You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 22, 2025

Vietnam’s Draft Resolution on Financial Centers: Implications for Fintech and Banking

Tasked with implementing the Politburo’s policy outlined in Notice No. 47-TB/TW dated November 15, 2024, the prime minister of Vietnam issued Decision No. 1718/QD-TTg on December 31, 2024, appointing himself as the head of a steering committee dedicated to the establishment of an international financial center in Ho Chi Minh City and a regional financial center in Da Nang by 2025. The Ministry of Planning and Investment has subsequently drafted an outline for the National Assembly’s Resolution on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Resolution”).

This Draft Resolution introduces two key policy groups: (i) policies governing the quantity, location, structure, organization, functions, and responsibilities of the financial centers; and (ii) policies applicable to various areas and matters within the financial centers.

Notably, under the Draft Resolution, fintech has been identified as a key sector, with a specific focus on the implementation of a “controlled sandbox” policy for business models involving virtual assets and cryptocurrencies. Under this framework, transactions related to virtual assets and cryptocurrencies will be permitted from July 1, 2026, subject to licensing, management, impact assessment, and risk oversight by the financial centers’ Management and Operations Committee.

Scope of Application and Key Principles

The Draft Resolution applies to a wide range of stakeholders, including investors, regulatory agencies, organizations, and individuals involved in the establishment, organization, and operation of regional and international financial centers in Vietnam. These financial centers will have clearly defined geographical boundaries and specific locations, which will be further specified and detailed by the People’s Committees of Ho Chi Minh City and Da Nang.

Companies successfully registered as members of these financial centers will benefit from special investor-friendly policy principles, which may differ from the general legal and regulatory framework applicable in other parts of Vietnam.

Most notably, the state will implement mechanisms and policies to encourage capital inflows, facilitate the adoption of advanced technology and modern management practices, and promote infrastructure development within the financial centers. The management agencies of the financial centers will apply specialized administrative procedures to meet investors’ needs in accordance with international standards and best practices. Additionally, where provisions of the Draft Resolution differ from existing laws, resolutions, or ordinances, the provisions of the Draft Resolution will prevail.

Policy Framework for Establishment and Governance of Financial Centers

The Draft Resolution outlines the framework for the establishment and governance of financial centers in Vietnam, which will include a comprehensive international financial center in Ho Chi Minh City and a regional-scale financial center in Da Nang. To ensure effective management and operations, the financial centers will be overseen by dedicated agencies, including a (i) management and operations committee, (ii) financial supervision committee, and (iii) international arbitration center.

The management and operations committee will be responsible for the overall administration and strategic oversight of the financial center. Its organizational structure will consist of a board of directors and several key departments, including strategic management, financial management, operations supervision, and management coordination.

The financial supervision committee will focus on ensuring compliance with international financial standards and regulations, fostering a transparent and integrity-driven environment. This committee will also comprise a board of directors supported by specialized departments, such as audit, legal, welfare, risk management, and governance and human resources.

Additionally, each financial center will host an international arbitration center, which will facilitate the resolution of disputes arising from investment and business activities within the financial ecosystem.

Specific Policies for Financial Centers

The Draft Resolution also sets forth specific policies that will govern key areas within the financial centers. These policies cover the membership registration system; currency, banking, and foreign exchange management; fintech; capital markets; personal and corporate income tax; immigration and residency; human resource training and development; labor, employment, and social security; strategic investments; land use and infrastructure development; and trade and business regulations. Furthermore, policies related to dispute resolution mechanisms for investment and business activities are also included.

A significant feature of the Draft Resolution is the introduction of a controlled sandbox policy for fintech enterprises, particularly those engaged in virtual assets and cryptocurrency-related business models. Under this framework, transactions involving virtual assets and cryptocurrencies will be clearly permitted within the financial centers starting from July 1, 2026. These transactions will be subject to licensing, regulatory oversight, impact assessment, and risk management measures administered by the Management and Operations Committee. Additionally, issues concerning anti-money laundering measures related to crypto assets and cryptocurrencies; the issuance, ownership, and trading of non-fungible tokens (NFTs) and utility tokens; and regulatory measures for crypto-asset mining activities (to limit risks to energy security and the environment) will be further regulated by the government.

In the domain of currency, banking, and foreign exchange management, the Draft Resolution proposes policies that reflect international best practices and address the practical needs of the financial centers. These policies include (i) anti-money laundering regulations, including those related to crypto assets; (ii) allowing financial transactions within the centers in both VND and freely convertible foreign currencies; and (iii) procedures and processes for priority areas in the financial centers for some traditional products in commercial banking activities.

The Draft Resolution also provides a streamlined regulatory framework for establishing and managing the operations of foreign credit institutions within the financial centers. Notably, banks and credit institutions headquartered in the centers will not be subject to foreign ownership restrictions or investment conditions when providing financial services within the centers or across borders. In addition, to align with international financial standards, the implementation of Basel III regulations is scheduled to commence on January 1, 2026. Furthermore, a digital banking model will be introduced, enabling commercial banks to offer advanced digital services within the financial centers from the same date.

Outlook

By establishing a structured regulatory framework, the forthcoming resolution aims to attract investment, drive financial innovation, and position Vietnam as a competitive player in the global financial landscape. A key highlight of the resolution is its focus on the fintech sector, particularly through initiatives such as the controlled sandbox for virtual assets and cryptocurrencies. This demonstrates Vietnam’s commitment to advancing digital transformation in financial services, fostering opportunities for fintech enterprises, and driving innovation across the industry.

RELATED INSIGHTS​ 

January 13, 2025
The State Bank of Vietnam’s Circular No. 50/2024/TT-NHNN regulating safety and security for the provision of online services in the banking sector (“Circular 50”), issued on October 31, 2024, took effect on January 1, 2025, with delayed effectiveness for certain provisions on (i) network, communication, and security systems, online banking application software, and mobile banking application software (July 1, 2025); (ii) transaction confirmation for payment transactions conducted via the straight-through processing method (January 1, 2026); and (iii) authentication forms and reporting obligations (July 1, 2026). The cybersecurity situation in Vietnam is complicated, and the banking and finance sector has been one of the top targets of high-tech criminals. Circular 50 seeks to enhance user protection by expanding the technical requirements to more services in the banking sector as well as standardizing how transactions are authenticated. Expanded Scope of Services Covered Previous regulations on safety and security of online services in the banking sector only covered banking services and intermediary payment services. Circular 50 expands the scope to include other services of credit institutions and foreign bank branches such as credit information services, foreign exchange services, securities depository services, and services related to factoring and letters of credit, which now need to comply with technical requirements and standards for online services such as firewalls and DMZ network barriers. Risk-Based Approach to Authentication Circular 50 sets out standards for payment transactions and card transactions by: Classifying various online transactions based on the type of client, the purpose of the transfer, the value of the specific transaction, and the total value of certain transactions during the day; and Applying various types of authentication for the corresponding types of online transactions, e.g., using passwords or PINs for small-value online transactions, and using OTPs (through SMS, voice, or email), biometric matching, or e-signatures for
January 10, 2025
On January 8, 2025, Thailand’s Office of the Personal Data Protection Committee published two notifications in the Government Gazette—one for data controllers and the other for data processors—concerning exemptions for data controllers and data processors from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019). The notification for data processors took effect on January 9, 2025, the day after its publication. The notification for data controllers will take effect on April 8, 2025. The content of these notifications is identical to that in the draft versions of the notifications previously released for public consultation in October 2024. For more information on the ROPA exemptions for data controllers and data processors, or on any aspect of personal data protection in Thailand, please contact Nopparat Lalitkomon at [email protected] or Wilin Somya at [email protected].
January 9, 2025
On January 1, 2025, Myanmar’s State Administration Council enacted Cybersecurity Law No. 1/2025, which aims to regulate various aspects of digital security and online activities. The law has not yet been implemented and will come into force on a date specified by the Myanmar president, who will also provide an official adoption and compliance timeline for individuals and organizations impacted by the new regulations. Below are some of the key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The
January 9, 2025
Thailand’s Fiscal Policy Office (FPO) has released a draft of its planned Financial Business Hub Act, which is in line with the government’s aim of positioning Thailand as a regional financial hub and a critical player in the global economy. The draft act, on which the FPO is accepting comments until January 9, 2025, details the framework for promoting and attracting international financial businesses and related services to operate in Thailand, proposes various incentives, and outlines supervisory guidelines. This article examines key elements of the draft Financial Business Hub Act relevant to financial business operators. Incentivized Financial Businesses The draft act identifies the financial businesses to be promoted and incentivized. These target businesses include: Commercial banking businesses, Payment service businesses, Securities businesses, Derivatives businesses, Digital assets businesses, Insurance and reinsurance brokerage businesses, and Other financial-related businesses as determined by the Committee for the Supervision and Promotion of Financial Centers. Thailand’s finance minister explained that initially, the draft law intends to target businesses using an “out-out” model, which describes the raising of capital abroad for investment abroad, before expanding to an “out-in” model, in which capital is raised abroad for investment domestically. Therefore, the draft law currently specifies that the target businesses must only provide services to nonresidents without soliciting residents of Thailand to use their services. Authorization Targeted financial business operators will need to receive authorization from the Committee for the Supervision and Promotion of Financial Centers. The main eligibility criteria for authorization are the incorporation an entity (e.g., a company registered in Thailand, a branch of a foreign juristic person) with an office in designated areas to be specified in a royal decree (currently expected to be Bangkok and adjacent provinces) and the possession of other qualifications as prescribed in the draft act. Target businesses in Thailand will