You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 14, 2021

Vietnam’s Decree 21 Updates Regulations on Security for Performance of Obligations

On May 15, 2021, Decree No. 21/2021/ND-CP of the Government of Vietnam dated March 19, 2021, guiding the implementation of the Civil Code of 2015 on security for performance of obligations (Decree 21) will come into effect and replace Decree No. 163/2006/ND-CP of the Government dated December 29, 2006, on security transactions, as amended by Decree No. 11/2012/ND-CP (together, “Decree 163”).

One of the most significant changes of Decree 21 in comparison to Decree 163 is the new system of terminology in relation to security for performance of obligations. In particular, the new decree provides new definitions for existing terms such as “guarantor” and “guarantee” and sets out the definitions of newly added terms such as “secured obligator,” “security contract,” and “reasonable duration.” This change reflects the intention of the legislators to unify the relevant terminology in accordance with the Civil Code of 2015.

Article 4 of Decree 21 lists out principles for the application of laws and the parties’ agreements on security for performance of obligations. Accordingly, in cases where the laws on specialized areas such as land, housing, insurance, banking, aviation, or intellectual property have provisions on security assets, establishment and implementation of means of security, or enforcement of security assets, the provisions of the specialized laws will prevail. Moreover, if the parties have agreements that are different from provisions in Decree 21 but do not violate (i) fundamental principles of civil law or (ii) conditions for a civil transaction to be valid or (iii) limitations on the exercise of civil rights in accordance with the Civil Code or other relevant laws, such agreements may be enforced.

Decree 21 devotes an entire chapter to regulations on security assets (collateral) which includes definitions and descriptions of security assets and detailed provisions on 10 types of security assets including land use rights and assets attached to land, objects, valuable papers, etc. Notably, Decree 21 no longer provides that a security asset may not be attached by the courts or authorities to perform the guarantor’s other obligations if the security transaction is valid and effective against third parties and the laws do not regulate otherwise, as provided under Decree 163. This change makes the new decree consistent with the existing regulations on enforcement of civil judgments which state that mortgaged or pledged assets may still be attached for the purpose of enforcement of civil judgments, provided that the applicable conditions are satisfied.

The new decree provides detailed regulations on the establishment and implementation of means of security and enforcement of security assets. Accordingly, a means of security may be established based on the agreement of the parties via a security contract or a lien. For enforcement of security assets, Decree 21 goes into detail on the enforcement of future assets or invested mortgaged assets for the first time.

Decree 163 will still be applicable to security agreements or security interests which were established and implemented prior to May 15, 2021. The parties to such security agreements or security interests which have not been implemented or have been implemented but contain provisions different from provisions under Decree 21 may, but are not required to, agree to amend the existing security agreements or security interests to comply with the new decree.

RELATED INSIGHTS​ 

November 14, 2025
Interest in data center land acquisition has increased significantly over the past year, with a notable rise in inquiries from investors seeking to establish digital infrastructure in Thailand. Although the sector is still in its early stages, this emerging wave of development represents a significant shift in Thailand’s technology infrastructure landscape, driven primarily by multinational technology companies and operators looking to expand their regional presence. Project Development The data center sector in Thailand is attracting a diverse range of international investors, though with clear geographic patterns. Most investors are from China, Singapore, and Japan, with some additional interest from countries outside Asia, including the United States and Europe. This investor base consists primarily of multinational tech companies and operators seeking to establish new facilities rather than acquire existing assets. Data center business activities are also a sector promoted by Thailand’s Board of Investment (BOI), which offers investors both tax and nontax privileges as well as exemptions to foreign investment and land-ownership restrictions. Projects currently underway are still largely in the land acquisition and construction phase. Unlike more mature markets where many facilities are operational and generating revenue, the predominant focus in Thailand remains on securing suitable land and beginning the building process. This means that while interest is high and land assembly is accelerating, the sector as a whole has not yet reached the operational phase that will ultimately drive licensing applications and full regulatory compliance. The licensing process itself remains at an early stage, as most projects must first complete their facilities before applying for the specific licenses required from the telecommunications authority. Once the facilities are built, the next critical step will be obtaining these telecommunications licenses, which are mandatory for data center operations. Legal and Regulatory Considerations The complexity of data center development in Thailand requires
November 13, 2025
Tilleke & Gibbins has contributed the Thailand chapter to Franchise 2026, part of the International Comparative Legal Guides (ICLG) series published by Global Legal Group. This annual guide offers comparative analysis of franchise laws and regulations across jurisdictions worldwide, providing practical insights for businesses and legal practitioners operating in the global franchise sector. Each country chapter in the 12th edition follows a Q&A format covering key aspects of franchise law and operations, including: Relevant legislation and rules governing franchise transactions Business organization options for franchised operations Competition law considerations Protection of intellectual property and brands Liability issues and risk mitigation Governing law and dispute resolution Real estate matters Online trading regulations Termination requirements Joint employer risks and vicarious liability Currency controls and taxation Commercial agency considerations Good faith obligations and fair dealing requirements Ongoing relationship management Franchise renewal processes Franchise migration procedures Sustainability commitments Electronic signatures and document retention Current developments in the franchise sector The Thailand chapter, authored by Alan Adcock and Kasama Sriwatanakul, provides an in-depth overview of the legal landscape for franchising and franchising-related activities in Thailand. The complete Thailand chapter is available as a PDF below. The Thailand chapter—and the full Franchise 2026 guide—are also freely available on the ICLG website.
November 7, 2025
Thailand and the United States signed a memorandum of understanding (MOU) titled “Cooperation to Diversify Global Critical Minerals Supply Chains and Promote Investments” on October 26, 2025, signaling a new strategic alignment aimed at developing Thailand’s mineral sector, particularly in rare earth elements (REEs). The MOU has implications for investments in technology, manufacturing, and other related sectors. This update outlines the key provisions of the MOU and the potential opportunities and legal navigating points for businesses. Objectives The primary driver of this agreement is the US initiative to diversify global supply chains for critical minerals and reduce reliance on current market leaders, particularly China. For Thailand, it represents a major opportunity to attract high-tech investment and develop its downstream processing industries. The cooperation is set to focus on five main areas: Technical knowledge: Exchange of technical expertise and international best practices to strengthen Thailand’s mining and processing sector. Joint cooperation: Establishing workshops, seminars, and scientific collaboration to boost innovation. Regulatory practice: Promoting good governance and streamlining regulatory and licensing procedures. Information sharing: Sharing data on potential projects and global market prices. Full-value chain: The MOU covers the entire mineral lifecycle, from exploration and extraction to processing, refining, and recycling. “First Opportunity to Invest” Clause The most debated provision within the MOU states that “participants expect to have the first opportunity to invest . . . in critical minerals assets that may be sold in Thailand.” Business implications: This clause is widely interpreted as granting US companies a first look or preferential access to investment opportunities in Thailand’s critical minerals sector. This could be a significant advantage for US-based or affiliated companies in mining, technology, and energy seeking to secure a foothold in a developing REE supply chain. Thai government position: Thai officials, including the prime minister, have publicly clarified
October 31, 2025
On September 29, 2025, Thailand’s Office of the Personal Data Protection Committee (PDPC Office) published its Regulations on the Review and Certification of Binding Corporate Rules B.E. 2568 (2025) (the Regulations). The Regulations provide clarity on the PDPC Office’s approach to reviewing and certifying binding corporate rules (BCRs) under Section 29 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA), and aim to facilitate international data transfers within a group of undertakings or enterprises (a “corporate group”). In conjunction with this development, the PDPC Office also approved BCRs for two companies operating in Thailand on September 30, 2025. This milestone represents the first concrete progress since the PDPC’s Notification on Criteria for the Protection of Personal Data Sent or Transferred to a Foreign Country pursuant to Section 29 of the PDPA B.E. 2566 (2023) came into effect in March 2024. Some key features of the Regulations are set out below. Categorization of BCRs BCRs are classified into two types: (1) BCRs for Controllers (BCR-C) and (2) BCRs for Processors (BCR-P). The category must be clearly specified when submitting the BCRs to the PDPC Office. Documentation Requirement The applicant must prepare and submit the application (a standard template may be provided by the PDPC Office in the future) along with supporting documents for review and certification in the Thai language. If the supporting documents are in a foreign language, a certified Thai translation should be provided. The translation must be notarized by a notary public or qualified person. Supporting documents may include, among others, a binding instrument such as an intra-group agreement, or a list of entities subject to the BCRs. Expedited Process Requirement Organizations with existing BCR approvals under the EU or UK GDPR, or from countries announced by the PDPC under Section 28, may apply through an