You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 11, 2025

Vietnam’s Regulatory Sandboxes: Paving the Way for Digital Innovation

Vietnam’s recent embrace of “regulatory sandboxes” reflects a deliberate policy choice to balance the need for robust oversight with an equally pressing imperative to catalyze innovation. A sandbox is a controlled, time-bound framework in which businesses may pilot emerging technologies, products, or business models under relaxed or tailor-made regulatory requirements, thereby allowing regulators to observe risks in real time while innovators validate commercial viability without bearing the full weight of the traditional compliance regime.

By issuing sandbox regulations, the government of Vietnam is signaling its commitment to accelerating digital transformation, attracting investment, and developing a knowledge-based economy, all while safeguarding financial stability, consumer protection, and national security. This strategy is embodied in a suite of instruments that together establish sector-specific sandboxes:

  • Decree No. 94/2025/ND-CP on the Regulatory Sandbox in the Banking Sector (Fintech Sandbox Decree), effective July 1, 2025.
  • Law on Digital Technology Industry (DTI Law), effective January 1, 2026, and Law on Science, Technology and Innovation (STI Law), effective October 1, 2025.
  • Resolution No. 222/2025/QH15 on International Financial Centers (IFC Resolution), effective September 1, 2025.

In addition, a draft resolution on the pilot implementation of the crypto-asset market (Draft Crypto Pilot Resolution) is expected to introduce a dedicated sandbox for crypto-asset service providers later this year, further underscoring Vietnam’s holistic, forward-looking approach to regulating emerging technologies.

Below is a brief summary of all the regulatory sandboxes, who they are open for, and what businesses are attracted.

Fintech Sandbox Decree

Under the Fintech Sandbox Decree, besides credit institutions and foreign bank branches, fintech companies operating in Vietnam can apply for a Certificate of Sandbox Participation issued by the State Bank of Vietnam to operate any of the following services in Vietnam:

  • Credit scoring: A solution applicable to information technology systems of credit institutions, branches of foreign banks, and fintech companies to score the creditworthiness of an individual or organization supporting the credit approval by credit institutions and branches of foreign banks.
  • Data sharing via open API: A standardized application programming interface set that may be used by computer systems of credit institutions, branches of foreign banks, fintech companies, and other third parties to send service requests to systems of credit institutions and branches of foreign banks sharing that Open API.
  • Peer-to-peer (P2P) lending: An information technology application solution provided by a P2P lending company to connect borrowers and lenders, and provide assistance for contract conclusion via a digital platform. The currency used in P2P lending solutions must be VND.

The maximum sandbox period is two years, with the possibility of extension of no more than two times, with each extension not exceeding one year.

See our previous article: Vietnam Issues Fintech Sandbox Decree

DTI Law and STI Law

Under the DTI Law, the regulatory sandbox is expressly designed to support and promote the development of “digital technology application products and services”. These products and services are defined to include:

  • Hardware products;
  • Software products;
  • Digital content products; and
  • Services in consultancy, design, installation, integration, management, operation, training, digitization, data processing, warranty, maintenance, repair, refurbishment, publication and distribution of digital technology products; providing digital technology products in the form of services and other digital technology services.

The regulatory sandbox for such products and services will be implemented according to the STI Law.

Under the STI Law, multiple regulatory sandboxes may be established based on government initiatives. In general, these sandboxes require a special license for participation; may provide liability exemptions for participating parties; and are subject to a maximum duration of three years, with a one-time extension of up to an additional three years.

See our previous article: Vietnam’s National Digital Transformation: Key Legal Developments to Expect in 2025

IFC Resolution

Under the IFC Resolution, international financial centers will be organized within specific geographic areas in Ho Chi Minh City and Da Nang, where preferential specific policies for entities registered or recognized as members will be applied.

One such policy is a regulatory sandbox for fintech technologies, products, services, and business models not yet prescribed by law, offering exemption from compliance with standards and technical regulations as well as exemption from liability for damage to the state during experimentation.

The products and services to be provided in the international financial centers include stocks, bonds, fund certificates, financial derivatives, fund management, insurance, reinsurance, banking and foreign exchange, green finance, carbon credits, fintech, digital assets, and other products and services prescribed by the government.

The IFC Resolution does not specify a specific expiry date, but would be replaced by a “Law on International Financial Centers” that is to be proposed in 2034. Approved projects and operation may continue to operate and receive incentives until the end of the project or operation.

See our previous article: Vietnam’s Resolution on International Financial Centers Brings New Opportunities

Draft Crypto Pilot Resolution

Under the Draft Crypto Pilot Resolution, there will be a regulatory sandbox for crypto asset services, including (i) organization of crypto asset transaction/trading markets; (ii) proprietary trading of crypto assets; (iii) custody of crypto assets; and (iv) provision of platforms for crypto asset issuance.

These crypto asset service providers are subject to a joint venture requirement in which the foreign ownership limit is 49%. The entity will need to satisfy stringent requirements to be issued a crypto asset service provider license from the Ministry of Finance.

It is currently contemplated that the regulatory sandbox will run until December 31, 2027. After this, depending on the result of the pilot program, the authority may consider the future legal framework.

Outlook

Vietnam’s regulatory sandboxes represent a significant step forward in fostering innovation and development within the country’s financial and technological sectors. By providing a controlled environment for new and innovative businesses to operate, these sandboxes offer a unique opportunity for companies to test their products and services without the onerous compliance requirements or fears of liability. These initiatives are expected to attract both domestic and international businesses, driving economic growth and positioning Vietnam as a leader in the digital economy.

As these regulatory frameworks take effect, it will be crucial for businesses to stay informed and adapt to the evolving landscape. Now that the Vietnamese government has opened up, the success of these sandboxes will depend on the participation of the business community. The ball is in the private sector’s court.

RELATED INSIGHTS​ 

December 24, 2024
On November 30, 2024, the Data Law was officially promulgated after an accelerated preparation process that began in February 2024. The Data Law is set to take effect on July 1, 2025. Having extraterritorial effect, the Data Law will impact both local and foreign individuals and enterprises. As noted in our previous legal update, the Data Law governs digital data, the National Data Center, the National General Database, digital data products and services, digital data management, and the rights, obligations, and responsibilities of agencies, organizations, and individuals related to digital data activities. This legal update provides an overview of the Data Law, with a deep focus on the key provisions likely to impact businesses operating or offering services in Vietnam. New Data Definition and Classification The Data Law broadly defines “digital data” as data about objects, phenomena, and events, which can include one or a combination of audio, images, numbers, text, or symbols represented in digital format (hereinafter referred to as “data”). This definition is very broad and potentially covers any information recorded or represented in digital forms, including personal and nonpersonal data (such as business data, transactional data, trade secrets, etc.). Data is further categorized into different types that can be used by public bodies. However, the rights and obligations associated with each type of data are not clearly addressed. The data classification criteria include: The nature of data sharing (shared data, private data, open data); The importance of data (core data, important data, and other data); Any other criteria to meet the requirements of data administration, processing, and protection, as determined by the data owner. While the Data Law requires private organizations to categorize data based on its level of importance, it still grants these organizations the right to categorize data based on other criteria. Cross-Border Data
December 12, 2024
Vietnam is a world leader in blockchain adoption and growth, appearing near the top of most rankings of cryptocurrency ownership and blockchain investment. Although the country has taken a cautious approach toward cryptocurrency (banning the use of cryptocurrencies like Bitcoin as a means of payment, for example), the government actively supports blockchain technology and its applications in non-financial sectors. Recognizing blockchain as a core technology of the Fourth Industrial Revolution, as a part of Vietnam’s broader digital transformation agenda, the government issued Decision No. 1236/QD-TTg on October 22, 2024, providing the National Strategy for Blockchain Application and Development to 2025, with Orientation to 2030. Like the National Strategy on Digital Infrastructure, the National Strategy on Blockchain outlines a very ambitious vision to position Vietnam as a regional leader in blockchain technology. The strategy aims for Vietnam to master and apply blockchain across all socio-economic sectors, supporting the nation’s goal of becoming a stable and prosperous digital nation by 2030. The specific goals set for 2025 include developing Vietnam’s blockchain infrastructure and ensuring compliance with cybersecurity and data protection laws; advancing blockchain research through three national innovation centers; building and upgrading 10 facilities dedicated to blockchain research and workforce training; and expanding blockchain education by integrating it into university programs. The strategy also aims to establish at least one blockchain center, special zone, or area, as a pilot, to build a national blockchain network; and foster a blockchain ecosystem by promoting its application across sectors such as banking and finance, transportation, healthcare, education and training, commerce, logistics, postal services, industrial production, energy, tourism, agriculture, public services, and more. The goals for 2030 include strengthening Vietnam’s national blockchain infrastructure to support both domestic and international services, positioning Vietnam as a global and regional leader in blockchain research, application, and development. The
December 11, 2024
On November 30, 2024, the National Assembly of Vietnam issued a new Law on Data (“Data Law”), the first of its kind in the country. Initiated by a legislative proposal in February 2024, the Data Law underwent an accelerated preparation process and was officially promulgated just nine months later. It is worth noting that the Data Law is not the same as the Personal Data Protection Law, which is still in draft form and is expected to be submitted to the National Assembly in November 2025. The scope of application of the Data Law is broader, including not only personal data but also other types of data. The Data Law governs digital data, the National Data Center, the National General Database, digital data products and services, digital data management, and the rights, obligations, and responsibilities of agencies, organizations, and individuals related to digital data activities. Set to take effect on July 1, 2025, the Data Law is expected to have a significant impact on businesses involved in data-processing activities. Below are some key takeaways from this pivotal legislation. Cross-Border Data Transfer and Processing The Data Law recognizes and protects the freedom of cross-border data transfer and processing, as well as the legitimate rights and interests of relevant agencies, organizations, and individuals. The government is assigned the responsibility to provide detailed regulations on cross-border data transfer and processing activities, including the transfer of offshore data into Vietnam. National Data Center Resolution No. 175/NQ-CP issued by the Vietnamese government in October 2023 set out ambitious goals for a new National Data Center, which will integrate and manage human-related data from the national database, databases of ministries and central and local authorities, and other databases. The National Data Center is expected to be a core platform to provide data-related services, support policy
December 11, 2024
Thailand has released a draft amended Electronic Transactions Act (ETA), which aims to overhaul the current version of the law from 2001 to correct its enforcement limitations and update the ETA to be consistent with current electronic transactions practice. The draft ETA is open for public comment until December 20, 2024. The draft ETA introduces a new supervisory scheme that (1) recognizes electronic transactions executed by both current and future technologies without having to enact regulations recognizing the technology, (2) replaces the licensing, registration, and notification scheme for electronic transaction service providers with a trust-mark scheme, and (3) introduces a new mechanism to regulate electronic transaction service providers. The major amendments under the draft ETA address: Relationship with other relevant laws. The draft ETA is designated as the primary law governing electronic transactions, whether between private parties or between private parties and the state. However, if specific laws—including those on electronic administrative procedures—prescribe methods for conducting particular electronic transactions, those laws will prevail. Definitions. The draft ETA revises some existing terms, such as “transaction,” which is now more clearly defined as “any act relating to civil or commercial activities, including administrative procedures, administrative contracts, and any other actions by government agencies or officials.” It also introduces new definitions, such as “biometric data,” “automated system,” and “electronic seal.” Electronic transaction reliability. The draft ETA now clearly provides that electronic transactions executed using a method or an electronic method stipulated by the Electronic Transactions Development Agency (ETDA) as reliable are themselves presumed to be “reliable.” In case of a challenge over the implementation of a certified method or certified service, the challenging party bears the burden of proof and related expenses. Electronic transferable instruments. The draft ETA adopts the UNCITRAL Model Law on Electronic Transferable Records (ETRs) in recognizing ETRs (e.g.,