You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 24, 2019

Update on the Implementation of Vietnam’s New Cybersecurity Law and Status of Implementing Decrees

Vietnam’s new Cybersecurity Law was promulgated on June 12, 2018 and came into effect on January 1, 2019, with a majority of its provisions enforceable from the effective date. However, there are still certain provisions of the law which need to be further guided by implementing regulations and guidelines. There are currently draft guidelines under consideration, including:

  • A decree to implement in detail some provisions of the law, which includes guidance on the important and controversial article 26 on data localization (to guide articles 10.4, 12.5, 23.1, 24.7, 26.4 and 36.5, among others);
  • A decree to regulate in detail the procedures for application of cybersecurity protection measures (to guide article 5.2 of the law); and
  • A decision of the prime minister on promulgation of the list of national security information systems (to guide articles 10.3 and 43.3 of the law)

As of the time of writing this update, none of the three proposed regulations has been promulgated. The draft decree that most concerns industry insiders is the first, which regulates data localization. The draft is now in the Office of the Government for consideration and approval but there has been no official news as to when it will be issued. Although there was some indication earlier in 2019 that the Government was expected to pass the decree by the end of the year, an unofficial source said that it appears to have now been delayed to Q1 of next year, 2020. The latest accessible version of the draft decree is the version dated August 21, 2019.

The Ministry of Public Security’s (MPS’s) process of drafting this decree has demonstrated the ministry’s willingness to be open to industry and public consultation, because the issues surrounding the data localization requirement have generated significant concerns and numerous comments from international organizations and companies. According to reports, up to September 2019, the MPS sent 216 letters to relevant ministries and agencies, both at the central and local levels, as well as organizations and experts for comments. Based on these consultations, the MPS has made some changes. For example, it made changes to the specifications of different types of data that needs to be stored in Vietnam and added more services which will give rise to a data localization requirement. In addition, the MPS reduced the number of conditions that trigger data localization from four to just three (in particular, leaving out the ambiguous condition of letting service users continue to carry out prohibited acts). However, it is still uncertain whether the final version the government will pass will be much different from or improve this version.

It is worth re-emphasizing that the most problematic provision of the Cybersecurity Law is article 26.3, which relates to the requirements of data localization. The article states:

“Domestic and foreign enterprises providing services on telecommunication networks or the internet or value-added services in cyberspace in Vietnam with activities of collecting, exploiting, analyzing, and processing personal information data, data on the relationships of service users, or data generated by service users in Vietnam must store such data in Vietnam for the period prescribed by the government. Foreign enterprises mentioned in this clause must open branches or representative offices in Vietnam.”

The draft decree has narrowed down this broad language. Based on the draft decree, storing data and/or having branches or representative offices in Vietnam is required for foreign service providers only for the protection of national security, social order and safety, social ethics and health of the community, and when there are legal bases for a full determination on the three following factors:

  • Such enterprise provides regulated services:
  • Such enterprise carries out activities of collecting, exploiting [using], analyzing and processing the regulated types of data; and
  • Such enterprise has been warned that the services it provides are used to commit a breach of the laws of Vietnam and it does not take any measures for avoiding, dealing with, fighting against or preventing such breach, or resisted, obstructed, or ignored requests from the relevant authorities.

Regulated services include: telecom services; services of data storage and sharing in cyberspace; supply of national or international domains to service users in Vietnam; e- commerce; online payment; intermediary payment; service of transport connection via cyberspace; social networking and social media; online electronic games; and services of providing, managing or operating other information in cyberspace in the form of a message, phone call, video call, email or online chat.

Regulated types of data include:

  • Data on personal information of service users in Vietnam, including data with information in the form of symbols, writing, numbers, images, sounds or similar forms in order to accurately determine the identity of any one person;
  • Data generated by service users in Vietnam, including account names for use of services, duration of use of services, credit card information, email addresses, IP addresses for the latest login and logout, and registered telephone numbers attached to the account or data relevant to the data on personal information of service users; and
  • Data on the relationships of service users in Vietnam, including friends, and groups with which the users connect or interact.

Relevant authorities include the Department for Cybersecurity and Prevention of High-tech Crime under the Ministry of Public Security and/ or the Cyber Task Force, which comprises the Department for Cybersecurity and Prevention of High-tech Crime under the Ministry of Public Security and the Cyber Operations Command under the Ministry of National Defense.

If an enterprise were required to store data or have a branch or representative office in Vietnam, it would receive an MPS decision requiring it to store data and/or establish a branch or representative office in Vietnam. Within six months from the date of the MPS’s decision, the enterprise must complete the storing of data and/or establishing of a branch or representative office in Vietnam. Compared to the previous draft, this draft has significantly shortened this period from 12 months to six months, which is a disadvantage for enterprises. The period for storing data will start from the date on which the enterprise receives a request for storage of data until such request ends. The period for the storage of data will be at least 12 months. The period for having a branch or representative office in Vietnam will start from the date on which the enterprise receives a request until the enterprise no longer operates in Vietnam or provides regulated services in Vietnam.

How has the Cybersecurity Law affected foreign service providers since it came into effect nearly 12 months ago? Clearly, foreign service providers now face more risks if they do not take steps to restrict sensitive content or respond to takedown requests. According to reports, a senior official at the Ministry of Information and Communications recently commented that foreign companies’ compliance relating to content issues has greatly increased. For example, according to the official, cooperation with takedown requests in some areas related to content has increased from 20-30% to nearly 80-90%. In addition, the official added that it is also expected that the enforcement of the Cybersecurity Law will result in greater compliance among service providers when the authorities request them to provide service users’ identities if a violation of the law is detected.

RELATED INSIGHTS​ 

March 16, 2026
Thailand’s Securities and Exchange Commission (SEC) has broadened the definition of institutional investors, expanded the types of qualifying investments, and updated financial qualification thresholds for various investor categories through a revised notification on the definitions of institutional investors, ultra-high net worth investors, and high net worth investors. The amended framework, which came into force on March 1, 2026, adds digital asset business operators, investment planners, and investment consultants to the roster of entities recognized as institutional investors, and broadens the definition of investment to account for digital tokens. Expanded Definition of Institutional Investors Under the SEC’s revised notification, the category of institutional investors now expressly includes digital asset business operators licensed under the Royal Decree on Digital Asset Businesses B.E. 2561 (2018). This addition recognizes the growing role of digital asset platforms and service providers in Thailand’s investment ecosystem and aligns the regulatory treatment of digital markets with that of traditional markets. The definition of institutional investors now also encompasses investment planners and investment consultants approved by the SEC. Previously, only SEC-approved investment analysts held this status; the expansion covers a broader scope of professionals who possess comparable expertise and experience in evaluating investment opportunities. Broadened Investment Definition The revised framework now defines investment to mean direct or indirect investment in a wider range of assets beyond deposits. Specifically, the definition covers: Securities under the Securities and Exchange Act Derivatives under the Derivatives Act Investment tokens offered to the public Government-issued digital tokens (G-tokens) as specified in a separate SEC notification This expansion ensures that financial status assessments reflect the full spectrum of an investor’s holdings, including emerging digital assets. Updated Financial Qualification Thresholds The amended SEC notification also provides updated qualification thresholds for angel investors, ultra-high net worth investors, and high net worth investors. While the core criteria
March 13, 2026
Vietnam’s Law on Intellectual Property (IP Law) has undergone continuous amendment in recent years, with the latest amendment issued at the end of 2025. Among the amended and supplemented provisions, the regulation that has perhaps attracted the most attention is a provision relating to the use of protected IP objects by artificial intelligence (AI) systems. Specifically, Article 7 of the 2025 IP Law introduces a completely new Clause 5, which reads in full as follows: “Organizations and individuals are permitted to use texts and data relating to intellectual property objects that have been lawfully published, and which the public is allowed to access, for the purposes of scientific research, experimentation, and training of artificial intelligence systems, provided that such use will not unreasonably affect the legitimate rights and interests of the authors and intellectual property rights holders in accordance with this Law. With respect to texts and data that are objects protected by copyright and related rights, the use of the texts and data as set forth herein must also be in accordance with the regulations of the Government.” Analyzing this newly added provision in the context of how it was conceived, as well as the challenges that still lie ahead, can provide some interesting insights. From Aspirations to Flight in Science and Technology From the end of 2024 and throughout 2025—the 50th anniversary of the country’s reunification—Vietnam witnessed numerous sweeping changes in many areas, including legislative development. It could be said that no sessions of the National Assembly have ever adopted as many laws, resolutions, and major policies as this one. The aspirations of the highest-level leadership have been concretized into major law and policy projects, which were drafted, developed, and passed at record speed. All of this was aimed at building a foundation for Vietnam to achieve
March 12, 2026
Thailand’s AI legislative framework took another step forward when the Office of the Consumer Protection Board (OCPB) issued a notification establishing guidelines for AI-generated advertising that may cause material misunderstanding about products or services. The notification, which is already in effect, was issued under the Consumer Protection Act B.E. 2522 (1979) and its amendments, which prohibit advertising that is unfair to consumers or may cause harm to society, including false or exaggerated statements and statements that may cause material misunderstanding about products or services. The notification addresses emerging advertising practices, including the use of images edited using software or AI to attract consumer interest or build credibility. The OCPB noted that such advertising may result in consumers misunderstanding the essential characteristics, condition, or usage of products, which violates consumer rights and causes damage. Key Requirements on AI-Generated or Digitally Manipulated Advertising Content For advertisements using still images or videos created or edited with software programs or AI tools that may cause the depicted product or service to differ from the actual product sold or service provided—which may cause misunderstanding regarding the condition, quality, quantity, or other essential aspects of the products or services—advertisers and business operators must comply with the following requirements: Prior authorization. Obtain approval from relevant regulatory authorities where required by law. Accurate representation. Ensure that the advertised size, quantity, volume, number, or composition matches the actual product or service being sold, whether in still images or videos. Mandatory AI disclosure labels. Display clear disclosures when AI or software is used to create or edit images, such as: “Real image or simulation edited using AI” “Photo from actual location or simulation edited using AI” “Photo from actual product or edited simulation” “Image created by AI” “Video created by AI” Clarity of disclosure. Ensure disclosures are clearly visible,
March 10, 2026
Thailand’s Ministry of Finance and Securities and Exchange Commission (SEC) have issued regulations broadening the criteria for determining who qualifies as a “major shareholder” of licensed securities and digital asset business operators. Under relevant SEC regulations, major shareholders of a regulated entity must obtain regulatory approval and undergo screening by the SEC. The revised framework introduces both shareholding-based and control-based tests to determine which shareholders require regulatory approval for a wider range of indirect ownership structures and de facto control. The Ministry of Finance notification took effect on February 21, 2026, while the SEC’s clarifying rules took effect on March 4, 2026. These changes aim to enhance transparency around beneficial ownership and strengthen regulatory oversight of entities operating in Thailand’s capital markets. Expanded Definition Under the revised framework, a “major shareholder” now includes persons who directly or indirectly hold more than 10% of the voting rights in a regulated company, as well as persons who exercise control over the regulated company or its shares. This system of two separate tests, based on both shareholding and control, differs from the prior regime, which focused primarily on shareholding thresholds and applied a more limited method for determining indirect shareholdings. The two tests (detailed below) operate independently of each other, and any person identified by either of the tests will be deemed a major shareholder. Shareholding-Based Test Broadens Indirect Ownership Attribution For the shareholding-based test, the SEC recognizes two existing methods for identifying indirect ownership, together with a new proportional attribution method. Any person captured under these methods, which are described below, will be regarded as a major shareholder of the regulated company and must obtain SEC approval as a major shareholder. First, the existing framework continues to apply to both first-tier and chain ownership structures. Approval is required for (1) first-tier