You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 10, 2023

Vietnam Issues Guidance on Law on Cinema

The National Assembly of Vietnam promulgated a new Law on Cinema in June 2022 with an effective date of January 1, 2023. To guide the implementation of the new law and the sanctioning of administrative violations thereof, the government of Vietnam issued two related decrees in the final days of 2022.

Cinema Decree

On December 31, 2022, the government issued Decree No. 131/2022/ND-CP elaborating a number of articles of the Cinema Law (“Cinema Decree”), which took effect with the new law on January 1, 2023.

Among the many issues under the Cinema Law guided by the Cinema Decree, one that is critical to over-the-top (OTT) media service providers is the set of conditions for performing the mandatory self-rating of films to be disseminated in cyberspace. According to the Cinema Law, meeting the film self-rating conditions is one of the prerequisites for online dissemination of films. If a film disseminator does not meet these conditions, it would be required to request the Ministry of Culture, Sports and Tourism (MOCST) to perform the rating.

The conditions for online disseminators to self-rate their films have now been set out under Article 12 of the Cinema Decree. Accordingly, these conditions include:

  • Having a film rating council or technical software or a mechanism to rate the films according to Vietnamese regulations on film rating and taking responsibility for the results of film rating.
  • Having a plan to amend and update film rating results at the request of the cinematography authority (for most providers, this is the Cinematography Department under the MOCST).
  • Having an administrative tool to support the rating of films according to each of the rating criteria and to flexibly display the updated rating immediately after the rating is changed.
  • Having a technical plan and process for suspending and removing films at the request of the cinematography authority. Upon a request for removal of the film, the disseminator must proceed to implement the removal functionality available on the administrative tool.

These officially enacted conditions are much more relaxed compared to those proposed in the first draft of the Cinema Decree (released for public consultation in October 2022), which required that a foreign film disseminator (e.g., an OTT service provider), among other conditions, must establish a local enterprise in Vietnam or enter into a business cooperation agreement with a local company to be eligible to perform the self-rating of films. This proposed requirement under the draft Cinema Decree was subject to heated discussions among relevant stakeholders at the time. The government seems to have taken industry opinions into consideration and decided to change the burdensome conditions.

The Cinema Decree also provides the formality requirements for an online film disseminator to request recognition from the MOCST that they meet the self-rating conditions, as well as the procedures for the MOCST to receive and handle the dossier (in Article 12.2 and 12.3).

In addition, the Cinema Decree gives details on the following critical obligations of online film disseminators:

  • To notify the MOCST of the list of films to be disseminated and the self-rating results of the films before disseminating films in cyberspace (Article 13).
  • To implement necessary technical measures for parental control, for display of warnings on inappropriate and age-restricted content, and for receiving and handling platform users’ complaints and reports on violations in relation to content, technical measures, or other violations of law (Article 14).
  • To provide contact points and contact information for receiving and handling requests from the cinematography authority (Article 15.1).
  • To stop disseminating and to remove violating films within 24 hours and other illegal content within 3 to 5 days upon the cinematography authority’s request (Article 15.2).

Cinema Sanction Decree

On December 30, 2022, the government issued Decree No. 128/2022/ND-CP amending Decree 38/2021/ND-CP on penalties for administrative violations in the field of culture and advertising (as previously amended by Decree 129/2021/ND-CP), focusing on the addition of sanctions for new violations in the field of cinematography (“Cinema Sanction Decree”). The Cinema Sanction Decree takes effect on February 15, 2023.

Some of the notable sanctions stipulated by the Cinema Sanction Decree include:

  • A monetary fine of VND 40–60 million (approx. USD 1,700–2,555) and forcible removal of the disseminated film for the act of online film dissemination without rating the film and displaying the rating results (Article 7.2b).
  • A monetary fine of VND 20–40 million (approx. USD 850–1,700) and forcible removal of disseminated films for the failure to notify the MOCST of the list of films to be disseminated and the results of film rating (Article 10.7a).
  • A monetary fine of VND 40–60 million (approx. USD 1,700–2,555) and forcible removal of disseminated films for the failure to provide contact points and contact information for receiving and handling requests from state authorities and feedback, complaints, and denunciations from service users according to the law (Article 10.7b).
  • A monetary fine of VND 60–80 million (approx. USD 2,555–3,400) and forcible removal of disseminated films for the failure to implement technical solutions and coordinate with competent state authorities in removing and preventing infringing films as prescribed by law (Article 10.7c).
  • A monetary fine of VND 80–100 million (approx. USD 3,400–4,260) and forcible removal of disseminated films for the failure to ensure the conditions for self-rating of films (Article 10.7d).
  • A monetary fine of VND 80–100 million (approx. USD 3,400–4,260) and forcible removal of disseminated films for the failure to implement necessary technical measures for parental control and for receiving and handling platform users’ complaints and reports (Article 10.7dd).

RELATED INSIGHTS​ 

January 10, 2025
On January 8, 2025, Thailand’s Office of the Personal Data Protection Committee published two notifications in the Government Gazette—one for data controllers and the other for data processors—concerning exemptions for data controllers and data processors from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019). The notification for data processors took effect on January 9, 2025, the day after its publication. The notification for data controllers will take effect on April 8, 2025. The content of these notifications is identical to that in the draft versions of the notifications previously released for public consultation in October 2024. For more information on the ROPA exemptions for data controllers and data processors, or on any aspect of personal data protection in Thailand, please contact Nopparat Lalitkomon at [email protected] or Wilin Somya at [email protected].
January 9, 2025
On January 1, 2025, Myanmar’s State Administration Council enacted Cybersecurity Law No. 1/2025, which aims to regulate various aspects of digital security and online activities. The law has not yet been implemented and will come into force on a date specified by the Myanmar president, who will also provide an official adoption and compliance timeline for individuals and organizations impacted by the new regulations. Below are some of the key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The
January 6, 2025
On December 24, 2024, the government of Vietnam issued Decree No. 163/2024/ND-CP, providing guidelines for implementing the new Telecommunications Law that took effect on July 1, 2024 (“Decree 163”). This new decree replaces Decree No. 25/2011/ND-CP and its amendments (“Decree 25”) and took effect immediately upon issuance, with regulations on data center services, cloud computing services, and basic telecom services over the internet (“over-the-top” or OTT telecom services) having an official effective date of January 1, 2025. Decree 163 introduces substantial changes across the telecom sector, covering various aspects including service provision, licensing, standards and technical regulations, quality, passive infrastructure planning, dispute resolution, and more. Hence, it is necessary for enterprises to conduct a compliance review to identify gaps between the new decree and their business models, and take necessary steps to ensure lawful business operations in Vietnam. Below are some highlights of Decree 163. Expanded Scope of Services For basic telecom services, Decree 163 has introduced machine-to-machine (M2M) communication and classified it as a basic telecom service. This establishes a regulatory framework for IoT device communication, previously unregulated in Decree 25. For value-added telecom services, in light of the new Telecommunications Law, Decree 163 provides more detailed regulations for new telecom services such as data center services, cloud computing services, and OTT telecom services, which were not addressed in Decree 25. Regulation of Three New Telecom Services Expanding on the Telecommunications Law’s definitions of data center services, cloud computing services, and OTT telecom services, Decree 163 applies a light-touch management approach to regulate these three new services, as follows: Offshore providers: Cross-border service providers are exempt from signing commercial agreements with licensed local telecom companies. They only need to notify the Vietnam Telecommunications Authority (VNTA) using the prescribed procedures and forms before offering services. Onshore providers: The foreign
December 24, 2024
On November 30, 2024, the Data Law was officially promulgated after an accelerated preparation process that began in February 2024. The Data Law is set to take effect on July 1, 2025. Having extraterritorial effect, the Data Law will impact both local and foreign individuals and enterprises. As noted in our previous legal update, the Data Law governs digital data, the National Data Center, the National General Database, digital data products and services, digital data management, and the rights, obligations, and responsibilities of agencies, organizations, and individuals related to digital data activities. This legal update provides an overview of the Data Law, with a deep focus on the key provisions likely to impact businesses operating or offering services in Vietnam. New Data Definition and Classification The Data Law broadly defines “digital data” as data about objects, phenomena, and events, which can include one or a combination of audio, images, numbers, text, or symbols represented in digital format (hereinafter referred to as “data”). This definition is very broad and potentially covers any information recorded or represented in digital forms, including personal and nonpersonal data (such as business data, transactional data, trade secrets, etc.). Data is further categorized into different types that can be used by public bodies. However, the rights and obligations associated with each type of data are not clearly addressed. The data classification criteria include: The nature of data sharing (shared data, private data, open data); The importance of data (core data, important data, and other data); Any other criteria to meet the requirements of data administration, processing, and protection, as determined by the data owner. While the Data Law requires private organizations to categorize data based on its level of importance, it still grants these organizations the right to categorize data based on other criteria. Cross-Border Data