You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 8, 2020

New Penalties for Posting Fake News on Social Networks

On February 3, 2020, the Vietnamese Government issued Decree No. 15/2020/ND-CP stipulating penalties for administrative violations in the fields of postal services, telecommunications, radio frequency, information technology, and electronic transactions (“Decree 15”). Decree 15 will replace the existing decree on penalties in the technology and telecom sectors (Decree No. 174/2013/ND-CP) and will take effect on April 15, 2020.

One of the most notable features provided by Decree 15 is the introduction of specific administrative penalties for users who post or share fake news on social networks, which will be imposed in addition to any civil and/or criminal liabilities related to distortion, slander, defamation and the like.

Penalties for Social Network Users

In particular, Article 101 of Decree 15 sets out the penalties for violations of regulations on the use of social networks. These include administrative fines of between VND 10 million (approx. USD 430) and VND 20 million (approx. USD 860) on social network users who commit the following violations:

  1. Posting or sharing false information (fake news) or untruthful, distorted, or slanderous information that offends the reputation of agencies or organizations or the honor and dignity of individuals;
  2. Posting or sharing information that advocates unsound customs, superstition, obscenity, or depravity which is not in line with the traditions and fine customs of the nation;
  3. Posting or sharing graphic depictions of acts of slashing, killing, accidents, or horror;
  4. Posting or sharing fabricated information that causes panic among the population or incites violence, crime, social evils or gambling, or that serves gambling activities;
  5. Posting or sharing press, literature and art works or publications without the permission of the copyright holder, or works that have not been approved for circulation, or have been banned or revoked;
  6. Advertising, promoting, or sharing information about banned goods and services;
  7. Posting or sharing inaccurate maps of Vietnam;
  8. Posting or sharing links to websites with banned content.

Higher administrative fines of VND 20 million (approx. USD 860) to VND 30 million (approx. USD 1,290) are imposed on the disclosure of information classified as state secrets or personal secrets, but which is not serious enough to face criminal punishment.

Moreover, in all of the above cases, the violators would also be required to remove the fake news or violating content that was posted or shared.

Penalties for Social Network Providers

Correspondingly, Decree 15 also imposes additional penalties on social network providers who fail to prevent fake news from being posted on their social networks.

In particular, Article 100.3 of Decree 15 imposes an administrative fine of VND 50 million (approx. USD 2,130) up to VND 70 million (approx. USD 3,000) on social network providers who fail to block or remove violating information (including fake news) from their platforms, and/or who intentionally provide, store, or transmit the violating content listed in items 1-7 above, or information that is considered not to be in the country’s interest.

Violating social network providers would also be required to remove the fake news or violating content that was posted or shared, and be subject to suspension of their social network license and/or revocation of their social network’s domain name.

Penalties in Other Fields

In addition to the foregoing newly stipulated penalties on fake news, the administrative penalties on various other violations in the fields of postal services, telecommunications, radio frequency, information technology and electronic transactions have also been overhauled. For example, penalties related to data privacy and security have been slightly increased. Notably, penalties on violations related to collecting personal information without consent are increased from VND 10 million (approx. 430) to VND 20 million (approx. USD 860); and penalties on violations related to adopting adequate cybersecurity measures are increased from VND 20 million (approx. USD 860) to VND 50 million (approx. USD 2,150).

For more information on Decree 15, please contact us at [email protected].

RELATED INSIGHTS​ 

June 26, 2023
Vietnam’s Ministry of Information and Communications (MIC) organized a workshop with industry representatives on June 19, 2023, to discuss its future policy direction for over-the-top (OTT) telecom services and internet data center (IDC) and cloud computing services. OTT telecom services, in the MIC’s interpretation, are communication services such as text messages or voice calls provided over the internet—for example, the services of Zalo, WhatsApp, WeChat, etc. The workshop, the first in an expected series, focused only on the discussion of policy on how to regulate these services. Light-Touch Management Approach A very positive signal of the MIC in the workshop was its clear intention to apply a “light-touch” approach to management. For cross-border provision of OTT telecom services and IDC/cloud computing services, the MIC intends to require notification and a post-check mechanism, instead of a heavy licensing or commercial arrangement regime like the one applicable to traditional telecom services. In addition, there is no limitation on foreign investment if foreigners would like to provide these services in Vietnam. With regard to domestic service providers, the MIC proposes a registration regime with a similar post-check mechanism. The MIC’s reason for registration instead of notification is because the provision of these services by domestic companies may involve setting up data center/cloud systems which require consideration of various issues including location, electricity sources, and connection with telecom infrastructure such as marine cable. However, the MIC is also hoping to make the registration process as light as possible for enterprises (for example, using online registration) to provide a favorable environment and conditions to facilitate development of the industry without obstacles or cumbersome administrative procedures for companies’ operations. For providers of these services, the MIC is also considering an exemption from the responsibility to pay fees for telecommunications activities rights, and from payment to
June 8, 2023
At a conference organized by Vietnam’s Ministry of Public Security (MPS) on June 7, 2023, government officials provided more guidance on the recently issued Personal Data Protection Decree (PDPD), which is set to take effect on July 1, 2023. Key takeaways included the following: A national portal on personal data protection for online submission of notifications and registrations will be launched before July 1, 2023. The MPS also plans to issue templates for data processing impact assessments (DPIAs) and transfer impact assessments (TIAs) in the near future. The PDPD requires data controllers, data processors, and data controller-processors to prepare a DPIA at the start of personal data processing. The MPS clarified that the DPIA is expected to be prepared and submitted once. Only changes to its content would require submission of an updated DPIA. Both DPIAs and TIAs (which are for cross-border data transfers) must be prepared in Vietnamese. Since the sale and purchase of personal data is strictly prohibited unless explicitly permitted by law, the MPS has handled approximately 14 cases involving unlawful trading of personal data, including sensitive data. Under the PDPD, sensitive data has a broader definition than under the GDPR (the European Union’s General Data Protection Regulation), and also includes location data, creditworthiness, and personal financial data. Consent is not a legal basis for the trading of personal data, including sensitive data. The 72-hour timeline for responding to a data subject’s request does not mean 72 working or business hours. Rather, it means 72 actual consecutive hours. Any organization transferring the personal data of Vietnamese citizens outside of Vietnam must comply with the PDPD, regardless of the organization’s location. For organizations incorporated overseas that must comply with the PDPD, there is no requirement to appoint a local representative (unlike the GDPR)—but appointment of a data
June 2, 2023
In Southeast Asia, artificial intelligence (AI) products and services are being leveraged across industries such as finance, healthcare, retail, agriculture, and manufacturing. Governments across the region are recognizing the benefits of harnessing AI and the positive impact of AI technology on economic development. As the rise in AI deployment creates opportunities for economic growth in Southeast Asia, regulatory and digital governance efforts should focus on ethical, inclusivity, and cybersecurity concerns to help ensure that the widespread use of AI technology in the region is sustainable. Two jurisdictions in the region that have already made significant strides in developing initiatives surrounding AI are Singapore and Thailand. Singapore Due to its more advanced technological infrastructure, Singapore was one of the first countries in the region to address AI-related issues. Singapore has been aligning its data protection policies and regulations with the changing digital landscape since 2012—the year Singapore passed its Personal Data Protection Act. In 2019, Singapore unveiled its National AI Strategy to increase the use of AI technologies and deploy “scalable, impactful AI solutions in key verticals by 2030.” The goal is to align talent, regulation, and business growth to ensure AI applications serve society. Singapore’s approach is to facilitate innovation while safeguarding consumer interests, as it strives to become one of the regional leaders in the field of AI. In terms of Singapore’s regulatory landscape, Singapore’s Personal Data Protection Commission (PDPC) oversees data and AI, including AI developers and AI-using companies, which consist of backroom operations, front-end usage companies, and distributors of equipment with AI features. The Singapore Academy of Law (SAL) oversees all laws applicable to AI systems and decides on issues that impact the AI industry. Singapore has joined various bilateral and regional trade arrangements to facilitate research, development, and collaboration in support of its growing digital
May 24, 2023
The draft Royal Decree on Artificial Intelligence System Service Business, which was introduced by the Office of the National Digital Economy and Society Commission earlier for public comment in October last year, focuses on potential risks from artificial intelligence (AI) systems to public health, safety, and freedoms. The framework emphasizes the importance of risk assessment, reporting requirements, and the establishment of specific measures and criteria deemed necessary to minimize AI risks. AI Systems Defined by the Decree Under the draft royal decree, an AI system is defined as a machine-based system that can make predictions, recommendations, or decisions that affect real or virtual environments pursuant to the objectives set by humans. The definition clarifies that artificial intelligence systems are designed to operate at different levels of autonomy, including: machine learning AI; logic-based and knowledge-based AI; statistical AI; Bayesian estimation AI; and search and optimization AI. Risk-based Approach The draft AI royal decree takes a risk-based approach to regulation and specifically identifies prohibited or high-risk AI services that could cause harm or engage in unethical practices to ensure that AI systems do not pose major risks to public health, safety, or freedoms. The extent of regulatory scrutiny applied to an AI system corresponds to the level of risk presented by the AI system. For example, AI systems that pose unacceptable risks are generally prohibited, AI systems considered to be high-risk are subject to a conformity assessment, and AI systems considered to be limited-risk are subject to transparency requirements. Compliance with specified criteria and procedures to minimize potential risks of each AI service would be further outlined in subregulations. Prohibited AI Systems The draft AI royal decree prohibits AI systems that: employ subliminal techniques to covertly influence human behavior (below the threshold of conscious awareness); utilize social scoring; access sensitive personal