You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 14, 2021

Vietnam’s Decree 21 Updates Regulations on Security for Performance of Obligations

On May 15, 2021, Decree No. 21/2021/ND-CP of the Government of Vietnam dated March 19, 2021, guiding the implementation of the Civil Code of 2015 on security for performance of obligations (Decree 21) will come into effect and replace Decree No. 163/2006/ND-CP of the Government dated December 29, 2006, on security transactions, as amended by Decree No. 11/2012/ND-CP (together, “Decree 163”).

One of the most significant changes of Decree 21 in comparison to Decree 163 is the new system of terminology in relation to security for performance of obligations. In particular, the new decree provides new definitions for existing terms such as “guarantor” and “guarantee” and sets out the definitions of newly added terms such as “secured obligator,” “security contract,” and “reasonable duration.” This change reflects the intention of the legislators to unify the relevant terminology in accordance with the Civil Code of 2015.

Article 4 of Decree 21 lists out principles for the application of laws and the parties’ agreements on security for performance of obligations. Accordingly, in cases where the laws on specialized areas such as land, housing, insurance, banking, aviation, or intellectual property have provisions on security assets, establishment and implementation of means of security, or enforcement of security assets, the provisions of the specialized laws will prevail. Moreover, if the parties have agreements that are different from provisions in Decree 21 but do not violate (i) fundamental principles of civil law or (ii) conditions for a civil transaction to be valid or (iii) limitations on the exercise of civil rights in accordance with the Civil Code or other relevant laws, such agreements may be enforced.

Decree 21 devotes an entire chapter to regulations on security assets (collateral) which includes definitions and descriptions of security assets and detailed provisions on 10 types of security assets including land use rights and assets attached to land, objects, valuable papers, etc. Notably, Decree 21 no longer provides that a security asset may not be attached by the courts or authorities to perform the guarantor’s other obligations if the security transaction is valid and effective against third parties and the laws do not regulate otherwise, as provided under Decree 163. This change makes the new decree consistent with the existing regulations on enforcement of civil judgments which state that mortgaged or pledged assets may still be attached for the purpose of enforcement of civil judgments, provided that the applicable conditions are satisfied.

The new decree provides detailed regulations on the establishment and implementation of means of security and enforcement of security assets. Accordingly, a means of security may be established based on the agreement of the parties via a security contract or a lien. For enforcement of security assets, Decree 21 goes into detail on the enforcement of future assets or invested mortgaged assets for the first time.

Decree 163 will still be applicable to security agreements or security interests which were established and implemented prior to May 15, 2021. The parties to such security agreements or security interests which have not been implemented or have been implemented but contain provisions different from provisions under Decree 21 may, but are not required to, agree to amend the existing security agreements or security interests to comply with the new decree.

RELATED INSIGHTS​ 

September 17, 2025
M&A specialists at Tilleke & Gibbins have contributed the Vietnam chapter to Private M&A 2025, a newly released guide from Lexology Panoramic. The publication provides practical insights into private mergers and acquisitions frameworks in jurisdictions worldwide. The Vietnam chapter addresses key aspects of private M&A transactions, including: Structure and process, legal regulation, and required consents Advisers, negotiation, and documentation Due diligence and disclosure obligations Pricing, consideration, and financing Conditions, preclosing covenants, and termination rights Representations, warranties, indemnities, and postclosing covenants Taxation of transfers Employees, pensions, and benefits Recent legal, regulatory, and market practice developments The chapter highlights how Vietnam’s legal framework governs private acquisitions and disposals, outlines typical transaction processes and structures, and provides guidance on common regulatory and practical considerations. It also notes recent trends, including increased scrutiny of merger control filings by the Vietnam Competition Commission and regulatory changes affecting M&A approvals. The full Vietnam chapter is available as a PDF through the button below. Readers can also gain 30 days of complimentary access to Private M&A 2025 and Lexology Panoramic’s full library of resources through this link.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.
September 10, 2025
Under Thai law, authorized directors stand as a company’s mind and will and, as such, may incur personal criminal liability for acts or omissions committed in the course of company business. When allegations surface, directors must be prepared for the practical reality that, before guilt or innocence is ever adjudicated, they could be deprived of liberty unless bail release is promptly achieved through the competent legal authority. When Bail Can Be Granted Two procedural moments trigger the need to consider bail. The first arises during the investigative phase, when a claim is lodged against a director with the competent law enforcement authorities. Upon receipt of a complaint, the assigned inquiry officer summons the director for questioning, compiles evidence, and ultimately forwards a prosecution or nonprosecution recommendation to the public prosecutor. Although the public prosecutor retains ultimate discretion to indict an accused director, the police or prosecutor may conclude that pretrial detention is necessary and may therefore apply to the court for an order to hold the director in court custody. The second moment occurs after a criminal case is filed directly with the court. This occurs once a court accepts a criminal case filed by a prosecutor against a director or, alternatively, when the court accepts a case filed by an individual for trial. For cases filed by individuals, the plaintiff presents prima facie evidence at the preliminary hearing, and the court will accept the complaint if it finds sufficient grounds, thereby conferring upon the director the status of a criminal defendant. Upon acceptance of the criminal case, the court then has the inherent authority to order custody pending trial unless the defendant secures bail release. Procedural Considerations Experienced litigants typically prepare bail security in advance and submit a bail petition at the earliest possible time. While there are
September 8, 2025
On September 1, 2025, Myanmar’s Directorate of Investment and Company Administration (DICA) issued Directive No. 106/2025 to remind all companies and organizations registered under the Myanmar Companies Law of their obligation to strictly comply with the DICA registrar’s orders, directives, and procedures. This directive highlights the importance of legal and procedural compliance in corporate filings, governance changes, and operational conduct. It also signals increased scrutiny over documentation submitted during annual returns, share transfers, and director appointments or resignations. Public companies will be subject to closer regulatory attention, and new company registrations will involve vetting of proposed directors to ensure prior compliance with applicable laws. Compliance The directive emphasizes the following points: Companies must ensure full compliance with the Myanmar Companies Law and all directives issued by the registrar. This includes the proper submission of annual returns and adherence to updated requirements for share transfers and changes in directors. Companies and organizations must comply with all applicable laws, rules, directives, and procedures issued by relevant ministries and departments. If any authority takes action due to noncompliance, the registrar may also take appropriate measures. Noncompliance may result in regulatory sanctions, including restrictions on future company participation and vetting under anti–money laundering and counter–terrorism financing protocols. Prospective directors of newly registered companies will be vetted to confirm no prior violations of applicable laws. Entities must respond promptly and accurately to document requests from the registrar, both during initial registration and in subsequent filings. Companies are strongly advised to review their internal compliance frameworks and ensure readiness to meet DICA’s documentation and procedural expectations. In particular, companies must respond promptly and accurately to document requests from the registrar, whether during initial registration or in subsequent filings. For more information on this DICA announcement, or on any aspect of corporate registration, or assistance with