You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 26, 2023

Key Changes in Vietnam’s Draft Telecom Law

Vietnam’s Ministry of Information and Communications (MIC) has been working to replace the outdated 2009 Telecom Law with a new version more suited to today’s digital economy. A draft Telecom Law was made available for public consultation from October 27 to December 27, 2022. On January 17, 2023, the MIC submitted an amended draft (the “Draft”) to the Ministry of Justice for appraisal (the Vietnamese version of the Draft and accompanying documents in the dossier can be accessed here). The Draft is scheduled to be discussed by the National Assembly in May 2023 and submitted for approval in October 2023.

The key content and changes of the Draft as compared to the existing law are set out below.

1. Licensing Telecom Services

For domestic enterprises, the 2009 Telecom Law only provides two types of licenses—telecom network establishment licenses and telecom service business licenses—without differentiating the conditions and licensing procedures for various types of telecom services. This no longer meets management requirements and does not encourage enterprises to participate in providing new services on already existing infrastructure.

Although the Draft retains the two main types of licenses—licenses to provide telecom services with network establishment for a term of not more than 15 years; and licenses to provide telecom services without network establishment with a term of no more than 10 years—it also provides different licensing conditions for different types of telecom service provision, with three kinds of licensing: (i) individual licenses for certain enterprises with specific conditions and obligations based on telecom management objectives at the time of licensing; (ii) class licenses for businesses that meet the prescribed licensing conditions; and (iii) registration, which requires businesses only to submit registration information according to the prescribed form to be licensed.

In addition, to avoid the situation of licensed telecom network enterprises delaying or not implementing telecom network establishment as licensed, the Draft regulates that enterprises providing telecom services with network establishment must meet conditions of charter capital, network deployment, and service quality.

2. Cross-Border Provision of Telecom Services

For overseas enterprises, the Draft regulates that the provision of cross-border telecom services to users in Vietnam:

  • Must comply with the provisions of Vietnamese law and international treaties to which Vietnam is a member;
  • Must be done through a commercial agreement with a Vietnamese telecom enterprise that has been licensed to provide telecom services;
  • Requires Vietnamese licensed telecom enterprises to register a sample commercial agreement [with the competent agency], to have necessary technical plans to perform the task of controlling and ensuring information security or perform emergency prevention and/or stop providing telecom services at the request of competent agencies;
  • Must ensure the requirements for safety, national security and defense, and legitimate public policy objectives;
  • Will be guided in detail by the government.

3. OTT Telecom Services

The Draft supplements the definition of OTT telecom services (for example, WhatsApp, Zalo, Viber, Line, etc.) which are called “internet application services in telecom.” Accordingly, these services are telecom services providing the main function of sending, transmitting, receiving, and processing information between two or more telecom service users via the internet. The Draft allows cross-border provision of OTT telecom services to Vietnam with regulations on service providers’ responsibilities in service provision as well as requirements for notification to the MIC of contact information and other content. Forms and procedures for notification must comply with the government’s regulations.

Some key responsibilities of OTT telecom service providers include:

  • If it is necessary to access information, data, or features on the user’s terminal to serve the provision of services, the service provider must notify the user of the need and obtain the user’s consent prior to performing access.
  • Service providers must be responsible for service quality according to registered or announced standards; ensuring the correct, sufficient, and accurate calculation of charges under the contract for using telecom services.
  • Service providers must report periodically or at the request of the specialized telecom management agency on the operation of the enterprise, and must be responsible for the accuracy and timeliness of the content and data of the report.

With “internet application services in telecom” defined as a type of telecom service, the question arises whether it is also subject to the general requirement of cross-border provision of telecom services—i.e., that it must be through a commercial agreement with a Vietnamese telecom enterprise that has been licensed to provide telecom services. It is recommended that this ambiguity should be clarified by the MIC to avoid uncertainty and difficult implementation in the future.

4. Telecom Wholesale and Retail Services

The regulations on wholesale management in the existing Telecom Law are incomplete, and only provide interconnection and common use of essential facilities without regulations on buying and selling of telecom traffic for resale. This leads to difficulties for businesses to cooperate and negotiate with each other, and for state agencies to intervene when there is a dispute. The Draft aims at supplementing provisions to ensure that both wholesale and retail telecom markets are regulated, promoting healthy competition, and facilitating businesses to enter the telecom market to develop new services and provide a variety of telecom services, telecom application services, and other new services.

The Draft provides definitions of telecom wholesale and retail services, the obligations of telecom enterprises providing wholesale services for telecom services that require state management, the obligations of telecom companies with a dominant market position, and acts that restrict competition in the telecom sector.

One act of unfair competition which is not permitted for telecom enterprises or groups of telecom enterprises having a dominant market position, or telecom enterprises holding essential facilities, is to cross-offset telecom services.

Some key obligations of telecom wholesale service providers include:

  • Providing services with fair and reasonable tariff charges and conditions, without discriminating between service-buying enterprises, or between the enterprise’s own retail unit and service-buying enterprises for resale under the same circumstances.
  • Transparency of tariff charges, telecom standards, and technical regulations; quality of telecom networks and services.
  • Implementing the principles of price management of telecom wholesale services set out by the specialized telecom management agency when determining and adjusting prices.

5. Satellite Telecom Services

According to the MIC, the development trend of LEO (low-earth orbit) satellite services with cross-border services having the nature of collecting data, is likely to affect national defense, network security, information security, and protection of users’ personal data and interests, and at the same time compete directly with the domestic terrestrial mobile and fixed broadband services.

Currently, regulations on licensing satellite telecom services are at the decree level and there is no specific provision on how to license a foreign enterprise providing cross-border satellite services via an agreement with licensed telecom Vietnamese enterprises. Therefore, having learned from international experience, the MIC aims to regulate satellite services by including in the Draft a provision on cross-border telecom service provision (item 2 above), together with licensing conditions of domestic telecom enterprises providing telecom services with network establishment.

6. Data Center Services and Cloud Computing Services

The Draft has a new chapter on data center services and cloud computing services. Data center services are services that provide computing capacity, storage, and technical infrastructure of a data center, which is a complex consisting of a system of technical infrastructure, information infrastructure and ancillary equipment installed into the system to perform storage, processing, exchange, and central management of data of one or more organizations and individuals. Cloud computing is a service model that allows people to easily access shared computing resources (networks, servers, storage, applications, services) through a network connection anytime, anywhere, and as required. Cloud computing services are services that provides cloud computing resources, including information infrastructure, platform, and software as a service (IaaS, PaaS, SaaS) on a network environment. The Draft does not classify data center services and cloud computing services, as the previous draft did, but leaves this classification to be further regulated by the government.

The Draft regulates that the business of data center services and cloud computing services is a conditional business. This new chapter also provides general conditions for service provision, and responsibilities and obligations of service providers in ensuring compliance with storage regulations, announcement of standards and technical regulations, responsibility for service quality, protection of personal information and interests of users, ensuring network information security, and handling content that violates copyright or intellectual property rights or violates the law at the request of a competent authority. In addition, this chapter also regulates the rights and obligations of service users and establishes policies to encourage investment and development of data center services.

Interestingly, unlike the earlier draft, this Draft does not clearly regulate how offshore service providers can provide data center services or cloud computing services to users in Vietnam. The previous Draft set out that all providers of data center services and IaaS cloud computing services, whether onshore or offshore, had to obtain a permit to provide the services by registration with the MIC via its online portal; while PaaS and SaaS cloud computing services were exempted from this requirement. The latest Draft, instead, simply provides that providers of these services must meet the conditions on investment and business before providing the services to users in Vietnam, leaving further guidance to the government.

RELATED INSIGHTS​ 

June 23, 2026
On May 26, 2026, Thailand’s Department of Land Transport (DLT) published for public consultation a draft amendment to the Ministerial Regulation on Electronic Ride-Hailing Vehicles that would, for the first time, allow juristic persons (legal entities) to register vehicles as electronic ride-hailing cars—a right that currently belongs exclusively to natural persons, limited to one person per one vehicle. If finalized in its current form, the regulation would significantly expand the supply side of Thailand’s ride-hailing market by enabling corporate fleet operators to enter the space. The public comment period is open through June 24, 2026. Key Principles Under the Draft Regulation Under the proposed amendment, juristic persons that maintain a fleet of at least 50 vehicles will be permitted to register vehicles as electronic ride-hailing cars. This represents a fundamental shift from the current framework, which restricts registration to individual natural persons on a one-person-one-car basis. Vehicle Specifications Corporate-owned ride-hailing vehicles must meet the following requirements: Be brand new from the factory, or no more than two years old from first registration with no more than 20,000 km of use. Not be a vehicle that has been reconstructed or repaired after involvement in a serious accident affecting safety—a standard consistent with public transport vehicles (RorYor. 6). Be classified as small, medium, or large in accordance with ministerial or director-general specifications. The vehicles may be equipped with safety devices such as interior or exterior cameras (video/photo recording) and can retain the original factory color of the vehicle body (no mandatory color change is required). License Plates Corporate ride-hailing vehicles will use license plates of the same size, characteristics, and color as those for private passenger vehicles not exceeding seven seats (RorYor. 1), rather than public transport plates. Potential Impact The government has stated that the regulation is intended to: Promote
June 23, 2026
On May 14, 2026, Thailand published a ministerial regulation in the Government Gazette to prescribe measures for prevention and suppression of technology crimes. The regulation creates a comprehensive procedural framework for returning money and digital assets to victims of technology crimes. It will take effect 90 days after publication (in mid-August 2026), giving affected entities a limited window to prepare. Mandatory Reporting Obligations for Financial Institutions When a deposit account, e-money account, or digital asset wallet is frozen in connection with a technology crime, the relevant financial institution or business operator must report transaction data to the Anti-Money Laundering Office (AMLO) via AMLO’s designated electronic system. Required data elements include account numbers (sender and receiver), names, identification or passport numbers, legal entity registration numbers, phone numbers, remaining balance, damage amount, transaction reference numbers, and the bank case ID. Institutions that already share data through the information-sharing system under the emergency decree are deemed to have satisfied this reporting obligation, creating an incentive for platform participation. When the Royal Thai Police or the Department of Special Investigation seize or freeze assets related to technology crimes, they must provide AMLO with investigation reports, complaint evidence, money-trail data, and account statements. Notification and Claims Process Once the AMLO secretary-general approves verified reports of a technology crime, the account information of persons connected to the crime will be published in the Government Gazette, triggering a 90-day window for victims to file claims and for related persons to file objections. Officers will also publish details on AMLO’s electronic media and send registered mail to identified victims, which will be deemed received after 7 days domestically or 15 days internationally. Victims have 90 days from the date the crime is published in the Government Gazette to file claims through AMLO’s electronic system. Claims must include
June 15, 2026
The surge in AI development has led to a desperate demand for large, high-quality training data. However, real-world data can be expensive to collect, difficult to access, and often subject to strict privacy and regulatory constraints. Synthetic data, which consists of artificially generated records that replicate the statistical properties of real-world data without reproducing specific individuals’ information, provides an appealing solution by generating artificial datasets at scale without relying on identifiable personal information. It combines speed, cost efficiency, and regulatory compliance, making it a sensible alternative for organizations seeking to reduce risks while maintaining data utility. When properly anonymized, synthetic datasets may fall outside the scope of laws such as the EU’s General Data Protection Regulation (GDPR) or Thailand’s Personal Data Protection Act (PDPA), reducing compliance burdens while still supporting high-quality model training. However, relying on synthetic data without rigorous legal due diligence could be a strategic mistake. It replaces one set of known risks (scraping, direct privacy liability) with a new set of complex liabilities. The narrative that synthetic data is a “silver bullet” for privacy and IP compliance is dangerous and could be misleading. While synthetic data addresses data scarcity, it also introduces new legal uncertainties. Legal counsel should anticipate downstream risks arising from compromised data sources. Models trained on unlawfully obtained data may need to be decommissioned, even if their outputs appear lawful. What is synthetic data? Synthetic data refers to artificially generated information created using AI techniques such as deep learning and generative models. Instead of copying real records, it reproduces the statistical patterns and relationships found in the original dataset. Synthetic data generally falls into three categories: Fully synthetic data – Entirely new data points generated from learned patterns. The model studies the structure of the original data and produces records that resemble real-world
June 11, 2026
Thailand’s Electronic Transactions Development Agency (ETDA) has released a revised draft Electronic Transactions Act (ETA) for public hearing from May 12, 2026, to June 15, 2026. This is not merely an amendment to certain provisions of the current ETA, but a comprehensive redrafting of the entire act. The revised draft ETA introduces several significant changes from the current framework, with practical implications for businesses operating in Thailand. Unified Coverage of Public and Private Sectors The current law segregates government transactions into a separate chapter with distinct rules. The draft ETA eliminates this division, defining “transaction” to encompass civil and commercial juristic acts as well as administrative procedures, administrative contracts, and other acts of government agencies. Enhanced E-Signature Definition The definition of “electronic signature” is broadened to expressly include biometric data and refocused on identifying the signatory and demonstrating intent regarding the content of the electronic data. Shift in Burden of Proof When a party challenges the reliability of electronic data created using a “trusted electronic method” or a method prescribed by the ETDA, the burden of proof and the cost of proving unreliability shifts to the challenger. Introduction of New Digital Method Concepts The draft ETA introduces several new digital method concepts that are not currently recognized under the existing ETA framework. These include: Electronic timestamping (e-timestamp) Electronic registered delivery Electronic company seals Electronic stamp duty compliance Electronic identity authentication and verification Electronic transferable records (electronic bills of lading, promissory notes, and similar negotiable instruments) Recognition of Automated Systems and Electronic Contracting The draft ETA expressly recognizes the legal validity and enforceability of contracts formed through automated systems, including contracts concluded entirely between automated systems or between an automated system and a person. A party may not deny the binding effect of such contracts solely because no human review