You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 10, 2023

Vietnam Issues Guidance on Law on Cinema

The National Assembly of Vietnam promulgated a new Law on Cinema in June 2022 with an effective date of January 1, 2023. To guide the implementation of the new law and the sanctioning of administrative violations thereof, the government of Vietnam issued two related decrees in the final days of 2022.

Cinema Decree

On December 31, 2022, the government issued Decree No. 131/2022/ND-CP elaborating a number of articles of the Cinema Law (“Cinema Decree”), which took effect with the new law on January 1, 2023.

Among the many issues under the Cinema Law guided by the Cinema Decree, one that is critical to over-the-top (OTT) media service providers is the set of conditions for performing the mandatory self-rating of films to be disseminated in cyberspace. According to the Cinema Law, meeting the film self-rating conditions is one of the prerequisites for online dissemination of films. If a film disseminator does not meet these conditions, it would be required to request the Ministry of Culture, Sports and Tourism (MOCST) to perform the rating.

The conditions for online disseminators to self-rate their films have now been set out under Article 12 of the Cinema Decree. Accordingly, these conditions include:

  • Having a film rating council or technical software or a mechanism to rate the films according to Vietnamese regulations on film rating and taking responsibility for the results of film rating.
  • Having a plan to amend and update film rating results at the request of the cinematography authority (for most providers, this is the Cinematography Department under the MOCST).
  • Having an administrative tool to support the rating of films according to each of the rating criteria and to flexibly display the updated rating immediately after the rating is changed.
  • Having a technical plan and process for suspending and removing films at the request of the cinematography authority. Upon a request for removal of the film, the disseminator must proceed to implement the removal functionality available on the administrative tool.

These officially enacted conditions are much more relaxed compared to those proposed in the first draft of the Cinema Decree (released for public consultation in October 2022), which required that a foreign film disseminator (e.g., an OTT service provider), among other conditions, must establish a local enterprise in Vietnam or enter into a business cooperation agreement with a local company to be eligible to perform the self-rating of films. This proposed requirement under the draft Cinema Decree was subject to heated discussions among relevant stakeholders at the time. The government seems to have taken industry opinions into consideration and decided to change the burdensome conditions.

The Cinema Decree also provides the formality requirements for an online film disseminator to request recognition from the MOCST that they meet the self-rating conditions, as well as the procedures for the MOCST to receive and handle the dossier (in Article 12.2 and 12.3).

In addition, the Cinema Decree gives details on the following critical obligations of online film disseminators:

  • To notify the MOCST of the list of films to be disseminated and the self-rating results of the films before disseminating films in cyberspace (Article 13).
  • To implement necessary technical measures for parental control, for display of warnings on inappropriate and age-restricted content, and for receiving and handling platform users’ complaints and reports on violations in relation to content, technical measures, or other violations of law (Article 14).
  • To provide contact points and contact information for receiving and handling requests from the cinematography authority (Article 15.1).
  • To stop disseminating and to remove violating films within 24 hours and other illegal content within 3 to 5 days upon the cinematography authority’s request (Article 15.2).

Cinema Sanction Decree

On December 30, 2022, the government issued Decree No. 128/2022/ND-CP amending Decree 38/2021/ND-CP on penalties for administrative violations in the field of culture and advertising (as previously amended by Decree 129/2021/ND-CP), focusing on the addition of sanctions for new violations in the field of cinematography (“Cinema Sanction Decree”). The Cinema Sanction Decree takes effect on February 15, 2023.

Some of the notable sanctions stipulated by the Cinema Sanction Decree include:

  • A monetary fine of VND 40–60 million (approx. USD 1,700–2,555) and forcible removal of the disseminated film for the act of online film dissemination without rating the film and displaying the rating results (Article 7.2b).
  • A monetary fine of VND 20–40 million (approx. USD 850–1,700) and forcible removal of disseminated films for the failure to notify the MOCST of the list of films to be disseminated and the results of film rating (Article 10.7a).
  • A monetary fine of VND 40–60 million (approx. USD 1,700–2,555) and forcible removal of disseminated films for the failure to provide contact points and contact information for receiving and handling requests from state authorities and feedback, complaints, and denunciations from service users according to the law (Article 10.7b).
  • A monetary fine of VND 60–80 million (approx. USD 2,555–3,400) and forcible removal of disseminated films for the failure to implement technical solutions and coordinate with competent state authorities in removing and preventing infringing films as prescribed by law (Article 10.7c).
  • A monetary fine of VND 80–100 million (approx. USD 3,400–4,260) and forcible removal of disseminated films for the failure to ensure the conditions for self-rating of films (Article 10.7d).
  • A monetary fine of VND 80–100 million (approx. USD 3,400–4,260) and forcible removal of disseminated films for the failure to implement necessary technical measures for parental control and for receiving and handling platform users’ complaints and reports (Article 10.7dd).

RELATED INSIGHTS​ 

June 19, 2024
On June 14, 2024, the Personal Data Protection Committee (PDPC) released a draft notification under the Personal Data Protection Act 2019 (PDPA), setting out criteria for how data controllers must delete, destroy, and de-identify personal data. According to the PDPA, a data subject can request that a data controller delete, destroy, or de-identify their personal data in any of the following circumstances: The personal data is no longer necessary for the purposes for which it was collected, used, or disclosed. The data subject has withdrawn their consent for the processing of the personal data, and no other lawful basis for processing remains. The data subject has objected to the processing of their personal data on grounds of legitimate interests or official tasks, the data controller has no other compelling grounds to refuse the request, and the data is not needed for legal claims. The data subject objects to the processing of their personal data for direct marketing purposes. The processing of personal data is unlawful. The draft stipulates that data controllers respond to a data subject’s request to delete, destroy, or de-identify personal data immediately, and within 60 days of receiving the request. If the data controller cannot fulfill the request immediately, they must take interim measures to ensure that the personal data is made difficult to collect, use, or disclose. This includes implementing measures such as preventing access to the data and applying appropriate security measures to protect the data from unauthorized use or disclosure. De-identification or Anonymization of Personal Data In certain circumstances, a data controller may opt to de-identify or anonymize personal data, rather than delete or destroy it. If doing so, the data controller must satisfy the following criteria: There must be a structured process to remove or eliminate all direct identifiers linked to the
May 15, 2024
On May 1, 2024, Thailand’s National Cyber Security Committee (NCSC) published the draft NCSC Notification Re: Cloud Cybersecurity Standards for a public hearing period, which was open until May 14, 2024. These standards have been drafted to drive the country’s cloud-first policy with the aim of minimizing risks from cyber threats to cloud services utilized by government agencies, supervising or regulating organizations, and critical information infrastructure (CII) organizations. The key points of the draft Cloud Cybersecurity Standards are below. Scope The standards apply to government agencies, supervising or regulating organizations, and CII organizations under the Cybersecurity Act B.E. 2562 (2019), as well as cloud service providers (defined below). The standards prescribe cloud system cybersecurity measures for cloud service customers (defined below) and providers only to the extent that the service is provided to the in-scope organizations outlined above. Definitions Cloud service customers (CSCs): In-scope organizations that have a formal contractual agreement to use cloud services provided by a cloud service provider. Cloud service providers (CSPs): Persons who enable cloud services to be used by a cloud service customer, responsible for maintaining infrastructure, platforms, and software that enable provision of the cloud services and for managing these resources to ensure their accessibility, security, and scalability for their cloud service customers. Application In-scope organizations that will use or have been using cloud services must comply with the Cloud Cybersecurity Standards by taking into account their data or technology information systems’ level of impact, as specified in the previously issued Notification of the NCSC Re: Standards for Defining the Security Category for Data and Information Systems B.E. 2566 (2023). The impact level related to personal data is to be rated as being at least at the medium level, and the minimum standards for that level specified in the draft Cloud Cybersecurity Standards
May 13, 2024
On May 2, 2024, Vietnam’s Ministry of Justice published on its online platform the most recent version of the draft decree on administrative sanctions for violations in the field of cybersecurity (“Draft Sanction Decree”) to gather feedback and contributions from the community and stakeholders. After receiving the Ministry of Justice’s assessment, the Ministry of Public Security (“MPS”), in charge of drafting the Draft Sanction Decree, may make further revisions before submitting it to the government for review and final decision on enactment. The decree is expected to have an effective date of June 1, 2024. The stringent penalties for infringements involving personal data of the previous draft version remain in this Draft Sanction Decree—a sign of the proactive stance of the MPS in enforcing the Personal Data Protection Decree (“PDPD”). Effective Date and Transitional Provisions It is important to note that the Draft Sanction Decree does not impose any new obligations on organizations or individuals, and only sets out the administrative sanctions that could be imposed on violators as soon as June 1, 2024, which is indicated as the effective date in Article 49. This signals the MPS’s eagerness to begin taking enforcement actions against recalcitrant organizations and individuals that have not complied with the various obligations imposed on them under the Law on Network Information Security (enacted in 2015), the Law on Cybersecurity (enacted in 2018) and its guiding decree (Decree 53 – enacted in 2022), and the most recent PDPD (enacted in 2023). Article 50.1 of the Draft Sanction Decree outlines the transitional provisions regarding administrative violations in the cybersecurity field. It clarifies that the decree does not have retroactive effect, by stating that violations occurring before its effective date, but discovered or under review after such effective date will be subject to the regulations on administrative
May 9, 2024
As non-cash payments continue to surge in Vietnam, the requirement for strong security standards and a clear legislative framework for intermediary payment services (“IPS”) is becoming more and more critical. Recognizing this, the State Bank of Vietnam (“SBV”) has been working on a draft decree to supersede the outdated Decree No. 101/2012/ND-CP dated November 22, 2012, on non-cash payments (“Draft Non-Cash Payment Decree”), which will lay the groundwork for non-cash payments in general and the provision of IPS in particular. Building upon this, the SBV recently issued a draft circular to replace Circular No. 39/2014/TT-NHNN dated December 11, 2014, on IPS (“Circular 39”) (“Draft IPS Circular”), which will offer more detailed guidance on the provision of IPS in Vietnam on top of the Draft Non-Cash Payment Decree. The Draft IPS Circular will be applicable to (i) IPS providers; (ii) foreign organizations providing IPS in Vietnam; and (iii) organizations and individuals involved in the provision of IPS. Some key updates regarding the Draft IPS Circular are as follows: Scope of Application The Draft IPS Circular sets out further guidance for the provision of IPS as listed under the Draft Non-Cash Payment Decree, including: (i) electronic clearing services; (ii) electronic wallet (“e-wallet”) services; (iii) collection and payment support services; (iv) financial switching services; (v) international financial switching services; and (vi) electronic payment gateway services. Notably, the Draft IPS Circular has explicitly excluded from its scope of application the provision of accounts by goods/service providers to their customers solely for the purpose of payment within the systems of such providers (e.g., cards/coupons or service/transaction accounts of online game service providers, transportation service providers, or securities companies, etc.). Requirements on the Provision of IPS Electronic Clearing Services: The Draft IPS Circular introduces regulations to cover certain elements of electronic clearing services that have