You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 28, 2025

Unpacking Vietnam’s Decree 163: Key Implications for Telecom Service Providers

Vietnam’s Decree No. 163/2024/ND-CP (Decree 163), which has been in full effect since January 1, 2025, provides crucial guidance on the implementation of Vietnam’s 2023 Telecom Law. Decree 163 replaced Decree No. 25/2011/ND-CP dated April 6, 2011 (Decree 25), which guided the implementation of the previous 2009 Telecom Law, and introduces many notable changes to the regulations on telecom service provision. Some key changes that will impact businesses engaged in the telecom sector in Vietnam are detailed below.

1. Classification of Telecom Services

The classification of telecom services into “basic telecom services” and “value-added telecom services” has been retained, in alignment with Vietnam’s WTO commitments in the telecom sector. However, Decree 163 expands the scope of both categories, as follows:

  • Basic telecom services: “Transmission services for machine-to-machine (M2M) communication” and “leasing services of all or part of the telecom network” are added. “Image transmission services” is changed to “transmission services for radio and television.”
  • Value-added telecom services: “Data center services,” “cloud computing services,” and “basic telecom services over the internet” (also known as over-the-top (OTT) telecom services) are added.

2. M2M Communication Services

Since M2M communication services are classified as basic telecom services, without exception, they are subject to the same regulatory framework. Specifically:

  • Cross-border provision: M2M communication services provided across borders must be conducted through a commercial agreement with a Vietnamese telecom enterprise licensed to provide telecom services with an international communication scope.
  • Onshore provision: Onshore M2M communication services will require a telecom license.

3. New Telecom Services (Data Center, Cloud, and OTT Telecom Services)

The 2023 Telecom Law adopted a light-touch management approach for data center, cloud, and OTT telecom services by not requiring the same licensing as previously regulated value-added telecom services, but instead mandating registration or notification before service provision. Decree 163 offers clearer guidance on this approach, specifically:

  • Cloud and OTT telecom services: Both onshore and offshore providers are required to notify the Vietnam Telecommunications Authority (VNTA) under the Ministry of Information and Communications (MIC).
  • Data center services: Offshore providers of data center services only need to notify the VNTA while onshore providers must register with the VNTA.

The required dossiers for notification and registration must be prepared in Vietnamese, following prescribed forms, and can be submitted in person, via postal service, or through the national public service portal. For onshore enterprises providing both data center and cloud computing services, only a registration form needs to be submitted, with cloud service details included in the same form.

Decree 163 specifies a relatively short timeline of three working days for processing these dossiers.

Key Obligations for Service Providers

Enterprises providing these three new services, which can include 100% foreign-owned enterprises in Vietnam, must fulfill certain obligations in addition to registration or notification requirements. These key obligations include storing and managing user information, user verification, and various specific obligations of onshore and offshore providers.

Offshore data center and cloud computing service providers also have certain additional obligations, such as promptly taking necessary measures to block access to information as requested by competent authorities.

Further, Decree 163 imposes certain obligations when data center and/or cloud services are provided to state agencies to serve state activities, such as storing data of the state agencies using these services within Vietnam.

4. Satellite Telecom Services

Onshore service provision: Decree 163 retains the conditions for the establishment of public fixed satellite and mobile satellite telecom networks regarding the charter capital and telecom network deployment from the previous Decree 25, including the commitment to invest at least VND 100 billion in the telecom network within the first three years.

Cross-border service provision: For providing cross-border telecom services via fixed satellite networks or mobile satellite networks, among other conditions, offshore providers must enter into a commercial agreement with a Vietnamese telecom enterprise licensed to provide telecom services with an international communication scope.

5. Telecom Market Management

Decree 163 introduces criteria for identifying telecom service markets under state management, and establishes criteria for identifying telecom enterprises and groups of enterprises with dominant market positions in state-managed service markets, using quantifiable principles suitable for telecom business activities. The decree tends to impose certain obligations on the identified telecom enterprises and groups of enterprises to ensure fair competition in the market.

6. Telecom Infrastructure Management

The development of telecom infrastructure in Vietnam is one of the key focuses of Decree 163, which covers the following main aspects of telecom infrastructure management, among others:

  • Protecting telecom infrastructure: Telecom enterprises are responsible for ensuring the safety of telecom infrastructure, including preventing attacks and incidents, maintaining stability with backups, preventing prohibited activities, ensuring safety for equipment and staff, and adhering to relevant standards and technical regulations.
  • Ensuring network information security: Telecom enterprises must ensure network information security in their operations by, among other measures, protecting information systems and handling incidents at the request of the MIC.
  • Sharing of passive telecom infrastructure: Decree 163 stipulates the authority to resolve the sharing of passive telecom infrastructure in cases where telecom enterprises cannot reach an agreement (except for price issues). The resolution of disputes will be handled by either the local Department of Information and Communications or the MIC, depending on the location of the passive telecom technical infrastructure in question. If the parties cannot reach an agreement on the price for sharing passive telecommunications infrastructure, negotiations must be carried out in accordance with the provisions of the pricing laws.
  • Sharing of active telecom infrastructure: The sharing of active telecommunications infrastructure among telecom enterprises is based on the principle of encouraging sharing to save costs for telecom network deployment, while ensuring compliance with competition law and radio frequency law.

7. Management of Mobile Subscriber Information

Decree 163 dedicates a section to the management of mobile subscriber information, offering comprehensive regulations on the subject. These include methods for registering mobile subscriber information, required documents for registration, verification of subscriber details, the scope of subscriber information, service provision after registration, registration for prepaid subscribers, storage and usage of subscriber data, subscriber responsibilities, and telecom enterprises’ obligations in addressing subscribers with incorrect information.

Business Recommendations

The 2023 Telecom Law, as detailed by Decree 163, demonstrates the government’s clear intent to catch up to and regulate recent advancements, innovations, and emerging business models in the technology and telecom sectors. The following are some recommendations for businesses:

  • Adopt proactive compliance strategies: Ensure familiarity with classifications and specific regulatory obligations for telecom services. Especially, businesses operating in the areas of M2M communication, cloud computing, data center services, and OTT telecom services should update internal compliance systems to address new requirements in these areas to avoid potential non-compliance risks.
  • Leverage emerging opportunities: With the government’s goal of opening markets and attracting foreign investment through incentives that support digital transformation, businesses should consider expanding and investing in areas like cloud computing, OTT services, and data centers to capitalize on emerging opportunities.
  • Adapt to digital transformation trends: Pay close attention to the new regulations aimed at facilitating digital transformation. For instance, consider investing in the development or optimization of mobile applications for subscriber registration and verification to align with the digital transformation push.
  • Strengthen data security and privacy practices: With increased regulatory focus on telecom infrastructure security and network information security, businesses should prioritize robust cybersecurity and network information security measures.

By navigating Decree 163 proactively, telecom enterprises can position themselves for sustainable growth while contributing to Vietnam’s digital economy ambitions.

RELATED INSIGHTS​ 

July 24, 2025
Vietnam’s Ministry of Public Security recently released a draft version of the 2025 Cybersecurity Law, which is intended to replace both the existing 2018 Cybersecurity Law and the 2015 Law on Network Information Security (LNIS). This consolidation reflects a broader effort by the Vietnamese government to streamline and centralize the legal framework governing cybersecurity, data protection, and information security to be under the sole authority of the Ministry of Public Security, moving away from the previous sharing of responsibility with the former Ministry of Information and Communications (which ceased operations earlier this year and merged with the Ministry of Science and Technology). This shift aims to eliminate overlaps and improve enforcement efficiency. The draft law is built upon the foundation of principles and provisions of both the 2018 Cybersecurity Law and the 2015 LNIS, while also introducing a wide range of amendments and new regulations. By merging the two laws, the government seeks to reduce legal fragmentation and ensure consistency in definitions, obligations, and enforcement mechanisms across related domains like data protection, IT system classification, and cybercrime prevention. The newly introduced amendments include enhanced obligations for service providers, stricter controls on information transmission, classification of IT systems, designation and protection of nationally important information systems, and sector-specific violations and compliance requirements. Highlights of the draft law are discussed below. Definition and Obligations of Service Providers The draft law clearly defines and significantly broadens the scope of entities considered “service providers” under its jurisdiction. This now includes businesses and individuals offering products or services in cyberspace, including both infrastructure and content online services, such as: Internet service providers (ISPs) and providers of telecommunications, hosting, servers, domain names, VPNs, proxy services, and cloud computing; Providers of social networks, websites, and online gaming; Financial institutions, banks, foreign bank branches in Vietnam, e-wallet
July 23, 2025
On July 4, 2025, Thailand’s Electronic Transactions Development Agency (ETDA) issued two significant notifications that introduce new compliance requirements for ride-hailing platforms operating in the country. The notifications formally designate these platforms as high-impact digital services under section 18(3) of the Royal Decree on Digital Platform Service Businesses and impose a comprehensive set of additional operational obligations. These measures are designed to address regulatory gaps and enhance oversight of digital platforms providing public passenger vehicle or motorcycle ride-hailing services. First, the Notification on the Designation of Ride-Hailing Platforms under section 18(3) formally designates all ride-hailing platforms that have notified the ETDA of their operations as high-impact digital platform services under section 18(3) of the royal decree. Unlike high-risk marketplace platforms, which are named individually, any ride-hailing platform that has notified the ETDA of its operations is automatically subject to these new requirements. Next, the Notification on Additional Obligations for Ride-Hailing Platforms imposes further obligations on ride-hailing platforms, supplementing the general requirements under section 21 of the royal decree. These notifications will come into force 90 days from their publication in the Government Gazette. New Compliance Obligations The new regulatory framework introduces a range of operational, technical, and reporting requirements for ride-hailing platforms, particularly concerning the issues described below. Vehicle and Driver Compliance Operators must: Ensure that all vehicles used on the platform are registered as public vehicles in accordance with Department of Land Transport requirements Verify all drivers hold valid public driving licenses Collect service fees in compliance with applicable fare regulations under the Vehicle Law Digital Platform Features and User Verification Operators must implement robust digital platform features for both drivers and riders, including: Comprehensive identity verification and confirmation processes for drivers and riders, utilizing both face-to-face and non-face-to-face methods, including biometric and digital ID checks Real-time GPS
July 17, 2025
On July 9, 2025, Thailand issued a notification that introduces comprehensive operational requirements for digital platform service providers operating as goods marketplaces, effective December 31, 2025 (i.e., 180 days after its publication in the Government Gazette). The regulation’s official name is Notification of the Electronic Transactions Committee Re: Other Actions for Digital Platform Service Operators in the Category of Marketplace for Goods with Specific Characteristics under Section 18(2) of the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification B.E. 2565 (2022), B.E. 2568 (2025). Scope of Application The notification applies exclusively to goods marketplace operators formally designated by the Electronic Transactions Development Agency (ETDA), which on the same day designated 19 platforms that had previously notified the ETDA of their operations. The goods requiring enhanced oversight by these operators are limited to those regulated by the Thai Food and Drug Administration (FDA) and the Thai Industrial Standards Institute (TISI). Development from Earlier Draft An earlier draft of the notification had included a requirement for offshore platforms to establish a local entity, but this requirement was removed from the final notification. Key Obligations Despite the removal of the local entity requirement, the notification imposes a range of additional obligations on designated goods marketplace operators: Transparency. Operators must implement robust transparency measures, including clear, accessible, and understandable disclosures to users in Thai. These disclosures must cover all relevant terms and conditions, comprehensive product information, and complaint management procedures. Operators must also submit an annual compliance report to the ETDA within 60 days after the end of their accounting period, including statistics on regulated goods. Business user registration and identity verification. Before permitting the sale or advertisement of regulated goods, operators must collect and verify business user information, including contact details, identification documents, registration
July 15, 2025
Thailand has established new safe harbor rules that require social media platforms to remove specified content within 24 hours of government notification. On July 5, 2025, the Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers was issued and took effect. This followed a hearing in May 2025 where only a select group of social media and online communication platform operators were invited to attend and comment on draft rules that could exempt social media platform operators from joint liability under the amended Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes in cases involving victims of technological crimes. Safe Harbor Rules The notification stipulates procedures that must be followed in order to receive the protection of the safe harbor rules. Upon being notified by the Division of Prevention and Suppression of Cybercrime, Office of the Permanent Secretary of the Ministry of Digital Economy and Society (MDES) of the presence of false or misleading information that may lead to the commission of a technological crime, social media service providers must immediately take down the specified content, with a maximum allowable turnaround time of 24 hours from the time of receiving the notification. Social media service providers are required to promptly report the outcome of each takedown to the MDES Division of Prevention and Suppression. This shift in Thailand’s regulatory approach to social media content moderation establishes clear government oversight mechanisms while providing platforms with liability protection for compliance. As the new rules took immediate effect, social media platforms need to ensure that they have adequate systems and processes in place to comply with the requirements.