You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 15, 2023

Significant Aspects of Vietnam’s New Law on E-Transactions

Vietnam’s new Law on Electronic Transactions No. 20/2023/QH15 (LOET 2023) was promulgated by the National Assembly on June 22, 2023, and will replace the existing Law on Electronic Transactions No. 51/2005/QH11 (LOET 2005) when it enters into effect on July 1, 2024. The LOET 2023 is aimed at facilitating transactions carried out in an electronic environment in all sectors. Derived from the fundamental principles of the LOET 2005, the LOET 2023 is similarly considered a framework law, developed based on the Model Law on E-Commerce of the United Nations Commission on International Trade Law (UNCITRAL). The main points of interest of the LOET 2023 are summarized below.

1. Scope of Application

Unlike the LOET 2005, which explicitly excludes certain areas such as the issuance of certificates of land use rights and birth certificates from the scope of application, the LOET 2023 covers all areas without exception. However, the LOET 2023 will still not interfere with the regulations of substantive laws that stipulate the content, conditions, and forms of transactions in their respective areas (Article 1.2). The LOET 2023 also provides that it will only be applicable if other laws either allow or remain silent on the electronic execution of transactions; otherwise, if another law specifically does not permit a transaction to be carried out electronically, such law shall apply (Article 1.3). This emphasizes that the applicability of the LOET 2023 depends on the electronic readiness of specific sectors.

2. Enabling E-Transactions in All Sectors

For traditional transactions or contracts to be legally valid, they typically require written documentation, the signatures of the involved parties, and the seals of organizations or companies, if required by substantive laws or common practice. Additionally, certain sectors mandate further steps like notarization or certification, such as in property transactions like house sales or inheritance documentation. The questions then arise: How are these requirements mirrored in the electronic environment, and in the event of a dispute between parties, how can electronic transactions be used to support the parties to facilitate the transaction?

2.1 Data Messages

A data message is information generated, sent, received, and stored by electronic means (Article 3.4). There are two types of data messages under the LOET 2023 (Article 7): (i) data messages in the form of electronic documents, electronic certificates, electronic records, electronic contracts, emails, telegrams, telegraphs, facsimiles, and other electronic data interchange (EDI) forms according to regulations of law; and (2) data messages that are created and generated during transactions or converted from written documents.

The LOET 2023 retains the main content of provisions under the LOET 2005 on the legal validity of data messages and the recognition of the validity of data messages as written documents, as original copies, and as evidence. Regarding the rules for sending and receiving data messages, the LOET 2023 offers more extensive regulations than the LOET 2005, such as new provisions recognizing the representative of a party as the originator of a data message (Articles 14.2(a) and 15.1). Additionally, it addresses situations where a party erroneously inputs information via an automatic information system without the opportunity to rectify the error; in this case, the party making the error is allowed to retract the entered information if it meets stipulated conditions (Article 14.3).

The LOET 2023 also provides for conversion from written documents to data messages and vice versa so that parties can use either option where appropriate or allowed by law (Article 12). Interestingly, a prerequisite for converting written documents into data messages is that the resulting data message must include a distinct indication certifying its conversion from the written document, along with details about the entity or individual making the conversion (Article 12.1(c)). It is unclear whether merely scanning a document into PDF format without additional information about the converter qualifies as a data message converted from a written document. The LOET 2023 leaves it to the government to provide further guidance on conversion issues (Article 12.4).

2.2 Electronic Contracts

An electronic contract (e-contract) is a contract that is made in the form of a data message (Article 3.16). The LOET 2023 generally retains the principles and rules on e-contracts of the LOET 2005, but adds regulations to enable the signing and performance of e-contracts through automatic information systems (Article 34), and empowers line ministries to promulgate regulations on conclusion and execution of e-contracts in their respective fields (Article 34.2).

An interesting note is that when entering into and executing e-contracts, the parties have the right to reach agreements related to those e-contracts on technical requirements, conditions to ensure integrity, and confidentiality (Article 36.2). This means the parties could agree on e-signature technology, e.g., simple or complicated, depending on the nature and free will of parties. However, this principle seems to be weakened in regard to e-signatures of individuals, as discussed below.

2.3 Electronic Signatures and Digital Signatures

An electronic signature (e-signature) is a signature created in the form of electronic data attached to or logically associated with a data message to identify the signatory and certify the signatory’s approval of the data message (Article 3.11). Electronic data is data generated, processed, and stored by electronic means (Article 3.7).

A digital signature is an e-signature using an asymmetric algorithm consisting of a private key and a public key. The private key is used for digitally signing and the public key is used to verify the digital signature. The digital signature ensures the authenticity, integrity, and non-repudiation but does not ensure the secrecy of the data message (Article 3.12). Digital signatures are generally considered more secure than other e-signatures. Digital signatures and digital signature certification services have long and commonly been used in Vietnam (and in the world) in e-transactions.

The LOET 2023 specifies three types of e-signatures:

  • Specialized e-signatures are e-signatures created and used by agencies and organizations for their particular purposes in accordance with their functions and tasks (Article 22.1(a)).
  • Public digital signatures are digital signatures used in public activities (there is no definition of what constitutes “public activities”) and secured by public digital signature certificates (Article 22.1(b)).
  • Specialized digital signatures for official use are digital signatures used in official activities and secured by e-certificates verifying them (Article 22.1(c)). Specialized e-signatures and digital signatures must meet stipulated conditions (Articles 22.2 and 22.3).

The LOET 2023 explicitly recognizes the legal validity of e-signatures by stipulating that their legal validity is not denied merely because they are in electronic form (Article 23.1). A secure specialized e-signature or a digital signature has the same legal validity as the signature of that individual on a written document (Article 23.2). A secure specialized e-signature is one that has been granted a safety certificate by the Ministry of Information and Communications (MIC) (Article 25.2). If an agency or organization uses a specialized e-signature in transactions, or seeks recognition of a secure specialized e-signature, it must register with the MIC to obtain a safety certificate for the secure specialized e-signature (Article 25.3).

Notably, the LOET 2023 lacks clear regulations regarding an individual’s e-signature. Consequently, it remains uncertain whether individuals can use self-created e-signatures in e-transactions. The combination of Article 23.2 and Article 22.1(b) suggests that individuals may be required to use a public digital signature in their e-transactions, which would significantly limit individual choice in selecting suitable technologies and potentially posing a burden on individuals engaging in e-transactions. This could be seen as a regression compared to the LOET 2005, which fully respects the parties’ freedom to choose e-signature technologies tailored to the nature of their transactions.

In addition, the LOET 2023 explicitly states that the use of other electronic confirmation methods that are not recognized as e-signatures for indicating the approval of data messages by signatories must comply with the provisions of other relevant laws (Article 22.4). This seems to exclude electronic verification methods such as one-time passwords (OTP), text messages (SMS), and biometrics, which are commonly used in banking and customs sectors, and defers regulation of such methods for substantive laws in specified sectors to regulate.

2.4 Electronic Seals

While the LOET 2005 has separate provisions on e-signatures for signatures and e-signatures for company seals, the LOET 2023 seems to merge both into a single e-signature requirement. In particular, according to the LOET 2005, where the law requires a document to be signed, such requirement with respect to a data message will be satisfied if the e-signature used to sign such data message meets stipulated conditions of security and authentication (Article 24.1 of the LOET 2005). Where the law requires a document to be affixed with the seal of an entity, such requirement with respect to a data message will be satisfied if the data message is signed with an entity’s secure e-signature which meets stipulated conditions (Article 24.2 of the LOET 2005).

The LOET 2023 does not use the word “seal” but uses “certification” instead. Article 23.3 regulates that if the law stipulates that a document must be certified by an agency or organization, such requirement with respect to a data message will be satisfied if the data message is signed by a secure specialized e-signature or digital signature of that agency or organization. Article 23.2 regulates that a secure specialized e-signature or digital signature has the same legal validity as the signature of that individual on a written document. This suggests that when a company uses its secure specialized e-signature or digital signature, this satisfies both signature and certification requirements, thus, serving both functions as a signature and a company seal at the same time.

2.5 Notarization and Certification

In certain sectors where substantive laws require documents to be notarized or certified, the requirement is fulfilled if the document is notarized according to the regulations of the laws on notarization, or certified according to regulations of the LOET 2023 and the laws on certification (Article 9.2). In other words, unless the laws on notarization explicitly prohibit notarization via electronic means, transactions which require notarization, such as sales contracts for houses, could be notarized electronically according to the rules specified in the laws on notarization.

3. Enabling Cross-Border E-Transactions

The LOET 2005 provides principles for recognition of foreign e-signatures and foreign e-signature certificates (Article 27.1 of LOET 2005). However, to date, guidance on implementation has only been provided under Decree 130/2018/ND-CP, which focuses exclusively on legal recognition for foreign digital signatures, leaving a gap in regulations for other technological aspects of foreign e-signatures. This shortcoming has hampered the advancement of cross-border e-transactions involving Vietnamese entities. The LOET 2023 is expected to deal with this deficiency.

According to the LOET 2023, subjects using recognized foreign e-signatures and recognized foreign e-signature certificates are foreign organizations and individuals, and Vietnamese organizations and individuals who transact with foreign organizations and individuals via electronic means, but whose domestically issued e-signatures and e-signature certificates have not been recognized in the other country (Article 26.3).

Conditions for foreign e-signatures and e-signature certificates to be recognized in Vietnam include (Article 26.2):

  • They must conform to the standards and technical regulations on e-signatures and e-signature certificates stipulated by Vietnamese law, or recognized international standards or international treaties to which Vietnam is a member; and
  • The foreign e-signature certificate is created based on complete and authenticated identification information of the foreign organization or individual.

Article 26.1 of the LOET 2023 also provides conditions for recognizing foreign e-signature certification service providers in Vietnam, which include the requirement of having a representative office in Vietnam (Article 26.1(dd)). It is not explicitly clear whether to be recognized in Vietnam, foreign e-signatures must be associated with foreign e-signature certificates that are issued by foreign e-signature certification service providers recognized in Vietnam. This matter will be guided further by the Minister of the MIC (Article 26.4).

4. Electronic Certificates

Electronic certificates (e-certificates) are licenses, certification papers, certificates, confirmation documents, and other approval documents issued by competent agencies and organizations in the form of electronic data (Article 3.5).

An e-certificate will be legally valid when it meets the following conditions (Article 19.1):

  • It is signed by a digital signature of a competent agency or organization;
  • The information in it can be accessed and used in a complete form; and
  • If the law requires the time relating to the e-certificate, it must be time-stamped

To be recognized and used in Vietnam, an e-certificate issued by a competent foreign agency or organization must be granted consular legalization, unless exempted as per Vietnamese law (Article 19.2).

E-certificates can be transferred if the law permits, but must meet stipulated conditions (Article 20.1). The information system to store and process e-certificates must be ensured to meet at least Level 3 of network information security in accordance with the Law on Network Information Security (Article 21.2).

The LOET 2005 uses the term “e-certificate” but denotes a different meaning, referring to the verification of a signing person or organization, similar to the concept of e-signature certificates under the LOET 2023.

5. Trust Services

Trust services include (i) timestamp services, (ii) data message certification services, and (iii) public digital signature certification services (Article 28.1). Timestamp services are services for attaching time information to data messages (Article 31.1). Data message certification services include services of storing and verifying the integrity of data messages and services of sending and receiving secure data messages (Article 32). Public digital signature certification services are services of certifying digital signatures in public activities (Article 33.1).

Although these trust services are new content compared to the LOET 2005, timestamp services and public digital signature certification services are not new services, and have been regulated under Decree No. 130/2018/ND-CP. The LOET 2023 retains and incorporates certain framework regulations of state management of timestamp services and digital signature services regulated in this decree. In particular, the LOET 2023 provides that these trust services are conditional business services and subject to licensing with a license duration of 10 years (Articles 28.2, 28.3).

6. Information Systems Serving E-Transactions

The LOET 2023 adds a new chapter (Chapter VI) on information systems serving e-transactions, which are defined as a combination of hardware, software, and databases established with the main purpose of serving e-transactions and ensuring the authenticity and reliability of e-transactions (Article 45.1). A digital platform serving e-transactions is an information system that creates an electronic environment allowing parties to conduct transactions, provide and use products and services, or develop products and services (Article 45.2). An intermediary digital platform serving e-transactions is a digital platform whose administrator is independent of the parties performing the transaction (Article 45.3).

E-transaction accounts are used to conduct e-transactions, store transaction history, and ensure the accuracy of the order/process of transactions of the account holder, and as evidence of the transaction history of the parties to e-transactions (Article 46.2). Agencies, organizations and individuals can choose to use e-transaction accounts based on their needs, unless otherwise provided for by law (Article 46.3). The transaction history of an e-transaction account will have legal validity for proving the transaction if it fulfills stipulated conditions (Article 46.4).

Administrators of information systems serving e-transactions are required to, among other things, provide information by electronic means for inspection purposes; report at the request of state management agencies in charge of e-transactions; and share data to serve state management of e-transactions (Article 47.1). Large intermediary digital platforms are required to, among other things, publish the mechanism to handle problems or content violating Vietnamese law arising in e-transactions and annually report to the MIC on incidents of taking advantage of the information system to violate Vietnamese law (Article 47.2). Extremely large intermediary digital platforms are required to, among other things, publish the basis used to make recommendations to users and allow users to opt out of such recommendations and uninstall any applications without affecting basic technical features of the system (Article 47.3). The government is to provide further guidance on the responsibilities of administrators of large and extremely large intermediary digital platforms based on the scale, number of users in Vietnam, or number of accesses from users in Vietnam of such platforms (Article 47.4).

7. Open Data

The LOET 2023 adds new content regarding the open data of state agencies, which is defined as data that is published or disclosed by a state agency for other parties to freely use, reuse, and share, in order to promote e-transactions, digital transformation, and development of the digital economy and digital society (Article 43.1). Organizations and individuals are free to access and use open data without being requested to provide identification, and are allowed to freely copy, share, exchange, and use open data or combine open data with other data, and use open data in their commercial or non-commercial products or services unless otherwise provided by law (Articles 43.3, 43.4).

RELATED INSIGHTS​ 

March 27, 2026
In response to the rapid advancement of artificial intelligence (AI) and evolving global digital trends, Thailand has undertaken significant efforts to establish a comprehensive national policy framework aimed at fostering an AI ecosystem. This framework seeks to promote the responsible development and deployment of AI technology to enhance Thailand’s economic competitiveness and improve quality of life, with targeted implementation by 2027. In furtherance of this national AI policy, regulatory authorities have initiated efforts to develop and refine the applicable legal framework, including the drafting of Thailand’s first unified AI legislation. Pending the composing and enactment of such comprehensive legislation, sector-specific regulators have proactively issued guidelines applicable to regulated entities within their respective jurisdictions, including financial institutions, banks, insurance companies, securities and derivatives business operators, and digital asset service providers. Concurrently, cross-sectoral regulatory bodies, notably the Personal Data Protection Committee (PDPC) and the National Cyber Security Agency (NCSA), have promulgated guidelines applicable to all business operators within their regulatory purview. While unified AI legislation has not been enacted, the design, development and use of AI in Thailand in various industries is still subject to existing sector-specific legislation. National AI policy The Thai cabinet approved the Thailand National AI Strategy and Action Plan (2022-2027) in July 2022, aiming to establish an AI development and application ecosystem by 2027. The strategy is built around five pillars: Preparing social, ethical, legal and regulatory readiness for AI; Developing national infrastructure; Increasing human capability and AI education; Driving AI technology and innovation; and Promoting AI adoption in public and private sectors. The above-mentioned national AI committee, under the National Digital Economy and Society Committee (NDESC), was established in August 2022, chaired by the prime minister. Comprehensive legislation Following the national AI strategy, the government has been developing comprehensive AI legislation to govern and promote AI
March 20, 2026
Thailand’s Board of Investment (BOI) now requires data center projects to demonstrate measurable benefits for local workforce development, R&D, SME capability, and domestic supply chains to qualify for corporate income tax (CIT) exemptions. BOI Notification No. Por. 3/2569, issued on February 6, 2026, updates the requirements for projects seeking promotion under BOI category 8.2.1 (data centers). All data center projects must now submit and implement plans covering development of Thai human resources and domestic supply chain support before benefiting from any CIT exemption. Human Resources Development Plan The BOI seeks to promote local talent development beyond basic training. Plans must include the following elements: Training for data center design, construction, and operations targeting vocational students, engineering and ICT undergraduates and postgraduates, and energy and building personnel in Thailand. Joint curricula with Thai universities and technical institutes. Collaborative R&D with Thai nationals or institutions in areas including AI, resource allocation, high-performance computing, and data center hardware and systems. Thai SME upskilling in electrical and energy systems and IT services. Domestic Supply Chain Support Plan Plans must demonstrate knowledge transfer in design, construction, cooling, security, and power and water management. Projects must also include usage or installation of domestically manufactured equipment or engage specialist domestic entities. Criteria for BOI Evaluation The BOI will assess data center operators’ eligibility for CIT incentives based on two criteria: Scale requirement: Training and joint-curriculum initiatives must reach a total participants equal to at least 10 times the project headcount and run for the duration of the CIT incentive. If this threshold is not met, the applicant must also implement continuous R&D or SME skills-development plans throughout the incentive period. Substantiality test: Supply-chain plans must be substantive, meet industry standards, and show measurable development of the domestic digital and data center supply base. To ensure compliance,
March 19, 2026
Thailand’s Electronic Transactions Development Agency (ETDA), which describes itself as a “co-creation regulator” working collaboratively with industry rather than imposing top-down rules, has unveiled its regulatory roadmap for digital platform businesses under the Royal Decree on Digital Platform Service Businesses B.E. 2565 (2022). The 2026 regulatory approach is guided by three core principles—“practicable, verifiable, shared responsibility”—aimed at elevating digital services to be safe, transparent, and fair. These principles inform ETDA’s 2026 priorities, which focus on three key dimensions: product and service standards on platforms, fair competition and fee transparency, and online fraud prevention. Product and Service Standards ETDA’s 2026 agenda addresses product and service standards across several platform categories: Online marketplace platforms. The Notification on Additional Measures for Online Marketplace Platforms under Section 18(2) came into force on December 31, 2025, designating 21 marketplace platforms that must verify products and merchants. Among other obligations, covered platforms must remove or suspend substandard products under the “notice and take down” principle. The ETDA has collaborated with the Food and Drug Administration and the Thai Industrial Standards Institute to develop inspection manuals and coordinate compliance procedures. Social commerce. The ETDA is preparing a new notification under Section 18(2) specifically targeting social commerce platforms with sales support functions, aiming to align regulation with evolving digital market conditions. Ride sharing. Since the postponement of the deadline to comply with the ETDA’s notification on ride-sharing platforms to March 31, 2026, the ETDA has supported drivers in registering with the Department of Land Transport through the Driver Verify registration system, which has already issued certifications to approximately 27,900 riders. The ETDA is also examining structural issues relating to appropriate insurance packages, motorcycle engine capacity expansion, and fair leasing fees and contract transfer costs in coordination with the Department of Land Transport, the Office of Insurance Commission,
March 19, 2026
Thailand’s Personal Data Protection Committee (PDPC) has launched a public consultation period to gather input for a forthcoming set of guidelines under the country’s Personal Data Protection Act (PDPA). This initiative follows the PDPC’s issuance of guidelines on consent and notification requirements in September 2022. The main consultation period, using an online questionnaire to gather feedback, runs until March 23, 2026. In addition, an interview-style online session for private-sector participants was held on March 17, and a two-day in-person event will be held on April 1–2—this is already fully booked and  walk-ins will not be accepted, but the session will be livestreamed on the PDPC’s Facebook page. The PDPC will use the public feedback to design draft guidelines that accurately reflect the operational realities of both public and private organizations, after which the guidelines will be shared with the public. Consultation Scope The PDPC has identified six priority areas for which upcoming guidance may be issued: Legal bases for processing: The online questionnaire assesses respondents’ understanding of consent requirements and seeks views on priority issues, such as explanations of the legal bases and considerations for selecting an appropriate legal basis depending on the nature of the processing activity. Security measures and data breach notification: The questionnaire examines respondents’ understanding of data breach reporting and security measure obligations. Topics proposed for inclusion in the guidelines include data breach prevention measures, incident response plans, risk assessment methods, and reporting procedures. Data protection officers: Respondents are invited to share their expectations regarding the DPO’s role and their experiences in contacting a DPO. The survey also asks respondents to identify priority issues, such as response timeframes for data subject requests and complaint procedures. Marketing and direct marketing: The online questionnaire seeks input on preferred topics for guidance, including individuals’ rights to refuse marketing