You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 23, 2021

Vietnam: New Decree Tightens Regulations on Cross-Border Online Advertising

To enforce more rigorous control of cross-border advertising activities, the Vietnamese government issued Decree No. 70/2021/ND-CP dated July 20, 2021 (Decree 70), amending and supplementing provisions of Decree No. 181/2013/ND-CP dated November 14, 2013, elaborating on some articles of the Law on Advertising. Decree 70 will take effect on September 15, 2021.

According to the Deputy Director of the Authority of Broadcasting and Electronic Information, Decree 70 will allow better control over cross-border advertisement on platforms such as Facebook or YouTube. To that end, Decree 70 stipulates new obligations for these providers while also consolidating executive authority over cross-border advertising activities under the Ministry of Information and Communications (MIC).

Revised Obligations for Cross-Border Advertising Services

Significantly, Decree 70 overhauls Article 13, which provides the definitions and obligations for cross-border advertising service providers. Accordingly, cross-border advertising services are explained as the utilization of websites hosted outside Vietnam to provide ads targeted at Vietnamese consumers and obtain revenue in Vietnam. Notably, Article 13 defines such websites as a “single or multi-website system …  providing users with services for storage, provision, use, search, or exchange of information, sound or image sharing, forum creation, or live chat to supply advertising services.” This would effectively encompass many types of online environments, specifically social network sites, such as Facebook.

In addition, more entities will be taxed on cross-border advertising revenue under Article 13, including not only service providers but also both domestic and overseas advertisers.

Under Decree 70, cross-border advertising services must comply with Vietnam’s cybersecurity and intellectual property laws in addition to the Law on Advertising. Decree 70 requires foreign providers of cross-border advertising services to supply the MIC with direct contact information 15 days before commencing cross-border advertising activities in Vietnam. Domestic advertising service providers that cooperate with foreign entities to provide cross-border advertising services in Vietnam must submit annual or ad hoc reports in a prescribed form as stipulated under the decree.

Service providers must also block and remove illegal or infringing content from their advertising platforms upon the MIC’s request, as well as supply information on organizations or individuals suspected of illegal online advertising activities.

Decree 70 also grants advertisers the right to demand that service providers not place advertising products in content that violates the law (particularly Article 8.1 of Cybersecurity Law and Article 28 of IP Law) and supply means for monitoring and removing illegal advertising content.

MIC’s Control over Cross-Border Advertising Services

In the past, cross-border advertising services were under the supervision and management of different authorities. Decree 70 revises this and consolidates all supervisory authority under the MIC. Departments and agencies of all levels must vigilantly detect illegal cross-border advertising activities and report to the MIC. Within a five-day window, the MIC will conduct investigations and notify service providers of the illegal ad content or activities that must be addressed or removed in 24 hours. If service providers fail to adhere to the MIC’s request, the MIC will take any appropriate legal measures to block the illegal advertisement. This authority is also extended to other competent agencies should the offense threaten Vietnam’s national security. It is unclear what the blocking measures would entail under Decree 70, and it will be interesting to see how this mechanism works in the future.

RELATED INSIGHTS​ 

September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 22, 2025
On September 15, 2025, Vietnam’s Ministry of Science and Technology announced that the country will issue an updated version of its National AI Strategy (first issued in 2021) and its first-ever AI Law by the end of this year. The ministry emphasized that the AI strategy is not just a legal framework, but a commitment to embracing AI to drive Vietnam into a new era. The AI adoption plan is set as a priority of the country, and marks a significant step in shaping Vietnam’s AI governance and innovation landscape. Highlights of the plan include the following: Strategic vision. Vietnam’s ambition is to leverage AI for economic growth, social development, and global competitiveness, under the guiding principle “AI for humans – safe, autonomous, cooperative, inclusive, and sustainable.” AI as national infrastructure. The updated strategy positions AI as core national infrastructure, comparable to electricity or the internet, aiming to provide every citizen with a “personal digital assistant.” Core principles for AI legislation. The AI Law will be built around the following six core principles: Risk-based regulation Transparency and accountability Human-centric development Domestic AI autonomy AI as a driver of sustainable growth Digital sovereignty, with data, infrastructure, and AI technology being three strategic pillars Ethics and openness. A National AI Ethics Code will accompany the upcoming law, aligned with international standards but tailored to the Vietnamese context. The government emphasizes open standards and open-source development. Market development and incentives. The government plans to expand domestic AI adoption, particularly in public services and key industries. The National Technology Innovation Fund (NATIF) will allocate at least 40% of its budget to AI projects, prioritizing SMEs through vouchers for locally developed AI solutions. Background on AI Law Development Regulations on AI are found in various Vietnamese laws and regulations, notably the recently adopted Law
September 16, 2025
Thailand has enacted amended alcohol control legislation that significantly tightens restrictions on marketing and advertising, strengthens enforcement, and creates mechanisms to support the country’s tourism objectives. The Alcoholic Beverage Control Act (No. 2) B.E. 2568 (2025), published in the Government Gazette on September 9, 2025, will take effect on November 8, 2025. Key aspects of the new law are outlined below. Continuation of Sales-Hour Restrictions Sales-hour restrictions remain in effect, though now under an updated regulatory pathway. Alcohol sales are permitted only between 11:00 a.m. and 2:00 p.m. and between 5:00 p.m. and midnight, with exceptions for airport terminals, entertainment venues under the Entertainment Place Act 1966, and hotels. Despite earlier discussions about relaxing these hours, no changes have been implemented under the new law. Enhanced Seller Responsibilities Sellers are now expressly permitted to check identification cards to verify purchaser age and may assess the condition of intoxicated customers. The assessment conditions will be announced in a forthcoming notification from the director of the Department of Disease Control. Sellers who willfully or negligently violate the law and cause damage to life, health, or property face possible penalties. Alcohol Vending Machines Permitted The law allows alcohol to be sold in vending machines that can verify buyer information and comply with rules, procedures, and conditions to be prescribed by the Alcoholic Beverage Control Committee. This means the industry must await the committee’s implementing regulations before deploying such machines. Expanded Marketing and Advertising Restrictions The amended law introduces a new suite of advertising restrictions, including more detailed and expansive definitions involving marketing and promotions. “Marketing communication” is broadly defined to include any direct or indirect act of publicizing, presenting, or disseminating information about alcoholic beverages through advertising, public relations, sales promotions, sponsorships, or any other means that may induce or encourage the
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.