You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 11, 2025

Vietnam’s Regulatory Sandboxes: Paving the Way for Digital Innovation

Vietnam’s recent embrace of “regulatory sandboxes” reflects a deliberate policy choice to balance the need for robust oversight with an equally pressing imperative to catalyze innovation. A sandbox is a controlled, time-bound framework in which businesses may pilot emerging technologies, products, or business models under relaxed or tailor-made regulatory requirements, thereby allowing regulators to observe risks in real time while innovators validate commercial viability without bearing the full weight of the traditional compliance regime.

By issuing sandbox regulations, the government of Vietnam is signaling its commitment to accelerating digital transformation, attracting investment, and developing a knowledge-based economy, all while safeguarding financial stability, consumer protection, and national security. This strategy is embodied in a suite of instruments that together establish sector-specific sandboxes:

  • Decree No. 94/2025/ND-CP on the Regulatory Sandbox in the Banking Sector (Fintech Sandbox Decree), effective July 1, 2025.
  • Law on Digital Technology Industry (DTI Law), effective January 1, 2026, and Law on Science, Technology and Innovation (STI Law), effective October 1, 2025.
  • Resolution No. 222/2025/QH15 on International Financial Centers (IFC Resolution), effective September 1, 2025.

In addition, a draft resolution on the pilot implementation of the crypto-asset market (Draft Crypto Pilot Resolution) is expected to introduce a dedicated sandbox for crypto-asset service providers later this year, further underscoring Vietnam’s holistic, forward-looking approach to regulating emerging technologies.

Below is a brief summary of all the regulatory sandboxes, who they are open for, and what businesses are attracted.

Fintech Sandbox Decree

Under the Fintech Sandbox Decree, besides credit institutions and foreign bank branches, fintech companies operating in Vietnam can apply for a Certificate of Sandbox Participation issued by the State Bank of Vietnam to operate any of the following services in Vietnam:

  • Credit scoring: A solution applicable to information technology systems of credit institutions, branches of foreign banks, and fintech companies to score the creditworthiness of an individual or organization supporting the credit approval by credit institutions and branches of foreign banks.
  • Data sharing via open API: A standardized application programming interface set that may be used by computer systems of credit institutions, branches of foreign banks, fintech companies, and other third parties to send service requests to systems of credit institutions and branches of foreign banks sharing that Open API.
  • Peer-to-peer (P2P) lending: An information technology application solution provided by a P2P lending company to connect borrowers and lenders, and provide assistance for contract conclusion via a digital platform. The currency used in P2P lending solutions must be VND.

The maximum sandbox period is two years, with the possibility of extension of no more than two times, with each extension not exceeding one year.

See our previous article: Vietnam Issues Fintech Sandbox Decree

DTI Law and STI Law

Under the DTI Law, the regulatory sandbox is expressly designed to support and promote the development of “digital technology application products and services”. These products and services are defined to include:

  • Hardware products;
  • Software products;
  • Digital content products; and
  • Services in consultancy, design, installation, integration, management, operation, training, digitization, data processing, warranty, maintenance, repair, refurbishment, publication and distribution of digital technology products; providing digital technology products in the form of services and other digital technology services.

The regulatory sandbox for such products and services will be implemented according to the STI Law.

Under the STI Law, multiple regulatory sandboxes may be established based on government initiatives. In general, these sandboxes require a special license for participation; may provide liability exemptions for participating parties; and are subject to a maximum duration of three years, with a one-time extension of up to an additional three years.

See our previous article: Vietnam’s National Digital Transformation: Key Legal Developments to Expect in 2025

IFC Resolution

Under the IFC Resolution, international financial centers will be organized within specific geographic areas in Ho Chi Minh City and Da Nang, where preferential specific policies for entities registered or recognized as members will be applied.

One such policy is a regulatory sandbox for fintech technologies, products, services, and business models not yet prescribed by law, offering exemption from compliance with standards and technical regulations as well as exemption from liability for damage to the state during experimentation.

The products and services to be provided in the international financial centers include stocks, bonds, fund certificates, financial derivatives, fund management, insurance, reinsurance, banking and foreign exchange, green finance, carbon credits, fintech, digital assets, and other products and services prescribed by the government.

The IFC Resolution does not specify a specific expiry date, but would be replaced by a “Law on International Financial Centers” that is to be proposed in 2034. Approved projects and operation may continue to operate and receive incentives until the end of the project or operation.

See our previous article: Vietnam’s Resolution on International Financial Centers Brings New Opportunities

Draft Crypto Pilot Resolution

Under the Draft Crypto Pilot Resolution, there will be a regulatory sandbox for crypto asset services, including (i) organization of crypto asset transaction/trading markets; (ii) proprietary trading of crypto assets; (iii) custody of crypto assets; and (iv) provision of platforms for crypto asset issuance.

These crypto asset service providers are subject to a joint venture requirement in which the foreign ownership limit is 49%. The entity will need to satisfy stringent requirements to be issued a crypto asset service provider license from the Ministry of Finance.

It is currently contemplated that the regulatory sandbox will run until December 31, 2027. After this, depending on the result of the pilot program, the authority may consider the future legal framework.

Outlook

Vietnam’s regulatory sandboxes represent a significant step forward in fostering innovation and development within the country’s financial and technological sectors. By providing a controlled environment for new and innovative businesses to operate, these sandboxes offer a unique opportunity for companies to test their products and services without the onerous compliance requirements or fears of liability. These initiatives are expected to attract both domestic and international businesses, driving economic growth and positioning Vietnam as a leader in the digital economy.

As these regulatory frameworks take effect, it will be crucial for businesses to stay informed and adapt to the evolving landscape. Now that the Vietnamese government has opened up, the success of these sandboxes will depend on the participation of the business community. The ball is in the private sector’s court.

RELATED INSIGHTS​ 

October 2, 2024
The first draft of Vietnam’s new Personal Data Protection Law (“Draft PDPL”) was released for public consultation on September 24, 2024, and is open for comments until November 24, 2024. (See further details here.) It is expected that the draft will be presented to the National Assembly before the end of 2024 and will be submitted for adoption in May 2025, with a tentative entry into force on January 1, 2026. As the Draft PDPL incorporates most of the provisions of Decree No. 13/2023/ND-CP on Personal Data Protection (“PDPD”), which has been the primary legal instrument on personal data protection since it took effect on July 1, 2023, it is likely that it will supersede the PDPD when it takes effect. [Please contact our Vietnam data protection team to request a detailed comparison of the Draft PDPL to the PDPD.] Noting that there might be further changes to the draft once the public consultation period closes, the Draft PDPL proposes new specific requirements for a number of services. Some highlights of the current version include the following: Marketing services: Although marketing services are already regulated under the PDPD, the Draft PDPL now recognizes that the use of personal data for marketing must comply with anti-spam regulations. The current draft does not clarify whether organizations are exempted from the consent requirement for the purpose of the initial call or message under the anti-spam regime. Marketing service providers are not allowed to outsource the services to another organization to perform or support the implementation of marketing business, which may prevent the sharing of personal data. Behavioral advertising: Behavioral advertising (targeted personalized advertising based on a user’s activity or personal data) requires the consent of the data subject in a modifiable manner that allows the data subject to refuse to share data
September 24, 2024
On September 24, 2024, the government of Vietnam issued the first draft of a new Law on Personal Data Protection (“Draft PDPL”). As foreshadowed in our previous legal update, the Ministry of Public Security has been very active in developing this draft law. With this draft, they promise to continue their considerable efforts to establish a robust personal data protection culture in Vietnam, as the Draft PDPL indicates a tentative entry into force on January 1, 2026. With a tentative adoption by the National Assembly in May 2025, the Draft PDPL does not include any transition period, save for micro-enterprises, SMEs, and startups, which are only exempted from appointing a data protection department in their first two years of existence, while the timeline to comply with other obligations under the PDPL remains the same as for other enterprises. The Draft PDPL includes 68 articles, divided into seven chapters, making it more extensive than last year’s Decree No. 13/2023/ND-CP on Personal Data Protection (“PDPD”), and expressly addresses personal data protection in many fields, including marketing services, behavioral advertising, big-data processing, AI, cloud computing, labor monitoring and recruitment, financial and credit information, health and insurance, and others. It remains unclear how the PDPL will interact with the PDPD (whether it will replace its predecessor or coexist with it), although the Draft PDPL provides that it will prevail over any laws that have provisions on personal data protection that differ from the provisions of the PDPL. Among the important new developments of the Draft PDPL when compared to the PDPD, we note: Consent remains the main legal basis for processing, with limited exceptions (still not including “legitimate interest”). However, consent for cross-border transfer is further regulated under the Draft PDPL, including for intra-group sharing. Data processing impact assessment dossiers for controllers and
September 24, 2024
In recent years, Thailand has witnessed significant developments in its personal finance sector, particularly in alternative lending options. This article explores two key concepts in the Thai financial landscape: nano finance and personal loans. These alternative lending models, regulated by the Bank of Thailand (BOT), aim to provide more accessible financial services to individuals and small entrepreneurs who might have limited access to traditional funding sources. Nano Finance: Empowering Small Entrepreneurs The nano finance scheme under the BOT’s supervision is designed to provide funding to small entrepreneurs who might have limited access to traditional financial resources. One of the key features of this scheme is the ability of licensed nano finance providers to use alternative data in assessing loan applicants’ ability to repay (information-based lending). To implement this approach, nano finance providers must have an internal policy on credit approval that supports: Identifying scope and processes for utilizing alternative factors or technologies in determining debt repayment capacity, credit line limits for each loan applicant and total credit limits, and acceptable debt repayment targets; Having resources and personnel with sufficient knowledge, capability, experience, and expertise to operate efficiently and effectively, as well as clear checks and balances; Establishing guidelines for selecting and analyzing factors or financial models to evaluate or predict loan applicants’ ability and willingness to repay; Having an internal sandbox to test key success factors of the selected factors or models; and Having a process for monitoring and reviewing the application of the selected factors or models in assessing debt repayment capability. This approach allows nano finance providers to make more informed lending decisions based on a broader range of data, potentially increasing access to finance for small entrepreneurs who may not have traditional credit histories or collateral. Personal Loans The personal loan scheme under BOT supervision aims
September 20, 2024
On September 12, 2024, the Bank of Thailand (BOT) Notification Re: Virtual Bank Supervision Criteria took effect. According to this notification, virtual banks must adhere to standards for traditional commercial banks, along with additional requirements tailored to address virtual banks’ digital nature and corporate structure. Specific Requirements The concepts of supervision remain unchanged from the consultation paper titled “Criteria for Supervising Virtual Banks”. Some of the key additional provisions and details on supervision criteria relate to the following: Financial business groups: The notification identifies virtual banks as financial businesses, subject to the BOT’s regulations on financial business group supervision. If a virtual bank is a part of another financial institution’s financial business group, the virtual bank must be under a solo consolidated group. After the “initial phase” (see below), other financial institutions and companies within the financial business group are prohibited from extending credit to or engaging in transactions similar to lending activities with the virtual bank. Capital fund requirements: If other financial institutions’ investment in a virtual bank increases the capital fund in the financial system beyond a safe level and this poses a risk to other financial institutions, the BOT may order the relevant financial institution to maintain capital funds as the BOT deems appropriate. Service channels and outsourcing: Virtual banks must provide services solely through digital channels, except when necessary. For example, with the BOT’s approval, a virtual bank may use other commercial bank electronic branches via an ATM pool system, use a banking agent to serve customer needs for cash, or occasionally provide on-site services. Initial Phase The “initial phase” runs from the date that the virtual bank commences its operations until it receives the BOT’s approval to become fully operational. During this period, certain BOT supervisory requirements are relaxed as follows: Governance: Virtual banks in the initial phase may request