You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 15, 2025

Vietnam’s E-Commerce Legal Framework: A Deep Dive into the Draft E-Commerce Law

More than a decade after the issuance of Decree No. 52/2013/ND-CP (as amended by Decree No. 85/2021/ND-CP; collectively, “Decree 52”), Vietnam’s legal framework for e-commerce is under growing pressure to keep pace with the evolving digital economy. While Decree 52 has provided a foundational framework, it has shown certain limitations in keeping up with issues such as counterfeit goods, intellectual property enforcement, unqualified products, and emerging models like livestream selling and affiliate marketing.

To address these regulatory gaps, the Ministry of Industry and Trade (MOIT) has released the 2025 Draft E-Commerce Law (“Draft Law”) for public consultation. The Draft Law is intended to supersede the current framework under Decree 52 and establish a more detailed and comprehensive legal foundation for the regulations of e-commerce activities in Vietnam. It is currently expected to be submitted to the National Assembly for review and potential adoption during its 10th session in October 2025.

In this article, we discuss the Draft Law’s most significant updates and legal developments in comparison to existing regulations, and assess the practical challenges that businesses may face in preparing for implementation in the near future.

Platform Classification: Toward a More Nuanced Framework

Unlike Decree 52’s simpler structure, which broadly categorized platforms into either (i) websites selling goods and services or (ii) websites providing e-commerce services, the Draft Law introduces a more detailed framework that aims to classify platforms based on their technical functions and business models. Specifically, the Draft Law introduces a four-tier classification system for e-commerce platforms, consisting of: (i) Direct Business Platforms, (ii) Intermediary Platforms, (iii) Social Networks with E-Commerce Functions, and (iv) Multi-Service Integrated Platforms. This approach reflects an effort to more accurately capture the complexity of today’s e-commerce landscape, including hybrid platforms such as TikTok Shop.

While this approach reflects the growing complexity of the digital/e-commerce landscape, it currently lacks clear criteria or thresholds for distinguishing between categories. This ambiguity may create uncertainty for platforms that operate across multiple functions, such as combining direct sales, third-party marketplaces, and social commerce features. While such models may potentially fall under the “Multi-Service Integrated Platforms” category, the Draft Law does not currently provide clear criteria to distinguish between overlapping platform types. As a result, it remains unclear how these platforms should be classified and which set of compliance obligations would apply.

Operator Responsibilities: Broader Scope and Heightened Compliance Burden

While Decree 52 required platform registration and basic post-facto monitoring, the Draft Law significantly expands the scope of responsibilities imposed on platform operators. Under the Draft Law, platforms must conduct identity verification for all sellers, including foreign sellers; however, the types of documents deemed legally sufficient for verifying foreign entities have not yet been clarified.

Furthermore, the Draft Law introduces the implementation of automated content moderation tools to screen seller-generated content prior to display, marking a notable advancement beyond the requirements of Decree 52. While the obligation to remove unlawful content within 24 hours upon request from competent authorities remains consistent with Decree 52, the Draft Law imposes additional responsibilities for proactive monitoring and enhanced compliance, particularly in light of heightened regulatory concerns regarding counterfeit goods and consumer protection.

Livestream and Affiliate Regulation: New Obligations to Fill Regulatory Gaps

Previously unregulated under Decree 52, livestream selling and affiliate marketing are now expressly addressed under the Draft Law. These provisions reflect growing regulatory concern over KOLs and influencers promoting products without clear origin and/supporting documentation.

While the new requirements are intended to improve transparency and strengthen consumer protection, they also introduce additional compliance burdens, not only for individual marketers, but also for platform operators. In particular, platforms must implement mechanisms to (i) warn users/viewers of content that is unsuitable for children and (ii) monitor livestream content in real time, enabling the removal of prohibited information and the termination of livestreams containing violating content.

Cross-Border Rules: From Local Presence to Legal Accountability

Under Decree 52, foreign e-commerce platforms targeting Vietnam via Vietnamese domain names, language interfaces, or a high volume of domestic transactions are required to register with the authorities and either establish a representative office or appoint an authorized local representative. While the existing regulations do not fully ensure enforcement against violating foreign platforms, this requirement ensured that authorities had a local point of contact.

The Draft Law retains these jurisdictional thresholds but introduces a significant shift. Accordingly, the appointed local entity is now subject to joint liability for the platform’s compliance with Vietnamese law. This change reflects the MOIT’s efforts to close enforcement loopholes, particularly in relation to counterfeit goods, consumer protection, and cross-border tax compliance.

Supporting Services: Strengthening Oversight Across the E-commerce Chain

Decree 52 made only general references to supporting services such as logistics and payment, without defining their legal responsibilities or integrating them into the compliance framework. The Draft Law takes a more structured approach by explicitly identifying four categories of supporting services: technical infrastructure, logistics, payment, and electronic contract authentication. Providers of these services are now subject to specific obligations, including coordination with platforms and regulators, and implementation of internal inspection and monitoring mechanisms.

This shift seems to reflect the MOIT’s growing concern that the lack of regulation over third-party service providers has contributed to the circulation of counterfeit goods and tax evasion. By formally incorporating these service providers into the compliance framework, the Draft Law aims to close enforcement gaps and strengthen accountability across the digital supply chain.

Algorithm Disclosure: A New Compliance Burden for Platforms

For the first time, the Draft Law introduces provisions requiring e-commerce platforms to disclose information about their algorithms, such as logic, design, and modeling, upon request by competent authorities during violation inspections. While intended to enhance transparency and prevent abuse, this requirement would raise significant concerns for platform operators. Specifically, algorithms are often a company’s core intellectual property developed through substantial investment, and the Draft Law has not yet addressed the scope, format, or confidentiality protections surrounding such disclosures.

Outlook

Compared to the current regime, the Draft Law reflects a more structured and expansive approach, touching not only on core platform activities but also on affiliated functions such as payment, logistics, livestreaming, and data handling. While several provisions await further clarification, the direction of the government is clear: Vietnam is moving toward a more comprehensive, compliance-driven model of digital commerce regulation. Businesses are thus recommended to proactively review how the new obligations may impact their structures, operations, and risk exposure. Companies that adapt early will be best positioned to navigate the transition smoothly and maintain regulatory confidence in an increasingly complex e-commerce environment.

RELATED INSIGHTS​ 

April 3, 2026
Thailand’s Securities and Exchange Commission (SEC) has established a comprehensive governance framework for the use of artificial intelligence and machine learning (AI/ML) in the capital markets. The framework provides guidance to capital market business operators on understanding the risks associated with AI/ML implementation and adopting appropriate practices to build public confidence in Thailand’s capital markets. While the guidelines are principle-based rather than prescriptive, they reflect the SEC’s expectations for responsible AI/ML governance and are likely to inform supervisory activities and industry standards going forward. Scope The framework applies to capital market business operators supervised by the SEC. This includes, for example, securities and derivatives firms, asset management companies, mutual fund and private fund managers, investment advisors and investment consultants (including robo-advisory service providers), derivatives intermediaries, and other licensed intermediaries and market operators in the Thai capital markets that deploy AI/ML in their operations. Core Principles of the Guidelines The framework is presented as a best-practice manual rather than prescriptive regulation, providing guidance that regulated entities may apply to their AI/ML governance and risk management as appropriate. While currently nonbinding, the guidelines signal the SEC’s expectations for the sector, particularly in relation to other binding SEC regulations such as those covering IT risk management and market conduct. The guidelines name four core principles for AI/ML deployment: Fairness: Design and develop AI/ML with consideration for fairness, equality, and social diversity to prevent discrimination against individuals or groups. Legal and ethical compliance: Ensure AI/ML use aligns with applicable laws, ethical standards, and organizational values and policies. Accountability: Establish clear responsibility—both internally and externally—for AI/ML activities and outcomes. Transparency: Provide adequate disclosure to users about AI/ML use, including explainability of decisions and traceability of activities. AI/ML Best Practices The guidelines prescribe best practices across four stages of the AI/ML lifecycle, as described below.
April 2, 2026
Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance. What Has Changed: OIC and PDPC Alignment The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers. Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible. Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors. Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels. DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on
April 1, 2026
On March 30, 2026, Thailand’s Customs Department announced a strategy to raise import duties on a broad range of consumer goods—including plastic items and electronics accessories—to their maximum statutory ceilings, which often sit at 30% or 40%. Many of these goods currently benefit from promotional or incentive rates as low as 5%. For importers, e-commerce platforms, and logistics providers, this development demands immediate attention. While these increases generally require cabinet approval, they do not require full parliamentary amendment of the Customs Tariff Decree B.E. 2530, as the Customs director-general and the finance minister hold delegated authority to adjust rates within existing statutory bounds. Businesses should not assume that the legislative process will provide significant lead time before higher rates take effect. Death of the De Minimis: Abolishing the THB 1,500 Loophole This “ceiling-rate” policy, which is designed to equalize the landed cost of foreign goods with the domestic production costs of Thai manufacturers, builds on a sweeping set of customs reforms that have already begun to reshape Thailand’s trade environment. The foundation of this new regime was laid on January 1, 2026, when Thailand formally abolished the longstanding THB 1,500 duty exemption for small imported parcels under Customs Notification No. 219/2568. Every imported item is now subject to VAT and applicable import duties for its declared value, regardless of parcel size or transaction amount. By narrowing the scope of exemptions previously granted to low-value goods under the Customs Tariff Decree B.E. 2530, the government has made clear that the era of tax-free cross-border micro-imports is over. Three-Phased Strategy and Legal Modernization The March 30 announcement is the second phase of a three-part regulatory roadmap: Immediate enforcement: The removal of the THB 1,500 loophole and the imposition of VAT on all parcels, effective January 1, 2026. Tariff realignment: The current
March 31, 2026
Thailand’s Office of the Consumer Protection Board has opened a public hearing period on draft regulations governing the transfer of direct sales and direct marketing businesses. The draft Notification of the Direct Sales and Direct Marketing Committee: Criteria and Procedures for Business Transfer and Amendment of Registration for Direct Sales or Direct Marketing Businesses establishes a compliance-focused process with strict documentation requirements and timelines for transferring direct sales and direct marketing businesses. The proposed framework also defines the roles of transferors and transferees and establishes application procedures with the Office of the Consumer Protection Board. Applications may be submitted in person or electronically and will be examined to confirm they are complete, authentic, and compliant with legal requirements. This includes verification that: The transferee meets all required qualifications; No disqualifying factors apply; and The applicant is not subject to legal restrictions. The public hearing period is open until April 29, 2026. Direct sales and direct marketing business operators should prepare for these proposed requirements to ensure compliant implementation once the regulations are finalized.