You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 28, 2025

Unpacking Vietnam’s Decree 163: Key Implications for Telecom Service Providers

Vietnam’s Decree No. 163/2024/ND-CP (Decree 163), which has been in full effect since January 1, 2025, provides crucial guidance on the implementation of Vietnam’s 2023 Telecom Law. Decree 163 replaced Decree No. 25/2011/ND-CP dated April 6, 2011 (Decree 25), which guided the implementation of the previous 2009 Telecom Law, and introduces many notable changes to the regulations on telecom service provision. Some key changes that will impact businesses engaged in the telecom sector in Vietnam are detailed below.

1. Classification of Telecom Services

The classification of telecom services into “basic telecom services” and “value-added telecom services” has been retained, in alignment with Vietnam’s WTO commitments in the telecom sector. However, Decree 163 expands the scope of both categories, as follows:

  • Basic telecom services: “Transmission services for machine-to-machine (M2M) communication” and “leasing services of all or part of the telecom network” are added. “Image transmission services” is changed to “transmission services for radio and television.”
  • Value-added telecom services: “Data center services,” “cloud computing services,” and “basic telecom services over the internet” (also known as over-the-top (OTT) telecom services) are added.

2. M2M Communication Services

Since M2M communication services are classified as basic telecom services, without exception, they are subject to the same regulatory framework. Specifically:

  • Cross-border provision: M2M communication services provided across borders must be conducted through a commercial agreement with a Vietnamese telecom enterprise licensed to provide telecom services with an international communication scope.
  • Onshore provision: Onshore M2M communication services will require a telecom license.

3. New Telecom Services (Data Center, Cloud, and OTT Telecom Services)

The 2023 Telecom Law adopted a light-touch management approach for data center, cloud, and OTT telecom services by not requiring the same licensing as previously regulated value-added telecom services, but instead mandating registration or notification before service provision. Decree 163 offers clearer guidance on this approach, specifically:

  • Cloud and OTT telecom services: Both onshore and offshore providers are required to notify the Vietnam Telecommunications Authority (VNTA) under the Ministry of Information and Communications (MIC).
  • Data center services: Offshore providers of data center services only need to notify the VNTA while onshore providers must register with the VNTA.

The required dossiers for notification and registration must be prepared in Vietnamese, following prescribed forms, and can be submitted in person, via postal service, or through the national public service portal. For onshore enterprises providing both data center and cloud computing services, only a registration form needs to be submitted, with cloud service details included in the same form.

Decree 163 specifies a relatively short timeline of three working days for processing these dossiers.

Key Obligations for Service Providers

Enterprises providing these three new services, which can include 100% foreign-owned enterprises in Vietnam, must fulfill certain obligations in addition to registration or notification requirements. These key obligations include storing and managing user information, user verification, and various specific obligations of onshore and offshore providers.

Offshore data center and cloud computing service providers also have certain additional obligations, such as promptly taking necessary measures to block access to information as requested by competent authorities.

Further, Decree 163 imposes certain obligations when data center and/or cloud services are provided to state agencies to serve state activities, such as storing data of the state agencies using these services within Vietnam.

4. Satellite Telecom Services

Onshore service provision: Decree 163 retains the conditions for the establishment of public fixed satellite and mobile satellite telecom networks regarding the charter capital and telecom network deployment from the previous Decree 25, including the commitment to invest at least VND 100 billion in the telecom network within the first three years.

Cross-border service provision: For providing cross-border telecom services via fixed satellite networks or mobile satellite networks, among other conditions, offshore providers must enter into a commercial agreement with a Vietnamese telecom enterprise licensed to provide telecom services with an international communication scope.

5. Telecom Market Management

Decree 163 introduces criteria for identifying telecom service markets under state management, and establishes criteria for identifying telecom enterprises and groups of enterprises with dominant market positions in state-managed service markets, using quantifiable principles suitable for telecom business activities. The decree tends to impose certain obligations on the identified telecom enterprises and groups of enterprises to ensure fair competition in the market.

6. Telecom Infrastructure Management

The development of telecom infrastructure in Vietnam is one of the key focuses of Decree 163, which covers the following main aspects of telecom infrastructure management, among others:

  • Protecting telecom infrastructure: Telecom enterprises are responsible for ensuring the safety of telecom infrastructure, including preventing attacks and incidents, maintaining stability with backups, preventing prohibited activities, ensuring safety for equipment and staff, and adhering to relevant standards and technical regulations.
  • Ensuring network information security: Telecom enterprises must ensure network information security in their operations by, among other measures, protecting information systems and handling incidents at the request of the MIC.
  • Sharing of passive telecom infrastructure: Decree 163 stipulates the authority to resolve the sharing of passive telecom infrastructure in cases where telecom enterprises cannot reach an agreement (except for price issues). The resolution of disputes will be handled by either the local Department of Information and Communications or the MIC, depending on the location of the passive telecom technical infrastructure in question. If the parties cannot reach an agreement on the price for sharing passive telecommunications infrastructure, negotiations must be carried out in accordance with the provisions of the pricing laws.
  • Sharing of active telecom infrastructure: The sharing of active telecommunications infrastructure among telecom enterprises is based on the principle of encouraging sharing to save costs for telecom network deployment, while ensuring compliance with competition law and radio frequency law.

7. Management of Mobile Subscriber Information

Decree 163 dedicates a section to the management of mobile subscriber information, offering comprehensive regulations on the subject. These include methods for registering mobile subscriber information, required documents for registration, verification of subscriber details, the scope of subscriber information, service provision after registration, registration for prepaid subscribers, storage and usage of subscriber data, subscriber responsibilities, and telecom enterprises’ obligations in addressing subscribers with incorrect information.

Business Recommendations

The 2023 Telecom Law, as detailed by Decree 163, demonstrates the government’s clear intent to catch up to and regulate recent advancements, innovations, and emerging business models in the technology and telecom sectors. The following are some recommendations for businesses:

  • Adopt proactive compliance strategies: Ensure familiarity with classifications and specific regulatory obligations for telecom services. Especially, businesses operating in the areas of M2M communication, cloud computing, data center services, and OTT telecom services should update internal compliance systems to address new requirements in these areas to avoid potential non-compliance risks.
  • Leverage emerging opportunities: With the government’s goal of opening markets and attracting foreign investment through incentives that support digital transformation, businesses should consider expanding and investing in areas like cloud computing, OTT services, and data centers to capitalize on emerging opportunities.
  • Adapt to digital transformation trends: Pay close attention to the new regulations aimed at facilitating digital transformation. For instance, consider investing in the development or optimization of mobile applications for subscriber registration and verification to align with the digital transformation push.
  • Strengthen data security and privacy practices: With increased regulatory focus on telecom infrastructure security and network information security, businesses should prioritize robust cybersecurity and network information security measures.

By navigating Decree 163 proactively, telecom enterprises can position themselves for sustainable growth while contributing to Vietnam’s digital economy ambitions.

RELATED INSIGHTS​ 

August 21, 2025
On August 18, 2025, Thailand’s Securities and Exchange Commission (SEC), in collaboration with the Ministry of Finance, the Anti-Money Laundering Office, and the Ministry of Tourism and Sports, announced the launch of TouristDigiPay. The initiative, implemented under the SEC’s Regulatory Sandbox, allows foreign tourists to convert digital assets into Thai baht for use in everyday transactions in Thailand. Foreign tourists who opt to participate in TouristDigiPay must open two accounts once they are in Thailand: An account with a licensed digital asset operator to sell or exchange digital assets for Thai baht; and A tourist wallet account with a licensed e-money operator regulated by the Bank of Thailand. Funds from digital asset sales will be transferred into the tourist wallet, enabling tourists to make payments at participating merchants that accept e-money. Key Regulatory Requirements The TouristDigiPay project will operate for a period of up to 18 months, with the following conditions: Only licensed digital asset brokers, dealers, and exchanges integrated with licensed e-money operators are eligible to participate. Operators must implement anti-money laundering (AML) protocols that are proportionate to the assessed risk level. These include: Conducting know-your-customer and customer-due-diligence (KYC/CDD) checks on all users. For monthly transactions exceeding THB 50,000 per person, verifying the source of the digital assets and assessing AML risk using internationally recognized blockchain forensic tools or equivalent procedures. Suspending or rejecting services if digital assets are transferred from wallets flagged for AML concerns. Ensuring that conversion between digital assets and fiat includes safeguards such as matching account names and returning digital assets only to the original wallet. The following transaction limits apply to participants in the TouristDigiPay initiative: Payments to small vendors are capped at THB 50,000 per month. Payments to vendors who have completed the know-your-merchant (KYM) process are capped at THB 500,000 per
August 15, 2025
More than a decade after the issuance of Decree No. 52/2013/ND-CP (as amended by Decree No. 85/2021/ND-CP; collectively, “Decree 52”), Vietnam’s legal framework for e-commerce is under growing pressure to keep pace with the evolving digital economy. While Decree 52 has provided a foundational framework, it has shown certain limitations in keeping up with issues such as counterfeit goods, intellectual property enforcement, unqualified products, and emerging models like livestream selling and affiliate marketing. To address these regulatory gaps, the Ministry of Industry and Trade (MOIT) has released the 2025 Draft E-Commerce Law (“Draft Law”) for public consultation. The Draft Law is intended to supersede the current framework under Decree 52 and establish a more detailed and comprehensive legal foundation for the regulations of e-commerce activities in Vietnam. It is currently expected to be submitted to the National Assembly for review and potential adoption during its 10th session in October 2025. In this article, we discuss the Draft Law’s most significant updates and legal developments in comparison to existing regulations, and assess the practical challenges that businesses may face in preparing for implementation in the near future. Platform Classification: Toward a More Nuanced Framework Unlike Decree 52’s simpler structure, which broadly categorized platforms into either (i) websites selling goods and services or (ii) websites providing e-commerce services, the Draft Law introduces a more detailed framework that aims to classify platforms based on their technical functions and business models. Specifically, the Draft Law introduces a four-tier classification system for e-commerce platforms, consisting of: (i) Direct Business Platforms, (ii) Intermediary Platforms, (iii) Social Networks with E-Commerce Functions, and (iv) Multi-Service Integrated Platforms. This approach reflects an effort to more accurately capture the complexity of today’s e-commerce landscape, including hybrid platforms such as TikTok Shop. While this approach reflects the growing complexity of
August 6, 2025
Thailand’s Digital Government Development Agency (DGA) has released drafts of two pivotal documents to guide Thai government agencies in adopting cloud technology and classifying data for cloud usage. These draft guidelines, open for public hearing through August 12, 2025, are part of the national “Go Cloud First” policy, which aims to accelerate digital transformation, improve efficiency, and ensure robust data security across the public sector. The new standards will have significant implications for both government agencies and cloud service providers operating in Thailand. Highlights of the draft guidelines are presented below. Government Cloud Usage Guidelines Cloud-first transformation: All government agencies are directed to prioritize cloud solutions for new IT projects, in line with the cabinet’s “Go Cloud First” policy. Cloud model selection: Agencies must assess their needs and select the most appropriate cloud deployment model—public, private, hybrid, or community cloud—based on the sensitivity of the data and operational requirements. Service types: The guidelines provide criteria for choosing between Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS), emphasizing the importance of using standard, non-customized services where possible. Cost management: Agencies are required to plan and separate cloud-related expenses, ensuring transparency and efficient budget allocation. Cloud migration: The guidelines outline the steps for migrating to the cloud and highlight the role of cloud service providers in facilitating the process, including supporting innovation and enabling smooth exit strategies. Procurement compliance: All cloud procurement must comply with public sector procurement laws and regulations. Only providers meeting government-mandated standards can be selected. Security and shared responsibility: The guidelines clarify the division of security responsibilities between cloud providers and government agencies. While providers manage infrastructure security, agencies remain responsible for data, application, and access controls. Legal framework: Agencies must comply with the Digital Government Administration Act, Cybersecurity
August 1, 2025
Thailand’s Personal Data Protection Committee (PDPC) announced to the press on August 1, 2025, that it had issued eight new administrative fines under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) in five cases of noncompliance by public and private entities. The enforcement actions reflect a growing commitment by the PDPC to penalize noncompliance across all sectors, regardless of organizational type or size. The total amount imposed to date was approximately THB 21.5 million (approx. USD 654,690), underscoring the financial risks tied to PDPA violations. The five cases—one involving a state agency and the remainder in the private sector—are summarized below. Case 1: State Agency Providing Online Services to the Public The order in this case stemmed from a cyberattack on a state agency’s web app, resulting in personal data of 200,000 data subjects being leaked to and sold on the dark web. The software developer was also found to have implemented no privacy by design, lacked an access control system, had no data breach prevention measures, and failed to conduct risk assessments or review existing security measures. Key noncompliance identified: Lack of appropriate security measures Weak password protection No risk assessment or ongoing review of security measures No data processing agreement with software developer that acted as data processor The state agency and the developer were each fined THB 153,120 (approx. USD 4,670). Case 2: Private Hospital This case involved a hospital that engaged an individual contractor to destroy patient medical record documents. However, the contractor stored the documents at their own premises, failed to follow the required destruction protocols, and ultimately used the medical records to wrap sweets, resulting in the leak of over 1,000 records during the destruction process. The contractor also failed to notify the hospital of the data breach. Although there was a