You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 10, 2023

Vietnam Issues Guidance on Law on Cinema

The National Assembly of Vietnam promulgated a new Law on Cinema in June 2022 with an effective date of January 1, 2023. To guide the implementation of the new law and the sanctioning of administrative violations thereof, the government of Vietnam issued two related decrees in the final days of 2022.

Cinema Decree

On December 31, 2022, the government issued Decree No. 131/2022/ND-CP elaborating a number of articles of the Cinema Law (“Cinema Decree”), which took effect with the new law on January 1, 2023.

Among the many issues under the Cinema Law guided by the Cinema Decree, one that is critical to over-the-top (OTT) media service providers is the set of conditions for performing the mandatory self-rating of films to be disseminated in cyberspace. According to the Cinema Law, meeting the film self-rating conditions is one of the prerequisites for online dissemination of films. If a film disseminator does not meet these conditions, it would be required to request the Ministry of Culture, Sports and Tourism (MOCST) to perform the rating.

The conditions for online disseminators to self-rate their films have now been set out under Article 12 of the Cinema Decree. Accordingly, these conditions include:

  • Having a film rating council or technical software or a mechanism to rate the films according to Vietnamese regulations on film rating and taking responsibility for the results of film rating.
  • Having a plan to amend and update film rating results at the request of the cinematography authority (for most providers, this is the Cinematography Department under the MOCST).
  • Having an administrative tool to support the rating of films according to each of the rating criteria and to flexibly display the updated rating immediately after the rating is changed.
  • Having a technical plan and process for suspending and removing films at the request of the cinematography authority. Upon a request for removal of the film, the disseminator must proceed to implement the removal functionality available on the administrative tool.

These officially enacted conditions are much more relaxed compared to those proposed in the first draft of the Cinema Decree (released for public consultation in October 2022), which required that a foreign film disseminator (e.g., an OTT service provider), among other conditions, must establish a local enterprise in Vietnam or enter into a business cooperation agreement with a local company to be eligible to perform the self-rating of films. This proposed requirement under the draft Cinema Decree was subject to heated discussions among relevant stakeholders at the time. The government seems to have taken industry opinions into consideration and decided to change the burdensome conditions.

The Cinema Decree also provides the formality requirements for an online film disseminator to request recognition from the MOCST that they meet the self-rating conditions, as well as the procedures for the MOCST to receive and handle the dossier (in Article 12.2 and 12.3).

In addition, the Cinema Decree gives details on the following critical obligations of online film disseminators:

  • To notify the MOCST of the list of films to be disseminated and the self-rating results of the films before disseminating films in cyberspace (Article 13).
  • To implement necessary technical measures for parental control, for display of warnings on inappropriate and age-restricted content, and for receiving and handling platform users’ complaints and reports on violations in relation to content, technical measures, or other violations of law (Article 14).
  • To provide contact points and contact information for receiving and handling requests from the cinematography authority (Article 15.1).
  • To stop disseminating and to remove violating films within 24 hours and other illegal content within 3 to 5 days upon the cinematography authority’s request (Article 15.2).

Cinema Sanction Decree

On December 30, 2022, the government issued Decree No. 128/2022/ND-CP amending Decree 38/2021/ND-CP on penalties for administrative violations in the field of culture and advertising (as previously amended by Decree 129/2021/ND-CP), focusing on the addition of sanctions for new violations in the field of cinematography (“Cinema Sanction Decree”). The Cinema Sanction Decree takes effect on February 15, 2023.

Some of the notable sanctions stipulated by the Cinema Sanction Decree include:

  • A monetary fine of VND 40–60 million (approx. USD 1,700–2,555) and forcible removal of the disseminated film for the act of online film dissemination without rating the film and displaying the rating results (Article 7.2b).
  • A monetary fine of VND 20–40 million (approx. USD 850–1,700) and forcible removal of disseminated films for the failure to notify the MOCST of the list of films to be disseminated and the results of film rating (Article 10.7a).
  • A monetary fine of VND 40–60 million (approx. USD 1,700–2,555) and forcible removal of disseminated films for the failure to provide contact points and contact information for receiving and handling requests from state authorities and feedback, complaints, and denunciations from service users according to the law (Article 10.7b).
  • A monetary fine of VND 60–80 million (approx. USD 2,555–3,400) and forcible removal of disseminated films for the failure to implement technical solutions and coordinate with competent state authorities in removing and preventing infringing films as prescribed by law (Article 10.7c).
  • A monetary fine of VND 80–100 million (approx. USD 3,400–4,260) and forcible removal of disseminated films for the failure to ensure the conditions for self-rating of films (Article 10.7d).
  • A monetary fine of VND 80–100 million (approx. USD 3,400–4,260) and forcible removal of disseminated films for the failure to implement necessary technical measures for parental control and for receiving and handling platform users’ complaints and reports (Article 10.7dd).

RELATED INSIGHTS​ 

September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 22, 2025
On September 15, 2025, Vietnam’s Ministry of Science and Technology announced that the country will issue an updated version of its National AI Strategy (first issued in 2021) and its first-ever AI Law by the end of this year. The ministry emphasized that the AI strategy is not just a legal framework, but a commitment to embracing AI to drive Vietnam into a new era. The AI adoption plan is set as a priority of the country, and marks a significant step in shaping Vietnam’s AI governance and innovation landscape. Highlights of the plan include the following: Strategic vision. Vietnam’s ambition is to leverage AI for economic growth, social development, and global competitiveness, under the guiding principle “AI for humans – safe, autonomous, cooperative, inclusive, and sustainable.” AI as national infrastructure. The updated strategy positions AI as core national infrastructure, comparable to electricity or the internet, aiming to provide every citizen with a “personal digital assistant.” Core principles for AI legislation. The AI Law will be built around the following six core principles: Risk-based regulation Transparency and accountability Human-centric development Domestic AI autonomy AI as a driver of sustainable growth Digital sovereignty, with data, infrastructure, and AI technology being three strategic pillars Ethics and openness. A National AI Ethics Code will accompany the upcoming law, aligned with international standards but tailored to the Vietnamese context. The government emphasizes open standards and open-source development. Market development and incentives. The government plans to expand domestic AI adoption, particularly in public services and key industries. The National Technology Innovation Fund (NATIF) will allocate at least 40% of its budget to AI projects, prioritizing SMEs through vouchers for locally developed AI solutions. Background on AI Law Development Regulations on AI are found in various Vietnamese laws and regulations, notably the recently adopted Law
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.
September 11, 2025
Thailand’s Securities and Exchange Commission (SEC) has amended its digital asset regulations to permit the offering, trading, and provision of services related to tokenized environmental commodities by licensed digital asset exchanges, brokers, and dealers. This regulatory development is aimed at facilitating Thailand’s green economy and net-zero goals while diversifying the products available in the regulated digital assets market. The environmental commodities currently being traded on certain market platforms and via over-the-counter channels include: Carbon credits: Tradable certificates representing a reduction of CO₂ emitted into the atmosphere. Renewable energy certificates (RECs): Tradable proof of electricity generated from renewable energy sources. Carbon allowances: Tradable permits to emit a capped amount of greenhouse gases. The tokenization of these instruments is essentially the process of converting them into digital tokens, making it possible to list them on blockchain exchanges for trading purposes. Background Tokenized carbon credits, RECs, and carbon allowances fall under the category of utility tokens for consumption purposes or tokens representing entitlement certificates—that is, group 1 utility tokens, which are not considered financial products. The offering, trading, and provision of secondary-market services of this type of token are exempted from licensing requirements for regulated digital asset businesses under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). Under the previous regulatory framework, licensed digital asset business operators were not allowed to provide services involving such unregulated tokens, as it was deemed to be engaging in “other businesses,” which digital asset operators generally cannot engage in without prior SEC approval. Regulatory Amendment Under the amended digital asset regulations, licensed digital asset exchanges, brokers, and dealers may now apply for SEC approval to offer services related to these tokenized assets as “other businesses,” including listing them for trading on digital asset exchanges. Apart from requiring operators to comply with the general conditions