You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 26, 2023

Vietnam Signals Intent to Loosen Control Over OTT Telecom and Cloud Services

Vietnam’s Ministry of Information and Communications (MIC) organized a workshop with industry representatives on June 19, 2023, to discuss its future policy direction for over-the-top (OTT) telecom services and internet data center (IDC) and cloud computing services. OTT telecom services, in the MIC’s interpretation, are communication services such as text messages or voice calls provided over the internet—for example, the services of Zalo, WhatsApp, WeChat, etc.

The workshop, the first in an expected series, focused only on the discussion of policy on how to regulate these services.

Light-Touch Management Approach

A very positive signal of the MIC in the workshop was its clear intention to apply a “light-touch” approach to management. For cross-border provision of OTT telecom services and IDC/cloud computing services, the MIC intends to require notification and a post-check mechanism, instead of a heavy licensing or commercial arrangement regime like the one applicable to traditional telecom services. In addition, there is no limitation on foreign investment if foreigners would like to provide these services in Vietnam.

With regard to domestic service providers, the MIC proposes a registration regime with a similar post-check mechanism. The MIC’s reason for registration instead of notification is because the provision of these services by domestic companies may involve setting up data center/cloud systems which require consideration of various issues including location, electricity sources, and connection with telecom infrastructure such as marine cable. However, the MIC is also hoping to make the registration process as light as possible for enterprises (for example, using online registration) to provide a favorable environment and conditions to facilitate development of the industry without obstacles or cumbersome administrative procedures for companies’ operations.

For providers of these services, the MIC is also considering an exemption from the responsibility to pay fees for telecommunications activities rights, and from payment to the Telecom Universal Service Fund, which traditional telecom companies are subject to. However, the provision of these services still needs to comply with relevant regulations on consumer protection, data protection, cybersecurity, network information security, national security, and service quality.

The MIC is contemplating the requirement of a service quality announcement. If the OTT telecom or IDC/cloud computing service providers can assure the quality of their services, they should let users know. If they cannot assure the quality of their service—for example, if they have no commercial arrangement with telecom service providers for the provision of their services or their service quality depends entirely on the service quality of the telecom carriers—this also needs to be publicly announced.

Regulated Under the Telecom Law?

Whether these OTT telecom services and IDC/cloud computing services should be regulated under the Telecom Law was a key issue discussed in the workshop. The MIC explained that the WTO defines value-added telecom services as services for storing and retrieving information through telecom networks, and Vietnam’s schedule of commitments on telecom services in the WTO also mentions information storage and information retrieval services. As IDC/cloud computing services involve storing and retrieving information through telecom networks, they should be considered telecom services. Countries such as China, Thailand, Korea have set a precedent by regulating IDC/cloud computing services as telecom services under their telecom laws. Currently, there are no regulations on conditions for market access and business conditions for providing these types of services, while Vietnam’s Investment Law clearly stipulates that data center services are conditional services. Thus, there is a need to regulate these services under the Telecom Law to overcome legal gaps and create facilitation and transparency for enterprises investing in and providing these services.

With regard to OTT communication services, 27 countries of the EU, China, and Korea are considering these services as telecom services and regulating them under their telecom laws. These OTT services are used more and more frequently and potentially will replace traditional telecom services, while the existing Telecom Law does not regulate these services, leading to the rights of users and information security not being ensured. Therefore, according to the MIC, it is appropriate to regulate these OTT services under the Telecom Law. However, according to the MIC, the Telecom Law will only provide a framework and will leave all the details to be regulated by a decree.

It is worth noting that the MIC only intends to regulate the provision of OTT telecom services when such services are the primary business of a company. When communication functions are merely add-ons and the company’s main business is not telecom services—for example, the chat/call functions of transportation services like Grab or social networks like YouTube—the MIC will consider exempting these add-on services from the scope of application of OTT telecom services.

While the industry representatives in the meeting were highly appreciative of the MIC’s approach and its openness and willingness to work closely with businesses and take their input into account, they expressed a strong sentiment for not including these services under the Draft Telecom Law. Rather, if these services need to be regulated, they should be regulated in a separate legal document.

The industry argument was that with the convergence of technology and the integration of many sectors and services, the differences between value-added telecom services and IT services have become very blurred and many countries have started deviating from this distinction. Data center/cloud computing services are more of the nature of IT services instead of telecom services. Also, OTT communication services do not use telecom resources such as frequency or numbering, they do not own telecom infrastructure to provide services, and they do not require interconnection to the public telecom network; they are essentially just applications and, like any application, they use the internet for service provision. Therefore, they should not be considered telecom services.

If the MIC still considers them telecom services and wishes to regulate them under the Telecom Law, the industry representatives strongly recommended that there should be separate chapters of the law and separate rules for these services, and the language of the law must clearly exempt these services from general rules governing traditional telecom services. In addition, the wording of the regulations should be straightforward and easy to understand, to avoid ambiguity and confusion in interpretation and implementation.

The MIC reassured the industry of their light-touch management approach and said this was just a matter of drafting techniques in putting those provisions under the Draft Telecom Law, and the MIC will involve the industry closely in the drafting process to ensure there is no confusion as to the policy intention in regulating these services.

 Moving Forward

The MIC appeared very open and willing to take input from the industry. It will continue holding workshops and dialogues and closely engage the industry in the drafting process, so that the Draft Telecom Law (amendment) which will be submitted to the National Assembly for a second reading and approval in November 2023 will achieve the purposes of creating transparency and facilitating an environment for business development and technology innovation.

It is therefore strongly recommended that businesses, associations, and experts should pay attention to the drafting process of this Draft Telecom Law and actively contribute opinions to the MIC.

RELATED INSIGHTS​ 

August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention
July 30, 2025
Artificial intelligence (AI) model training and data scraping are essential processes in the development of modern AI systems. AI model training involves using large datasets to teach machine learning algorithms to recognize patterns, make predictions, or generate new content. Data scraping refers to the automated extraction of information from websites or digital sources, often to assemble the vast datasets required for effective AI training. As these practices become more widespread, questions about the legality of using third-party content—especially copyrighted works—have become increasingly important. In Thailand, the legal landscape for AI developers is shaped primarily by the Copyright Act, which presents unique challenges due to the absence of a fair-use exception. This article examines the copyright-related risks and legal uncertainties facing AI developers under Thailand’s current copyright law and practices, offering strategic guidance for navigating this complex environment. Copyright Risks in AI Scraping and Training Thailand’s Copyright Act does not provide a broad fair use or fair dealing exception, unlike some other jurisdictions, such as the United States. This absence has significant consequences for AI developers: No general defense for AI training: Any use of copyrighted material for AI model training is presumed to be infringing unless a specific, narrow statutory exception applies or explicit permission is obtained from the rights holder. There is no general legal basis for using copyrighted works in AI training without authorization. Increased rights clearance burden: Developers must identify and secure licenses for every copyrighted work included in their training datasets. Given the scale and diversity of data required for effective AI models, this process can be both impractical and costly. Legal ambiguity and litigation risk: The lack of clear statutory guidance or case law leaves developers in a legal gray area. There is no established precedent clarifying whether certain uses of copyrighted material for
July 24, 2025
Thai authorities have escalated efforts to block unlawful cross-border digital asset business operators. On June 19, 2025, the Ministry of Digital Economy and Society (MDES) issued a notification empowering it to ban internet access to operations or services offered by digital asset business operators who lack licenses from the Thailand Securities and Exchange Commission (SEC) under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This ban, issued under the 2023 Royal Decree on Measures for the Prevention and Suppression of Technology Crime, particularly aims to block Thai users’ access to services offered by unlicensed offshore digital asset providers via their own apps or websites or through public social media platforms. Compliance Requirements The notification requires internet service providers and social media platforms selected by MDES to immediately impose internet access restrictions on identified apps, websites, and IP addresses of illegal operators upon receiving MDES orders. Takedown Orders There are two tracks for competent officials at MDES to issue orders to operators: If the competent official is notified by the SEC of licensing noncompliance by a particular digital asset business operator, the competent official can issue a takedown order to the operator upon approval from the permanent secretary of MDES. If the competent official independently discovers, or receives a complaint from any third party other than the SEC, that a digital asset business operator may have violated licensing requirements, the competent official can ask the SEC to verify and confirm the relevant facts and noncompliance before seeking approval from the permanent secretary of MDES to issue the takedown order. Streamlined Enforcement Prior to this notification, the SEC could obtain takedown orders only from Thai courts under the 2007 Computer Crime Act to take down or block access to unlicensed digital asset platforms and apps. This was a relatively
July 24, 2025
Vietnam’s Ministry of Public Security recently released a draft version of the 2025 Cybersecurity Law, which is intended to replace both the existing 2018 Cybersecurity Law and the 2015 Law on Network Information Security (LNIS). This consolidation reflects a broader effort by the Vietnamese government to streamline and centralize the legal framework governing cybersecurity, data protection, and information security to be under the sole authority of the Ministry of Public Security, moving away from the previous sharing of responsibility with the former Ministry of Information and Communications (which ceased operations earlier this year and merged with the Ministry of Science and Technology). This shift aims to eliminate overlaps and improve enforcement efficiency. The draft law is built upon the foundation of principles and provisions of both the 2018 Cybersecurity Law and the 2015 LNIS, while also introducing a wide range of amendments and new regulations. By merging the two laws, the government seeks to reduce legal fragmentation and ensure consistency in definitions, obligations, and enforcement mechanisms across related domains like data protection, IT system classification, and cybercrime prevention. The newly introduced amendments include enhanced obligations for service providers, stricter controls on information transmission, classification of IT systems, designation and protection of nationally important information systems, and sector-specific violations and compliance requirements. Highlights of the draft law are discussed below. Definition and Obligations of Service Providers The draft law clearly defines and significantly broadens the scope of entities considered “service providers” under its jurisdiction. This now includes businesses and individuals offering products or services in cyberspace, including both infrastructure and content online services, such as: Internet service providers (ISPs) and providers of telecommunications, hosting, servers, domain names, VPNs, proxy services, and cloud computing; Providers of social networks, websites, and online gaming; Financial institutions, banks, foreign bank branches in Vietnam, e-wallet