You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2024

Vietnam’s New Decree on Non-Cash Payments

Vietnam’s financial landscape is set to further transform on July 1, 2024, when the government’s long-awaited Decree No. 52/2024/ND-CP dated May 15, 2024 (“Decree 52”), will officially replace Decree No. 101/2012/ND-CP dated November 22, 2012, on non-cash payments (“Decree 101”).

Decree 52 marks an important milestone by introducing the country’s first-ever legal definition of e-money. In addition, the decree brings forth new updates to regulations governing payment and intermediary payment services, laying the groundwork for more comprehensive guidance that will be provided in draft circulars now being developed by the State Bank of Vietnam (SBV).

Non-Cash Payment Instruments

The new definition of non-cash payment instruments under Decree 52 expands upon the previous definition in Decree 101. Notably, it clearly specifies the issuing entities as payment service providers, financial companies licensed to issue credit cards, and e-wallet service providers. Additionally, the new definition further clarifies that bank cards include debit, credit, and prepaid cards, and adds e-wallets to the list of non-cash payment instruments. Unlawful non-cash payment instruments are still defined as those that are not otherwise specified.

E-Money

Prior to Decree 52, the concept of e-money lacked a precise legal definition, despite its growing prevalence in forms like prepaid cards and e-wallets. The absence of a clear framework for e-money led to confusion with terms like “cryptpcurrency” and “virtual currency” and left significant ambiguity on whether e-money includes certain instruments, such as online game cards and mobile money. Decree 52 addresses this issue by clearly defining e-money as value in Vietnamese dong (VND) stored electronically and prepaid by customers to banks, foreign bank branches, and e-wallet service providers. It also specifically designates e-wallets and prepaid cards as types of storage mechanisms for e-money.

Non-Cash Payment Services

Decree 52 categorizes non-cash payment services into services with and without client payment accounts. Payment services with client accounts involve various financial transactions like money transfers and card payments, while services without client accounts focus on transactions not requiring such accounts. The decree also expands the range of entities providing these services to include not only banks and financial institutions but also public postal service providers (as defined by the Law on Post). So far, regulations for non-cash payment services provided by public postal service providers have been outlined in Circular No. 38/2019/TT-NHNN dated December 31, 2019. Decree 52 now further formalizes the inclusion of public postal service providers, a move that emphasizes expanded access to financial services, particularly in underbanked areas.

In a bid to further clarify and regulate these payment services, the SBV is currently working on a draft circular that will replace Circular No. 46/2014/TT-NHNN dated December 31, 2014, on non-cash payment services. This circular aims to offer updated guidance on all aspects of non-cash payment services under Decree 52 to address the new practical challenges in the current non-cash payment landscape.

Intermediary Payment Services

Decree 52 defines intermediary payment service (IPS) providers as non-bank organizations licensed by the SBV to provide IPSs, which encompass financial switching services, international financial switching services, electronic clearing services, e-wallet services, collection and payment support services, and payment gateway services. Compared to the old IPS regime under Decree 101 and Circular No. 39/2014/TT-NHNN dated December 11, 2014 (“Circular 39”), Decree 52 removes electronic money transfer support services from the list of IPSs.

The decree also sets stringent requirements for obtaining an IPS license, encompassing capital adequacy, technical capabilities, and personnel qualifications. The most notable requirements for organizations applying for an IPS license include the following:

  • The organization must not be in the process of division, separation, consolidation, merger, conversion, dissolution, or bankruptcy.
  • For financial switching services and electronic clearing services, the organization must provide only IPSs.
  • The organization must fulfill minimum charter capital requirements of either (1) VND 50 billion (approx. USD 1,964,560) for e-wallet services, collection and payment support services, and payment gateway services, or (2) VND 300 billion (approx. USD 11,787,360) for financial switching services, international financial switching services, and electronic clearing services.
  • The organization must comply with information system security level 4 requirements for financial switching services and electronic clearing services, or level 3 for other IPSs.
  • The organization must meet specific technical and personnel requirements.

Decree 52 also introduces new regulations for the provision of IPSs with international elements. These affect:

  • Foreign service providers providing IPSs to nonresident customers and foreigners residing in Vietnam to perform payment transactions for goods and services in Vietnam; and
  • Providers of IPSs that customers use to perform payment transactions for foreign goods and services.

The SBV is currently preparing a draft circular that will replace Circular 39 on IPSs and is expected to be issued soon.

Safety and Security of Non-Cash Payments

Under Decree 52, payment service and IPS providers are responsible for ensuring the safety and confidentiality of transactions, conducting inspections of payment-accepting units, and actively managing risks to prevent the misuse of their services for illegal activities. IPS providers specifically must adhere to information system security requirements with varying levels of compliance depending on the specific services offered (level 4 for financial switching services and electronic clearing services, and level 3 for other IPSs). IPS providers should therefore also carefully review relevant regulations under the Law on Network Information Security and Decree No. 85/2016/ND-CP dated July 1, 2016, on the security of information systems by levels, for full compliance in this regard.

In addition to these requirements, payment service and IPS providers should also pay attention to the new, stringent requirements under Decision No. 2345/QD-NHNN dated December 18, 2023, on security measures for online payments and bank card transactions. To solidify the compulsory measures set out under this decision, the SBV is currently drafting a circular to replace Circular No. 35/2016/TT-NHNN dated December 29, 2016, which will further guide the requirements on safety and security for online banking services.

Other Notes

In addition to the above, Decree 52 also has the following key points:

  • Monitoring Activities: Decree 52 grants the SBV extensive supervisory powers over payment systems, payment services, and IPSs. The SBV is authorized to promulgate regulations, conduct remote and on-site supervision, and request information from relevant entities. Payment service providers and IPS providers must comply with these regulations and provide the requested information. Notably, the SBV has the authority to determine and supervise economically important payment systems to maintain their stability and security. To provide more guidance in this regard, the SBV is also currently working on a draft circular that will replace Circular No. 20/2018/TT-NHNN dated August 30, 2018, on supervision of payment systems.
  • Payment Agents: The SBV is developing a draft circular on payment agents for non-cash payment services as regulated under Decree 52. This initiative aims to enhance financial inclusion by enabling banks and foreign bank branches to expand their customer base and service reach without incurring the costs associated with expanding their physical networks. By partnering with payment agents, banks can offer basic financial services in remote areas, reducing travel time for customers and improving overall service efficiency.
  • Transitional Period: Decree 52 provides various transitional periods for different stakeholders to align with its new regulations, as follows:
    • Commercial banks and foreign bank branches have 24 months to comply with Decree 52 for international payment system participation;
    • IPS providers licensed for money transfer support services under Decree 101 can continue operations as agreed between the parties;
    • Financial switching service providers connected to international payment systems have 24 months to comply and apply for a new license under Decree 52;
    • Public postal service enterprises have 24 months to apply for approval to provide payment services other than through customer payment accounts; and
    • IPS providers licensed before Decree 52’s effective date can operate until their licenses expire, unless they apply for new licenses under Decree 52’s regime.

Outlook

Decree 52 introduces significant changes to the non-cash payment landscape in Vietnam, including the country’s first legal definition of e-money and expanded regulations for non-cash payment and IPS services. In light of the new regime under Decree 52, the SBV is also developing a number of new circulars to provide further guidance on implementing these regulations. Payment and IPS providers should therefore closely follow legal developments in this field to ensure full compliance with the fast-evolving regulatory framework.

RELATED INSIGHTS​ 

August 4, 2026
Tilleke & Gibbins has contributed the Vietnam chapter to Fintech 2027, a global guide published by Lexology Panoramic that provides comparative insights into the legal and regulatory frameworks governing fintech businesses across multiple jurisdictions. The Vietnam chapter offers a comprehensive overview of the country’s rapidly evolving fintech landscape, examining both the regulatory environment and practical considerations for businesses operating in or entering the Vietnamese market. Topics covered include: Fintech landscape and initiatives: General innovation climate; government and regulatory support Financial regulation: Regulatory bodies; regulated activities; consumer lending; secondary market loan trading; collective investment schemes; alternative investment funds; peer-to-peer and marketplace lending; crowdfunding; invoice trading; payment services; open banking; robo-advice; insurance products; credit references Cross-border regulation: Passporting; requirement for a local presence Sales and marketing: Restrictions on the promotion and marketing of financial products and services Cryptoassets and tokens: Distributed ledger technology; cryptoassets; token issuance Artificial intelligence: Regulatory framework governing AI systems and AI-enabled financial services Change of control: Notification and consent requirements for regulated businesses Financial crime: Anti-bribery and anti-money laundering procedures; regulatory guidance Data protection and cybersecurity: Data protection obligations; cybersecurity requirements applicable to fintech businesses Outsourcing and cloud computing: Outsourcing of material functions; use of cloud computing in the financial services industry Intellectual property rights: IP protection for software; employee- and contractor-created IP; joint ownership; trade secrets; branding; remedies for infringement Competition: Competition law issues affecting fintech businesses Tax: Incentives for innovation and investment; developments affecting tax and compliance obligations Immigration: Immigration options for recruiting skilled foreign personnel; special measures available through Vietnam’s international financial centers The chapter also examines a number of significant recent developments shaping Vietnam’s fintech sector, including the introduction of the country’s first comprehensive regulatory framework for cryptoassets, the adoption of a dedicated law on artificial intelligence, implementation of the banking regulatory sandbox,
August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must
July 28, 2026
Data protection officers (DPOs) have become a fixture of Thailand’s privacy compliance landscape since the Personal Data Protection Act B.E. 2562 (2019) (PDPA) took full effect and the Office of the Personal Data Protection Committee (PDPC) began requiring certain organizations to appoint them. On July 7, 2026, the Office of the PDPC presented draft guidance on DPOs as part of a public consultation on a series of draft personal data protection manuals and recommendations. The draft offers the clearest indication yet of how the regulator expects the DPO role to work in practice, addressing recurring implementation issues under the PDPA—including when an organization must appoint a DPO, how the DPO should operate independently, how to manage conflicts of interest, and how data subjects and regulators should be able to contact the DPO. Because it remains in draft, organizations have an opportunity to weigh the practical implications now before the guidance is finalized. When a DPO Must Be Appointed The draft guidance clarifies the triggers for mandatory DPO appointment, including: Regular and systematic monitoring of personal data or systems on a large scale, such as tracking, analyzing, or predicting behavior, attitudes, or individual characteristics. Core activities involving large-scale processing of sensitive personal data, such as health data, biometric data, or criminal records. Certain foreign-organization representative arrangements. Public-sector coverage under relevant notifications identifying government entities that must appoint a DPO. Processing involving 100,000 or more data subjects may be considered large-scale. The guidance also contemplates voluntary DPO appointment for organizations that wish to raise their privacy governance standards, and such organizations should still comply with the standards applicable to DPOs under the law. Independence and Reporting Lines The draft guidance identifies lack of DPO independence as a core risk because an ineffective or constrained DPO may be unable to raise deficiencies
July 27, 2026
Vietnam’s new E-Commerce Law, which took effect on 1 July 2026 along with its implementing Decree No. 248/2026/ND-CP (Decree 248), marks a significant development in the country’s approach to online intellectual property (IP) enforcement, reflecting a clear shift from a reactive model of intermediary liability to one that expects platforms to play a more active role in preventing infringement. From notice-and-takedown to platform responsibility The most significant change introduced by the E-Commerce Law is the transformation of the legal role of e-commerce platforms. The existing safe harbor provisions under the IP Law and the copyright notice-and-takedown regime established by Decree 17/2023/ND-CP (Decree 17) largely required intermediaries to act only after receiving notice of infringement. Once infringing content had been removed, the platform’s legal obligation was generally considered fulfilled. The new legislation adopts a fundamentally different approach. Article 17 of the E-Commerce Law requires intermediary platforms to screen information relating to goods and services before publication in order to prevent listings involving counterfeit or IP-infringing goods, and goods of unknown origin. Rather than relying exclusively on complaints from rights holders, platforms are now expected to implement preventive measures before infringing listings become publicly available. Decree 248 further requires platforms to update keyword filters based on recommendations issued by competent authorities. These filtering mechanisms are intended to prevent prohibited listings from appearing on the platform and represent a further move away from a purely complaint-driven enforcement model. The legislation also introduces Vietnam’s first statutory stay-down obligation. Under the E-Commerce Law and Decree 248, major digital platforms must maintain automated systems capable of reviewing, warning against, and removing unlawful listings while also implementing measures to prevent repeat violations, defined under Decree 248 as conduct that has previously been identified and handled by the platform, but continues to recur. This obligation addresses one