You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 18, 2023

Vietnam Issues Landmark Personal Data Protection Decree

On April 17, 2023, the Vietnamese government issued Decree No. 13/2023/ND on the Protection of Personal Data (“PDPD”), following extensive public consultations and multiple rounds of review since the first release of its draft version in February 2021. This is a long-awaited legal instrument which is designed to be the very first comprehensive regulation on the protection of personal data in Vietnam. The PDPD is set to take effect on July 1, 2023, without any transitional period. All Vietnamese and foreign organizations and individuals located in Vietnam and/or directly participating in or related to personal data processing activities in Vietnam must comply with the PDPD.

As expected, the PDPD sets out significantly new requirements on the processing of personal data. The most critical provisions include:

  • Eight principles for the processing of personal data: (i) lawfulness, (ii) transparency, (iii) purpose limitation, (iv) data minimization, (v) accuracy, (vi) integrity, confidentiality, and security, (iv) storage limitation, and (viii) accountability (Article 3).
  • Critical new definitions and concepts, notably including personal data (Article 2.1); basic personal data (Article 2.3); sensitive data (Article 2.4); data subject (Article 2.6); data controller (Article 2.9); data processor (Article 2.10); parties controlling and processing personal data (Article 2.11); third parties (Article 2.12); and cross-border transfer of personal data (Article 2.14).
  • Eleven data subject rights, including the right to know; right to consent; right to access; right to withdraw consent; right to delete data; right to restrict data processing; right to request the provision of data; right to object to data processing; right to complain, denounce and initiate lawsuits; right to claim compensation for damage; and right to self-defense (Article 9).
  • Specific responsibilities of data controllers (Article 38), data processors (Article 39) and third parties (Article 41).
  • Specific requirements in the exercise of data subject rights (Articles 14-16).
  • Rules on data subjects’ consent, including the requirements on validity, acceptable formats and withdrawal of consent (Articles 11 and 12).
  • Requirements on data processing impact assessment (Article 24).
  • Conditions for cross-border transfer of personal data, including a transfer impact assessment and post-transfer notification sent to the Department of Cyber Security and Hi-Tech Crime Prevention of the Ministry of Public Security (Article 25).
  • Rules on privacy notices, including timing to send the notices and mandatory content of the notices (Article 13).
  • Rules on processing of personal data obtained through audio and video recording activities in public places (Article 18).
  • Rules on processing of personal data of individuals who are declared missing or deceased (Article 19).
  • Processing of children’s personal data (Article 20).
  • Rules on protection of personal data in the business of marketing services and introducing advertising products (Article 21).
  • Cases where personal data can be processed without consent (Article 17).
  • Measures to protect personal data in general (Article 26), basic personal data (Article 27) and sensitive personal data (Article 28). The measures to protect sensitive personal data include assigning a data protection officer.

The PDPD will have far-reaching implications across virtually all business operations in Vietnam. We will provide further analysis on the anticipated impact of the PDPD in upcoming articles to help companies chart their compliance strategies.

Related: For a deeper exploration of the changes introduced by the PDPD, please see “A Closer Look at Vietnam’s First-Ever Personal Data Protection Decree.”

RELATED INSIGHTS​ 

March 12, 2026
Thailand’s AI legislative framework took another step forward when the Office of the Consumer Protection Board (OCPB) issued a notification establishing guidelines for AI-generated advertising that may cause material misunderstanding about products or services. The notification, which is already in effect, was issued under the Consumer Protection Act B.E. 2522 (1979) and its amendments, which prohibit advertising that is unfair to consumers or may cause harm to society, including false or exaggerated statements and statements that may cause material misunderstanding about products or services. The notification addresses emerging advertising practices, including the use of images edited using software or AI to attract consumer interest or build credibility. The OCPB noted that such advertising may result in consumers misunderstanding the essential characteristics, condition, or usage of products, which violates consumer rights and causes damage. Key Requirements on AI-Generated or Digitally Manipulated Advertising Content For advertisements using still images or videos created or edited with software programs or AI tools that may cause the depicted product or service to differ from the actual product sold or service provided—which may cause misunderstanding regarding the condition, quality, quantity, or other essential aspects of the products or services—advertisers and business operators must comply with the following requirements: Prior authorization. Obtain approval from relevant regulatory authorities where required by law. Accurate representation. Ensure that the advertised size, quantity, volume, number, or composition matches the actual product or service being sold, whether in still images or videos. Mandatory AI disclosure labels. Display clear disclosures when AI or software is used to create or edit images, such as: “Real image or simulation edited using AI” “Photo from actual location or simulation edited using AI” “Photo from actual product or edited simulation” “Image created by AI” “Video created by AI” Clarity of disclosure. Ensure disclosures are clearly visible,
March 10, 2026
Thailand’s Ministry of Finance and Securities and Exchange Commission (SEC) have issued regulations broadening the criteria for determining who qualifies as a “major shareholder” of licensed securities and digital asset business operators. Under relevant SEC regulations, major shareholders of a regulated entity must obtain regulatory approval and undergo screening by the SEC. The revised framework introduces both shareholding-based and control-based tests to determine which shareholders require regulatory approval for a wider range of indirect ownership structures and de facto control. The Ministry of Finance notification took effect on February 21, 2026, while the SEC’s clarifying rules took effect on March 4, 2026. These changes aim to enhance transparency around beneficial ownership and strengthen regulatory oversight of entities operating in Thailand’s capital markets. Expanded Definition Under the revised framework, a “major shareholder” now includes persons who directly or indirectly hold more than 10% of the voting rights in a regulated company, as well as persons who exercise control over the regulated company or its shares. This system of two separate tests, based on both shareholding and control, differs from the prior regime, which focused primarily on shareholding thresholds and applied a more limited method for determining indirect shareholdings. The two tests (detailed below) operate independently of each other, and any person identified by either of the tests will be deemed a major shareholder. Shareholding-Based Test Broadens Indirect Ownership Attribution For the shareholding-based test, the SEC recognizes two existing methods for identifying indirect ownership, together with a new proportional attribution method. Any person captured under these methods, which are described below, will be regarded as a major shareholder of the regulated company and must obtain SEC approval as a major shareholder. First, the existing framework continues to apply to both first-tier and chain ownership structures. Approval is required for (1) first-tier
March 6, 2026
Thailand’s Legislation Consideration Committee of the Ministry of Interior has ruled that in-game loot boxes in online games do not constitute gambling under the Gambling Act B.E. 2478 (1935). This first-of-its-kind ruling provides useful guidance for online game operators and digital entertainment companies operating in Thailand. Background The ruling came in response to an inquiry concerning an online role-playing game operator that launched a campaign featuring a loot box mechanism. The mechanism allowed players to purchase a token in exchange for the opportunity to receive a virtual loot box containing randomized in-game items. The key features of this were as follows: The items received were digital, noncash items usable only within the game. The items could not be exchanged, redeemed, or converted into cash with the game operator. Items may differ in rarity but remain purely virtual. The central question was whether paying money to obtain randomized in-game items constituted a risk-based activity involving the chance to receive money or property of monetary value, which would constitute gambling under the Gambling Act. Committee Ruling The committee reached the following conclusions regarding the characteristics of the game’s loot-box mechanism: No cash or monetary equivalent: Players did not receive cash or property that could be exchanged for cash. The in-game items were merely usage rights within the online game ecosystem. No real-world monetary valuation: There was no determination of item value in real currency, and no mechanism for redeeming or converting items into money with the game operator. Any off-platform trading of in-game items between players is irrelevant to online game operators, as any value arising from such transactions is determined by the market rather than by the operators themselves. Service fee characterization: Payments made by players purchasing in-game loot boxes constituted fees for online game services. Accordingly, the committee concluded
March 5, 2026
Thailand’s Securities and Exchange Commission (SEC) has filed a criminal complaint against a licensed digital asset broker, its overseas trading platform, and its executives for allegedly operating an unlicensed digital asset exchange targeting Thai customers. The case marks an escalation in the SEC’s enforcement efforts against unlicensed offshore platforms that attempt to serve Thai users through local licensed entities. Criminal Complaint On February 20, 2026, the SEC filed a criminal complaint with the Economic Crime Suppression Division against a local licensed digital asset broker, its overseas global trading platform, and its executives. The SEC alleges that the parties violated the Digital Asset Business Emergency Decree B.E. 2561 (2018) by cooperatively operating a digital asset exchange business on a cross-border basis since 2023 without the required SEC license. According to the SEC, the local broker promoted the overseas platform’s services to the public through Thai-language posts on social media channels, with services available exclusively to customers residing in Thailand. Access to the global platform was provided through the local broker’s website and mobile application. Customers who registered for the local broker’s services were automatically granted access to the global platform without having to undergo a separate identity verification process. The SEC also found that the local broker provided back-office system support services to the global platform. The SEC considers these activities to constitute joint operation of an unlicensed digital asset exchange. The former executives of the local broker are being held liable as the responsible persons during the relevant period. The SEC emphasized that the complaint initiates the criminal process, and the decision to prosecute or convict the accused parties will ultimately be made by law enforcement authorities and the criminal courts. Platform Blocking The SEC has also coordinated with the Ministry of Digital Economy and Society to block public