You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 12, 2023

Vietnam 2022 ICT Legislation Year in Review

The year 2022 witnessed a dynamic environment in the development of information and communications technology (ICT) policy in Vietnam. The following are some highlights of remarkable legislative developments in the ICT space from the past year, and some notes on key draft laws and regulations that are in the pipeline for 2023.

1. Telecommunications

Although it has helped Vietnam develop modern telecommunications network infrastructure and a diversified and competitive telecom market with a variety of services, Vietnam’s Telecom Law, which has been in effect since 2010, has posed problems and inadequacies in meeting today’s more complex evolution of new service types and new business models as well as the trend of convergence of telecom, information technology, and automation.

Accordingly, the Ministry of Information and Communications (MIC) has been working to replace the existing Telecom Law, with a Draft Telecom Law made available for public consultation from October 27 to December 27, 2022 (the Vietnamese version can be accessed here).

The primary amendment of the Telecom Law focuses on widening the scope of application to regulate data center and cloud computing services. Data center services include data center space rental services, server rental services, and data storage space rental services. Cloud computing services include services providing server resources, storage capacity, and networks (IaaS services); services that provide the ability to create, develop, manage, and operate software, including applications (PaaS services); and software delivery services, including applications (SaaS services).

According to the Draft Telecom Law, it could be interpreted that all providers of data center services and IaaS cloud computing services, whether onshore or offshore, must obtain a permit to provide the services by registration with the MIC via its online portal; while PaaS and SaaS cloud computing services are exempted from this requirement.

In addition, the Draft Telecom Law adds new content related to the management of OTT telecom services, or “information communication service without using telecom number storage” according to the language of the Draft Telecom Law (for example, WhatsApp, Zalo, Viber, Line, etc.). These services have not been regulated before and for a long time the MIC has attempted to regulate these services via a draft Circular on OTT telecom services, without success. This content is now put into the Draft Telecom Law but with much lighter requirements compared to the previous draft Circular. The Draft Telecom Law allows cross-border provision of OTT telecom services to Vietnam with regulations on service providers’ responsibilities in service provision as well as requirements for notification to the MIC. The content for notification includes representative name and contact information (phone, email). Forms and procedures for notification must comply with the government’s regulations.

Another new area contemplated in the Draft Telecom Law which is worthy of mention is telecom wholesale and retail services. The Draft Telecom Law supplements obligations of telecom companies with a dominant position in the market for important retail services that require state management of competition, as well as obligations of telecom enterprises providing telecom wholesale services with the aim of creating favorable conditions for enterprises to negotiate and buy telecom traffic, and to promote the wholesale market and contribute to promoting competition in the retail market through the wholesale market.

The Draft Telecom Law is scheduled to be discussed by the National Assembly in May 2023 and submitted for approval in October 2023.

2. Cybersecurity

The long-awaited Decree 53 on the implementation of the Cybersecurity Law (which took effect in 2019) was issued on August 15, 2022, with an effective date of October 1, 2022. Decree 53 provides further guidance on a number of key issues, including:

  • Data localization requirements which may create potential troubles for not only overseas enterprises but also domestic enterprises;
  • Takedown of illegal online content with corresponding responsibilities of the Ministry of Public Security (MPS), the Ministry of Defense, and the MIC;
  • Collection of electronic data relating to illegal activities in cyberspace to serve the purposes of investigation and handling of such activities according to stipulated conditions and procedures;
  • Suspension or stoppage of information system operation, and/or revocation of domain names when the operation of the information system violates the laws on national security and cybersecurity, or when the information system is being used for the purpose of infringing upon national security or social order and safety; and
  • Responsibilities of relevant stakeholders in coordinating and assisting the authorities in preventing and handling the violations, including cross-border violations.

Regarding the controversial issue of data localization requirements, it is worth noting that domestic enterprises may be impacted more than overseas enterprises.

For overseas enterprises, only those fulfilling all the following conditions are subject to the MPS’s decision to store regulated data and establish a branch or representative office in Vietnam within a grace period of 12 months:

  1. Providing services falling within 10 enumerated types of regulated services;
  2. Collecting, exploiting, analyzing, and/or processing regulated data; and
  3. Have received a warning from the Department for Cybersecurity and Prevention of High-Tech Crime (A05) under the MPS but have not taken any measures for avoiding, dealing with, fighting against, or preventing the breach mentioned in the notification, or have resisted, obstructed, or ignored requests from the relevant authorities.

For domestic enterprises, the requirements are more stringent. Without further clarification of the MPS, nearly all online domestic service providers which collect, use, analyze, and/or process regulated data are required to store the regulated data in Vietnam without triggering conditions and without a grace period. For more information of the Decree 53, please refer to our previous articles here and here.

3. Data Privacy

The government recently released Resolution 156/NQ-CP on December 6, 2022, which requires the MPS to quickly finalize the draft Decree on Personal Data Protection (draft PDPD) and submit it to the government for submission to the National Assembly Standing Committee for comments before the government promulgates it. Therefore, it is expected that the PDPD could be issued in 2023. Within 2022, there was no official updated version of the draft PDPD available for public assessment of the major changes from the previous publicly accessible version. For more information of the main content of the draft PDPD, please see our previous articles here, here, and here.

4. OTT TV Services & VOD Films

Decree 71 was issued on October 1, 2022, with an effective date of January 1, 2023, to amend the prior Decree 06 on the Management, Provision, and Use of Radio and Television Services. The new decree will have a major impact on over-the-top (OTT) television services and on-demand content (VOD) in Vietnam. Although there are still ambiguities in the wording of Decree 71, the government has expressed a clear intention to regulate the cross-border provision of foreign OTT TV services, including provision via Internet applications. Accordingly, overseas companies might no longer be eligible to provide OTT pay TV services to users in Vietnam on a cross-border basis as they are currently doing with regard to OTT VOD, but may now have to establish a company in Vietnam or cooperate with a licensed Vietnamese pay TV service provider to provide such services.

The MIC has recently taken their first moves to enforce the new requirements under Decree 71. The Authority of Broadcasting and Electronic Information (ABEI) under the MIC has announced the enforcement actions via two official letters on their website, whose main points are summarized as follows:

  • On January 5, 2023, the MIC sent an official letter to a number of foreign OTT service enterprises, requesting a report by January 15, 2023, on the plan to carry out the procedures for applying for a license to provide pay radio and television services The official letter clearly states that if the enterprises continue to maintain the current service provision and do not comply with the provisions of Decree 71 (i.e., do not establish an enterprise in Vietnam to apply for the pay TV license or do not comply with other obligations of local service providers), they will be administratively sanctioned according to the provisions of Decree No. 119/2020/ND-CP dated October 7, 2020.
  • Via official letter No. 6272/BTTTT-PTTH&TTDT dated December 31, 2022, the ABEI has also requested businesses importing, manufacturing, and distributing smart TVs in Vietnam to review the legality of pre-installing unlicensed OTT apps in smart TVs and/or including shortcut buttons on remote controls of smart TVs allowing users to easily access to unlicensed OTT apps, to ensure that they do not violate the provisions of Decree 71.

Interestingly, Decree 71 does not differentiate between provision of film-only VOD from the provision of other types of VOD, which leads to a potential inconsistency between the state management of film-only versus other types of VOD, i.e., more specifically, there may be a potential inconsistency between Decree 71 and the Cinema Law and its guiding decree, Decree No. 131/2022/ND-CP promulgated by the government on December 31, 2022 (“Cinema Decree”). We discuss the new Cinema Decree in more detail in this article.

According to Decree 71, films are specified as a type of “on-demand radio and television content,” and the provision of “on-demand radio and television content” via the internet/internet applications falls within the definition of “TV services,” which are subject to the same requirements imposed on other types of TV services, including local establishment and licensing requirements.

Under the Cinema Law and the Cinema Decree, however, there is no such requirement for foreign providers of VOD films. According to the Cinema Decree, offshore enterprises are allowed to disseminate their films in Vietnam’s cyberspace without having to establish a company in Vietnam and to obtain a license. The film disseminators must only comply with the obligation to self-rate their films according to the government’s guidance.

Given the foregoing potential inconsistency in application of Decree 71 and the Cinema Law, it is strongly recommended that the government should clearly exempt the provision of films on demand in cyberspace from the governing scope of Decree 71 and clarify that such provision is subject to the requirements under the Cinema Law and the management of Ministry of Culture, Sports and Tourism. For further information on Decree 71, please refer to our previous article here.

5. E-Commerce

The government has entrusted the MIC to draft a new Law on E-Transactions, because after 17-years, the existing law has shown shortcomings in the new era of rapid technology and e-commerce development. The Minister of the MIC emphasized that the Law on E-Transactions should be amended to reflect and fully govern current industry technologies, including those relating to the digital environment’s traditional transactions, but with varying degrees of reliability, different costs, and different complexity. The revised law must ensure a wide scope of application and lower costs and less complexity of e-transactions compared to traditional transactions.

Accordingly, the Draft Law on E-Transactions (version 4 of which is publicly accessible) widens the scope of application to attempt to cover all areas of transactions. It retains key principles of the current law, but also provides more comprehensive regulations relating to e-contracts, e-signatures/digital signatures, and data messages. Furthermore, it provides new regulations on e-certificates, trust services and information systems serving e-transactions (digital platforms). For more information, please refer to our previous article here.

The Draft Law on E-Transactions was reviewed for the first reading by the National Assembly in November 2022; however, later draft versions are not available for public access. This draft law is scheduled for approval on the second reading by the National Assembly in May 2023.

RELATED INSIGHTS​ 

July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 21, 2026
Thailand’s Ministry of Digital Economy and Society (MDES) published a notification establishing an expedited court-ordered takedown mechanism for online content in cases of “urgent necessity.” The notification, which was issued on July 17, 2026, under the Computer Crime Act B.E. 2550 (2007), as amended, took effect the following day. It significantly expands the categories of content subject to rapid government-initiated removal. Content Categories Subject to Takedown The notification defines “urgent necessity” (section 20, paragraph 5, of the Computer Crime Act) as circumstances where any delay in suppressing computer data may impact national security, religion, the monarchy, good morals, social culture, or public order. In this regard, it establishes four broad categories of content: Computer Crime Act offenses. National security offenses. IP and other criminal offenses, where it is contrary to public order or good morals and a competent officer has requested its suppression. Content contrary to public order or good morals, a broad residual category encompassing 14 subcategories approved by the Computer Data Screening Committee. The fourth category is the most expansive. Its 14 subcategories include: Content defaming, mocking, satirizing, or devaluing the monarchy. Online gambling advertising or facilitation. Offering illegal firearms for sale. Offering baraku (hookah) products or e-cigarettes for sale. Offering cannabis inflorescences or processed cannabis products for sale. Advertising or soliciting prostitution. Content inciting violence, hatred, or social division. Unauthorized overseas employment advertising. Offering boiled kratom juice for sale. Online sale or advertising of alcoholic beverages. Content satirizing or degrading Buddhism. Money lending at interest rates exceeding legally prescribed limits. Advertising or disseminating information about surrogacy services. Forgery of documents, cards, or official documents. Enforcement Procedure In cases of urgent necessity, a competent official assigned by the MDES permanent secretary must file a petition with supporting evidence to the court with jurisdiction, requesting an order to
July 20, 2026
On July 16, 2026, Thailand’s Personal Data Protection Committee (PDPC) published a notification in the Government Gazette establishing detailed rules governing data subjects’ right of access under section 30 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notification will take effect 60 days after publication—mid-September 2026—giving data controllers a limited window to bring their processes into compliance. Scope The notification covers requests to access or obtain copies of personal data and requests for disclosure of the source of data collected without consent. Data subjects may exercise their rights directly or through authorized representatives. Key Requirements Important requirements set by the notification include the following: Required request channels. Controllers must provide at least two request channels: direct submission at the business location and registered mail. Electronic channels are optional but, if offered, may also be used for fulfilling requests. Request contents. Requests must be in writing or in electronic form and include the data subject’s name, the preferred access method, details of the data requested, and the requester’s signature. Controllers may request additional identifying information as needed. Identity and authority verification. Controllers may require official identity documents for verification. Authorized representatives must provide authorization documents and identity documents for both the data subject and the representative. Alternative verification methods (e.g., digital authentication) are permitted if they do not unreasonably obstruct data subjects’ rights. Review and response timelines. Controllers must review requests within 15 days. If the request is incomplete, the controller must notify the requester and allow at least 15 days to correct deficiencies. If not corrected, the request may be treated as abandoned. Once verified, controllers must fulfill requests within 30 days, extendable by another 30 days for large-volume or complex requests with notice to the requester. Methods for providing access or copies. Controllers may fulfill
July 16, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) published a series of draft guidance documents for public consultation on July 7, 2026. Issued under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), the drafts address a range of compliance issues and offer insight into the regulator’s current enforcement priorities. This article examines two of those drafts: one on lawful bases for processing personal data, and another on marketing and direct marketing. Together, they reflect the Office of the PDPC’s evolving expectations on lawful-basis selection, accountability, and the use of personal data in marketing. Organizations operating in Thailand should assess the practical implications now, before the guidance is finalized. Lawful Bases: A Structured Selection Process The draft guidance on lawful bases introduces a systematic five-step process for selecting an appropriate lawful basis for each processing activity. Organizations are expected to: Identify the processing activity involved. Assess the appropriate lawful basis. Evaluate whether the data is necessary for the processing. Conduct a legitimate interest assessment (LIA) where applicable. Ensure transparency through privacy notices. The guidance provides practical explanations and examples for each lawful basis under section 24 of the PDPA—including archiving, research, statistics, vital interests, contractual necessity, legal obligation, public task, legitimate interests, and consent—as well as the bases applicable to sensitive personal data under section 26. The aim is to promote more consistent and accurate lawful-basis selection across public- and private-sector organizations. A recurring theme throughout the guidance is that organizations should select the lawful basis that most accurately reflects the actual purpose and circumstances of the processing activity. The guidance cautions against treating consent as a default or catch-all basis where another lawful basis is more appropriate. For processing based on legitimate interests, organizations should conduct and document an LIA. Processing involving sensitive personal data may require