You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 9, 2016

Legal Update: New Regulations in the ICT Sector in Vietnam

The final months of 2015 saw a flurry of new legislation in Vietnam’s Information Communication and Technology (ICT) sector. Some of the new regulations have recently taken effect, while others will become effective later in 2016. Below we provide an overview of some key legislation:

  • Information security. The new Law on Information Security is Vietnam’s first comprehensive statute in this area. Previously, data-security regulations were scattered across different pieces of legislation, such as the Law on Information Technology and the Law on Telecommunications. The new law includes, among other things, provisions on ensuring safety and security of information; protecting personal information in the network environment; and preventing spam, computer viruses, and harmful software. The Law on Information Security was passed on November 19, 2015, and will take effect on July 1, 2016.
  • Broadcasting services. Decree 06/2016/ND-CP on management, provision, and use of broadcasting services, which will come into force on March 15, 2016, regulates pay TV and the co-production of radio and TV programs. Replacing the current Decision 20 and Circular 19, Decree 06 has new, clearer regulations on Internet TV and offers some licensing exemptions for foreign channels which do not receive royalty payments. In addition, under the new decree, the number of foreign channels cannot exceed 30 percent of the total number of pay TV channels in Vietnam. The key content in Circular 19 on coproduction of radio and TV programs is retained in Decree 06, including the ban on coproduction of news and politics programs.
  • Internet resources. Circular 24/2015/TT-BTTTT on management and use of Internet resources provides additional grounds for dealing with “.vn” domain name disputes. For more information about Circular 24, please refer to our previous legal update.
  • Used IT products. The list of used IT products that are prohibited from importation has been updated in Circular 31/2015/TT-BTTTT (passed on October 29, 2015, and effective from December 15, 2015). This list notably still includes refurbished IT products, but upcoming legislation (see below) is expected to include some exceptions for refurbished goods.
  • Used machinery, equipment, and production lines. Circular 23/2015/TT-BTTT on importing used machinery, equipment, and production lines was passed on November 13, 2015, and will take effect on July 1, 2016, replacing Circular 20. Circular 23 will make it significantly easier for ICT companies to import used equipment by reducing restrictions and facilitating customs clearance.
  • Quality control of telecom services. Circular 35/2015/TT-BTTTT mainly updates the list of telecommunication services subject to quality control to keep up with the latest advances in technology. This circular came into effect on February 15, 2016.
  • Safety and security of information systems in banking operations. Circular 31/2015/TT-NHNN provides comprehensive security regulations in banking operations in areas including safety and security of information systems and management of online transaction services. Importantly, the circular clearly sets out that it applies not only to the State Bank of Vietnam and credit institutions, but also to foreign bank branches and providers of intermediary payment services—a new category not covered by the previous regulations. The new circular passed on December 28, 2015, and took effect on March 1, 2016.

In addition, a number of key regulations have been proposed which are currently still in draft form, including:

  • A circular on Over-The-Top services is currently on hold at the Ministry of Information and Communications (MIC).
  • A draft circular on cross-border service provision of public information was released for a public consultation period, which ended in June 2015. The circular is under consideration and is expected to be approved by the MIC in 2016.
  • There has been a long-pending draft of a decree on IT services, but it remains on hold.
  • A circular on the list of IT services has been drafted and released for public consultation. It is under consideration for approval. 
  • Procedures for registration of information content service provision on mobile telecommunication networks may be addressed under a new circular. A draft was released for public consultation from July 6 to September 6, 2015, and is under further regulatory review.
  • The existing Circular 12/2013 on telecom licensing may be amended. Draft amendments have been publicly released, but a timeline for the amendments is not yet available.
  • Finally, there may be a future decision of the Prime Minister to allow importation of refurbished IT products, components, and accessories, as long as they meet certain stipulated conditions.

To learn more about these regulations, please contact [email protected].

 

RELATED INSIGHTS​ 

March 10, 2026
Thailand’s Ministry of Finance and Securities and Exchange Commission (SEC) have issued regulations broadening the criteria for determining who qualifies as a “major shareholder” of licensed securities and digital asset business operators. Under relevant SEC regulations, major shareholders of a regulated entity must obtain regulatory approval and undergo screening by the SEC. The revised framework introduces both shareholding-based and control-based tests to determine which shareholders require regulatory approval for a wider range of indirect ownership structures and de facto control. The Ministry of Finance notification took effect on February 21, 2026, while the SEC’s clarifying rules took effect on March 4, 2026. These changes aim to enhance transparency around beneficial ownership and strengthen regulatory oversight of entities operating in Thailand’s capital markets. Expanded Definition Under the revised framework, a “major shareholder” now includes persons who directly or indirectly hold more than 10% of the voting rights in a regulated company, as well as persons who exercise control over the regulated company or its shares. This system of two separate tests, based on both shareholding and control, differs from the prior regime, which focused primarily on shareholding thresholds and applied a more limited method for determining indirect shareholdings. The two tests (detailed below) operate independently of each other, and any person identified by either of the tests will be deemed a major shareholder. Shareholding-Based Test Broadens Indirect Ownership Attribution For the shareholding-based test, the SEC recognizes two existing methods for identifying indirect ownership, together with a new proportional attribution method. Any person captured under these methods, which are described below, will be regarded as a major shareholder of the regulated company and must obtain SEC approval as a major shareholder. First, the existing framework continues to apply to both first-tier and chain ownership structures. Approval is required for (1) first-tier
March 6, 2026
Thailand’s Legislation Consideration Committee of the Ministry of Interior has ruled that in-game loot boxes in online games do not constitute gambling under the Gambling Act B.E. 2478 (1935). This first-of-its-kind ruling provides useful guidance for online game operators and digital entertainment companies operating in Thailand. Background The ruling came in response to an inquiry concerning an online role-playing game operator that launched a campaign featuring a loot box mechanism. The mechanism allowed players to purchase a token in exchange for the opportunity to receive a virtual loot box containing randomized in-game items. The key features of this were as follows: The items received were digital, noncash items usable only within the game. The items could not be exchanged, redeemed, or converted into cash with the game operator. Items may differ in rarity but remain purely virtual. The central question was whether paying money to obtain randomized in-game items constituted a risk-based activity involving the chance to receive money or property of monetary value, which would constitute gambling under the Gambling Act. Committee Ruling The committee reached the following conclusions regarding the characteristics of the game’s loot-box mechanism: No cash or monetary equivalent: Players did not receive cash or property that could be exchanged for cash. The in-game items were merely usage rights within the online game ecosystem. No real-world monetary valuation: There was no determination of item value in real currency, and no mechanism for redeeming or converting items into money with the game operator. Any off-platform trading of in-game items between players is irrelevant to online game operators, as any value arising from such transactions is determined by the market rather than by the operators themselves. Service fee characterization: Payments made by players purchasing in-game loot boxes constituted fees for online game services. Accordingly, the committee concluded
March 5, 2026
Thailand’s Securities and Exchange Commission (SEC) has filed a criminal complaint against a licensed digital asset broker, its overseas trading platform, and its executives for allegedly operating an unlicensed digital asset exchange targeting Thai customers. The case marks an escalation in the SEC’s enforcement efforts against unlicensed offshore platforms that attempt to serve Thai users through local licensed entities. Criminal Complaint On February 20, 2026, the SEC filed a criminal complaint with the Economic Crime Suppression Division against a local licensed digital asset broker, its overseas global trading platform, and its executives. The SEC alleges that the parties violated the Digital Asset Business Emergency Decree B.E. 2561 (2018) by cooperatively operating a digital asset exchange business on a cross-border basis since 2023 without the required SEC license. According to the SEC, the local broker promoted the overseas platform’s services to the public through Thai-language posts on social media channels, with services available exclusively to customers residing in Thailand. Access to the global platform was provided through the local broker’s website and mobile application. Customers who registered for the local broker’s services were automatically granted access to the global platform without having to undergo a separate identity verification process. The SEC also found that the local broker provided back-office system support services to the global platform. The SEC considers these activities to constitute joint operation of an unlicensed digital asset exchange. The former executives of the local broker are being held liable as the responsible persons during the relevant period. The SEC emphasized that the complaint initiates the criminal process, and the decision to prosecute or convict the accused parties will ultimately be made by law enforcement authorities and the criminal courts. Platform Blocking The SEC has also coordinated with the Ministry of Digital Economy and Society to block public
February 27, 2026
The Bank of Thailand (BOT) has officially implemented a new regulatory framework supervising systemically important retail payment systems (SIRPS), effective February 21, 2026, with PromptPay being the first payment system designated as a SIRPS. Under this new set of regulations, the BOT may designate payment systems under the Payment Systems Act B.E. 2560 (2017) as SIRPSs based on quantitative and qualitative assessments. Once a system is designated as a SIRPS, the operator becomes subject to expanded supervisory obligations beyond the general requirements of the Payment Systems Act. Enhanced Supervisory Requirements SIRPS operators must comply with a heightened supervisory regime across three key areas, outlined below. 1. Governance SIRPS operators must maintain robust and transparent governance structures, including: Balanced board composition, with at least one-third of the board comprising independent directors who represent stakeholders in the system (such as payment service providers, consumers, and experts). Independent directors may serve for no more than two consecutive terms. Subcommittees to assist the board in overseeing compliance, policy implementation, and operational strategy. Clear separation between executives responsible for risk and information security and those overseeing day-to-day business operations. Risk Management and System SecuritySIRPS operators must implement comprehensive risk management frameworks, including: Clear service agreements between the SIRPS operator and its direct participants (payment service providers who connect directly to the SIRPS), defining roles and responsibilities among stakeholders. These agreements must include obligations for direct SIRPS participants to supervise any indirect participants they onboard to ensure compliance with service agreements and business rules. A business continuity plan covering both IT and non-IT aspects, with annual review. The SIRPS must target service availability comparable to international payment infrastructures, including the ability to recover operations within two hours of a disruption and to maintain scalable operational capacity. Tools and controls to monitor and manage material or