You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 27, 2026

Vietnam’s E-Commerce Law Reshapes Online IP Enforcement

Managing Intellectual Property

Vietnam’s new E-Commerce Law, which took effect on 1 July 2026 along with its implementing Decree No. 248/2026/ND-CP (Decree 248), marks a significant development in the country’s approach to online intellectual property (IP) enforcement, reflecting a clear shift from a reactive model of intermediary liability to one that expects platforms to play a more active role in preventing infringement.

From notice-and-takedown to platform responsibility

The most significant change introduced by the E-Commerce Law is the transformation of the legal role of e-commerce platforms. The existing safe harbor provisions under the IP Law and the copyright notice-and-takedown regime established by Decree 17/2023/ND-CP (Decree 17) largely required intermediaries to act only after receiving notice of infringement. Once infringing content had been removed, the platform’s legal obligation was generally considered fulfilled. The new legislation adopts a fundamentally different approach.

Article 17 of the E-Commerce Law requires intermediary platforms to screen information relating to goods and services before publication in order to prevent listings involving counterfeit or IP-infringing goods, and goods of unknown origin. Rather than relying exclusively on complaints from rights holders, platforms are now expected to implement preventive measures before infringing listings become publicly available.

Decree 248 further requires platforms to update keyword filters based on recommendations issued by competent authorities. These filtering mechanisms are intended to prevent prohibited listings from appearing on the platform and represent a further move away from a purely complaint-driven enforcement model.

The legislation also introduces Vietnam’s first statutory stay-down obligation. Under the E-Commerce Law and Decree 248, major digital platforms must maintain automated systems capable of reviewing, warning against, and removing unlawful listings while also implementing measures to prevent repeat violations, defined under Decree 248 as conduct that has previously been identified and handled by the platform, but continues to recur.

This obligation addresses one of the most persistent challenges in online brand protection. Under the previous framework, counterfeit listings frequently reappeared shortly after removal under different seller accounts or slightly modified product descriptions, forcing rights holders into an endless cycle of repeated takedown requests. The new legislation requires platforms not only to remove infringing listings but also to implement reasonable measures to reduce their reappearance.

Although the legislation does not prescribe any particular technology, compliance will likely require platforms to invest in tools such as image recognition, product fingerprinting, and seller behavior analysis. Whether implementation proves consistently effective remains to be seen, but it is clear that major platforms are expected to take active steps to prevent, rather than merely respond to, online infringement.

A unified enforcement framework for all IP rights

Another significant reform is the expansion of statutory online enforcement beyond copyright. Vietnam’s notice-and-takedown procedure under Decree 17 applies only to copyright and related rights. Trademark owners, patent holders and industrial design owners have traditionally relied on administrative enforcement or civil litigation, neither of which offers the speed or flexibility of platform-level enforcement.

The 2025 amendment to the IP Law and now the E-Commerce Law remove this distinction. These laws prohibit the trading of IP-infringing goods without limiting protection to any particular category of IP, while Decree 248 requires platforms to inspect, review, and promptly remove information relating to any IP-infringing goods upon requests from competent authorities.

The legislation also formalizes cooperation between e-commerce platforms and rights holders. Decree 248 requires platforms to establish publicly available complaint mechanisms through which IP owners may request the review, temporary removal, or blocking of listings showing indications of infringement. Although many major platforms had already introduced voluntary brand protection programs, the new legislation transforms this practice into a statutory obligation.

Notably, the E-Commerce Law does not establish a statutory counter-notice procedure comparable to that available under Decree 17 for copyright disputes. Government-directed removals remain subject to administrative review, while complaints submitted directly by rights holders are generally handled under each platform’s published complaint procedures. Compared with the copyright regime, this approach provides greater certainty for rights holders, although it also places greater responsibility on platforms to maintain fair and transparent complaint mechanisms.

For trademark owners, who account for the majority of online IP enforcement actions in Vietnam, the reforms provide the first dedicated statutory framework for platform-level enforcement.

Enforcement beyond the platform

The 2025 IP Law established a general framework governing intermediary service providers operating in cyberspace. Building on that foundation, the E-Commerce Law and Decree 248 prescribe how those principles apply in the e-commerce context through specific obligations for businesses supporting online transactions, giving practical effect to Vietnam’s broader intermediary liability reforms by extending compliance obligations across the e-commerce ecosystem.

Decree 248 extends these obligations beyond e-commerce platforms to technical infrastructure providers, logistics companies, and payment service providers. Upon requests from competent authorities, these entities may be required to block access to noncompliant platforms, suspend logistics services for infringing goods, or terminate payment services supporting infringing activities.

This significantly strengthens the enforcement framework against commercial-scale online infringement. Rather than focusing solely on individual listings, the legislation enables enforcement authorities to target the broader infrastructure supporting counterfeit operations. In many cases, disrupting payment, logistics, or technical services may prove more effective than repeatedly removing infringing listings.

The E-Commerce Law also strengthens Vietnam’s jurisdiction over foreign platforms. Overseas platforms exceeding specified transaction thresholds with Vietnamese consumers must register with the Ministry of Industry and Trade, establish a legal presence or appoint an authorized representative in Vietnam, and comply with the same obligations as domestic platforms. These localization requirements substantially improve the practical enforceability of Vietnamese law against cross-border platforms.

Looking ahead

Vietnam’s E-Commerce Law represents a significant evolution in the country’s online IP enforcement framework. Many aspects of implementation will continue to develop through regulatory guidance and enforcement practice. Nevertheless, it is clear that Vietnam has moved beyond a purely reactive model of intermediary liability toward one that expects major digital platforms to play an active role in preventing online infringement.

This article first appeared in Managing Intellectual Property.

RELATED INSIGHTS​ 

July 24, 2025
Vietnam’s Ministry of Public Security recently released a draft version of the 2025 Cybersecurity Law, which is intended to replace both the existing 2018 Cybersecurity Law and the 2015 Law on Network Information Security (LNIS). This consolidation reflects a broader effort by the Vietnamese government to streamline and centralize the legal framework governing cybersecurity, data protection, and information security to be under the sole authority of the Ministry of Public Security, moving away from the previous sharing of responsibility with the former Ministry of Information and Communications (which ceased operations earlier this year and merged with the Ministry of Science and Technology). This shift aims to eliminate overlaps and improve enforcement efficiency. The draft law is built upon the foundation of principles and provisions of both the 2018 Cybersecurity Law and the 2015 LNIS, while also introducing a wide range of amendments and new regulations. By merging the two laws, the government seeks to reduce legal fragmentation and ensure consistency in definitions, obligations, and enforcement mechanisms across related domains like data protection, IT system classification, and cybercrime prevention. The newly introduced amendments include enhanced obligations for service providers, stricter controls on information transmission, classification of IT systems, designation and protection of nationally important information systems, and sector-specific violations and compliance requirements. Highlights of the draft law are discussed below. Definition and Obligations of Service Providers The draft law clearly defines and significantly broadens the scope of entities considered “service providers” under its jurisdiction. This now includes businesses and individuals offering products or services in cyberspace, including both infrastructure and content online services, such as: Internet service providers (ISPs) and providers of telecommunications, hosting, servers, domain names, VPNs, proxy services, and cloud computing; Providers of social networks, websites, and online gaming; Financial institutions, banks, foreign bank branches in Vietnam, e-wallet
July 23, 2025
On July 4, 2025, Thailand’s Electronic Transactions Development Agency (ETDA) issued two significant notifications that introduce new compliance requirements for ride-hailing platforms operating in the country. The notifications formally designate these platforms as high-impact digital services under section 18(3) of the Royal Decree on Digital Platform Service Businesses and impose a comprehensive set of additional operational obligations. These measures are designed to address regulatory gaps and enhance oversight of digital platforms providing public passenger vehicle or motorcycle ride-hailing services. First, the Notification on the Designation of Ride-Hailing Platforms under section 18(3) formally designates all ride-hailing platforms that have notified the ETDA of their operations as high-impact digital platform services under section 18(3) of the royal decree. Unlike high-risk marketplace platforms, which are named individually, any ride-hailing platform that has notified the ETDA of its operations is automatically subject to these new requirements. Next, the Notification on Additional Obligations for Ride-Hailing Platforms imposes further obligations on ride-hailing platforms, supplementing the general requirements under section 21 of the royal decree. These notifications will come into force 90 days from their publication in the Government Gazette. New Compliance Obligations The new regulatory framework introduces a range of operational, technical, and reporting requirements for ride-hailing platforms, particularly concerning the issues described below. Vehicle and Driver Compliance Operators must: Ensure that all vehicles used on the platform are registered as public vehicles in accordance with Department of Land Transport requirements Verify all drivers hold valid public driving licenses Collect service fees in compliance with applicable fare regulations under the Vehicle Law Digital Platform Features and User Verification Operators must implement robust digital platform features for both drivers and riders, including: Comprehensive identity verification and confirmation processes for drivers and riders, utilizing both face-to-face and non-face-to-face methods, including biometric and digital ID checks Real-time GPS
July 17, 2025
On July 9, 2025, Thailand issued a notification that introduces comprehensive operational requirements for digital platform service providers operating as goods marketplaces, effective December 31, 2025 (i.e., 180 days after its publication in the Government Gazette). The regulation’s official name is Notification of the Electronic Transactions Committee Re: Other Actions for Digital Platform Service Operators in the Category of Marketplace for Goods with Specific Characteristics under Section 18(2) of the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification B.E. 2565 (2022), B.E. 2568 (2025). Scope of Application The notification applies exclusively to goods marketplace operators formally designated by the Electronic Transactions Development Agency (ETDA), which on the same day designated 19 platforms that had previously notified the ETDA of their operations. The goods requiring enhanced oversight by these operators are limited to those regulated by the Thai Food and Drug Administration (FDA) and the Thai Industrial Standards Institute (TISI). Development from Earlier Draft An earlier draft of the notification had included a requirement for offshore platforms to establish a local entity, but this requirement was removed from the final notification. Key Obligations Despite the removal of the local entity requirement, the notification imposes a range of additional obligations on designated goods marketplace operators: Transparency. Operators must implement robust transparency measures, including clear, accessible, and understandable disclosures to users in Thai. These disclosures must cover all relevant terms and conditions, comprehensive product information, and complaint management procedures. Operators must also submit an annual compliance report to the ETDA within 60 days after the end of their accounting period, including statistics on regulated goods. Business user registration and identity verification. Before permitting the sale or advertisement of regulated goods, operators must collect and verify business user information, including contact details, identification documents, registration
July 15, 2025
Thailand has established new safe harbor rules that require social media platforms to remove specified content within 24 hours of government notification. On July 5, 2025, the Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers was issued and took effect. This followed a hearing in May 2025 where only a select group of social media and online communication platform operators were invited to attend and comment on draft rules that could exempt social media platform operators from joint liability under the amended Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes in cases involving victims of technological crimes. Safe Harbor Rules The notification stipulates procedures that must be followed in order to receive the protection of the safe harbor rules. Upon being notified by the Division of Prevention and Suppression of Cybercrime, Office of the Permanent Secretary of the Ministry of Digital Economy and Society (MDES) of the presence of false or misleading information that may lead to the commission of a technological crime, social media service providers must immediately take down the specified content, with a maximum allowable turnaround time of 24 hours from the time of receiving the notification. Social media service providers are required to promptly report the outcome of each takedown to the MDES Division of Prevention and Suppression. This shift in Thailand’s regulatory approach to social media content moderation establishes clear government oversight mechanisms while providing platforms with liability protection for compliance. As the new rules took immediate effect, social media platforms need to ensure that they have adequate systems and processes in place to comply with the requirements.