You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 28, 2025

Unpacking Vietnam’s Decree 163: Key Implications for Telecom Service Providers

Vietnam’s Decree No. 163/2024/ND-CP (Decree 163), which has been in full effect since January 1, 2025, provides crucial guidance on the implementation of Vietnam’s 2023 Telecom Law. Decree 163 replaced Decree No. 25/2011/ND-CP dated April 6, 2011 (Decree 25), which guided the implementation of the previous 2009 Telecom Law, and introduces many notable changes to the regulations on telecom service provision. Some key changes that will impact businesses engaged in the telecom sector in Vietnam are detailed below.

1. Classification of Telecom Services

The classification of telecom services into “basic telecom services” and “value-added telecom services” has been retained, in alignment with Vietnam’s WTO commitments in the telecom sector. However, Decree 163 expands the scope of both categories, as follows:

  • Basic telecom services: “Transmission services for machine-to-machine (M2M) communication” and “leasing services of all or part of the telecom network” are added. “Image transmission services” is changed to “transmission services for radio and television.”
  • Value-added telecom services: “Data center services,” “cloud computing services,” and “basic telecom services over the internet” (also known as over-the-top (OTT) telecom services) are added.

2. M2M Communication Services

Since M2M communication services are classified as basic telecom services, without exception, they are subject to the same regulatory framework. Specifically:

  • Cross-border provision: M2M communication services provided across borders must be conducted through a commercial agreement with a Vietnamese telecom enterprise licensed to provide telecom services with an international communication scope.
  • Onshore provision: Onshore M2M communication services will require a telecom license.

3. New Telecom Services (Data Center, Cloud, and OTT Telecom Services)

The 2023 Telecom Law adopted a light-touch management approach for data center, cloud, and OTT telecom services by not requiring the same licensing as previously regulated value-added telecom services, but instead mandating registration or notification before service provision. Decree 163 offers clearer guidance on this approach, specifically:

  • Cloud and OTT telecom services: Both onshore and offshore providers are required to notify the Vietnam Telecommunications Authority (VNTA) under the Ministry of Information and Communications (MIC).
  • Data center services: Offshore providers of data center services only need to notify the VNTA while onshore providers must register with the VNTA.

The required dossiers for notification and registration must be prepared in Vietnamese, following prescribed forms, and can be submitted in person, via postal service, or through the national public service portal. For onshore enterprises providing both data center and cloud computing services, only a registration form needs to be submitted, with cloud service details included in the same form.

Decree 163 specifies a relatively short timeline of three working days for processing these dossiers.

Key Obligations for Service Providers

Enterprises providing these three new services, which can include 100% foreign-owned enterprises in Vietnam, must fulfill certain obligations in addition to registration or notification requirements. These key obligations include storing and managing user information, user verification, and various specific obligations of onshore and offshore providers.

Offshore data center and cloud computing service providers also have certain additional obligations, such as promptly taking necessary measures to block access to information as requested by competent authorities.

Further, Decree 163 imposes certain obligations when data center and/or cloud services are provided to state agencies to serve state activities, such as storing data of the state agencies using these services within Vietnam.

4. Satellite Telecom Services

Onshore service provision: Decree 163 retains the conditions for the establishment of public fixed satellite and mobile satellite telecom networks regarding the charter capital and telecom network deployment from the previous Decree 25, including the commitment to invest at least VND 100 billion in the telecom network within the first three years.

Cross-border service provision: For providing cross-border telecom services via fixed satellite networks or mobile satellite networks, among other conditions, offshore providers must enter into a commercial agreement with a Vietnamese telecom enterprise licensed to provide telecom services with an international communication scope.

5. Telecom Market Management

Decree 163 introduces criteria for identifying telecom service markets under state management, and establishes criteria for identifying telecom enterprises and groups of enterprises with dominant market positions in state-managed service markets, using quantifiable principles suitable for telecom business activities. The decree tends to impose certain obligations on the identified telecom enterprises and groups of enterprises to ensure fair competition in the market.

6. Telecom Infrastructure Management

The development of telecom infrastructure in Vietnam is one of the key focuses of Decree 163, which covers the following main aspects of telecom infrastructure management, among others:

  • Protecting telecom infrastructure: Telecom enterprises are responsible for ensuring the safety of telecom infrastructure, including preventing attacks and incidents, maintaining stability with backups, preventing prohibited activities, ensuring safety for equipment and staff, and adhering to relevant standards and technical regulations.
  • Ensuring network information security: Telecom enterprises must ensure network information security in their operations by, among other measures, protecting information systems and handling incidents at the request of the MIC.
  • Sharing of passive telecom infrastructure: Decree 163 stipulates the authority to resolve the sharing of passive telecom infrastructure in cases where telecom enterprises cannot reach an agreement (except for price issues). The resolution of disputes will be handled by either the local Department of Information and Communications or the MIC, depending on the location of the passive telecom technical infrastructure in question. If the parties cannot reach an agreement on the price for sharing passive telecommunications infrastructure, negotiations must be carried out in accordance with the provisions of the pricing laws.
  • Sharing of active telecom infrastructure: The sharing of active telecommunications infrastructure among telecom enterprises is based on the principle of encouraging sharing to save costs for telecom network deployment, while ensuring compliance with competition law and radio frequency law.

7. Management of Mobile Subscriber Information

Decree 163 dedicates a section to the management of mobile subscriber information, offering comprehensive regulations on the subject. These include methods for registering mobile subscriber information, required documents for registration, verification of subscriber details, the scope of subscriber information, service provision after registration, registration for prepaid subscribers, storage and usage of subscriber data, subscriber responsibilities, and telecom enterprises’ obligations in addressing subscribers with incorrect information.

Business Recommendations

The 2023 Telecom Law, as detailed by Decree 163, demonstrates the government’s clear intent to catch up to and regulate recent advancements, innovations, and emerging business models in the technology and telecom sectors. The following are some recommendations for businesses:

  • Adopt proactive compliance strategies: Ensure familiarity with classifications and specific regulatory obligations for telecom services. Especially, businesses operating in the areas of M2M communication, cloud computing, data center services, and OTT telecom services should update internal compliance systems to address new requirements in these areas to avoid potential non-compliance risks.
  • Leverage emerging opportunities: With the government’s goal of opening markets and attracting foreign investment through incentives that support digital transformation, businesses should consider expanding and investing in areas like cloud computing, OTT services, and data centers to capitalize on emerging opportunities.
  • Adapt to digital transformation trends: Pay close attention to the new regulations aimed at facilitating digital transformation. For instance, consider investing in the development or optimization of mobile applications for subscriber registration and verification to align with the digital transformation push.
  • Strengthen data security and privacy practices: With increased regulatory focus on telecom infrastructure security and network information security, businesses should prioritize robust cybersecurity and network information security measures.

By navigating Decree 163 proactively, telecom enterprises can position themselves for sustainable growth while contributing to Vietnam’s digital economy ambitions.

RELATED INSIGHTS​ 

April 9, 2026
As part of its ongoing public consultation process for the development of new practical guidelines under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), Thailand’s Personal Data Protection Committee (PDPC) held a two‑day public hearing on April 1–2, 2026. The hearing followed an online questionnaire and stakeholder engagement activities conducted in March 2026 and reflects the PDPC’s continued efforts to develop guidance that aligns international regulatory standards with Thai operational realities. The public hearing provided a forum for participants from both the public and private sectors to exchange views with the PDPC on the proposed guidance so that it responds to the needs of the business community while supporting effective and balanced enforcement of the PDPA. The PDPC emphasized that the consultation process is part of a wider policy objective to build trust in the convenient, secure, and internationally aligned exchange of data. Structure of the Consultation Process According to the PDPC, the initiative to develop the draft PDPA guidelines is being implemented through three core phases: Review of international best practices. The PDPC has conducted a comparative review of data protection guidance and regulatory approaches in jurisdictions with internationally recognized standards, including Singapore, the United Kingdom, the European Union (EU), and Japan. These materials are intended to serve as a reference point for developing practical recommendations across key subject areas under the PDPA. Identification of practical issues and challenges. To ensure that the guidelines respond to real‑world compliance challenges in Thailand, the PDPC has gathered views from a broad range of stakeholders across the public sector, the private sector, and the general public. This phase included focus group discussions and questionnaires aimed at identifying areas to provide organizations with greater clarity and consistency on regulatory expectations. Preparation of draft guidelines. Insights from the comparative study and stakeholder
April 3, 2026
On March 16, 2026, Vietnam’s Ministry of Public Security released a draft version of a new Decree on the Prevention and Combating of Cybercrime and High-Tech Crime to replace the currently effective Decree 25/2014/ND-CP. In the draft, the ministry has proposed a comprehensive regulatory framework aimed at addressing violations occurring within the cybersecurity domain, including measures related to intellectual property. Acts of Online IP Infringement Article 9 of the draft decree notably introduces specific provisions addressing online intellectual property infringement, with detailed lists of acts considered to constitute infringement in the online environment. Copyright and related rights infringement includes: Uploading or sharing works, performances, sound recordings, video recordings, broadcasts, computer programs, software, research, documents, theses, or other intellectual creations on digital platforms without the consent of the rights holder. Unauthorized livestreaming of copyrighted television programs, sporting events, or artistic performances. Uploading, sharing, storing, transmitting, or providing links to infringing works or digital content via websites, social networks, applications, or digital platforms. Providing or using software, tools, devices, or access codes to circumvent technological protection measures or evade lawful control mechanisms implemented by rights holders. Using artificial intelligence (AI) tools to replicate the ideas or structure of another person’s work without significant new creativity or without proper attribution, thereby causing damage to the original author. Industrial property infringement includes: Manufacturing, trading, advertising, or distributing counterfeit goods bearing counterfeit trademarks, geographical indications, or industrial designs, as well as goods infringing industrial property rights through online platforms. Unauthorized registration, appropriation, or use of domain names, account names, or digital identifiers that create confusion regarding the rights holder or the origin of goods or services. Producing, using, or offering for sale products containing all or part of a patented invention via online platforms. Advertising or introducing products with technical features or characteristics identical
April 3, 2026
Thailand’s Securities and Exchange Commission (SEC) has established a comprehensive governance framework for the use of artificial intelligence and machine learning (AI/ML) in the capital markets. The framework provides guidance to capital market business operators on understanding the risks associated with AI/ML implementation and adopting appropriate practices to build public confidence in Thailand’s capital markets. While the guidelines are principle-based rather than prescriptive, they reflect the SEC’s expectations for responsible AI/ML governance and are likely to inform supervisory activities and industry standards going forward. Scope The framework applies to capital market business operators supervised by the SEC. This includes, for example, securities and derivatives firms, asset management companies, mutual fund and private fund managers, investment advisors and investment consultants (including robo-advisory service providers), derivatives intermediaries, and other licensed intermediaries and market operators in the Thai capital markets that deploy AI/ML in their operations. Core Principles of the Guidelines The framework is presented as a best-practice manual rather than prescriptive regulation, providing guidance that regulated entities may apply to their AI/ML governance and risk management as appropriate. While currently nonbinding, the guidelines signal the SEC’s expectations for the sector, particularly in relation to other binding SEC regulations such as those covering IT risk management and market conduct. The guidelines name four core principles for AI/ML deployment: Fairness: Design and develop AI/ML with consideration for fairness, equality, and social diversity to prevent discrimination against individuals or groups. Legal and ethical compliance: Ensure AI/ML use aligns with applicable laws, ethical standards, and organizational values and policies. Accountability: Establish clear responsibility—both internally and externally—for AI/ML activities and outcomes. Transparency: Provide adequate disclosure to users about AI/ML use, including explainability of decisions and traceability of activities. AI/ML Best Practices The guidelines prescribe best practices across four stages of the AI/ML lifecycle, as described below.
April 2, 2026
Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance. What Has Changed: OIC and PDPC Alignment The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers. Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible. Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors. Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels. DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on