You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 4, 2026

Vietnam’s Draft Crypto Sanctions Decree: Enforcement Comes to the Pilot Market

On November 18, 2025, Vietnam’s Ministry of Finance released for public consultation a draft decree on administrative sanctions in the field of crypto assets and crypto asset markets (the “Draft Decree”), intended to implement Resolution No. 05/2025/NQ-CP dated September 9, 2025, on the pilot crypto asset market in Vietnam (“Resolution 05”). While Resolution 05 sets out who may participate and under what conditions, the Draft Decree addresses a more practical question for market participants, i.e., what happens if those conditions are not met. In doing so, the Draft Decree offers important insight into how Vietnamese regulators intend to supervise, discipline, and ultimately shape the crypto market during the pilot phase.

Regulatory Scope and Overall Sanctions Architecture

The Draft Decree applies to both domestic and foreign organizations and individuals engaging in crypto-related activities in Vietnam’s market. Covered entities include: (i) crypto asset issuers; (ii) crypto asset service providers, including trading platforms and market operators; (iii) Vietnamese and foreign investors participating in the pilot market; and (iv) other organizations involved in the offering, issuance, or provision of crypto-related services in Vietnam.

The breadth of this scope is deliberate. It appears to reflect a regulatory view that cross-border structures, offshore platforms, and indirect participation may not necessarily insulate market actors from compliance obligations once they operate within the pilot framework. For the crypto industry, this may mark a shift from regulatory ambiguity toward a more explicit articulation of jurisdictional reach.

At first glance, the Draft Decree’s monetary penalties appear restrained. The maximum fine per administrative violation is capped at VND 200 million (approx. USD 7,700) for organizations and VND 100 million (approx. USD 3,800) for individuals. However, focusing solely on fine levels risks missing the point. The Draft Decree also places great regulatory weight on supplementary sanctions and corrective measures, including: (i) temporary suspension of activities; (ii) revocation of licenses for defined periods; (iii) disgorgement of unlawful gains; (iv) mandatory corrective disclosures; and (v) orders to remove, suspend, or rectify noncompliant platforms, systems, or information.

Repeated violations, particularly of disclosure obligations, may be treated as aggravating circumstances, allowing authorities to escalate penalties within the statutory range rather than issuing multiple isolated fines. This signals a focus on patterns of conduct, not one-off technical breaches.

Key Sanctions: Scope, Type, and Penalty Levels

The sanctions applicable to key violations under the Draft Decree are outlined below. Unless stated otherwise, the prescribed penalties apply to organizations, with individuals subject to penalties at generally 50% of the amounts imposed on organizations for the same violations.

Sanctions Applicable to Crypto Asset Issuance and Offerings

Issuers that breach regulatory requirements – such as foreign ownership restrictions or disclosure obligations – may be subject to monetary fines ranging from VND 70 million to VND 200 million (approx. USD 2,700 to USD-7,700), with higher penalties applicable to serious violations, including unauthorized offerings or failure to publish a prospectus. In addition to fines, regulators may impose temporary suspension of issuance or offering activities, require corrective or supplemental disclosures, and order the disgorgement of illegal gains.

These measures underline a key regulatory priority: Offerings are viewed as the primary risk entry point for retail investors, and compliance failures at this stage are treated as fundamentally serious.

Obligations and Sanctions Applicable to Crypto Asset Service Providers

The Draft Decree also devotes substantial attention to crypto asset service providers, reflecting their central role in market integrity. Depending on severity, service providers may face fines from VND 30 million to VND 200 million (approx. USD 1,200 to USD 7,700) for breaches of operational, disclosure, and investor protection obligations. Sanctionable conduct includes failures in disclosure and reporting, deficiencies in KYC and account opening procedures, misleading marketing, inadequate monitoring of trading activities, improper segregation of client assets, and weaknesses in cybersecurity or system controls.

In more serious cases, particularly where investor interests or market integrity are affected, authorities may apply temporary suspension of services, license revocation for a specified period, and orders to correct, remove, or cease the use of noncompliant systems or information, in addition to monetary penalties.

Sanctions Applicable to the Operation of Crypto Asset Trading Markets

Operators of crypto asset trading markets are subject to some of the highest penalties under the Draft Decree. Fines of VND 70 million to VND 200 million (approx. USD 2,700 to USD-7,700) apply to violations such as failure to disclose market launch information, noncompliance with obligations following license revocation, or operating without proper authorization. Supplementary measures may include temporary suspension of market operations, revocation of operating licenses, and disgorgement of illegal profits derived from non-compliant activities.

Investor Conduct and Cross-Border Transaction-Related Violations

Notably, the Draft Decree does not focus exclusively on platforms and issuers. Investors themselves, both domestic and foreign, are within scope. Domestic and foreign investors may be fined VND 10 million to VND 100 million (approx. USD 400 to USD 3,800) for conducting transactions outside licensed platforms or breaching foreign exchange, account usage, or reporting requirements. In addition to monetary penalties, regulators may require rectification of noncompliant transactions, submission of corrective disclosures or reports, and, where violations show signs of criminal conduct, referral to competent investigative authorities.

Competent Authorities and Enforcement Framework

The Draft Decree confers broad and overlapping sanctioning powers on multiple authorities. In principle, sanctions may be imposed by provincial People’s Committees, financial authorities, securities regulators, and competent public security authorities, except that violations relating to foreign investors’ fund transfers and anti-money laundering obligations fall within the sanctioning competence of State Bank of Vietnam authorities.

The Draft Decree also limits sanctioning powers by authority level: Certain officials are capped at lower fine thresholds and may not impose supplementary sanctions. Where a violation attracts sanctions exceeding an authority’s competence, the case file must be promptly transferred to the competent authority for handling.

Notably, certain violations, including investors trading outside licensed platforms, the provision or promotion of crypto services without a license, operating beyond the scope of an approved license, and breaches of anti-money laundering regulations, may also be referred for criminal investigation if they exhibit signs of criminal conduct. In such cases, the relevant authority must transfer the case file to competent investigative bodies for further proceedings.

Outlook

Read as a whole, the Draft Decree reflects a measured yet unequivocally firm regulatory stance. While the pilot market is intended to foster innovation, it does so within clearly defined and actively enforced boundaries. Importantly, the enforcement toolkit is designed to correct conduct and screen out noncompliant participants, rather than to function as a purely punitive mechanism. For participants across the crypto ecosystem, including issuers, exchanges, service providers, funds, and sophisticated investors, the message is clear: Vietnam’s crypto pilot may be experimental, but its compliance expectations are not.

The Ministry of Finance is expected to finalize the Draft Decree and submit it to the government for approval, potentially clearing the way for enforceable administrative sanctions from early 2026.

RELATED INSIGHTS​ 

August 23, 2024
Thailand’s Securities and Exchange Commission (SEC) amended its utility token supervisory framework by issuing seven notifications that came into effect on August 13, 2024. Ready-to-use utility tokens (tokens that can be used immediately to acquire specific goods or services), which were previously unregulated, are now subject to the supervisory scheme set forth by the seven new notifications in both primary and secondary markets. This is intended to provide an investor protection mechanism that responds to the characteristics, risks, and usage of the different types of ready-to-use utility tokens. Under the new notifications, ready-to-use utility tokens are categorized into two groups. These are detailed below. Group 1 Utility Tokens Group 1 utility tokens include ready-to-use utility tokens issued for consumption purposes or as a digital representation of a certificate. Examples include loyalty points, digital movie or concert tickets, NFTs, and carbon credits, among others. Principally, there is no change in the regulation of group 1 utility tokens under the new notifications. In the primary market, issuance of this type of token is not subject to the initial coin offering (ICO) requirements. In the secondary market, providing services related to group 1 utility tokens is not considered to be the same as operating a digital asset business with licensing requirements under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). Licensed digital asset operators (including exchanges, brokers, and dealers) are not permitted to list or trade group 1 utility tokens. To provide services in relation to group 1 utility tokens, these licensed digital asset operators must establish a separate entity to provide those services and must not use names or messages that could cause the public to misunderstand that the separate entity is engaged in a digital asset business under SEC supervision. Group 2 Utility Tokens Group 2 utility tokens
August 22, 2024
The Personal Data Protection Committee (PDPC) of Thailand’s Ministry of Digital Economy and Society (MDES) has announced the first administrative fine under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). A major private company was fined THB 7 million for noncompliance with specific PDPA requirements, resulting in the unauthorized disclosure of personal data to a call center gang (phone scam fraudsters). Key Findings of Noncompliance The PDPC determined that there were three key violations of specific requirements of the PDPA: Failure to appoint a data protection officer (DPO): Despite processing personal data for over 100,000 individuals as part of its core operations, the company did not appoint a DPO. Inadequate security measures: The company lacked the required security measures, leading to a data breach involving a call center gang, causing widespread damage. Delayed data breach notification: The company did not notify authorities of the data breach within the required timeframe and failed to address the breach promptly, making it impossible to remedy the situation. In addition to the monetary fine, the PDPC, along with the PDPA’s Expert Committee, issued a corrective order requiring the company to undertake the following actions and notify the Office of the PDPC of the relevant correction measures within seven days of receiving the order: Implement up-to-date security measures: The company must improve its current security measures to prevent future breaches and ensure that the security measures are up-to-date with changing technologies. Raise awareness of personnel: The company must provide training to relevant personnel to ensure awareness of data compliance and protection practices. This significant administrative action establishes a precedent for addressing data breaches in both governmental and commercial sectors in Thailand. It also confirms the importance of PDPA compliance, particularly the need for robust security measures, timely breach notifications, and the appointment of
August 15, 2024
On August 9, 2024, Thailand’s Electronic Transactions Development Agency (ETDA) opened a period for public feedback regarding the 2022 Royal Decree on Digital Platforms and its subregulations. To collect this feedback, the ETDA has prepared a 44-question survey on specific attributes of the royal decree and its requirements, covering issues such as the definition of digital platform services (DPSs), types of services that are subject to notification requirements, information that must be submitted annually, and the royal decree’s extraterritorial scope. Business operators that fall within the scope of the royal decree and wish to provide feedback on its effectiveness should prepare and submit the survey online to the ETDA by the end of August 2024. Royal Decree on Digital Platforms Thailand’s Royal Decree on Digital Platforms was published in the Government Gazette on December 22, 2022. It defines a DPS as any service that facilitates or mediates transactions between users through a digital platform, such as e-commerce, food delivery, ride-hailing, online travel agency, online payment provider, or social media platform. The decree requires DPS operators to notify the ETDA before commencing operations, with some limited exemptions. The decree also empowers the ETDA to issue notifications (i.e., subregulations) and guidelines for implementing the decree and to monitor and enforce compliance by DPS operators. The ETDA may impose administrative sanctions, such as warnings, fines, service suspension, or revocation of notification, for any violation of the royal decree or the ETDA’s subregulations. In-scope DPS operators should take this opportunity to provide comments to the ETDA in order to voice their opinions on the practicality of the requirements and support the regulator in shaping the requirements of the royal decree and its subregulations. For more information on this initiative from the ETDA, or on any aspect related to the Royal Decree on Digital
August 5, 2024
On June 28, 2024, Thailand’s Board of Investment (BOI) updated its list of promoted activities to include data hosting, which is listed as “Activity 8.2.4 Data Hosting Services.” Qualifying data hosting services are eligible for a corporate income tax exemption (capped) for eight years, along with other tax and nontax incentives, such as import duty exemption on imported machinery to be used in the project, the right for foreigners to own land, and work permit and visa facilitation for expats, among others. To be eligible for these BOI incentives, projects must: Provide services for leasing host servers for data storage (data hosting); Have at least two data centers located in Thailand that meet or exceed the ISO/IEC 27001 data center standards; and Have an investment amount (excluding cost of land and working capital) of at least THB 5 billion. Apart from the above specific criteria, projects also need to comply with the general BOI criteria, such as a debt-to-equity ratio no higher than 3:1, submission of a feasibility study report, and use of new machinery, among others. For more details on BOI incentives for software and data center activities, or on any aspect of investment promotion in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], or Napassorn Lertussavavivat at [email protected].