You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 28, 2025

Unpacking Vietnam’s Decree 163: Key Implications for Telecom Service Providers

Vietnam’s Decree No. 163/2024/ND-CP (Decree 163), which has been in full effect since January 1, 2025, provides crucial guidance on the implementation of Vietnam’s 2023 Telecom Law. Decree 163 replaced Decree No. 25/2011/ND-CP dated April 6, 2011 (Decree 25), which guided the implementation of the previous 2009 Telecom Law, and introduces many notable changes to the regulations on telecom service provision. Some key changes that will impact businesses engaged in the telecom sector in Vietnam are detailed below.

1. Classification of Telecom Services

The classification of telecom services into “basic telecom services” and “value-added telecom services” has been retained, in alignment with Vietnam’s WTO commitments in the telecom sector. However, Decree 163 expands the scope of both categories, as follows:

  • Basic telecom services: “Transmission services for machine-to-machine (M2M) communication” and “leasing services of all or part of the telecom network” are added. “Image transmission services” is changed to “transmission services for radio and television.”
  • Value-added telecom services: “Data center services,” “cloud computing services,” and “basic telecom services over the internet” (also known as over-the-top (OTT) telecom services) are added.

2. M2M Communication Services

Since M2M communication services are classified as basic telecom services, without exception, they are subject to the same regulatory framework. Specifically:

  • Cross-border provision: M2M communication services provided across borders must be conducted through a commercial agreement with a Vietnamese telecom enterprise licensed to provide telecom services with an international communication scope.
  • Onshore provision: Onshore M2M communication services will require a telecom license.

3. New Telecom Services (Data Center, Cloud, and OTT Telecom Services)

The 2023 Telecom Law adopted a light-touch management approach for data center, cloud, and OTT telecom services by not requiring the same licensing as previously regulated value-added telecom services, but instead mandating registration or notification before service provision. Decree 163 offers clearer guidance on this approach, specifically:

  • Cloud and OTT telecom services: Both onshore and offshore providers are required to notify the Vietnam Telecommunications Authority (VNTA) under the Ministry of Information and Communications (MIC).
  • Data center services: Offshore providers of data center services only need to notify the VNTA while onshore providers must register with the VNTA.

The required dossiers for notification and registration must be prepared in Vietnamese, following prescribed forms, and can be submitted in person, via postal service, or through the national public service portal. For onshore enterprises providing both data center and cloud computing services, only a registration form needs to be submitted, with cloud service details included in the same form.

Decree 163 specifies a relatively short timeline of three working days for processing these dossiers.

Key Obligations for Service Providers

Enterprises providing these three new services, which can include 100% foreign-owned enterprises in Vietnam, must fulfill certain obligations in addition to registration or notification requirements. These key obligations include storing and managing user information, user verification, and various specific obligations of onshore and offshore providers.

Offshore data center and cloud computing service providers also have certain additional obligations, such as promptly taking necessary measures to block access to information as requested by competent authorities.

Further, Decree 163 imposes certain obligations when data center and/or cloud services are provided to state agencies to serve state activities, such as storing data of the state agencies using these services within Vietnam.

4. Satellite Telecom Services

Onshore service provision: Decree 163 retains the conditions for the establishment of public fixed satellite and mobile satellite telecom networks regarding the charter capital and telecom network deployment from the previous Decree 25, including the commitment to invest at least VND 100 billion in the telecom network within the first three years.

Cross-border service provision: For providing cross-border telecom services via fixed satellite networks or mobile satellite networks, among other conditions, offshore providers must enter into a commercial agreement with a Vietnamese telecom enterprise licensed to provide telecom services with an international communication scope.

5. Telecom Market Management

Decree 163 introduces criteria for identifying telecom service markets under state management, and establishes criteria for identifying telecom enterprises and groups of enterprises with dominant market positions in state-managed service markets, using quantifiable principles suitable for telecom business activities. The decree tends to impose certain obligations on the identified telecom enterprises and groups of enterprises to ensure fair competition in the market.

6. Telecom Infrastructure Management

The development of telecom infrastructure in Vietnam is one of the key focuses of Decree 163, which covers the following main aspects of telecom infrastructure management, among others:

  • Protecting telecom infrastructure: Telecom enterprises are responsible for ensuring the safety of telecom infrastructure, including preventing attacks and incidents, maintaining stability with backups, preventing prohibited activities, ensuring safety for equipment and staff, and adhering to relevant standards and technical regulations.
  • Ensuring network information security: Telecom enterprises must ensure network information security in their operations by, among other measures, protecting information systems and handling incidents at the request of the MIC.
  • Sharing of passive telecom infrastructure: Decree 163 stipulates the authority to resolve the sharing of passive telecom infrastructure in cases where telecom enterprises cannot reach an agreement (except for price issues). The resolution of disputes will be handled by either the local Department of Information and Communications or the MIC, depending on the location of the passive telecom technical infrastructure in question. If the parties cannot reach an agreement on the price for sharing passive telecommunications infrastructure, negotiations must be carried out in accordance with the provisions of the pricing laws.
  • Sharing of active telecom infrastructure: The sharing of active telecommunications infrastructure among telecom enterprises is based on the principle of encouraging sharing to save costs for telecom network deployment, while ensuring compliance with competition law and radio frequency law.

7. Management of Mobile Subscriber Information

Decree 163 dedicates a section to the management of mobile subscriber information, offering comprehensive regulations on the subject. These include methods for registering mobile subscriber information, required documents for registration, verification of subscriber details, the scope of subscriber information, service provision after registration, registration for prepaid subscribers, storage and usage of subscriber data, subscriber responsibilities, and telecom enterprises’ obligations in addressing subscribers with incorrect information.

Business Recommendations

The 2023 Telecom Law, as detailed by Decree 163, demonstrates the government’s clear intent to catch up to and regulate recent advancements, innovations, and emerging business models in the technology and telecom sectors. The following are some recommendations for businesses:

  • Adopt proactive compliance strategies: Ensure familiarity with classifications and specific regulatory obligations for telecom services. Especially, businesses operating in the areas of M2M communication, cloud computing, data center services, and OTT telecom services should update internal compliance systems to address new requirements in these areas to avoid potential non-compliance risks.
  • Leverage emerging opportunities: With the government’s goal of opening markets and attracting foreign investment through incentives that support digital transformation, businesses should consider expanding and investing in areas like cloud computing, OTT services, and data centers to capitalize on emerging opportunities.
  • Adapt to digital transformation trends: Pay close attention to the new regulations aimed at facilitating digital transformation. For instance, consider investing in the development or optimization of mobile applications for subscriber registration and verification to align with the digital transformation push.
  • Strengthen data security and privacy practices: With increased regulatory focus on telecom infrastructure security and network information security, businesses should prioritize robust cybersecurity and network information security measures.

By navigating Decree 163 proactively, telecom enterprises can position themselves for sustainable growth while contributing to Vietnam’s digital economy ambitions.

RELATED INSIGHTS​ 

March 27, 2026
In response to the rapid advancement of artificial intelligence (AI) and evolving global digital trends, Thailand has undertaken significant efforts to establish a comprehensive national policy framework aimed at fostering an AI ecosystem. This framework seeks to promote the responsible development and deployment of AI technology to enhance Thailand’s economic competitiveness and improve quality of life, with targeted implementation by 2027. In furtherance of this national AI policy, regulatory authorities have initiated efforts to develop and refine the applicable legal framework, including the drafting of Thailand’s first unified AI legislation. Pending the composing and enactment of such comprehensive legislation, sector-specific regulators have proactively issued guidelines applicable to regulated entities within their respective jurisdictions, including financial institutions, banks, insurance companies, securities and derivatives business operators, and digital asset service providers. Concurrently, cross-sectoral regulatory bodies, notably the Personal Data Protection Committee (PDPC) and the National Cyber Security Agency (NCSA), have promulgated guidelines applicable to all business operators within their regulatory purview. While unified AI legislation has not been enacted, the design, development and use of AI in Thailand in various industries is still subject to existing sector-specific legislation. National AI policy The Thai cabinet approved the Thailand National AI Strategy and Action Plan (2022-2027) in July 2022, aiming to establish an AI development and application ecosystem by 2027. The strategy is built around five pillars: Preparing social, ethical, legal and regulatory readiness for AI; Developing national infrastructure; Increasing human capability and AI education; Driving AI technology and innovation; and Promoting AI adoption in public and private sectors. The above-mentioned national AI committee, under the National Digital Economy and Society Committee (NDESC), was established in August 2022, chaired by the prime minister. Comprehensive legislation Following the national AI strategy, the government has been developing comprehensive AI legislation to govern and promote AI
March 20, 2026
Thailand’s Board of Investment (BOI) now requires data center projects to demonstrate measurable benefits for local workforce development, R&D, SME capability, and domestic supply chains to qualify for corporate income tax (CIT) exemptions. BOI Notification No. Por. 3/2569, issued on February 6, 2026, updates the requirements for projects seeking promotion under BOI category 8.2.1 (data centers). All data center projects must now submit and implement plans covering development of Thai human resources and domestic supply chain support before benefiting from any CIT exemption. Human Resources Development Plan The BOI seeks to promote local talent development beyond basic training. Plans must include the following elements: Training for data center design, construction, and operations targeting vocational students, engineering and ICT undergraduates and postgraduates, and energy and building personnel in Thailand. Joint curricula with Thai universities and technical institutes. Collaborative R&D with Thai nationals or institutions in areas including AI, resource allocation, high-performance computing, and data center hardware and systems. Thai SME upskilling in electrical and energy systems and IT services. Domestic Supply Chain Support Plan Plans must demonstrate knowledge transfer in design, construction, cooling, security, and power and water management. Projects must also include usage or installation of domestically manufactured equipment or engage specialist domestic entities. Criteria for BOI Evaluation The BOI will assess data center operators’ eligibility for CIT incentives based on two criteria: Scale requirement: Training and joint-curriculum initiatives must reach a total participants equal to at least 10 times the project headcount and run for the duration of the CIT incentive. If this threshold is not met, the applicant must also implement continuous R&D or SME skills-development plans throughout the incentive period. Substantiality test: Supply-chain plans must be substantive, meet industry standards, and show measurable development of the domestic digital and data center supply base. To ensure compliance,
March 19, 2026
Thailand’s Electronic Transactions Development Agency (ETDA), which describes itself as a “co-creation regulator” working collaboratively with industry rather than imposing top-down rules, has unveiled its regulatory roadmap for digital platform businesses under the Royal Decree on Digital Platform Service Businesses B.E. 2565 (2022). The 2026 regulatory approach is guided by three core principles—“practicable, verifiable, shared responsibility”—aimed at elevating digital services to be safe, transparent, and fair. These principles inform ETDA’s 2026 priorities, which focus on three key dimensions: product and service standards on platforms, fair competition and fee transparency, and online fraud prevention. Product and Service Standards ETDA’s 2026 agenda addresses product and service standards across several platform categories: Online marketplace platforms. The Notification on Additional Measures for Online Marketplace Platforms under Section 18(2) came into force on December 31, 2025, designating 21 marketplace platforms that must verify products and merchants. Among other obligations, covered platforms must remove or suspend substandard products under the “notice and take down” principle. The ETDA has collaborated with the Food and Drug Administration and the Thai Industrial Standards Institute to develop inspection manuals and coordinate compliance procedures. Social commerce. The ETDA is preparing a new notification under Section 18(2) specifically targeting social commerce platforms with sales support functions, aiming to align regulation with evolving digital market conditions. Ride sharing. Since the postponement of the deadline to comply with the ETDA’s notification on ride-sharing platforms to March 31, 2026, the ETDA has supported drivers in registering with the Department of Land Transport through the Driver Verify registration system, which has already issued certifications to approximately 27,900 riders. The ETDA is also examining structural issues relating to appropriate insurance packages, motorcycle engine capacity expansion, and fair leasing fees and contract transfer costs in coordination with the Department of Land Transport, the Office of Insurance Commission,
March 19, 2026
Thailand’s Personal Data Protection Committee (PDPC) has launched a public consultation period to gather input for a forthcoming set of guidelines under the country’s Personal Data Protection Act (PDPA). This initiative follows the PDPC’s issuance of guidelines on consent and notification requirements in September 2022. The main consultation period, using an online questionnaire to gather feedback, runs until March 23, 2026. In addition, an interview-style online session for private-sector participants was held on March 17, and a two-day in-person event will be held on April 1–2—this is already fully booked and  walk-ins will not be accepted, but the session will be livestreamed on the PDPC’s Facebook page. The PDPC will use the public feedback to design draft guidelines that accurately reflect the operational realities of both public and private organizations, after which the guidelines will be shared with the public. Consultation Scope The PDPC has identified six priority areas for which upcoming guidance may be issued: Legal bases for processing: The online questionnaire assesses respondents’ understanding of consent requirements and seeks views on priority issues, such as explanations of the legal bases and considerations for selecting an appropriate legal basis depending on the nature of the processing activity. Security measures and data breach notification: The questionnaire examines respondents’ understanding of data breach reporting and security measure obligations. Topics proposed for inclusion in the guidelines include data breach prevention measures, incident response plans, risk assessment methods, and reporting procedures. Data protection officers: Respondents are invited to share their expectations regarding the DPO’s role and their experiences in contacting a DPO. The survey also asks respondents to identify priority issues, such as response timeframes for data subject requests and complaint procedures. Marketing and direct marketing: The online questionnaire seeks input on preferred topics for guidance, including individuals’ rights to refuse marketing