You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 15, 2020

Vietnam Issues Guidelines on Cloud Computing for E-Government Deployment

On April 3, 2020, Vietnam’s Ministry of Information and Communication (MIC) issued Official Letter No. 1145/BTTTT-CATTT to provide guidelines on a set of technical criteria and specifications for cloud computing solutions for e-government deployment (the “Guidelines”).

State agencies and organizations will rely on these Guidelines to assess and select solutions or lease cloud computing services for the development of e-government. Private-sector entities are also encouraged to refer to these Guidelines when setting up and deploying their own cloud computing platform solutions.

The set of technical criteria and specifications include two groups of criteria: Group 1 – technical criteria and specifications, and Group 2 – criteria for information security.

Group 1 includes criteria, specifications, and features related to: (1) virtual machines, (2) storage devices, (3) networks and software-defined networking, (4) physical machines, (5) administration and operation, and (6) integration and other relevant requirements.

Group 2 includes requirements related to: (1) basic requirements on information security features and (2) requirements for setting up security configurations for cloud computing infrastructure.

These two groups are specified in detail in the Guidelines and its annexes. Annex 1 related to Group 1 sets out the minimum technical criteria and specifications for cloud computing infrastructure, and sets out a table to describe features, criteria, and specifications for each specific feature. If a feature has only one criterion or technical specification, a cloud computing solution is evaluated as “passing” when the solution provides that feature and “not passing” if the solution does not provide that feature. If a feature has many different criteria and specifications, that feature is evaluated as “passing” when all criteria and technical specifications are met or “not passing” when at least one of the criteria or technical specifications is not achieved. Similarly, Annex 2 related to Group 2 sets out the minimum technical criteria and specifications for information security of cloud computing infrastructure.

The Guidelines also provide the concept of cloud computing (definition and basic characteristics of cloud computing), the classification of methods for deploying cloud computing (public cloud, private cloud, hybrid cloud, and multi-cloud) and the classification of cloud computing service provision models: IaaS (Infrastructure as a Service) – suitable for private cloud deployment; PaaS (Platform as a Service) – suitable for public cloud deployment; and SaaS (Software as a Service) suitable for public cloud.

Furthermore, the Guidelines provide two options for deploying a cloud computing platform: self-deployment, administration, and operation; or leasing professional cloud computing services from other companies.

With regard to the option of self-deployment, administration, and operation, state agencies and organizations are required to have an experienced, capable team to build, administrate, operate, maintain, and ensure information security of the platform. Therefore, they are recommended to implement the second option of leasing professional cloud computing services. However, for certain information systems with specific requirements and which require system administrators to self-manage and operate, state agencies and organizations need to consider hiring professional enterprises to build cloud computing infrastructure. After the system is built, the professional enterprises will hand it over, transfer technology, and provide training and guidance on system administration and operation.

With the option of leasing professional cloud computing services, the MIC recommends that state agencies and organizations prioritize the selection of cloud computing service providers which meet technical criteria and specifications and are on the list announced by the MIC. Selected cloud computing service providers must comply with relevant laws and regulations on network information security, comply with stipulated technical standards, and fulfill technical criteria and specifications stipulated in these Guidelines.

For more information on the cloud computing technical criteria and specifications, please contact us at [email protected].

RELATED INSIGHTS​ 

March 6, 2026
Thailand’s Legislation Consideration Committee of the Ministry of Interior has ruled that in-game loot boxes in online games do not constitute gambling under the Gambling Act B.E. 2478 (1935). This first-of-its-kind ruling provides useful guidance for online game operators and digital entertainment companies operating in Thailand. Background The ruling came in response to an inquiry concerning an online role-playing game operator that launched a campaign featuring a loot box mechanism. The mechanism allowed players to purchase a token in exchange for the opportunity to receive a virtual loot box containing randomized in-game items. The key features of this were as follows: The items received were digital, noncash items usable only within the game. The items could not be exchanged, redeemed, or converted into cash with the game operator. Items may differ in rarity but remain purely virtual. The central question was whether paying money to obtain randomized in-game items constituted a risk-based activity involving the chance to receive money or property of monetary value, which would constitute gambling under the Gambling Act. Committee Ruling The committee reached the following conclusions regarding the characteristics of the game’s loot-box mechanism: No cash or monetary equivalent: Players did not receive cash or property that could be exchanged for cash. The in-game items were merely usage rights within the online game ecosystem. No real-world monetary valuation: There was no determination of item value in real currency, and no mechanism for redeeming or converting items into money with the game operator. Any off-platform trading of in-game items between players is irrelevant to online game operators, as any value arising from such transactions is determined by the market rather than by the operators themselves. Service fee characterization: Payments made by players purchasing in-game loot boxes constituted fees for online game services. Accordingly, the committee concluded
March 5, 2026
Thailand’s Securities and Exchange Commission (SEC) has filed a criminal complaint against a licensed digital asset broker, its overseas trading platform, and its executives for allegedly operating an unlicensed digital asset exchange targeting Thai customers. The case marks an escalation in the SEC’s enforcement efforts against unlicensed offshore platforms that attempt to serve Thai users through local licensed entities. Criminal Complaint On February 20, 2026, the SEC filed a criminal complaint with the Economic Crime Suppression Division against a local licensed digital asset broker, its overseas global trading platform, and its executives. The SEC alleges that the parties violated the Digital Asset Business Emergency Decree B.E. 2561 (2018) by cooperatively operating a digital asset exchange business on a cross-border basis since 2023 without the required SEC license. According to the SEC, the local broker promoted the overseas platform’s services to the public through Thai-language posts on social media channels, with services available exclusively to customers residing in Thailand. Access to the global platform was provided through the local broker’s website and mobile application. Customers who registered for the local broker’s services were automatically granted access to the global platform without having to undergo a separate identity verification process. The SEC also found that the local broker provided back-office system support services to the global platform. The SEC considers these activities to constitute joint operation of an unlicensed digital asset exchange. The former executives of the local broker are being held liable as the responsible persons during the relevant period. The SEC emphasized that the complaint initiates the criminal process, and the decision to prosecute or convict the accused parties will ultimately be made by law enforcement authorities and the criminal courts. Platform Blocking The SEC has also coordinated with the Ministry of Digital Economy and Society to block public
February 27, 2026
The Bank of Thailand (BOT) has officially implemented a new regulatory framework supervising systemically important retail payment systems (SIRPS), effective February 21, 2026, with PromptPay being the first payment system designated as a SIRPS. Under this new set of regulations, the BOT may designate payment systems under the Payment Systems Act B.E. 2560 (2017) as SIRPSs based on quantitative and qualitative assessments. Once a system is designated as a SIRPS, the operator becomes subject to expanded supervisory obligations beyond the general requirements of the Payment Systems Act. Enhanced Supervisory Requirements SIRPS operators must comply with a heightened supervisory regime across three key areas, outlined below. 1. Governance SIRPS operators must maintain robust and transparent governance structures, including: Balanced board composition, with at least one-third of the board comprising independent directors who represent stakeholders in the system (such as payment service providers, consumers, and experts). Independent directors may serve for no more than two consecutive terms. Subcommittees to assist the board in overseeing compliance, policy implementation, and operational strategy. Clear separation between executives responsible for risk and information security and those overseeing day-to-day business operations. Risk Management and System SecuritySIRPS operators must implement comprehensive risk management frameworks, including: Clear service agreements between the SIRPS operator and its direct participants (payment service providers who connect directly to the SIRPS), defining roles and responsibilities among stakeholders. These agreements must include obligations for direct SIRPS participants to supervise any indirect participants they onboard to ensure compliance with service agreements and business rules. A business continuity plan covering both IT and non-IT aspects, with annual review. The SIRPS must target service availability comparable to international payment infrastructures, including the ability to recover operations within two hours of a disruption and to maintain scalable operational capacity. Tools and controls to monitor and manage material or
February 26, 2026
Thailand is preparing to offer new tools for intellectual property enforcement as the Electronic Transactions Development Agency (ETDA) recently released for public consultation a draft notification requiring social media platforms to verify user identities and conduct know-your-customer (KYC) checks on advertisers. The draft Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers, which is to be issued under the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023), as amended in 2025, primarily aims to combat online fraud and technology-related crimes. However, its new obligations also provide IP owners with valuable tools to identify anonymous infringers. Key Regulatory Mandates The draft notification imposes several verification requirements on social media platforms operating in Thailand. These requirements also strengthen IP rights holders’ ability to identify anonymous infringers, as platforms must: Verify user identities through registered phone numbers and link all accounts to verifiable identities. Conduct KYC checks on advertisers, including individuals, companies, and any third-party payers. Perform heightened identity checks for high-risk or repeat offenders before publishing advertisements. Promptly remove content flagged by the Anti-Technology Crime Division and prescreen advertisements for prohibited or high-risk content. How IP Owners Can Use This Notification for Enforcement The phone number–based verification requirement enables IP owners to work more effectively with enforcement authorities in tracing individuals or entities responsible for infringing content. The comprehensive advertiser KYC obligations, including mandatory disclosure of third-party payment sources, create a clear audit trail even when bad actors attempt to obscure their identity through intermediaries or shell accounts. This traceability is essential for pursuing damages and dismantling organized counterfeit operations. The ETDA is now considering adjustments to the draft notification after receiving comments during the public consultation period, which ended on February 2, 2026. Following finalization