You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 11, 2025

Vietnam’s Regulatory Sandboxes: Paving the Way for Digital Innovation

Vietnam’s recent embrace of “regulatory sandboxes” reflects a deliberate policy choice to balance the need for robust oversight with an equally pressing imperative to catalyze innovation. A sandbox is a controlled, time-bound framework in which businesses may pilot emerging technologies, products, or business models under relaxed or tailor-made regulatory requirements, thereby allowing regulators to observe risks in real time while innovators validate commercial viability without bearing the full weight of the traditional compliance regime.

By issuing sandbox regulations, the government of Vietnam is signaling its commitment to accelerating digital transformation, attracting investment, and developing a knowledge-based economy, all while safeguarding financial stability, consumer protection, and national security. This strategy is embodied in a suite of instruments that together establish sector-specific sandboxes:

  • Decree No. 94/2025/ND-CP on the Regulatory Sandbox in the Banking Sector (Fintech Sandbox Decree), effective July 1, 2025.
  • Law on Digital Technology Industry (DTI Law), effective January 1, 2026, and Law on Science, Technology and Innovation (STI Law), effective October 1, 2025.
  • Resolution No. 222/2025/QH15 on International Financial Centers (IFC Resolution), effective September 1, 2025.

In addition, a draft resolution on the pilot implementation of the crypto-asset market (Draft Crypto Pilot Resolution) is expected to introduce a dedicated sandbox for crypto-asset service providers later this year, further underscoring Vietnam’s holistic, forward-looking approach to regulating emerging technologies.

Below is a brief summary of all the regulatory sandboxes, who they are open for, and what businesses are attracted.

Fintech Sandbox Decree

Under the Fintech Sandbox Decree, besides credit institutions and foreign bank branches, fintech companies operating in Vietnam can apply for a Certificate of Sandbox Participation issued by the State Bank of Vietnam to operate any of the following services in Vietnam:

  • Credit scoring: A solution applicable to information technology systems of credit institutions, branches of foreign banks, and fintech companies to score the creditworthiness of an individual or organization supporting the credit approval by credit institutions and branches of foreign banks.
  • Data sharing via open API: A standardized application programming interface set that may be used by computer systems of credit institutions, branches of foreign banks, fintech companies, and other third parties to send service requests to systems of credit institutions and branches of foreign banks sharing that Open API.
  • Peer-to-peer (P2P) lending: An information technology application solution provided by a P2P lending company to connect borrowers and lenders, and provide assistance for contract conclusion via a digital platform. The currency used in P2P lending solutions must be VND.

The maximum sandbox period is two years, with the possibility of extension of no more than two times, with each extension not exceeding one year.

See our previous article: Vietnam Issues Fintech Sandbox Decree

DTI Law and STI Law

Under the DTI Law, the regulatory sandbox is expressly designed to support and promote the development of “digital technology application products and services”. These products and services are defined to include:

  • Hardware products;
  • Software products;
  • Digital content products; and
  • Services in consultancy, design, installation, integration, management, operation, training, digitization, data processing, warranty, maintenance, repair, refurbishment, publication and distribution of digital technology products; providing digital technology products in the form of services and other digital technology services.

The regulatory sandbox for such products and services will be implemented according to the STI Law.

Under the STI Law, multiple regulatory sandboxes may be established based on government initiatives. In general, these sandboxes require a special license for participation; may provide liability exemptions for participating parties; and are subject to a maximum duration of three years, with a one-time extension of up to an additional three years.

See our previous article: Vietnam’s National Digital Transformation: Key Legal Developments to Expect in 2025

IFC Resolution

Under the IFC Resolution, international financial centers will be organized within specific geographic areas in Ho Chi Minh City and Da Nang, where preferential specific policies for entities registered or recognized as members will be applied.

One such policy is a regulatory sandbox for fintech technologies, products, services, and business models not yet prescribed by law, offering exemption from compliance with standards and technical regulations as well as exemption from liability for damage to the state during experimentation.

The products and services to be provided in the international financial centers include stocks, bonds, fund certificates, financial derivatives, fund management, insurance, reinsurance, banking and foreign exchange, green finance, carbon credits, fintech, digital assets, and other products and services prescribed by the government.

The IFC Resolution does not specify a specific expiry date, but would be replaced by a “Law on International Financial Centers” that is to be proposed in 2034. Approved projects and operation may continue to operate and receive incentives until the end of the project or operation.

See our previous article: Vietnam’s Resolution on International Financial Centers Brings New Opportunities

Draft Crypto Pilot Resolution

Under the Draft Crypto Pilot Resolution, there will be a regulatory sandbox for crypto asset services, including (i) organization of crypto asset transaction/trading markets; (ii) proprietary trading of crypto assets; (iii) custody of crypto assets; and (iv) provision of platforms for crypto asset issuance.

These crypto asset service providers are subject to a joint venture requirement in which the foreign ownership limit is 49%. The entity will need to satisfy stringent requirements to be issued a crypto asset service provider license from the Ministry of Finance.

It is currently contemplated that the regulatory sandbox will run until December 31, 2027. After this, depending on the result of the pilot program, the authority may consider the future legal framework.

Outlook

Vietnam’s regulatory sandboxes represent a significant step forward in fostering innovation and development within the country’s financial and technological sectors. By providing a controlled environment for new and innovative businesses to operate, these sandboxes offer a unique opportunity for companies to test their products and services without the onerous compliance requirements or fears of liability. These initiatives are expected to attract both domestic and international businesses, driving economic growth and positioning Vietnam as a leader in the digital economy.

As these regulatory frameworks take effect, it will be crucial for businesses to stay informed and adapt to the evolving landscape. Now that the Vietnamese government has opened up, the success of these sandboxes will depend on the participation of the business community. The ball is in the private sector’s court.

RELATED INSIGHTS​ 

July 24, 2025
Vietnam’s Ministry of Public Security recently released a draft version of the 2025 Cybersecurity Law, which is intended to replace both the existing 2018 Cybersecurity Law and the 2015 Law on Network Information Security (LNIS). This consolidation reflects a broader effort by the Vietnamese government to streamline and centralize the legal framework governing cybersecurity, data protection, and information security to be under the sole authority of the Ministry of Public Security, moving away from the previous sharing of responsibility with the former Ministry of Information and Communications (which ceased operations earlier this year and merged with the Ministry of Science and Technology). This shift aims to eliminate overlaps and improve enforcement efficiency. The draft law is built upon the foundation of principles and provisions of both the 2018 Cybersecurity Law and the 2015 LNIS, while also introducing a wide range of amendments and new regulations. By merging the two laws, the government seeks to reduce legal fragmentation and ensure consistency in definitions, obligations, and enforcement mechanisms across related domains like data protection, IT system classification, and cybercrime prevention. The newly introduced amendments include enhanced obligations for service providers, stricter controls on information transmission, classification of IT systems, designation and protection of nationally important information systems, and sector-specific violations and compliance requirements. Highlights of the draft law are discussed below. Definition and Obligations of Service Providers The draft law clearly defines and significantly broadens the scope of entities considered “service providers” under its jurisdiction. This now includes businesses and individuals offering products or services in cyberspace, including both infrastructure and content online services, such as: Internet service providers (ISPs) and providers of telecommunications, hosting, servers, domain names, VPNs, proxy services, and cloud computing; Providers of social networks, websites, and online gaming; Financial institutions, banks, foreign bank branches in Vietnam, e-wallet
July 23, 2025
On July 4, 2025, Thailand’s Electronic Transactions Development Agency (ETDA) issued two significant notifications that introduce new compliance requirements for ride-hailing platforms operating in the country. The notifications formally designate these platforms as high-impact digital services under section 18(3) of the Royal Decree on Digital Platform Service Businesses and impose a comprehensive set of additional operational obligations. These measures are designed to address regulatory gaps and enhance oversight of digital platforms providing public passenger vehicle or motorcycle ride-hailing services. First, the Notification on the Designation of Ride-Hailing Platforms under section 18(3) formally designates all ride-hailing platforms that have notified the ETDA of their operations as high-impact digital platform services under section 18(3) of the royal decree. Unlike high-risk marketplace platforms, which are named individually, any ride-hailing platform that has notified the ETDA of its operations is automatically subject to these new requirements. Next, the Notification on Additional Obligations for Ride-Hailing Platforms imposes further obligations on ride-hailing platforms, supplementing the general requirements under section 21 of the royal decree. These notifications will come into force 90 days from their publication in the Government Gazette. New Compliance Obligations The new regulatory framework introduces a range of operational, technical, and reporting requirements for ride-hailing platforms, particularly concerning the issues described below. Vehicle and Driver Compliance Operators must: Ensure that all vehicles used on the platform are registered as public vehicles in accordance with Department of Land Transport requirements Verify all drivers hold valid public driving licenses Collect service fees in compliance with applicable fare regulations under the Vehicle Law Digital Platform Features and User Verification Operators must implement robust digital platform features for both drivers and riders, including: Comprehensive identity verification and confirmation processes for drivers and riders, utilizing both face-to-face and non-face-to-face methods, including biometric and digital ID checks Real-time GPS
July 17, 2025
On July 9, 2025, Thailand issued a notification that introduces comprehensive operational requirements for digital platform service providers operating as goods marketplaces, effective December 31, 2025 (i.e., 180 days after its publication in the Government Gazette). The regulation’s official name is Notification of the Electronic Transactions Committee Re: Other Actions for Digital Platform Service Operators in the Category of Marketplace for Goods with Specific Characteristics under Section 18(2) of the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification B.E. 2565 (2022), B.E. 2568 (2025). Scope of Application The notification applies exclusively to goods marketplace operators formally designated by the Electronic Transactions Development Agency (ETDA), which on the same day designated 19 platforms that had previously notified the ETDA of their operations. The goods requiring enhanced oversight by these operators are limited to those regulated by the Thai Food and Drug Administration (FDA) and the Thai Industrial Standards Institute (TISI). Development from Earlier Draft An earlier draft of the notification had included a requirement for offshore platforms to establish a local entity, but this requirement was removed from the final notification. Key Obligations Despite the removal of the local entity requirement, the notification imposes a range of additional obligations on designated goods marketplace operators: Transparency. Operators must implement robust transparency measures, including clear, accessible, and understandable disclosures to users in Thai. These disclosures must cover all relevant terms and conditions, comprehensive product information, and complaint management procedures. Operators must also submit an annual compliance report to the ETDA within 60 days after the end of their accounting period, including statistics on regulated goods. Business user registration and identity verification. Before permitting the sale or advertisement of regulated goods, operators must collect and verify business user information, including contact details, identification documents, registration
July 15, 2025
Thailand has established new safe harbor rules that require social media platforms to remove specified content within 24 hours of government notification. On July 5, 2025, the Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers was issued and took effect. This followed a hearing in May 2025 where only a select group of social media and online communication platform operators were invited to attend and comment on draft rules that could exempt social media platform operators from joint liability under the amended Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes in cases involving victims of technological crimes. Safe Harbor Rules The notification stipulates procedures that must be followed in order to receive the protection of the safe harbor rules. Upon being notified by the Division of Prevention and Suppression of Cybercrime, Office of the Permanent Secretary of the Ministry of Digital Economy and Society (MDES) of the presence of false or misleading information that may lead to the commission of a technological crime, social media service providers must immediately take down the specified content, with a maximum allowable turnaround time of 24 hours from the time of receiving the notification. Social media service providers are required to promptly report the outcome of each takedown to the MDES Division of Prevention and Suppression. This shift in Thailand’s regulatory approach to social media content moderation establishes clear government oversight mechanisms while providing platforms with liability protection for compliance. As the new rules took immediate effect, social media platforms need to ensure that they have adequate systems and processes in place to comply with the requirements.