You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 6, 2025

New Decree Provides Guidance on Vietnam’s Telecom Law

On December 24, 2024, the government of Vietnam issued Decree No. 163/2024/ND-CP, providing guidelines for implementing the new Telecommunications Law that took effect on July 1, 2024 (“Decree 163”). This new decree replaces Decree No. 25/2011/ND-CP and its amendments (“Decree 25”) and took effect immediately upon issuance, with regulations on data center services, cloud computing services, and basic telecom services over the internet (“over-the-top” or OTT telecom services) having an official effective date of January 1, 2025.

Decree 163 introduces substantial changes across the telecom sector, covering various aspects including service provision, licensing, standards and technical regulations, quality, passive infrastructure planning, dispute resolution, and more. Hence, it is necessary for enterprises to conduct a compliance review to identify gaps between the new decree and their business models, and take necessary steps to ensure lawful business operations in Vietnam.

Below are some highlights of Decree 163.

Expanded Scope of Services

For basic telecom services, Decree 163 has introduced machine-to-machine (M2M) communication and classified it as a basic telecom service. This establishes a regulatory framework for IoT device communication, previously unregulated in Decree 25.

For value-added telecom services, in light of the new Telecommunications Law, Decree 163 provides more detailed regulations for new telecom services such as data center services, cloud computing services, and OTT telecom services, which were not addressed in Decree 25.

Regulation of Three New Telecom Services

Expanding on the Telecommunications Law’s definitions of data center services, cloud computing services, and OTT telecom services, Decree 163 applies a light-touch management approach to regulate these three new services, as follows:

  • Offshore providers: Cross-border service providers are exempt from signing commercial agreements with licensed local telecom companies. They only need to notify the Vietnam Telecommunications Authority (VNTA) using the prescribed procedures and forms before offering services.
  • Onshore providers: The foreign ownership cap is removed, allowing 100% foreign-owned enterprises in Vietnam. OTT telecom and cloud computing providers must notify the VNTA while data center providers must register with the VNTA before providing services.

Management of Subscriber Information

Decree 163 allows subscribers to register their information online via telecom providers’ applications and strengthens mobile subscriber information management to prevent fraud and ensure accuracy.

Telecom enterprises must comprehensively verify subscriber identities by:

  • Matching identity document details with the National Population Database.
  • Using a one-time authentication code (OTP) sent to a previously registered SIM for registering and activating additional SIMs.
  • Implementing video call verification to collect, verify, and confirm customer identification to ensure the same accuracy as in-person verification.

Outlook

Decree 163 tackles modern challenges, including emerging services, subscriber fraud, and cross-border service provision, offering clearer guidance compared to Decree 25. While the government aims to foster fair competition, efficient infrastructure, and consumer protection, Decree 163 also signals increased regulatory oversight in the telecom sector.

RELATED INSIGHTS​ 

February 6, 2025
The Thai government has proposed amendments to the Gambling Act B.E. 2478 (1935), aiming to address the growing influence of online gambling activities and strengthen regulatory oversight. These amendments, if enacted, would introduce significant changes, particularly concerning online gambling operators, participants, and related advertising activities. The draft amendment is currently in the public hearing process, which is scheduled to conclude on February 14, 2025. Key highlights of the proposed amendments are discussed below. Online Gambling In the proposed amendment, “online gambling” refers to gambling via a computer system or electronic system either through the internet or through remote communication. Organizing, participating in, or engaging in any type of online gambling is prohibited unless authorized by the competent authority. This opens the door for the authorization of casino-style online gambling in Thailand. However, the proposed amendment also imposes strict penalties on both operators and gamblers engaging in unauthorized online gambling: Anyone who organizes unauthorized online gambling is subject to imprisonment for 7–12 years. This penalty also applies to those responsible for managing electronic systems or tools used to facilitate gambling, as well as anyone involved in advertising, promoting, or deceiving others, either directly or indirectly, to engage in online gambling without proper authorization. Any person who engages in unauthorized online gambling is subject to imprisonment for 1–3 years. Dealers, supervisors of gambling or gambling activities, runners conveying wagers or other betting information, and owners of premises who knowingly permit such unauthorized activities are subject to imprisonment for 5–7 years. Penalties for Unauthorized Offline Gambling Operators The proposed amendment revokes the previous penalties under the Gambling Act and proposes stronger penalties. Both the original penalties and the proposed replacements depend on the type of gambling activity under the law, which classifies gambling activities into two types—list A and list B. List
February 3, 2025
On January 28, 2025, the Office of the Personal Data Protection Committee (PDPC) hosted Data Privacy Day 2025, bringing together over 1,000 participants from both the public and private sectors. The event underscored the importance of personal data protection and aimed to raise nationwide awareness while fostering a culture of compliance. During the event, the PDPC reaffirmed its commitment to strengthening Thailand’s data protection framework to align with international standards. The initiative also emphasized the collective goal of achieving zero data breaches. During the first session of the event, Mr. Prasert Jantararuangtong, deputy prime minister and minister of digital economy and society, delivered a speech highlighting the role of personal data protection in fostering Thailand’s digital economy. He emphasized that strong data protection measures enhance business credibility, build consumer trust, and attract foreign investment. He also addressed the PDPC’s “zero data breach” policy and the ongoing issue of data leaks, which have been exploited by call-center scam operations to deceive the public and cause financial harm. Additionally, Mr. Prasert announced that the Thai cabinet has approved a draft amendment to the Emergency Decree on Cyber Crime Prevention and Suppression B.E. 2566 (2023), commonly referred to as the “Cyber Crime Decree.” The draft will now proceed to the Council of State for review before its official enactment. Key provisions of the amendment include holding financial institutions, telecom providers, and social media platforms accountable for technology-related crimes; requiring compensation for victims; and enforcing stricter security measures. Cyber offenses, including personal data trading, face harsher penalties of up to THB 5 million in fines or five years of imprisonment. Authorities are also empowered to suspend suspicious SIM cards for committing illegal activities and expedite monetary refunds for victims without court approval. In the second session, the Office of the PDPC presented its
January 30, 2025
The Thai cabinet has approved a draft amendment of the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes as proposed by the Ministry of Digital Economy and Society to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Following the Council of State’s review, the emergency decree will be become effective immediately upon its enactment and publication in the Government Gazette. While the draft amendment is not yet publicly available, the government recently indicated that the emergency decree aims to empower authorities with decisive measures to combat cybercrime effectively. It underscores the shared responsibility among various sectors, including banking, telecommunications, and online platforms, in safeguarding against technological crimes. Key provisions of the draft amendment of the emergency decree include: Telecommunications provider obligations: Telecommunications service providers must suspend SIM cards associated with criminal activities. The National Broadcasting and Telecommunications Commission and mobile service providers themselves are authorized to temporarily suspend mobile phone numbers if there is reasonable suspicion of involvement in criminal activities. Banking responsibilities: Financial institutions are required to promptly report mule accounts to the Anti-Money Laundering Office to facilitate quick restitution to victims. The Anti-Money Laundering Transaction Committee is empowered to order the return of funds to victims without requiring a final court ruling. Penalties for noncompliance: The amended emergency decree introduces penalties for noncompliance by regulated entities that fail to prevent criminal activities for offenses related to technology crimes in the following cases: Digital asset services: Those engaged in the buying, selling, or exchanging of digital assets, such as cryptocurrencies and digital tokens, as well as digital asset businesses that launder money obtained from online crimes by converting it into digital currency, will be subject to imprisonment for up to one year, a fine of up to THB 100,000,
January 24, 2025
Following Vietnam’s adoption of the new Law on Data (“Data Law”) on November 30, 2024, there remained uncertainty as to what impact the new framework would have on businesses in Vietnam and abroad. The government has now released a package of four draft legal documents aimed at guiding the implementation of the Data Law: (1) a decree on the National Data Development Fund (“NDDF Decree”), (2) a decree related to regulations on scientific, technological, and innovation activities and data products and services (“Decree on Specific Activities”), (3) a decree detailing a number of articles and measures to implement the Data Law (“Implementation Decree”), and (4) a decision on the lists of important data and core data. This article will provide an overview of the draft legislation. 1. NDDF Decree The draft NDDF Decree relates to the establishment, management and use of a National Data Development Fund (“NDDF”), which is a non-profit and non-budgetary state financial fund established and managed by the Minister of the Ministry of Public Security (MPS). The NDDF has legal personality and is fully state owned, operating similarly to a single-member limited liability company. Its main objectives are to support, promote, and invest in artificial intelligence (AI), the Internet of Things (IoT), and other new technologies and innovation. The NDDF may lend to, invest in, or otherwise support eligible organizations. The draft NDDF Decree also proposes a series of regulations on donations to the NDDF and from the NDDF (through expense support), the lending activities of the NDDF to commercial banks, which will in turn lend to eligible organizations, the investment activities in data products and services innovative start-ups, and other kinds of support. The government commits to provide VND 1 trillion (approx. USD 40 million) to the NDDF, evidencing the importance the government places on