You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 11, 2025

Vietnam Issues New Cybersecurity Law

On December 10, 2025, the National Assembly of Vietnam passed a new Cybersecurity Law, which will take effect on July 1, 2026. The new Cybersecurity Law was developed based on the consolidation of the 2018 Cybersecurity Law and the 2015 Law on Network Information Security.

While the final approved version of the new Cybersecurity Law has not yet been published, according to official reports, the following notable requirements are confirmed to be included:

  • The new Cybersecurity Law dedicates a specific article to prohibited acts related to cybersecurity, under which it strictly prohibits posting or disseminating information online that propagandizes against the Socialist Republic of Vietnam. The law also prohibits, among other things, (i) the appropriation, trading, seizure, or intentional disclosure of information classified as state secrets, work secrets, business secrets, personal secrets, family secrets, and private life; (ii) intentionally eavesdropping, recording, or filming online conversations without authorization; and (iii) the use of artificial intelligence (AI) or new technologies to conduct prohibited acts.
  • The Ministry of Public Security (MPS) has the authority to require enterprises providing telecommunications, internet, and online services, as well as system administrators, to remove information violating cybersecurity laws from systems under their management. The MPS is also assigned responsibility for ensuring information security in cyberspace and data security, establishing mechanisms for IP address identity management, verifying digital account registration information, and issuing warnings and sharing information on cybersecurity threats.
  • Information systems are classified into five levels (similar to the 2015 Law on Network Information Security) based on the degree of harm to national security and social order if an incident occurs.
  • The MPS is the lead agency assisting the government in state management of cybersecurity. The Ministry of National Defense is responsible for managing military information systems, and the Government Cipher Committee manages cryptographic and cipher information systems.

Interestingly, while the last publicly circulated draft version of the new Cybersecurity Law submitted to the National Assembly for approval had reinstated controversial data localization requirements, the official reports have not mentioned this aspect. It remains to be seen whether the data localization requirements have survived and are included in the official version of the new Cybersecurity Law.

RELATED INSIGHTS​ 

April 30, 2024
On March 25, 2024, Thailand’s Securities and Exchange Commission (SEC) published an amendment to its Notification re: Public Digital Token Offering to strengthen governance for initial coin offerings (ICOs). The amendments took effect on April 16, 2024, and reflect the SEC’s commitment to creating a safer and more transparent ICO environment, enhancing investor protection, and building confidence in ICOs as a fundraising tool. The key changes are outlined below: New Checks and Balances Requirements The new regulations require digital token issuers to implement checks and balances to protect investor rights—including an annual audit requirement and measures to prevent and manage conflicts of interest. These measures must be clearly disclosed in the ICO filing documents. In addition, certain project-related decisions must be approved by the issuer’s board of directors, which is also responsible for the accountability of such decisions. Improved Rules Concerning Voting Rights The SEC has introduced rules concerning voting rights and procedures for digital token holders, particularly for token types that previously lacked regulatory clarity. These rules specify the procedures for soliciting votes, the rationale behind vote requests, and the criteria for determining voting outcomes. The new rules, however, do not apply to real estate-backed tokens or infrastructure-backed tokens. Enhanced Advertising Regulations The SEC has revised advertising guidelines to ensure that investors receive essential information. The updated rules now require all ICO advertising to be fair and informative and to avoid misleading content. Advertisements must include appropriate risk warnings and a credible source for any claims made. The notification also stresses that it is the responsibility of digital token issuers to strictly supervise and ensure that those who create advertisements with or for an issuer comply with all relevant advertising regulations, including the following: Warning of investment risk: Advertisements must include warnings about investment risks and contact information
April 5, 2024
On March 15, 2024, Thailand’s Board of Investment (BOI) updated its investment incentives for software development and data centers by issuing a regulation replacing the previous categories of software or platforms for digital services or content (category 8.1) and data centers (category 8.2.1). The new and updated categories are detailed below. Software and Platform Development Under the new promotion policy, the BOI has made separate subcategories for “development” and “improvement” of software or platforms, each with its own set of incentives. The BOI is expected to clarify the characteristics of these two activities in a forthcoming announcement. Qualifying development activities are eligible for a corporate income tax (CIT) exemption for eight years (capped), while improvement activities are not eligible for any CIT exemption. A number of adjustments have been made to the eligibility criteria for development of software and platforms for digital services or content. These include the following: Salary expenditures for Thai information technology (IT) personnel hired temporarily after applying for investment promotion can now be included in the calculation of total salary expenditures for Thai IT personnel hired subsequent to applying for investment promotion. Previously, only salary expenditures for permanently employed personnel could be included in this figure. The minimum salary expenditures for each project remain unchanged at THB 1.5 million per year. Similarly, salary expenditures for temporary hiring of Thai IT personnel can be included in calculating the actual expenditures in the year that the project would like to benefit from the CIT exemption. Projects must commence operations within 12 months of the promotion certificate being issued. No extensions are allowed. Projects are no longer allowed to extend the machinery importation period. The other eligibility criteria for development of software and platforms for digital services or content remain unchanged. Projects in the new BOI subcategory for
April 4, 2024
On March 18, 2024, the president of the Supreme Court of Thailand announced the establishment of a specialized Technology Crime Division within the Criminal Court of Thailand. This represents a significant commitment to cybercrime within the Thai judiciary and a step forward in Thailand’s ability to investigate cybercrime. The rise in cybercrime investigations in recent years has made it increasingly difficult for Thailand’s traditional criminal courts to consider and issue enforcement orders in support of ongoing investigations in a timely manner. The new Technology Crime Division addresses this challenge. This new division has jurisdiction over cybercrime and technology-related crime, fraud or extortion using computers, and criminal offenses relating to personal data protection laws. In addition, this new division has jurisdiction over all requests from competent law enforcement officers seeking court orders under the Computer Crimes Act B.E. 2550, the Personal Data Protection Act B.E. 2562, and the Cybersecurity Act B.E. 2562. The Technology Crime Division will have trainees and judges with expertise in technology and cybercrime—not only to facilitate expert prosecution of cybercrime but also to offer critical and time-sensitive support to law enforcement investigations of alleged cybercrime. The Technology Crime Division is not yet operational. The president of the Supreme Court is expected to announce the division’s opening date in the coming months. For more details on Thailand’s measures for dealing with cybercrime, please contact Michael Ramirez at [email protected] or Piyawat Vitooraporn at [email protected].
March 29, 2024
Thailand’s Cybersecurity Regulating Committee (CRC) released a notification under the Cybersecurity Act on February 22, 2024, setting key operational obligations for critical information infrastructure (CII) organizations. The notification takes effect on June 20, 2024. CII organizations are state or private entities that carry out services related to national security, public services, banking and finance, information technology and telecommunications, transportation and logistics, energy and public utilities, or public health. CII organizations will be identified by the National Cyber Security Committee (NCSC) and notified of their status. The key obligations of CII organizations are laid out below. Reporting to the National Cyber Security Agency (NCSA) CII organizations must provide the following to the NCSA: A list of executive and operational staff, along with emergency contacts who can be reached within 60 minutes in the event of a cyber threat. The NCSA must be notified of any updates to this list within 15 days following any changes. A list of internal departments or individuals who are the responsible persons, owners, and holders of the computer systems, along with emergency contacts who can be reached within 60 minutes in the event of a cyber threat. The NCSA must be notified of any updates to this list at least 7 days prior to any changes (or within 15 days after the change if there is a necessary reason). Policies, Guidelines, and Procedures As specified in the National Cyber Security Committee (NCSC) guidelines, CII organizations must prepare the following internal documents by June 20, 2025: Cybersecurity practice guidelines, consisting of an inspection plan, risk assessment, and incident response plan. Cybersecurity standards framework, consisting of measures for risk identification, risk prevention, threat detection and monitoring, incident responses, and resilience and recovery. CII organizations must also prepare the following: Mechanisms, procedures, and steps for monitoring and detecting