You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 27, 2026

Vietnam’s E-Commerce Law Reshapes Online IP Enforcement

Managing Intellectual Property

Vietnam’s new E-Commerce Law, which took effect on 1 July 2026 along with its implementing Decree No. 248/2026/ND-CP (Decree 248), marks a significant development in the country’s approach to online intellectual property (IP) enforcement, reflecting a clear shift from a reactive model of intermediary liability to one that expects platforms to play a more active role in preventing infringement.

From notice-and-takedown to platform responsibility

The most significant change introduced by the E-Commerce Law is the transformation of the legal role of e-commerce platforms. The existing safe harbor provisions under the IP Law and the copyright notice-and-takedown regime established by Decree 17/2023/ND-CP (Decree 17) largely required intermediaries to act only after receiving notice of infringement. Once infringing content had been removed, the platform’s legal obligation was generally considered fulfilled. The new legislation adopts a fundamentally different approach.

Article 17 of the E-Commerce Law requires intermediary platforms to screen information relating to goods and services before publication in order to prevent listings involving counterfeit or IP-infringing goods, and goods of unknown origin. Rather than relying exclusively on complaints from rights holders, platforms are now expected to implement preventive measures before infringing listings become publicly available.

Decree 248 further requires platforms to update keyword filters based on recommendations issued by competent authorities. These filtering mechanisms are intended to prevent prohibited listings from appearing on the platform and represent a further move away from a purely complaint-driven enforcement model.

The legislation also introduces Vietnam’s first statutory stay-down obligation. Under the E-Commerce Law and Decree 248, major digital platforms must maintain automated systems capable of reviewing, warning against, and removing unlawful listings while also implementing measures to prevent repeat violations, defined under Decree 248 as conduct that has previously been identified and handled by the platform, but continues to recur.

This obligation addresses one of the most persistent challenges in online brand protection. Under the previous framework, counterfeit listings frequently reappeared shortly after removal under different seller accounts or slightly modified product descriptions, forcing rights holders into an endless cycle of repeated takedown requests. The new legislation requires platforms not only to remove infringing listings but also to implement reasonable measures to reduce their reappearance.

Although the legislation does not prescribe any particular technology, compliance will likely require platforms to invest in tools such as image recognition, product fingerprinting, and seller behavior analysis. Whether implementation proves consistently effective remains to be seen, but it is clear that major platforms are expected to take active steps to prevent, rather than merely respond to, online infringement.

A unified enforcement framework for all IP rights

Another significant reform is the expansion of statutory online enforcement beyond copyright. Vietnam’s notice-and-takedown procedure under Decree 17 applies only to copyright and related rights. Trademark owners, patent holders and industrial design owners have traditionally relied on administrative enforcement or civil litigation, neither of which offers the speed or flexibility of platform-level enforcement.

The 2025 amendment to the IP Law and now the E-Commerce Law remove this distinction. These laws prohibit the trading of IP-infringing goods without limiting protection to any particular category of IP, while Decree 248 requires platforms to inspect, review, and promptly remove information relating to any IP-infringing goods upon requests from competent authorities.

The legislation also formalizes cooperation between e-commerce platforms and rights holders. Decree 248 requires platforms to establish publicly available complaint mechanisms through which IP owners may request the review, temporary removal, or blocking of listings showing indications of infringement. Although many major platforms had already introduced voluntary brand protection programs, the new legislation transforms this practice into a statutory obligation.

Notably, the E-Commerce Law does not establish a statutory counter-notice procedure comparable to that available under Decree 17 for copyright disputes. Government-directed removals remain subject to administrative review, while complaints submitted directly by rights holders are generally handled under each platform’s published complaint procedures. Compared with the copyright regime, this approach provides greater certainty for rights holders, although it also places greater responsibility on platforms to maintain fair and transparent complaint mechanisms.

For trademark owners, who account for the majority of online IP enforcement actions in Vietnam, the reforms provide the first dedicated statutory framework for platform-level enforcement.

Enforcement beyond the platform

The 2025 IP Law established a general framework governing intermediary service providers operating in cyberspace. Building on that foundation, the E-Commerce Law and Decree 248 prescribe how those principles apply in the e-commerce context through specific obligations for businesses supporting online transactions, giving practical effect to Vietnam’s broader intermediary liability reforms by extending compliance obligations across the e-commerce ecosystem.

Decree 248 extends these obligations beyond e-commerce platforms to technical infrastructure providers, logistics companies, and payment service providers. Upon requests from competent authorities, these entities may be required to block access to noncompliant platforms, suspend logistics services for infringing goods, or terminate payment services supporting infringing activities.

This significantly strengthens the enforcement framework against commercial-scale online infringement. Rather than focusing solely on individual listings, the legislation enables enforcement authorities to target the broader infrastructure supporting counterfeit operations. In many cases, disrupting payment, logistics, or technical services may prove more effective than repeatedly removing infringing listings.

The E-Commerce Law also strengthens Vietnam’s jurisdiction over foreign platforms. Overseas platforms exceeding specified transaction thresholds with Vietnamese consumers must register with the Ministry of Industry and Trade, establish a legal presence or appoint an authorized representative in Vietnam, and comply with the same obligations as domestic platforms. These localization requirements substantially improve the practical enforceability of Vietnamese law against cross-border platforms.

Looking ahead

Vietnam’s E-Commerce Law represents a significant evolution in the country’s online IP enforcement framework. Many aspects of implementation will continue to develop through regulatory guidance and enforcement practice. Nevertheless, it is clear that Vietnam has moved beyond a purely reactive model of intermediary liability toward one that expects major digital platforms to play an active role in preventing online infringement.

This article first appeared in Managing Intellectual Property.

RELATED INSIGHTS​ 

July 2, 2026
Thailand’s Electronic Transactions Development Agency (ETDA) released a new version of the draft Act on Artificial Intelligence on July 2, 2026, for a public hearing period expected to be approximately 30 days. The draft act adopts a risk-based regulatory approach modeled in part on international frameworks—particularly the EU’s AI Act—while incorporating provisions tailored to Thailand’s regulatory landscape and digital economy objectives. If enacted in its current form, the law would introduce extraterritorial obligations, a tiered risk classification system, strict liability for AI-related damages, and new transparency requirements for AI-generated content. Scope and Extraterritorial Application The draft act applies to AI development, deployment, or any other action affecting people in Thailand, even if the action occurs outside the country. Of note: This extraterritorial reach creates compliance obligations for global AI companies whose systems impact Thai residents or consumers, even if the provider has no physical presence in Thailand. Foreign AI providers serving Thai deployers or users must appoint a local coordinator or authorized representative. Depending on the type of AI system, the representative may need full authority to act on behalf of the provider without any limitation of liability. Certain activities are exempt from the draft act’s oversight, including AI used by natural persons solely for personal or household activities, AI for educational research conducted by higher education institutions with ethics committee approval, research and development activities conducted prior to distribution or service provision, and other AI systems prescribed by royal decree. Risk-Based Classification Framework The draft act establishes a tiered risk classification system with three main categories: Prohibited AI. The act outright prohibits AI systems employing cognitive-behavioral manipulation using subliminal techniques, AI systems causing unfair broad-scale discrimination from processing irrelevant data, and other categories of serious risk as determined by announcement of a forthcoming committee that will be responsible
June 29, 2026
Thailand’s cabinet has approved the draft Act on Liability for Defective Goods, commonly called Thailand’s “Lemon Law.” The Draft Act is currently pending consideration by Parliament. The draft law aims to strengthen buyers’ position in pursuing cases against sellers. While the Civil and Commercial Code offers provisions governing liability for defective goods, it is difficult in practice for buyers to successfully make a claim against sellers, particularly where defects are latent and not discoverable at the time of sale or delivery. By introducing product-specific rules and clearer remedies, the new law is intended to modernize Thailand’s consumer protection framework and align it more closely with international standards, and to help relieve the buyer’s burden of proof against the seller in product liability cases. If enacted, the draft act will take effect 180 days after publication in the Government Gazette, giving businesses a transition period to assess their compliance obligations. This article provides an overview of the key provisions of the draft act and highlights some practical considerations for businesses operating in Thailand. Scope and Key Definitions The draft act applies to sellers—defined as persons who sell goods in the ordinary course of business—and protects buyers, a term defined broadly to include not just the original purchaser but also transferees and successors in title. This expands the class of people who can bring claims. The law does not apply to used goods, live animals, or goods exempted by future ministerial regulation. It also leaves intact any separate warranties, promises, advertisements, or other guarantees a seller has given; those remain enforceable alongside the new statutory rights. General Liability for Defective Goods Sellers are liable for defects that exist at the time of delivery, regardless of whether the seller knew about them. Liability arises where a defect reduces: The benefit intended under
June 25, 2026
On June 18, 2026, Thailand’s Office of the Personal Data Protection Committee (PDPC) published two notifications in the Government Gazette establishing Thailand’s first formal certification framework for personal data protection standards under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notifications, which took immediate effect, introduce a voluntary certification framework aimed at promoting accountability, strengthening organizational data protection governance, and aligning Thailand more closely with international frameworks that recognize certification as a key compliance tool. Certification Criteria The first notification sets out the assessment criteria for organizations seeking certification. Applicants must undergo an evaluation against a framework comprising four assessment categories, 10 focus areas, and 128 assessment criteria covering key elements of a privacy management program. These include: Organizational oversight and internal policies and procedures. Human resource development, including staff training and awareness programs. Clearly defined operational processes and procedures covering data subject rights, transparency obligations, records of processing activities, and lawful basis management, as well as contractual safeguards such as data-processing and data-sharing agreements and risk assessments, including Data Protection Impact Assessments. Technical measures encompassing data security controls and breach response capabilities Based on the assessment results, organizations may be awarded either a PDPA Compliance Certificate or a higher-level PDPA Certificate accompanied by a certification mark. Application and Assessment Process The second notification establishes the application and assessment process for obtaining certification. Eligible applicants include government agencies and private-sector entities that demonstrate sufficient privacy governance maturity and meet the prescribed eligibility requirements. Applicants must submit their applications along with supporting documentation for review. Upon receiving an application, the Office of the PDPC will conduct a detailed evaluation, which may include both documentary review and on-site inspections. Incomplete applications may be rejected, though applicants are typically given a limited period to correct deficiencies before a final decision
June 23, 2026
On May 26, 2026, Thailand’s Department of Land Transport (DLT) published for public consultation a draft amendment to the Ministerial Regulation on Electronic Ride-Hailing Vehicles that would, for the first time, allow juristic persons (legal entities) to register vehicles as electronic ride-hailing cars—a right that currently belongs exclusively to natural persons, limited to one person per one vehicle. If finalized in its current form, the regulation would significantly expand the supply side of Thailand’s ride-hailing market by enabling corporate fleet operators to enter the space. The public comment period is open through June 24, 2026. Key Principles Under the Draft Regulation Under the proposed amendment, juristic persons that maintain a fleet of at least 50 vehicles will be permitted to register vehicles as electronic ride-hailing cars. This represents a fundamental shift from the current framework, which restricts registration to individual natural persons on a one-person-one-car basis. Vehicle Specifications Corporate-owned ride-hailing vehicles must meet the following requirements: Be brand new from the factory, or no more than two years old from first registration with no more than 20,000 km of use. Not be a vehicle that has been reconstructed or repaired after involvement in a serious accident affecting safety—a standard consistent with public transport vehicles (RorYor. 6). Be classified as small, medium, or large in accordance with ministerial or director-general specifications. The vehicles may be equipped with safety devices such as interior or exterior cameras (video/photo recording) and can retain the original factory color of the vehicle body (no mandatory color change is required). License Plates Corporate ride-hailing vehicles will use license plates of the same size, characteristics, and color as those for private passenger vehicles not exceeding seven seats (RorYor. 1), rather than public transport plates. Potential Impact The government has stated that the regulation is intended to: Promote