money laundering investigations. Taking effect the following day, the Regulation of the Anti-Money Laundering Board on the Custody and Management of Seized or Frozen Assets (No. 3) B.E. 2569 applies to digital asset businesses, cryptocurrency holders, and anyone subject to asset seizure under Thailand’s anti-money laundering laws. For the first time, authorities now have a detailed roadmap for transferring seized digital property from private or foreign control into secure state custody. Digital asset businesses holding customer assets under investigation must be prepared to comply with these rules compelling repatriation of such assets in enforcement actions. Expanded Definition of Digital Assets The regulation defines digital assets to include not only those covered by Thailand’s existing digital asset business law but also any other property that can be stored using the same methods as digital assets. This broad formulation means the custody rules will apply to emerging blockchain-based assets and tokenized property that may not yet fall within the statutory definition of a digital asset business, giving authorities flexibility as the technology evolves. Mandatory Transfer to Domestic Custody When digital assets are held with service providers outside Thailand, AMLO will first attempt to transfer them to an account the office maintains with a licensed domestic digital asset business operator. If the domestic operator does not support that particular asset, the office will instead move the assets to its own cold wallet (offline, internet-isolated storage system). If neither option is feasible, the seizing official will report the situation to the Anti-Money Laundering Committee for alternative instructions. A similar hierarchy governs assets held in an accused party’s private wallet or by any third party that is not a