You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 10, 2025

Regulations on E-signatures and Trust Services in Vietnam

For companies and individuals doing business in Vietnam, a common question is whether electronic signatures (e-signatures) are legally recognized under Vietnamese law. This matter is governed by Law No. 20/2023/QH15 on Electronic Transactions issued on June 22, 2023 (ETL 2023) and its guiding legal documents such as Decree No. 23/2025/ND-CP dated February 21, 2025, and Circular 06/2024/TT-BTTTT dated July 1, 2024 (Circular 06).

Recognition of Validity of E-signatures in Vietnam

As a general principle, the ETL 2023 confirms that an e-signature cannot be denied legal validity solely due to its electronic form.

The law categorizes e-signatures into three types:

  • Type 1: Specialized e-signatures for organizations
  • Type 2: Public digital signatures for individuals and organizations
  • Type 3: Specialized digital signatures for government agencies

Among these types, only secure specialized e-signatures (a secure e-signature of type 1) and digital signatures (type 2) are explicitly granted the same legal validity as handwritten (wet) signatures. This distinction is particularly important in legal disputes and for transactions with government agencies. (For more details, please refer to our previous article.)

Domestic e-signatures

A domestic organization can choose to use secure specialized e-signatures (type 1) and/or digital signatures (type 2) while a Vietnam-based individual can choose digital signatures (type 2) for their transactions—particularly for those involving government agencies and transactions of high value and complexity which require stronger legal protection.

Specialized e-signatures (type 1) can be created by the organizations themselves, and additionally must be “secure” to be explicitly recognized as having the same legal validity as handwritten signatures. For clarity, “securespecialized e-signatures are those certified (granted a safety certificate) by the Ministry of Science and Technology (MST). (This was formerly the responsibility of the Ministry of Information and Communications, which was merged with MST under Vietnam’s 2025 administrative restructuring.)

Digital signatures (type 2) are issued to organizations and individuals by licensed public digital signature certification service providers. Other types of e-signatures could be legally recognized and protected when they meet all the requirements outlined in the ETL 2023.

Foreign e-signatures

Cross-border e-transactions raise the question of how foreign e-signatures are legally recognized and protected under Vietnamese law. While Vietnamese law does not provide explicit guidance, two main pathways for recognition can be inferred:

First, foreign organizations and individuals can obtain e-signature certificates from foreign e-signature certification service providers recognized in Vietnam, provided these providers meet statutory conditions and are duly recognized in Vietnam. However, to date, no foreign e-signature certification service providers have been officially recognized in Vietnam, creating a significant barrier to legal recognition of foreign e-signatures in practice.

Second, it is possible under Vietnamese law for (i) foreign organizations and individuals, and (ii) Vietnamese organizations and individuals whose Vietnamese e-signatures and e-signature certificates are not recognized abroad to apply for recognition of specific foreign e-signatures and e-signature certificates from MST. However, Circular 06 limits eligibility for recognition with regard to “foreign organizations and individuals” under the second pathway to only foreign organizations legally operating in Vietnam and foreign individuals residing in Vietnam. This effectively excludes foreign organizations and individuals without a local presence, who must rely on the first pathway.

Foreign E-signatures Accepted in International Transactions:

Article 27 of the ETL 2023 allows foreign e-signatures to be accepted in international transactions, but it remains ambiguous whether such acceptance equates to legal protection under Vietnamese law, or merely shifts the legal risk to the accepting party.

While foreign e-signatures in this context are not expressly granted the same legal status as handwritten signatures, one could argue that, provided they satisfy all the requirements set out in the ETL 2023, they should not be denied legal validity under the general principles established by the law.

Trust Services

Trust services—including timestamping, data message certification, and public digital signature certification—play a critical role in ensuring the authenticity of involved parties, integrity of data messages, and non-repudiation of e-transactions.

Timestamping services attach time information to data messages, with timestamps generated as digital signatures. Data message certification encompasses services for storing and verifying the integrity of data messages, as well as services of sending and receiving secure data messages. Public digital signature certification refers to certifying digital signatures (type 2) provided by licensed public digital signature certification service providers.

These trust services are regulated businesses and require providers to meet specific licensing criteria under Decree 23.

Outlook

Vietnam’s legal framework appears to offer a more workable approach for domestic e-signature deployment and use, while still presenting practical challenges for cross-border recognition of foreign e-signatures. However, as Vietnam continues to prioritize digital transformation, the digital economy, and digital society, and as the demand for e-transactions and e-signatures grows, these limitations are expected to be addressed in the near future to better support e-government and the digital economy.

In the meantime, the use of e-transactions and e-signatures is inevitable and unstoppable in today’s fast-paced digital era. Parties engaging in international transactions with Vietnamese counterparts should ensure they fully understand the legal requirements for the acceptance of foreign e-signatures, enabling them to fully leverage the benefits of digital transactions in their business operations.

RELATED INSIGHTS​ 

April 3, 2026
Thailand’s Securities and Exchange Commission (SEC) has established a comprehensive governance framework for the use of artificial intelligence and machine learning (AI/ML) in the capital markets. The framework provides guidance to capital market business operators on understanding the risks associated with AI/ML implementation and adopting appropriate practices to build public confidence in Thailand’s capital markets. While the guidelines are principle-based rather than prescriptive, they reflect the SEC’s expectations for responsible AI/ML governance and are likely to inform supervisory activities and industry standards going forward. Scope The framework applies to capital market business operators supervised by the SEC. This includes, for example, securities and derivatives firms, asset management companies, mutual fund and private fund managers, investment advisors and investment consultants (including robo-advisory service providers), derivatives intermediaries, and other licensed intermediaries and market operators in the Thai capital markets that deploy AI/ML in their operations. Core Principles of the Guidelines The framework is presented as a best-practice manual rather than prescriptive regulation, providing guidance that regulated entities may apply to their AI/ML governance and risk management as appropriate. While currently nonbinding, the guidelines signal the SEC’s expectations for the sector, particularly in relation to other binding SEC regulations such as those covering IT risk management and market conduct. The guidelines name four core principles for AI/ML deployment: Fairness: Design and develop AI/ML with consideration for fairness, equality, and social diversity to prevent discrimination against individuals or groups. Legal and ethical compliance: Ensure AI/ML use aligns with applicable laws, ethical standards, and organizational values and policies. Accountability: Establish clear responsibility—both internally and externally—for AI/ML activities and outcomes. Transparency: Provide adequate disclosure to users about AI/ML use, including explainability of decisions and traceability of activities. AI/ML Best Practices The guidelines prescribe best practices across four stages of the AI/ML lifecycle, as described below.
April 2, 2026
Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance. What Has Changed: OIC and PDPC Alignment The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers. Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible. Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors. Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels. DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on
March 30, 2026
On March 24, 2026, the Trade Competition Commission of Thailand (TCCT) published its long-anticipated Guidelines on Multi-Sided Platforms and E-Commerce Businesses in the Government Gazette, following the conclusion of a public hearing conducted last year. The guidelines entered into force on March 25, 2026, and significantly expand the application of Thai competition law to digital platform ecosystems. These rules introduce targeted restrictions on platform conduct, such as price-ranking algorithms and tying and bunding, that leverages network effects, and will have far-reaching implications across Thailand’s digital economy—affecting not only platform operators but also platform participants, including sellers, logistics providers, advertisers, and payment service providers operating on or alongside such platforms. The guidelines clarify how existing prohibitions under the Trade Competition Act B.E. 2560 (2017) (TCA)—including abuse of market dominance, cartel conduct, and unfair trade practices—apply in the context of platform-based business models. While many provisions reflect earlier draft guidelines, the final version delivers more precise definitions and clearer enforcement parameters, increasing regulatory certainty while also raising compliance expectations. Applicability The guidelines introduce core definitions that determine their coverage: Multi-sided platform: A platform that acts as an intermediary connecting two or more groups of users, enabling them to have direct interaction in order to exchange or rely on services from one another. Examples include digital platforms for trading goods or services (e-commerce), as defined below. Digital platform for trading goods or services (e-commerce): A platform that acts as an intermediary connecting the distribution, purchase, sale, or exchange of goods or services. This includes operations carried out to facilitate transactions or interactions between business operators through an electronic transaction system, regardless of whether a service fee is charged. Operator of a digital platform business for trading goods or services: A provider of digital platform services for trading goods or services, as described
March 27, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has publicly indicated that it is preparing a new regulatory framework for data center operators that may introduce foreign-ownership restrictions. In particular, the NBTC is considering reclassifying data center operations from a type 1 telecommunications business license to a type 3 license. If implemented, this change would subject data center operators to a significantly more stringent regulatory regime, especially in relation to foreign ownership and control. The NBTC has indicated that it intends to propose a draft framework to the NBTC board. This would be followed by a public hearing process, with a view to implementing the new rules within 2026. Under the Telecommunications Business Act B.E. 2544 (2001), as amended, telecommunications businesses operating under type 3 licenses are subject to foreign ownership restrictions, including a requirement that less than 50% of the total issued shares be held by foreign shareholders. In addition, type 3 licensees are subject to foreign dominance restrictions, which prohibit arrangements that allow foreigners to dominate the business. These foreign dominance restrictions are broad in scope and may capture various forms of direct and indirect control or influence. This includes circumstances in which a foreign national is able to influence or control the formulation of policy, management, or business operations, or the appointment of directors or senior executives. At this stage, the exact scope of the proposed rules remains unclear. Businesses with existing or planned data center operations in Thailand should therefore monitor upcoming NBTC developments in this regard and prepare for the expected public hearing process.