You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 9, 2016

Legal Update: New Regulations in the ICT Sector in Vietnam

The final months of 2015 saw a flurry of new legislation in Vietnam’s Information Communication and Technology (ICT) sector. Some of the new regulations have recently taken effect, while others will become effective later in 2016. Below we provide an overview of some key legislation:

  • Information security. The new Law on Information Security is Vietnam’s first comprehensive statute in this area. Previously, data-security regulations were scattered across different pieces of legislation, such as the Law on Information Technology and the Law on Telecommunications. The new law includes, among other things, provisions on ensuring safety and security of information; protecting personal information in the network environment; and preventing spam, computer viruses, and harmful software. The Law on Information Security was passed on November 19, 2015, and will take effect on July 1, 2016.
  • Broadcasting services. Decree 06/2016/ND-CP on management, provision, and use of broadcasting services, which will come into force on March 15, 2016, regulates pay TV and the co-production of radio and TV programs. Replacing the current Decision 20 and Circular 19, Decree 06 has new, clearer regulations on Internet TV and offers some licensing exemptions for foreign channels which do not receive royalty payments. In addition, under the new decree, the number of foreign channels cannot exceed 30 percent of the total number of pay TV channels in Vietnam. The key content in Circular 19 on coproduction of radio and TV programs is retained in Decree 06, including the ban on coproduction of news and politics programs.
  • Internet resources. Circular 24/2015/TT-BTTTT on management and use of Internet resources provides additional grounds for dealing with “.vn” domain name disputes. For more information about Circular 24, please refer to our previous legal update.
  • Used IT products. The list of used IT products that are prohibited from importation has been updated in Circular 31/2015/TT-BTTTT (passed on October 29, 2015, and effective from December 15, 2015). This list notably still includes refurbished IT products, but upcoming legislation (see below) is expected to include some exceptions for refurbished goods.
  • Used machinery, equipment, and production lines. Circular 23/2015/TT-BTTT on importing used machinery, equipment, and production lines was passed on November 13, 2015, and will take effect on July 1, 2016, replacing Circular 20. Circular 23 will make it significantly easier for ICT companies to import used equipment by reducing restrictions and facilitating customs clearance.
  • Quality control of telecom services. Circular 35/2015/TT-BTTTT mainly updates the list of telecommunication services subject to quality control to keep up with the latest advances in technology. This circular came into effect on February 15, 2016.
  • Safety and security of information systems in banking operations. Circular 31/2015/TT-NHNN provides comprehensive security regulations in banking operations in areas including safety and security of information systems and management of online transaction services. Importantly, the circular clearly sets out that it applies not only to the State Bank of Vietnam and credit institutions, but also to foreign bank branches and providers of intermediary payment services—a new category not covered by the previous regulations. The new circular passed on December 28, 2015, and took effect on March 1, 2016.

In addition, a number of key regulations have been proposed which are currently still in draft form, including:

  • A circular on Over-The-Top services is currently on hold at the Ministry of Information and Communications (MIC).
  • A draft circular on cross-border service provision of public information was released for a public consultation period, which ended in June 2015. The circular is under consideration and is expected to be approved by the MIC in 2016.
  • There has been a long-pending draft of a decree on IT services, but it remains on hold.
  • A circular on the list of IT services has been drafted and released for public consultation. It is under consideration for approval. 
  • Procedures for registration of information content service provision on mobile telecommunication networks may be addressed under a new circular. A draft was released for public consultation from July 6 to September 6, 2015, and is under further regulatory review.
  • The existing Circular 12/2013 on telecom licensing may be amended. Draft amendments have been publicly released, but a timeline for the amendments is not yet available.
  • Finally, there may be a future decision of the Prime Minister to allow importation of refurbished IT products, components, and accessories, as long as they meet certain stipulated conditions.

To learn more about these regulations, please contact [email protected].

 

RELATED INSIGHTS​ 

April 10, 2026
Thailand has introduced new regulatory guidance requiring digital platform operators to adopt structured, transparent, and fair fee practices. On March 16, 2026, the Electronic Transactions Development Agency (ETDA) published Announcement No. DPS 2/2569, titled “Guidelines for Transparency and Fairness in Digital Platform Service Fee Determination,” issued under the Royal Decree on Digital Platform Service Business Operations B.E. 2565 (2022). The guidelines establish a framework governing how digital platform operators should set, disclose, and adjust fees charged to users and related service providers such as logistics and payment providers. Although framed as best-practice guidance rather than legally binding rules with explicit penalties, the guidelines carry regulatory weight under the royal decree and represent a significant step toward structured governance of digital platform fee practices in Thailand. The guidelines establish various transparency principles and divide fees into two distinct categories—compulsory and additional—with specific governance principles for each. Transparency Principles The guidelines recommend that digital platform operators adopt several transparency measures to ensure that users can fully understand the costs of using a platform. Fee catalog. All fees should be consolidated into a single, accessible location, which should include the fee name, definition, scope of covered services, calculation methodology, rate, billing period, and calculation examples. Minimum service disclosure. Operators should disclose the minimum service that users can expect, such as baseline visibility, product listing capabilities, access to transaction data, and back-end dashboard access. Price structure disclosure. Operators should disclose the categories of costs underlying their fees, such as system maintenance, cybersecurity, and operational costs. While exact cost figures need not be made public, operators should be able to provide numerical data to regulators upon request. Clear fee formulas. Fee calculations should be simple and easy to understand—for example, percentage of net sales, cost per order, or cost per product listing. Operators should
April 10, 2026
As digital commerce continues to reshape consumer behavior in Thailand, the Office of the Consumer Protection Board (OCPB) has been taking steps to review and update key regulations for online platforms. The OCPB has had a particular focus on addressing the risks posed by e-marketplace businesses—from misleading product information to fraudulent online transactions. Some of the regulator’s current legislative efforts related to Thailand’s labeling regulations as well as potential changes to the country’s law on direct sales and marketing. Proposed Changes to Consumer Protection Labeling Regulations On February 24, 2026, the OCPB convened a public hearing to review the Notification of the Committee on Labels re: Specification of Goods as Controlled Label Goods B.E. 2565 (2022) and its annex issued under the Consumer Protection Act. The closed-door session, which started the OPCD’s process of seeking feedback on the proposed changes, brought together representatives from government agencies, business operators, and consumer groups. The OCPB explained that its review of the labeling regulations aims to address regulatory gaps arising from evolving commercial practices, particularly the expansion of e-commerce and cross-border transactions. Authorities highlighted recurring issues involving product information that is unclear, incomplete, or potentially misleading in digital sales channels. The proposed revisions are intended to improve consumers’ access to accurate and complete product information, ensure that label disclosures remain relevant amid the growth of e-commerce, and strengthen protections against deceptive or misleading digital advertising. The review is being undertaken pursuant to the Consumer Protection Act B.E. 2522 (1979). As part of the initiative, the OCPB signaled a potential update to the categories of “controlled label products” as well as enhanced disclosure obligations for business operators, with the broader aim of promoting greater transparency, reinforcing operator accountability, and aligning Thailand’s labeling framework with current market conditions. The OCPB secretary general emphasized that
April 9, 2026
As part of its ongoing public consultation process for the development of new practical guidelines under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), Thailand’s Personal Data Protection Committee (PDPC) held a two‑day public hearing on April 1–2, 2026. The hearing followed an online questionnaire and stakeholder engagement activities conducted in March 2026 and reflects the PDPC’s continued efforts to develop guidance that aligns international regulatory standards with Thai operational realities. The public hearing provided a forum for participants from both the public and private sectors to exchange views with the PDPC on the proposed guidance so that it responds to the needs of the business community while supporting effective and balanced enforcement of the PDPA. The PDPC emphasized that the consultation process is part of a wider policy objective to build trust in the convenient, secure, and internationally aligned exchange of data. Structure of the Consultation Process According to the PDPC, the initiative to develop the draft PDPA guidelines is being implemented through three core phases: Review of international best practices. The PDPC has conducted a comparative review of data protection guidance and regulatory approaches in jurisdictions with internationally recognized standards, including Singapore, the United Kingdom, the European Union (EU), and Japan. These materials are intended to serve as a reference point for developing practical recommendations across key subject areas under the PDPA. Identification of practical issues and challenges. To ensure that the guidelines respond to real‑world compliance challenges in Thailand, the PDPC has gathered views from a broad range of stakeholders across the public sector, the private sector, and the general public. This phase included focus group discussions and questionnaires aimed at identifying areas to provide organizations with greater clarity and consistency on regulatory expectations. Preparation of draft guidelines. Insights from the comparative study and stakeholder
April 3, 2026
On March 16, 2026, Vietnam’s Ministry of Public Security released a draft version of a new Decree on the Prevention and Combating of Cybercrime and High-Tech Crime to replace the currently effective Decree 25/2014/ND-CP. In the draft, the ministry has proposed a comprehensive regulatory framework aimed at addressing violations occurring within the cybersecurity domain, including measures related to intellectual property. Acts of Online IP Infringement Article 9 of the draft decree notably introduces specific provisions addressing online intellectual property infringement, with detailed lists of acts considered to constitute infringement in the online environment. Copyright and related rights infringement includes: Uploading or sharing works, performances, sound recordings, video recordings, broadcasts, computer programs, software, research, documents, theses, or other intellectual creations on digital platforms without the consent of the rights holder. Unauthorized livestreaming of copyrighted television programs, sporting events, or artistic performances. Uploading, sharing, storing, transmitting, or providing links to infringing works or digital content via websites, social networks, applications, or digital platforms. Providing or using software, tools, devices, or access codes to circumvent technological protection measures or evade lawful control mechanisms implemented by rights holders. Using artificial intelligence (AI) tools to replicate the ideas or structure of another person’s work without significant new creativity or without proper attribution, thereby causing damage to the original author. Industrial property infringement includes: Manufacturing, trading, advertising, or distributing counterfeit goods bearing counterfeit trademarks, geographical indications, or industrial designs, as well as goods infringing industrial property rights through online platforms. Unauthorized registration, appropriation, or use of domain names, account names, or digital identifiers that create confusion regarding the rights holder or the origin of goods or services. Producing, using, or offering for sale products containing all or part of a patented invention via online platforms. Advertising or introducing products with technical features or characteristics identical