You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 18, 2023

Vietnam Issues Landmark Personal Data Protection Decree

On April 17, 2023, the Vietnamese government issued Decree No. 13/2023/ND on the Protection of Personal Data (“PDPD”), following extensive public consultations and multiple rounds of review since the first release of its draft version in February 2021. This is a long-awaited legal instrument which is designed to be the very first comprehensive regulation on the protection of personal data in Vietnam. The PDPD is set to take effect on July 1, 2023, without any transitional period. All Vietnamese and foreign organizations and individuals located in Vietnam and/or directly participating in or related to personal data processing activities in Vietnam must comply with the PDPD.

As expected, the PDPD sets out significantly new requirements on the processing of personal data. The most critical provisions include:

  • Eight principles for the processing of personal data: (i) lawfulness, (ii) transparency, (iii) purpose limitation, (iv) data minimization, (v) accuracy, (vi) integrity, confidentiality, and security, (iv) storage limitation, and (viii) accountability (Article 3).
  • Critical new definitions and concepts, notably including personal data (Article 2.1); basic personal data (Article 2.3); sensitive data (Article 2.4); data subject (Article 2.6); data controller (Article 2.9); data processor (Article 2.10); parties controlling and processing personal data (Article 2.11); third parties (Article 2.12); and cross-border transfer of personal data (Article 2.14).
  • Eleven data subject rights, including the right to know; right to consent; right to access; right to withdraw consent; right to delete data; right to restrict data processing; right to request the provision of data; right to object to data processing; right to complain, denounce and initiate lawsuits; right to claim compensation for damage; and right to self-defense (Article 9).
  • Specific responsibilities of data controllers (Article 38), data processors (Article 39) and third parties (Article 41).
  • Specific requirements in the exercise of data subject rights (Articles 14-16).
  • Rules on data subjects’ consent, including the requirements on validity, acceptable formats and withdrawal of consent (Articles 11 and 12).
  • Requirements on data processing impact assessment (Article 24).
  • Conditions for cross-border transfer of personal data, including a transfer impact assessment and post-transfer notification sent to the Department of Cyber Security and Hi-Tech Crime Prevention of the Ministry of Public Security (Article 25).
  • Rules on privacy notices, including timing to send the notices and mandatory content of the notices (Article 13).
  • Rules on processing of personal data obtained through audio and video recording activities in public places (Article 18).
  • Rules on processing of personal data of individuals who are declared missing or deceased (Article 19).
  • Processing of children’s personal data (Article 20).
  • Rules on protection of personal data in the business of marketing services and introducing advertising products (Article 21).
  • Cases where personal data can be processed without consent (Article 17).
  • Measures to protect personal data in general (Article 26), basic personal data (Article 27) and sensitive personal data (Article 28). The measures to protect sensitive personal data include assigning a data protection officer.

The PDPD will have far-reaching implications across virtually all business operations in Vietnam. We will provide further analysis on the anticipated impact of the PDPD in upcoming articles to help companies chart their compliance strategies.

Related: For a deeper exploration of the changes introduced by the PDPD, please see “A Closer Look at Vietnam’s First-Ever Personal Data Protection Decree.”

RELATED INSIGHTS​ 

May 5, 2025
On April 29, 2025, the government of Vietnam promulgated Decree No. 94/2025/ND-CP with regulations on a controlled “sandbox” for innovative fintech solutions in the banking sector (Decree 94). The decree aims to promote innovation, modernize banking, and enhance financial inclusion while assessing risks and benefits of fintech solutions in a controlled testing environment. Fintech Sandbox Currently, the fintech sandbox focuses on three specific areas: Credit scoring Open API data sharing Peer-to-peer (P2P) lending Eligible participants for the fintech sandbox include: Credit institutions and foreign bank branches (except for P2P lending) Fintech companies operating in Vietnam Cross-border supply by foreign providers is not included in the sandbox framework. Eligible participants are permitted to provide fintech solutions only within the scope specified in the Certificate of Sandbox Participation issued by the State Bank of Vietnam in consultation with other ministries. P2P lending companies face specific restrictions within the fintech sandbox, including prohibitions against: Providing security for customer loans Operating as a customer (i.e., P2P lender or borrower) Providing P2P lending solutions to pawn shops The maximum sandbox period is two years, with the possibility of extension as permitted by law. The outcomes of the fintech sandbox will serve as a practical basis for authorities to develop and refine future fintech regulations. It is worth noting that participation in the sandbox does not guarantee that participants will meet relevant business and investment conditions that may be stipulated in future regulations. Decree 94 will take effect on July 1, 2025, signaling that the Vietnamese government intends to take a proactive approach to fostering fintech development. Implications Parties interested in participating in the fintech sandbox should begin preparing now to be ready to apply for a Certificate of Sandbox Participation when the decree takes effect.
May 2, 2025
Attorneys from Tilleke & Gibbins have updated the latest edition of Doing Business in Thailand, a Q&A-style guide from Thomson Reuters Practical Law that offers an overview of key legal considerations for companies operating in jurisdictions worldwide. The contribution outlines the country’s legal and regulatory framework for foreign investment and business operations and reflects the latest legislative developments. The chapter addresses the following core topics: Legal system: Structure of the courts and the codified nature of Thai law. Foreign investment: Business restrictions under the Foreign Business Act, sector-specific regulations, exchange control rules, and investment incentives. Business vehicles: Overview of partnerships, private and public limited companies, and other legal entities. Employment: Labor protections, employment contracts, foreign worker requirements, and termination procedures. Tax: Corporate and personal income tax, indirect taxes, and tax obligations for residents and non-residents. Intellectual property: Registration and enforcement of patents, trademarks, designs, and copyrights. Data protection: Key provisions of the Personal Data Protection Act and related compliance obligations. Competition law: Regulatory framework under the Trade Competition Act. Anti-bribery and corruption: Relevant legislation and enforcement mechanisms. E-commerce and digital business: Legal regime for online transactions and digital platforms. Marketing and advertising: Consumer protection laws and regulations affecting advertising and marketing practices. Product regulation and liability: Safety standards, liability regimes, and roles of enforcement authorities. Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The insurance and reinsurance guide is a valuable resource for legal practitioners, covering numerous jurisdictions worldwide. To view the latest version of the guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
April 30, 2025
With a favorable crypto climate from the Trump administration in the United States, Thailand is ready for digital asset platforms and has market appetite. This article highlights the country’s regulatory initiatives supporting the growth of digital assets like crypto, stablecoins, and smart contracts, along with efforts to establish clear oversight. Bank of Thailand Sandbox Stablecoins used as a medium of payment, particularly those pegged to the Thai baht (THB) for public use, are considered as mirroring fiat currency, which violates the Currency Act B.E. 2501 (1958). These can also be classified as e-money under the Payment Systems Act B.E. 2560 (2017). The Bank of Thailand (BOT) urges issuers to engage in preconsultation prior to implementation, due to concerns about stablecoins being used in place of THB currency. Other FX- or asset-backed stablecoins are not recognized as legal tender under Thai law, and users must bear their own risks. The BOT recognizes the potential and benefits of these technologies in reducing operational costs for financial service providers and addressing the needs of financial service users. Consequently, the BOT issued a sandbox framework in June 2024. In particular, the enhanced regulatory sandbox allows nonlicensed entities to test financial innovations in controlled conditions. These tests must have a clearly defined duration (usually under one year) and involve a limited user group with an exit strategy. Several programmable payment projects—automated transactions with predefined conditions for the payment of goods and services—were piloted under this sandbox, which closed for applications in September 2024. Eight participants are planning to launch their test runs this year, some of which include asset tokenization or exchange global stablecoins in their programmable payment projects. Thai Securities and Exchange Commission Sandbox Given that digital asset businesses fall under the Royal Decree on Digital Asset Businesses B.E. 2561 (2018), supervised by
April 30, 2025
The Bank of Thailand (BOT) is accepting public comments until May 2, 2025, on three draft notifications that will institute an enhanced supervision scheme and impose additional requirements for systemically important retail payment system (SIRPS) operators to align with international standards and encourage open infrastructure and competition. The SIRPS operators will be determined by the BOT from the “designated payment system operators” under the Payment Systems Act B.E. 2560 (2017). SIRPS Designation The BOT will announce a list of payment system operators designated as SIRPS operators and thus subject to enhanced supervision. The BOT will evaluate whether the payment system operator should be deemed a SIRPS operator when it meets the criteria in either the BOT’s quantitative or qualitative assessments, which cover the following: Quantitative assessment: The payment system’s transaction values, market share, cross-border payment network scale and value, and settlement with other financial market infrastructure. Qualitative assessment: The payment system’s function as a part of the country’s payment system infrastructure, the significance of the system users’ roles in the payment services, the substitutability of the payment system, and the impact level on the public and users in the event of an emergency or system suspension. Supervision of SIRPS Business Operations SIRPS operators will be subject to heightened supervision in three areas, in addition to various BOT regulations on designated payment system supervision, as follows: Governance: SIRPS operators will be required to have a balanced board composition with an independent director and directors with varied expertise, establish subcommittees to assist the board in supervising the operator’s compliance with its policy and strategy, and have senior executives overseeing risk and technology security separately from the executives overseeing business operations. Risk management and security: SIRPS operators will be required to have comprehensive risk management to ensure system stability and security. This