You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 26, 2023

Vietnam Signals Intent to Loosen Control Over OTT Telecom and Cloud Services

Vietnam’s Ministry of Information and Communications (MIC) organized a workshop with industry representatives on June 19, 2023, to discuss its future policy direction for over-the-top (OTT) telecom services and internet data center (IDC) and cloud computing services. OTT telecom services, in the MIC’s interpretation, are communication services such as text messages or voice calls provided over the internet—for example, the services of Zalo, WhatsApp, WeChat, etc.

The workshop, the first in an expected series, focused only on the discussion of policy on how to regulate these services.

Light-Touch Management Approach

A very positive signal of the MIC in the workshop was its clear intention to apply a “light-touch” approach to management. For cross-border provision of OTT telecom services and IDC/cloud computing services, the MIC intends to require notification and a post-check mechanism, instead of a heavy licensing or commercial arrangement regime like the one applicable to traditional telecom services. In addition, there is no limitation on foreign investment if foreigners would like to provide these services in Vietnam.

With regard to domestic service providers, the MIC proposes a registration regime with a similar post-check mechanism. The MIC’s reason for registration instead of notification is because the provision of these services by domestic companies may involve setting up data center/cloud systems which require consideration of various issues including location, electricity sources, and connection with telecom infrastructure such as marine cable. However, the MIC is also hoping to make the registration process as light as possible for enterprises (for example, using online registration) to provide a favorable environment and conditions to facilitate development of the industry without obstacles or cumbersome administrative procedures for companies’ operations.

For providers of these services, the MIC is also considering an exemption from the responsibility to pay fees for telecommunications activities rights, and from payment to the Telecom Universal Service Fund, which traditional telecom companies are subject to. However, the provision of these services still needs to comply with relevant regulations on consumer protection, data protection, cybersecurity, network information security, national security, and service quality.

The MIC is contemplating the requirement of a service quality announcement. If the OTT telecom or IDC/cloud computing service providers can assure the quality of their services, they should let users know. If they cannot assure the quality of their service—for example, if they have no commercial arrangement with telecom service providers for the provision of their services or their service quality depends entirely on the service quality of the telecom carriers—this also needs to be publicly announced.

Regulated Under the Telecom Law?

Whether these OTT telecom services and IDC/cloud computing services should be regulated under the Telecom Law was a key issue discussed in the workshop. The MIC explained that the WTO defines value-added telecom services as services for storing and retrieving information through telecom networks, and Vietnam’s schedule of commitments on telecom services in the WTO also mentions information storage and information retrieval services. As IDC/cloud computing services involve storing and retrieving information through telecom networks, they should be considered telecom services. Countries such as China, Thailand, Korea have set a precedent by regulating IDC/cloud computing services as telecom services under their telecom laws. Currently, there are no regulations on conditions for market access and business conditions for providing these types of services, while Vietnam’s Investment Law clearly stipulates that data center services are conditional services. Thus, there is a need to regulate these services under the Telecom Law to overcome legal gaps and create facilitation and transparency for enterprises investing in and providing these services.

With regard to OTT communication services, 27 countries of the EU, China, and Korea are considering these services as telecom services and regulating them under their telecom laws. These OTT services are used more and more frequently and potentially will replace traditional telecom services, while the existing Telecom Law does not regulate these services, leading to the rights of users and information security not being ensured. Therefore, according to the MIC, it is appropriate to regulate these OTT services under the Telecom Law. However, according to the MIC, the Telecom Law will only provide a framework and will leave all the details to be regulated by a decree.

It is worth noting that the MIC only intends to regulate the provision of OTT telecom services when such services are the primary business of a company. When communication functions are merely add-ons and the company’s main business is not telecom services—for example, the chat/call functions of transportation services like Grab or social networks like YouTube—the MIC will consider exempting these add-on services from the scope of application of OTT telecom services.

While the industry representatives in the meeting were highly appreciative of the MIC’s approach and its openness and willingness to work closely with businesses and take their input into account, they expressed a strong sentiment for not including these services under the Draft Telecom Law. Rather, if these services need to be regulated, they should be regulated in a separate legal document.

The industry argument was that with the convergence of technology and the integration of many sectors and services, the differences between value-added telecom services and IT services have become very blurred and many countries have started deviating from this distinction. Data center/cloud computing services are more of the nature of IT services instead of telecom services. Also, OTT communication services do not use telecom resources such as frequency or numbering, they do not own telecom infrastructure to provide services, and they do not require interconnection to the public telecom network; they are essentially just applications and, like any application, they use the internet for service provision. Therefore, they should not be considered telecom services.

If the MIC still considers them telecom services and wishes to regulate them under the Telecom Law, the industry representatives strongly recommended that there should be separate chapters of the law and separate rules for these services, and the language of the law must clearly exempt these services from general rules governing traditional telecom services. In addition, the wording of the regulations should be straightforward and easy to understand, to avoid ambiguity and confusion in interpretation and implementation.

The MIC reassured the industry of their light-touch management approach and said this was just a matter of drafting techniques in putting those provisions under the Draft Telecom Law, and the MIC will involve the industry closely in the drafting process to ensure there is no confusion as to the policy intention in regulating these services.

 Moving Forward

The MIC appeared very open and willing to take input from the industry. It will continue holding workshops and dialogues and closely engage the industry in the drafting process, so that the Draft Telecom Law (amendment) which will be submitted to the National Assembly for a second reading and approval in November 2023 will achieve the purposes of creating transparency and facilitating an environment for business development and technology innovation.

It is therefore strongly recommended that businesses, associations, and experts should pay attention to the drafting process of this Draft Telecom Law and actively contribute opinions to the MIC.

RELATED INSIGHTS​ 

July 24, 2025
Vietnam’s Ministry of Public Security recently released a draft version of the 2025 Cybersecurity Law, which is intended to replace both the existing 2018 Cybersecurity Law and the 2015 Law on Network Information Security (LNIS). This consolidation reflects a broader effort by the Vietnamese government to streamline and centralize the legal framework governing cybersecurity, data protection, and information security to be under the sole authority of the Ministry of Public Security, moving away from the previous sharing of responsibility with the former Ministry of Information and Communications (which ceased operations earlier this year and merged with the Ministry of Science and Technology). This shift aims to eliminate overlaps and improve enforcement efficiency. The draft law is built upon the foundation of principles and provisions of both the 2018 Cybersecurity Law and the 2015 LNIS, while also introducing a wide range of amendments and new regulations. By merging the two laws, the government seeks to reduce legal fragmentation and ensure consistency in definitions, obligations, and enforcement mechanisms across related domains like data protection, IT system classification, and cybercrime prevention. The newly introduced amendments include enhanced obligations for service providers, stricter controls on information transmission, classification of IT systems, designation and protection of nationally important information systems, and sector-specific violations and compliance requirements. Highlights of the draft law are discussed below. Definition and Obligations of Service Providers The draft law clearly defines and significantly broadens the scope of entities considered “service providers” under its jurisdiction. This now includes businesses and individuals offering products or services in cyberspace, including both infrastructure and content online services, such as: Internet service providers (ISPs) and providers of telecommunications, hosting, servers, domain names, VPNs, proxy services, and cloud computing; Providers of social networks, websites, and online gaming; Financial institutions, banks, foreign bank branches in Vietnam, e-wallet
July 23, 2025
On July 4, 2025, Thailand’s Electronic Transactions Development Agency (ETDA) issued two significant notifications that introduce new compliance requirements for ride-hailing platforms operating in the country. The notifications formally designate these platforms as high-impact digital services under section 18(3) of the Royal Decree on Digital Platform Service Businesses and impose a comprehensive set of additional operational obligations. These measures are designed to address regulatory gaps and enhance oversight of digital platforms providing public passenger vehicle or motorcycle ride-hailing services. First, the Notification on the Designation of Ride-Hailing Platforms under section 18(3) formally designates all ride-hailing platforms that have notified the ETDA of their operations as high-impact digital platform services under section 18(3) of the royal decree. Unlike high-risk marketplace platforms, which are named individually, any ride-hailing platform that has notified the ETDA of its operations is automatically subject to these new requirements. Next, the Notification on Additional Obligations for Ride-Hailing Platforms imposes further obligations on ride-hailing platforms, supplementing the general requirements under section 21 of the royal decree. These notifications will come into force 90 days from their publication in the Government Gazette. New Compliance Obligations The new regulatory framework introduces a range of operational, technical, and reporting requirements for ride-hailing platforms, particularly concerning the issues described below. Vehicle and Driver Compliance Operators must: Ensure that all vehicles used on the platform are registered as public vehicles in accordance with Department of Land Transport requirements Verify all drivers hold valid public driving licenses Collect service fees in compliance with applicable fare regulations under the Vehicle Law Digital Platform Features and User Verification Operators must implement robust digital platform features for both drivers and riders, including: Comprehensive identity verification and confirmation processes for drivers and riders, utilizing both face-to-face and non-face-to-face methods, including biometric and digital ID checks Real-time GPS
July 17, 2025
On July 9, 2025, Thailand issued a notification that introduces comprehensive operational requirements for digital platform service providers operating as goods marketplaces, effective December 31, 2025 (i.e., 180 days after its publication in the Government Gazette). The regulation’s official name is Notification of the Electronic Transactions Committee Re: Other Actions for Digital Platform Service Operators in the Category of Marketplace for Goods with Specific Characteristics under Section 18(2) of the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification B.E. 2565 (2022), B.E. 2568 (2025). Scope of Application The notification applies exclusively to goods marketplace operators formally designated by the Electronic Transactions Development Agency (ETDA), which on the same day designated 19 platforms that had previously notified the ETDA of their operations. The goods requiring enhanced oversight by these operators are limited to those regulated by the Thai Food and Drug Administration (FDA) and the Thai Industrial Standards Institute (TISI). Development from Earlier Draft An earlier draft of the notification had included a requirement for offshore platforms to establish a local entity, but this requirement was removed from the final notification. Key Obligations Despite the removal of the local entity requirement, the notification imposes a range of additional obligations on designated goods marketplace operators: Transparency. Operators must implement robust transparency measures, including clear, accessible, and understandable disclosures to users in Thai. These disclosures must cover all relevant terms and conditions, comprehensive product information, and complaint management procedures. Operators must also submit an annual compliance report to the ETDA within 60 days after the end of their accounting period, including statistics on regulated goods. Business user registration and identity verification. Before permitting the sale or advertisement of regulated goods, operators must collect and verify business user information, including contact details, identification documents, registration
July 15, 2025
Thailand has established new safe harbor rules that require social media platforms to remove specified content within 24 hours of government notification. On July 5, 2025, the Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers was issued and took effect. This followed a hearing in May 2025 where only a select group of social media and online communication platform operators were invited to attend and comment on draft rules that could exempt social media platform operators from joint liability under the amended Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes in cases involving victims of technological crimes. Safe Harbor Rules The notification stipulates procedures that must be followed in order to receive the protection of the safe harbor rules. Upon being notified by the Division of Prevention and Suppression of Cybercrime, Office of the Permanent Secretary of the Ministry of Digital Economy and Society (MDES) of the presence of false or misleading information that may lead to the commission of a technological crime, social media service providers must immediately take down the specified content, with a maximum allowable turnaround time of 24 hours from the time of receiving the notification. Social media service providers are required to promptly report the outcome of each takedown to the MDES Division of Prevention and Suppression. This shift in Thailand’s regulatory approach to social media content moderation establishes clear government oversight mechanisms while providing platforms with liability protection for compliance. As the new rules took immediate effect, social media platforms need to ensure that they have adequate systems and processes in place to comply with the requirements.