You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 30, 2026

New Decree Strengthens Vietnam’s Copyright Framework in the AI Era

Managing Intellectual Property

Vietnam’s Decree No. 134/2026/ND‑CP, which took effect on 9 April 2026, plays an important role in detailing and implementing Vietnam’s Intellectual Property (IP) Law in the context of rapid digital transformation and the growing application of artificial intelligence (AI). The new decree provides comprehensive guidance on the application of copyright and related‑rights regulations, addressing key issues such as authorship, ownership, statutory exceptions and limitations, registration procedures, and enforcement mechanisms.

Through these measures, Decree 134 seeks to achieve an appropriate balance between safeguarding the legitimate interests of rightsholders and fostering innovation, research, and technological advancement, thereby strengthening the state’s framework for the effective management, protection, and exploitation of intellectual property in the digital and AI‑driven environment.

Some notable aspects of Decree 134 are discussed below.

Copyright for AI-Created Works

Decree 134 provides important guidance on the determination of copyright and related rights in works created with the assistance of AI. Article 5a reaffirms the principle that human creativity remains central to copyright protection, clarifying that copyright or related rights arise only where a human makes a substantial and decisive intellectual contribution, exercises effective control over the creative outcome, and assumes responsibility for the content and its legality.

At the same time, the provision confirms that AI is regarded solely as a technological tool rather than a rights‑holding subject, thus ensuring consistency with the fundamental concepts of authorship and ownership under the IP Law. By introducing requirements on transparency, proof of human contribution, and compliance with AI‑specific labelling and technical marking obligations, Decree 134 establishes a clear and enforceable legal framework for the responsible use of AI in creative activities.

Lawful Use of Copyrighted Texts and Data

Article 37a of Decree 134 sets out the specific conditions under which copyrighted texts and data may be lawfully used for scientific research, experimentation, and the training of AI systems, requiring that such use be based on lawfully published materials, accessed from legitimate sources, and conducted without circumventing or disabling technological protection measures implemented by rightsholders. It further establishes substantive limitations to ensure that such use does not conflict with the normal exploitation of protected works, does not cause unreasonable prejudice to the legitimate interests of authors, performers, and rightsholders, and does not result in AI outputs that substitute the market or create unfair competition with protected subject matter.

The right of authors, performers, and rightsholders to reserve their copyright and related rights against this use of protected texts and data is also recognized under Article 37b. Such reservations must be exercised through clear and publicly accessible mechanisms, including machine‑readable rights‑management information, technological protection measures, or public declarations made via authorized collective management organizations. This reservation right specifically does not apply where the use of texts and data fully satisfies the strict conditions set out in Article 37a.

Users of copyrighted texts and data for research, experimentation, and AI training are required  to retain technical records, training data, and usage data in accordance with applicable AI‑related regulations, and to provide such information to competent authorities upon request for verification, dispute resolution, or enforcement purposes. In addition, Article 37c reinforces the obligation to respect the reservation of rights exercised by rightsholders, notably clarifying that where AI‑trained systems are commercially exploited, users must comply with the foregoing obligations and fulfill royalty‑payment duties in accordance with the law, ensuring that AI innovation is aligned with fair remuneration and effective rights protection.

Specialized Database on Copyright and Related Rights

To strengthen the institutional framework for copyright protection and enforcement in the digital environment, Decree 134 introduces a centralized, specialized database on copyright and related rights. This publicly accessible database will consolidate key data on registrations, collective management organizations, royalty tariffs, intermediary service providers, and other relevant matters to enhance information sharing, regulatory oversight, and lawful access, while ensuring compliance with data‑protection and confidentiality requirements.

Copyright Exclusions

Article 8.4 clarifies the scope of subject matter excluded from copyright protection by providing detailed interpretations of ideas, slogans, and the independent title of a work. The provision reaffirms that ideas or creative concepts not fixed in a material form, slogans lacking independent creativity beyond ordinary linguistic expression, and titles considered separately from the content of the work do not constitute protected works.

Legal Validity of Electronic Registration Certificates

Article 38.9 formally recognizes the legal validity of electronic copyright and related‑rights registration certificates, an important step toward modernizing copyright administration. The provision authorizes the competent authority to issue certificates in electronic form as the default, while allowing paper certificates to be issued upon request, and confirms that electronic certificates have the same legal value as paper documents.

Suspension of Examination During Disputes

Under Article 39.2a, the relevant authority must temporarily suspend the examination of registration applications where the subject matter is involved in an ongoing dispute, complaint, denunciation, or criminal investigation relating to IP infringement. By requiring formal notification to applicants and clearly defining the duration of such suspension, this important procedural safeguard helps prevent the issuance of registration certificates that could interfere with judicial, arbitral, or investigative proceedings, while ensuring procedural fairness through the resumption of processing or the return of applications once the suspension period ends.

A Promising Step Forward

In summary, Decree 134 represents a significant step forward in modernizing and strengthening Vietnam’s copyright and related‑rights framework in response to rapid digital transformation and the growing impact of AI. By providing detailed guidance on AI‑assisted creation, lawful data use for AI training, rightsholder reservations, user responsibilities, registration procedures, and digital administration, the decree enhances legal certainty and regulatory coherence while maintaining a human‑centric approach to copyright protection.

At the same time, it reinforces transparency, accountability, and fair remuneration, ensuring that technological innovation proceeds in harmony with the legitimate interests of authors, performers, and rightsholders. Taken together, these measures demonstrate the state’s commitment to effective IP management and to fostering a balanced, sustainable environment for creativity, innovation, and economic development in the digital and AI‑driven landscape.

This article first appeared in Managing Intellectual Property.

RELATED INSIGHTS​ 

August 10, 2026
Thailand has finalized its social media KYC (“know your customer”) rules under Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers (No. 2), which was published in the Government Gazette on May 5, 2026, and will take effect on November 1, 2026. While an early draft of the notification proposed requiring social media platforms to arrange identification of every user account, the final notification is significantly more targeted, focusing on paid online advertising and advertiser identity verification. Though the regulatory initiative primarily aims to combat online fraud and technology-related crimes, it also has important consequences for intellectual property enforcement, because the verified platform records that will be generated under the new requirements can help IP rights holders to identify anonymous online infringers. Key Regulatory Mandates The notification requires social media service providers to verify the identity of advertisers before their paid advertisements are published and disseminated in Thailand through social media, regardless of whether the advertising fees come from the advertisers or third parties. Verification of an advertiser is valid for one year, after which verification would have to be performed again before the platform could publish additional paid advertisements from the advertiser. Permitted verification methods are specified under the notification. A platform may verify an advertiser by checking identity evidence and confirming the connection between the advertiser and that identity evidence, with the notification giving facial comparison against certain government-issued identity documents as an example. Alternatively, platforms may verify advertisers through a digital identity verification and authentication system with an identity-proofing assurance level not lower than the level prescribed by Thailand’s Electronic Transactions Commission. The notification further requires platforms to retain only the advertiser’s information necessary to identify the advertiser, beginning from the start of the advertising activity and for
August 10, 2026
On July 31, 2026, Thailand’s Big Data Institute (BDI) launched a public consultation on the principles of a proposed new data-sharing law, with comments accepted until August 31, 2026. If enacted, the law would establish Thailand’s first comprehensive framework for government and private-sector data sharing, creating a systematic, secure, and transparent regime to support analytics, policymaking, research, and innovation. Central Data-Sharing Platform The draft law establishes a central system for data sharing, managed by the BDI. Government agencies would be required to connect to the BDI’s Data Integration and Intelligence Platform (also referred to as D2), in accordance with the BDI’s rules and procedures. Five Dimensions of Data Sharing The draft law covers five key types of data sharing between government (G), businesses (B), and consumers (C): G2B: Private organizations may request government data specifically for research and development purposes. The BDI will assess the applicant’s data governance, security, and privacy capabilities whether such measures meet prescribed standards before forwarding the request to the relevant government agency within 90 days. Any dispute may be escalated to a newly established Data-Sharing Promotion Committee for final determination. G2G: Government agencies may request data from other agencies through the central system. The data-holding agency must respond within 90 days, taking legality, necessity, proportionality, public interest, and personal data protection into account. Disputes may be referred to the Data-Sharing Promotion Committee for adjudication. B2G: In emergency situations involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society may require private entities to provide data through the central data-sharing system. Government agencies must specify the data requested, demonstrate its necessity and expected benefits, and request only data reasonably available to the data holder. Requests for personal data must be limited to the minimum amount necessary. B2C: Royal decrees may
August 10, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) recently released draft guidance on records of processing activities (ROPA) for personal data controllers and processors under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft guidance, which was presented to the public on July 7, 2026, addresses both controller records of collection, use, and disclosure of personal data and processor records of processing activities carried out on behalf of controllers. If implemented, the guidance will significantly expand organizational expectations for ROPA preparation, maintenance, and use across all sectors. Key Takeaways The draft guidance contains several important implications for organizations subject to the PDPA: ROPA reframed as a core accountability tool. The guidance elevates ROPA from an administrative record to a central accountability mechanism, connecting controller duties with recordkeeping obligations. ROPA as a source for privacy notices and governance documents. ROPA should serve as the primary source for privacy notices and align with consent management, retention schedules, DPIAs, incident response plans, and vendor contracts. Expanded scope across all activities. ROPA must cover all processing activities across the organization—including security, finance, HR, and external contractors—with correct controller or processor classification for each. Ongoing maintenance and auditability. ROPA must be updated for any change to systems, purposes, or processors, reviewed at least annually, and maintained with version control and a designated owner. Enhanced vendor, processor, and cross-border transfer requirements. Organizations must document all processors, external recipients, and cross-border transfers, specifying purposes, access scope, and destination countries. Linkage with risk assessment, DPIAs, and LIAs. ROPA should assign risk levels to each activity and identify when data protection impact assessments (DPIAs) or legitimate interests assessments (LIAs) are required, functioning as a risk-management tool. ROPA and data breach readiness. Incomplete ROPA can delay breach response and notification. Organizations should map data flows, vendors,
August 4, 2026
Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) could soon see some important changes, as a draft bill to amend the PDPA has been introduced in the House of Representatives. The draft amendment is currently in the public consultation phase, with comments accepted from July 16 to August 15, 2026. If enacted in its current form, the amendment would make three key changes: expanding the government exemption to cover anticorruption operations, introducing a statutory definition of “government agency,” and restructuring the lawful bases for personal data processing to align with international standards. Background The PDPA has encountered several enforcement challenges since its implementation, including three core problems identified by the bill’s sponsors: (1) the current exemptions for government agencies do not cover anticorruption and misconduct-prevention operations; (2) the PDPA lacks a clear statutory definition of “government agency,” causing legal uncertainty as to which entities are covered; and (3) the existing framework for lawful bases of data processing does not align with international standards—particularly the multiple-lawful-bases system in the EU’s General Data Protection Regulation (GDPR)—making compliance inflexible for both government and private sector entities. Expanded Government Exemption The current PDPA exempts government agencies performing duties related to national security (including fiscal security), public safety, anti-money laundering, forensic science, and cybersecurity. The proposed amendment adds “prevention and suppression of corruption and misconduct” to this list of exempted functions. This would allow anticorruption bodies—most notably the National Anti-Corruption Commission (NACC), which is identified as a directly affected party—to collect, use, and disclose personal data without being subject to PDPA requirements when carrying out their duties. New Statutory Definition of “Government Agency” Notably, while the current PDPA use the term “government agency” in several provisions, the term is not comprehensively defined, creating potential uncertainty as to its scope. The draft bill therefore