You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 15, 2024

Vietnam Revs Up Fintech Sector with Updated Draft of Sandbox Decree

Vietnam’s fintech industry is booming, and the rapid emergence of tech startups and non-bank institutions offering innovative financial services has been outpacing existing regulations. This regulatory gap not only creates uncertainty for both innovators and consumers, but also poses a number of imminent risks in areas such as consumer protection, data privacy, cybersecurity, and anti-money laundering, among others.

The State Bank of Vietnam (SBV) is stepping up to tackle these challenges by accelerating the promulgation of a long-awaited Fintech Sandbox Decree with the issuance of an updated draft (“Draft Fintech Sandbox Decree”) on March 4, 2024. The Draft Fintech Sandbox Decree establishes a controlled environment where fintech companies and financial institutions can test solutions that do not fall squarely within the parameters of existing regulations. The pilot activities will be limited in scope, scale, and duration, with a number of precautionary measures in place. The SBV will supervise this “sandbox” closely, effectively mitigating risks and gathering valuable data to inform future regulations.

Who Can Participate in the Sandbox?

  • Traditional financial institutions (credit institutions): Banks and other institutions licensed to provide financial services can participate in the sandbox to test new offerings or refine existing ones.
  • Independent fintech companies: Startups and established companies specializing in fintech solutions can leverage the sandbox to pilot innovative ideas before seeking wider market adoption.
  • Other relevant organizations involved in the pilot: Depending on the specific solution being tested, other entities may also be involved in the sandbox.
  • Geographical scope: Limited to Vietnamese territory; cross-border testing is not allowed.

Focusing on Three Solution Categories

Earlier versions of the Draft Fintech Sandbox Decree included categories like blockchain technology and other innovative business models, but these were removed in the latest version. To allow the SBV to assess the associated risks and work on the solutions more effectively, this version focuses only on the following three solutions:

  • Credit scoring: Fintech companies can pilot new credit scoring models to assess the creditworthiness of individuals or organizations.
  • Data sharing via Open Application Programming Interface (“Open API”): Secured data-sharing mechanisms using Open APIs can be tested within the sandbox.
  • Peer-to-peer lending (“P2P Lending”): Platforms that connect lenders and borrowers can be piloted in the sandbox.

Participation Conditions

Fintech companies must meet specific criteria depending on the solution they are piloting. The criteria will vary depending on the complexity and potential risks associated with the solution. For example, P2P lending platforms might face strict requirements on cybersecurity and network information security.

All participants must submit a registration dossier and obtain a Certificate of Participation from the SBV.

Monitoring and Risk Control

The SBV will closely monitor activities, evaluate participation, and assess the effectiveness of the piloted solutions, with a dedicated team to oversee activities within the sandbox, ensuring that participants comply with applicable regulations and that pilots are conducted safely and effectively.

Participating organizations are required to submit regular reports and provide ad hoc information on the pilot process, operational indicators, risks encountered, and the results of the pilot implementation to the SBV.

Customer Protection

Participating organizations have a responsibility to ensure customer rights and interests. This includes informing them about potential risks associated with using the piloted solution, obtaining their informed consent, and clearly outlining data privacy practices.

Participating organizations must implement robust security measures to safeguard customer data collected during the pilot program.

For dispute settlement, organizations are required to establish a customer complaint handling department and have clear mechanisms in place to address any disputes or complaints arising from the use of their piloted solutions.

Sandbox Conclusion

The pilot period will last a maximum of two years, with the SBV having the authority to adjust the length based on the actual implementation. After the pilot period, the SBV will decide on the next steps based on participating organizations’ reports, its own monitoring data, and any feedback received from relevant state authorities. Options will include terminating the pilot, certifying its completion, or extending the pilot period.

Participation in the Sandbox Mechanism does not guarantee an operating license or market approval for the piloted solutions.

Outlook

Once it is officially passed, it is hoped that the Fintech Sandbox Decree will usher in a new era of controlled experimentation in the sector, fostering a dynamic fintech ecosystem where innovation can thrive alongside robust regulations. By balancing innovation with consumer protection, cybersecurity, and data protection, it has the potential to transform Vietnam into a hub for groundbreaking fintech solutions, all while safeguarding the integrity of the financial system and consumers’ interests.

Now that the sandbox program has been streamlined to include only the three most prominent fintech solutions, the SBV might be able to speed up the official issuance of the Fintech Sandbox Decree.

RELATED INSIGHTS​ 

July 1, 2025
Now halfway through 2025, Thailand continues to advance in the realm of data privacy, with the ambitious goal of achieving zero data breaches. The Personal Data Protection Committee (PDPC), an independent government body established by the Personal Data Protection Act (PDPA), is taking a more proactive approach, having published several rulings and orders to enhance data protection measures and clarify compliance expectations for businesses. Here is a look back at Thailand’s data privacy developments in the first half of the year. Strengthening Law Enforcement and New Guidance for Compliance Enforcement of existing data protection laws and regulations has taken a step forward this year. Some of the specific initiatives include: Increased enforcement by the PDPC. A key trend to watch from the first half of 2025 is the PDPC’s active enforcement of the PDPA as it intensifies oversight through compliance orders and public warnings against noncompliant organizations while ramping up efforts to prevent and halt the illegal trading of personal data by actively monitoring emerging societal issues. Call center scams and cyber fraud control. Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Orders from the Expert Committee. Several orders issued by the Expert Committee under the PDPA were announced in the first half of this year. These include directives for data controllers to take corrective actions to comply with the PDPA, as well as initiatives to raise awareness of data privacy within organizations, reflecting the regulator’s focus on promoting organizational awareness and compliance. A guideline report summarizing the Expert Committee’s decisions and orders was also published to serve as a reference for compliance. Public issue monitoring. The PDPC has been taking a more proactive approach
June 27, 2025
Three American giants are actively protecting their intellectual property rights against generative AI, as two legal battles commence on both sides of the Atlantic. In the UK, Seattle-based media company Getty Images accuses UK-based Stability AI of multiple IP infringements. In the US, The Walt Disney Company and Universal Studios are teaming up against Midjourney, an AI startup, with their main ground being copyright infringement. Both cases are centered around questions legal minds have been posing since the introduction of generative AI: Is the output of generative AI an infringement? And who is ultimately responsible for the output, the platform or the user? Getty Images v. Stability AI Getty initially filed a claim in the High Court in 2023, which resulted in Stability applying for reverse summary judgment on the grounds that Getty had no real prospect of success, arguing that their operations took place outside the UK. However, the High Court judge hearing the case decided that the claims brought by Getty did have a real prospect of succeeding in court. Despite this, Stability saw a small victory when the court ruled that the representative action brought by Getty would not succeed due to the difficulties in identifying who qualified for the class. The proposed class was comprised of 50,000 rightsholders who alleged their rights were also infringed. Stability was successful in arguing that identifying these individuals would be challenging due to the unclear definition of the class. This current trial is centered around four main grounds: Copyright infringement. Getty accuses Stability of using content that Getty owns or has an exclusive license for when training their model, Stable Diffusion, resulting in the generated output containing substantial parts of that content. Getty is also alleging secondary copyright infringement, arguing that Stability is importing an article into the UK
June 26, 2025
Vietnam’s new Personal Data Protection Law (PDPL) was passed by the National Assembly on June 26, 2025, and will enter into force on January 1, 2026. The PDPL introduces several new concepts, exemptions, and obligations in comparison with the current Decree No. 13/2023/ND-CP on personal data protection (PDPD), while other contents remain essentially the same. The relationship between the PDPD and the PDPL has not been clearly addressed; however, it is expected that the government will issue a new decree providing necessary guidance on certain requirements under the PDPL, and the PDPD will remain in effect until it is replaced by this new decree. Some key points of the new PDPL include the following: Personal data will be further defined by lists of basic personal data and sensitive personal data to be issued by the government. The consent-centric approach of the PDPD remains in place, along with additional exemptions for certain data processing activities. The requirements for the data processing impact assessment (DPIA) and transfer impact assessment (TIA) remain unchanged. However, there are new exemptions for the TIA, including for the processing and storing in the cloud of employee data, and when the data subject is the person sending its own data outside of Vietnam. Consent obtained under the PDPD remains valid under the PDPL. DPIAs and TIAs submitted under the PDPD are valid under the PDPL but may need to be updated to be in line with the requirements of the PDPL. Administrative fines depend on the type of violation. The fine for sale and purchase of personal data will be 10 times the revenue from the sale or VND 3 billion (about USD 115,000), whichever is higher. The fine for cross-border transfer violations is 5% of the violator’s revenue of the preceding year or VND 3 billion,
June 25, 2025
Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption. The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight. For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues. The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks. Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully. Risks of GenAI Use The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant: Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training.