You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 15, 2025

Vietnam’s E-Commerce Legal Framework: A Deep Dive into the Draft E-Commerce Law

More than a decade after the issuance of Decree No. 52/2013/ND-CP (as amended by Decree No. 85/2021/ND-CP; collectively, “Decree 52”), Vietnam’s legal framework for e-commerce is under growing pressure to keep pace with the evolving digital economy. While Decree 52 has provided a foundational framework, it has shown certain limitations in keeping up with issues such as counterfeit goods, intellectual property enforcement, unqualified products, and emerging models like livestream selling and affiliate marketing.

To address these regulatory gaps, the Ministry of Industry and Trade (MOIT) has released the 2025 Draft E-Commerce Law (“Draft Law”) for public consultation. The Draft Law is intended to supersede the current framework under Decree 52 and establish a more detailed and comprehensive legal foundation for the regulations of e-commerce activities in Vietnam. It is currently expected to be submitted to the National Assembly for review and potential adoption during its 10th session in October 2025.

In this article, we discuss the Draft Law’s most significant updates and legal developments in comparison to existing regulations, and assess the practical challenges that businesses may face in preparing for implementation in the near future.

Platform Classification: Toward a More Nuanced Framework

Unlike Decree 52’s simpler structure, which broadly categorized platforms into either (i) websites selling goods and services or (ii) websites providing e-commerce services, the Draft Law introduces a more detailed framework that aims to classify platforms based on their technical functions and business models. Specifically, the Draft Law introduces a four-tier classification system for e-commerce platforms, consisting of: (i) Direct Business Platforms, (ii) Intermediary Platforms, (iii) Social Networks with E-Commerce Functions, and (iv) Multi-Service Integrated Platforms. This approach reflects an effort to more accurately capture the complexity of today’s e-commerce landscape, including hybrid platforms such as TikTok Shop.

While this approach reflects the growing complexity of the digital/e-commerce landscape, it currently lacks clear criteria or thresholds for distinguishing between categories. This ambiguity may create uncertainty for platforms that operate across multiple functions, such as combining direct sales, third-party marketplaces, and social commerce features. While such models may potentially fall under the “Multi-Service Integrated Platforms” category, the Draft Law does not currently provide clear criteria to distinguish between overlapping platform types. As a result, it remains unclear how these platforms should be classified and which set of compliance obligations would apply.

Operator Responsibilities: Broader Scope and Heightened Compliance Burden

While Decree 52 required platform registration and basic post-facto monitoring, the Draft Law significantly expands the scope of responsibilities imposed on platform operators. Under the Draft Law, platforms must conduct identity verification for all sellers, including foreign sellers; however, the types of documents deemed legally sufficient for verifying foreign entities have not yet been clarified.

Furthermore, the Draft Law introduces the implementation of automated content moderation tools to screen seller-generated content prior to display, marking a notable advancement beyond the requirements of Decree 52. While the obligation to remove unlawful content within 24 hours upon request from competent authorities remains consistent with Decree 52, the Draft Law imposes additional responsibilities for proactive monitoring and enhanced compliance, particularly in light of heightened regulatory concerns regarding counterfeit goods and consumer protection.

Livestream and Affiliate Regulation: New Obligations to Fill Regulatory Gaps

Previously unregulated under Decree 52, livestream selling and affiliate marketing are now expressly addressed under the Draft Law. These provisions reflect growing regulatory concern over KOLs and influencers promoting products without clear origin and/supporting documentation.

While the new requirements are intended to improve transparency and strengthen consumer protection, they also introduce additional compliance burdens, not only for individual marketers, but also for platform operators. In particular, platforms must implement mechanisms to (i) warn users/viewers of content that is unsuitable for children and (ii) monitor livestream content in real time, enabling the removal of prohibited information and the termination of livestreams containing violating content.

Cross-Border Rules: From Local Presence to Legal Accountability

Under Decree 52, foreign e-commerce platforms targeting Vietnam via Vietnamese domain names, language interfaces, or a high volume of domestic transactions are required to register with the authorities and either establish a representative office or appoint an authorized local representative. While the existing regulations do not fully ensure enforcement against violating foreign platforms, this requirement ensured that authorities had a local point of contact.

The Draft Law retains these jurisdictional thresholds but introduces a significant shift. Accordingly, the appointed local entity is now subject to joint liability for the platform’s compliance with Vietnamese law. This change reflects the MOIT’s efforts to close enforcement loopholes, particularly in relation to counterfeit goods, consumer protection, and cross-border tax compliance.

Supporting Services: Strengthening Oversight Across the E-commerce Chain

Decree 52 made only general references to supporting services such as logistics and payment, without defining their legal responsibilities or integrating them into the compliance framework. The Draft Law takes a more structured approach by explicitly identifying four categories of supporting services: technical infrastructure, logistics, payment, and electronic contract authentication. Providers of these services are now subject to specific obligations, including coordination with platforms and regulators, and implementation of internal inspection and monitoring mechanisms.

This shift seems to reflect the MOIT’s growing concern that the lack of regulation over third-party service providers has contributed to the circulation of counterfeit goods and tax evasion. By formally incorporating these service providers into the compliance framework, the Draft Law aims to close enforcement gaps and strengthen accountability across the digital supply chain.

Algorithm Disclosure: A New Compliance Burden for Platforms

For the first time, the Draft Law introduces provisions requiring e-commerce platforms to disclose information about their algorithms, such as logic, design, and modeling, upon request by competent authorities during violation inspections. While intended to enhance transparency and prevent abuse, this requirement would raise significant concerns for platform operators. Specifically, algorithms are often a company’s core intellectual property developed through substantial investment, and the Draft Law has not yet addressed the scope, format, or confidentiality protections surrounding such disclosures.

Outlook

Compared to the current regime, the Draft Law reflects a more structured and expansive approach, touching not only on core platform activities but also on affiliated functions such as payment, logistics, livestreaming, and data handling. While several provisions await further clarification, the direction of the government is clear: Vietnam is moving toward a more comprehensive, compliance-driven model of digital commerce regulation. Businesses are thus recommended to proactively review how the new obligations may impact their structures, operations, and risk exposure. Companies that adapt early will be best positioned to navigate the transition smoothly and maintain regulatory confidence in an increasingly complex e-commerce environment.

RELATED INSIGHTS​ 

August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with
August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention
July 30, 2025
Artificial intelligence (AI) model training and data scraping are essential processes in the development of modern AI systems. AI model training involves using large datasets to teach machine learning algorithms to recognize patterns, make predictions, or generate new content. Data scraping refers to the automated extraction of information from websites or digital sources, often to assemble the vast datasets required for effective AI training. As these practices become more widespread, questions about the legality of using third-party content—especially copyrighted works—have become increasingly important. In Thailand, the legal landscape for AI developers is shaped primarily by the Copyright Act, which presents unique challenges due to the absence of a fair-use exception. This article examines the copyright-related risks and legal uncertainties facing AI developers under Thailand’s current copyright law and practices, offering strategic guidance for navigating this complex environment. Copyright Risks in AI Scraping and Training Thailand’s Copyright Act does not provide a broad fair use or fair dealing exception, unlike some other jurisdictions, such as the United States. This absence has significant consequences for AI developers: No general defense for AI training: Any use of copyrighted material for AI model training is presumed to be infringing unless a specific, narrow statutory exception applies or explicit permission is obtained from the rights holder. There is no general legal basis for using copyrighted works in AI training without authorization. Increased rights clearance burden: Developers must identify and secure licenses for every copyrighted work included in their training datasets. Given the scale and diversity of data required for effective AI models, this process can be both impractical and costly. Legal ambiguity and litigation risk: The lack of clear statutory guidance or case law leaves developers in a legal gray area. There is no established precedent clarifying whether certain uses of copyrighted material for
July 24, 2025
Thai authorities have escalated efforts to block unlawful cross-border digital asset business operators. On June 19, 2025, the Ministry of Digital Economy and Society (MDES) issued a notification empowering it to ban internet access to operations or services offered by digital asset business operators who lack licenses from the Thailand Securities and Exchange Commission (SEC) under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This ban, issued under the 2023 Royal Decree on Measures for the Prevention and Suppression of Technology Crime, particularly aims to block Thai users’ access to services offered by unlicensed offshore digital asset providers via their own apps or websites or through public social media platforms. Compliance Requirements The notification requires internet service providers and social media platforms selected by MDES to immediately impose internet access restrictions on identified apps, websites, and IP addresses of illegal operators upon receiving MDES orders. Takedown Orders There are two tracks for competent officials at MDES to issue orders to operators: If the competent official is notified by the SEC of licensing noncompliance by a particular digital asset business operator, the competent official can issue a takedown order to the operator upon approval from the permanent secretary of MDES. If the competent official independently discovers, or receives a complaint from any third party other than the SEC, that a digital asset business operator may have violated licensing requirements, the competent official can ask the SEC to verify and confirm the relevant facts and noncompliance before seeking approval from the permanent secretary of MDES to issue the takedown order. Streamlined Enforcement Prior to this notification, the SEC could obtain takedown orders only from Thai courts under the 2007 Computer Crime Act to take down or block access to unlicensed digital asset platforms and apps. This was a relatively