You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 26, 2023

Vietnam Signals Intent to Loosen Control Over OTT Telecom and Cloud Services

Vietnam’s Ministry of Information and Communications (MIC) organized a workshop with industry representatives on June 19, 2023, to discuss its future policy direction for over-the-top (OTT) telecom services and internet data center (IDC) and cloud computing services. OTT telecom services, in the MIC’s interpretation, are communication services such as text messages or voice calls provided over the internet—for example, the services of Zalo, WhatsApp, WeChat, etc.

The workshop, the first in an expected series, focused only on the discussion of policy on how to regulate these services.

Light-Touch Management Approach

A very positive signal of the MIC in the workshop was its clear intention to apply a “light-touch” approach to management. For cross-border provision of OTT telecom services and IDC/cloud computing services, the MIC intends to require notification and a post-check mechanism, instead of a heavy licensing or commercial arrangement regime like the one applicable to traditional telecom services. In addition, there is no limitation on foreign investment if foreigners would like to provide these services in Vietnam.

With regard to domestic service providers, the MIC proposes a registration regime with a similar post-check mechanism. The MIC’s reason for registration instead of notification is because the provision of these services by domestic companies may involve setting up data center/cloud systems which require consideration of various issues including location, electricity sources, and connection with telecom infrastructure such as marine cable. However, the MIC is also hoping to make the registration process as light as possible for enterprises (for example, using online registration) to provide a favorable environment and conditions to facilitate development of the industry without obstacles or cumbersome administrative procedures for companies’ operations.

For providers of these services, the MIC is also considering an exemption from the responsibility to pay fees for telecommunications activities rights, and from payment to the Telecom Universal Service Fund, which traditional telecom companies are subject to. However, the provision of these services still needs to comply with relevant regulations on consumer protection, data protection, cybersecurity, network information security, national security, and service quality.

The MIC is contemplating the requirement of a service quality announcement. If the OTT telecom or IDC/cloud computing service providers can assure the quality of their services, they should let users know. If they cannot assure the quality of their service—for example, if they have no commercial arrangement with telecom service providers for the provision of their services or their service quality depends entirely on the service quality of the telecom carriers—this also needs to be publicly announced.

Regulated Under the Telecom Law?

Whether these OTT telecom services and IDC/cloud computing services should be regulated under the Telecom Law was a key issue discussed in the workshop. The MIC explained that the WTO defines value-added telecom services as services for storing and retrieving information through telecom networks, and Vietnam’s schedule of commitments on telecom services in the WTO also mentions information storage and information retrieval services. As IDC/cloud computing services involve storing and retrieving information through telecom networks, they should be considered telecom services. Countries such as China, Thailand, Korea have set a precedent by regulating IDC/cloud computing services as telecom services under their telecom laws. Currently, there are no regulations on conditions for market access and business conditions for providing these types of services, while Vietnam’s Investment Law clearly stipulates that data center services are conditional services. Thus, there is a need to regulate these services under the Telecom Law to overcome legal gaps and create facilitation and transparency for enterprises investing in and providing these services.

With regard to OTT communication services, 27 countries of the EU, China, and Korea are considering these services as telecom services and regulating them under their telecom laws. These OTT services are used more and more frequently and potentially will replace traditional telecom services, while the existing Telecom Law does not regulate these services, leading to the rights of users and information security not being ensured. Therefore, according to the MIC, it is appropriate to regulate these OTT services under the Telecom Law. However, according to the MIC, the Telecom Law will only provide a framework and will leave all the details to be regulated by a decree.

It is worth noting that the MIC only intends to regulate the provision of OTT telecom services when such services are the primary business of a company. When communication functions are merely add-ons and the company’s main business is not telecom services—for example, the chat/call functions of transportation services like Grab or social networks like YouTube—the MIC will consider exempting these add-on services from the scope of application of OTT telecom services.

While the industry representatives in the meeting were highly appreciative of the MIC’s approach and its openness and willingness to work closely with businesses and take their input into account, they expressed a strong sentiment for not including these services under the Draft Telecom Law. Rather, if these services need to be regulated, they should be regulated in a separate legal document.

The industry argument was that with the convergence of technology and the integration of many sectors and services, the differences between value-added telecom services and IT services have become very blurred and many countries have started deviating from this distinction. Data center/cloud computing services are more of the nature of IT services instead of telecom services. Also, OTT communication services do not use telecom resources such as frequency or numbering, they do not own telecom infrastructure to provide services, and they do not require interconnection to the public telecom network; they are essentially just applications and, like any application, they use the internet for service provision. Therefore, they should not be considered telecom services.

If the MIC still considers them telecom services and wishes to regulate them under the Telecom Law, the industry representatives strongly recommended that there should be separate chapters of the law and separate rules for these services, and the language of the law must clearly exempt these services from general rules governing traditional telecom services. In addition, the wording of the regulations should be straightforward and easy to understand, to avoid ambiguity and confusion in interpretation and implementation.

The MIC reassured the industry of their light-touch management approach and said this was just a matter of drafting techniques in putting those provisions under the Draft Telecom Law, and the MIC will involve the industry closely in the drafting process to ensure there is no confusion as to the policy intention in regulating these services.

 Moving Forward

The MIC appeared very open and willing to take input from the industry. It will continue holding workshops and dialogues and closely engage the industry in the drafting process, so that the Draft Telecom Law (amendment) which will be submitted to the National Assembly for a second reading and approval in November 2023 will achieve the purposes of creating transparency and facilitating an environment for business development and technology innovation.

It is therefore strongly recommended that businesses, associations, and experts should pay attention to the drafting process of this Draft Telecom Law and actively contribute opinions to the MIC.

RELATED INSIGHTS​ 

June 19, 2025
The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices. The BOT is accepting public comments on the draft guidelines until June 30, 2025. Scope and Application The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct. The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching. Key Risk Management Principles The guidelines lay out two main principles in managing AI risk. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows: Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management
June 19, 2025
Thailand’s Electronic Transactions Development Agency (ETDA) has announced plans for increased enforcement of the Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022). The ETDA outlined a comprehensive enforcement framework and review process during an online meeting with digital platform service operators on June 11, 2025. The ETDA’s enhanced enforcement approach includes systematic reviews of notification submissions, formal correction orders, and potential criminal penalties for noncompliance. Digital platform operators should immediately assess their current notification status and prepare for increased regulatory scrutiny. Review and Amendment of Previously Submitted Notification Data The ETDA will begin reviewing operation notification forms and annual reports submitted by digital platform service operators to assess each platform’s risk level and develop tailored regulatory obligations. In this comprehensive review process, the ETDA will: Examine the accuracy and completeness of submitted notification data; Request additional information as needed by phone or email; and Issue formal orders as needed requiring operators to correct or complete missing information. Operators who fail to comply with ETDA orders may face suspension of operations, revocation of their notification receipt, and public disclosure of their noncompliant status on the ETDA’s website. The ETDA will conduct follow-up workshops in July 2025 for operators whose data remains unclear or incomplete. Enforcement Framework and Penalties The ETDA outlined a three-tiered enforcement framework with escalating consequences for different types of violations, as follows: Failure to notify before commencing operations: Operators who begin services without proper notification may face criminal penalties under the Electronic Transactions Act, including up to one year of imprisonment, fines of up to THB 100,000 (approx. USD 3,070), or both. Additional consequences include suspension of operations and potential liability for company directors. Failure to correct or comply with official orders: Noncompliance with ETDA correction
June 13, 2025
In today’s digital age, cyberattacks have become a real threat to organizations worldwide. These attacks can range from phishing and malware to ransomware and distributed denial of service (DDoS) attacks. As the frequency and sophistication of these attacks increase, so does the importance of cybersecurity compliance. In the corporate world, compliance refers to the process of ensuring that a company and its employees adhere to all relevant laws, regulations, standards, and ethical practices—but it should not stop there. Compliance should also encompass asset recovery and disciplinary measures, which can both help organizations address incidents effectively and promote good governance. Cyberattacks are malicious attempts to access or damage a computer system or network, often carried out for financial gain, for political activism, or simply to cause disruption. For instance, a successful attack might involve an attacker creating an email address that closely resembles a legitimate one, perhaps by changing only one or two characters. That email address is then inserted into an existing conversation thread, making it appear as if the user with this email address was already part of the discussion. This tactic can easily deceive a recipient into believing the email was sent from a trusted source, thereby leading them to click on malicious links, provide sensitive information, or even make payments in accordance with the attacker’s request or instructions. Phishing attacks like these are particularly dangerous and can have a serious impact on the ongoing business of a corporation because they exploit the trust and familiarity established in the original email chain. Effective Mitigation Approaches Mechanisms for addressing the aftermath of a crisis provide important recourse to affected organizations, but effective compliance mechanisms can minimize the risk of such crises ever occurring. Companies should therefore prioritize preventative measures and implementation of effective crisis management schemes. Various legal
May 28, 2025
Tilleke & Gibbins attorneys in Vietnam have contributed the 2025 edition of Doing Business in Vietnam, a comprehensive Q&A-style resource from Thomson Reuters Practical Law that provides essential insights for companies navigating business operations in Vietnam. The guide presents a detailed overview of the country’s legal framework and regulatory environment, reflecting recent updates in Vietnamese legislation and practice. This annually updated guide offers key information on the following areas: Legal system: Structure of the Vietnamese judiciary and the role of codified law. Foreign investment: Conditions for market access, licensing requirements, foreign ownership restrictions, and investment incentives. Business vehicles: Formation and operation of legal entities, including limited liability companies, joint-stock companies, and representative offices. Employment: Employment contracts, social insurance, labor rights, and procedures for hiring foreign nationals. Tax: Overview of corporate income tax, personal income tax, value-added tax, and other tax obligations. Intellectual property: Procedures for protecting and enforcing patents, trademarks, copyrights, and other IP rights. Data protection: Compliance requirements under Vietnam’s data privacy laws, including the Personal Data Protection Decree. Competition law: Antitrust rules and regulatory oversight under the Law on Competition. Anti-bribery and corruption: Legal framework and enforcement practices aimed at curbing corrupt activities. E-commerce and digital business: Regulations governing online platforms, digital content, and cross-border services. Marketing and advertising: Laws and guidelines on advertising standards and consumer protection. Product regulation and liability: Safety requirements, product liability issues, and roles of relevant authorities. Doing Business in Vietnam is part of Practical Law’s global series of legal guides designed to support international practitioners and businesses. To access the most recent edition of the Vietnam guide, visit the Practical Law website and sign up for a free trial.