You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 11, 2025

Vietnam’s Regulatory Sandboxes: Paving the Way for Digital Innovation

Vietnam’s recent embrace of “regulatory sandboxes” reflects a deliberate policy choice to balance the need for robust oversight with an equally pressing imperative to catalyze innovation. A sandbox is a controlled, time-bound framework in which businesses may pilot emerging technologies, products, or business models under relaxed or tailor-made regulatory requirements, thereby allowing regulators to observe risks in real time while innovators validate commercial viability without bearing the full weight of the traditional compliance regime.

By issuing sandbox regulations, the government of Vietnam is signaling its commitment to accelerating digital transformation, attracting investment, and developing a knowledge-based economy, all while safeguarding financial stability, consumer protection, and national security. This strategy is embodied in a suite of instruments that together establish sector-specific sandboxes:

  • Decree No. 94/2025/ND-CP on the Regulatory Sandbox in the Banking Sector (Fintech Sandbox Decree), effective July 1, 2025.
  • Law on Digital Technology Industry (DTI Law), effective January 1, 2026, and Law on Science, Technology and Innovation (STI Law), effective October 1, 2025.
  • Resolution No. 222/2025/QH15 on International Financial Centers (IFC Resolution), effective September 1, 2025.

In addition, a draft resolution on the pilot implementation of the crypto-asset market (Draft Crypto Pilot Resolution) is expected to introduce a dedicated sandbox for crypto-asset service providers later this year, further underscoring Vietnam’s holistic, forward-looking approach to regulating emerging technologies.

Below is a brief summary of all the regulatory sandboxes, who they are open for, and what businesses are attracted.

Fintech Sandbox Decree

Under the Fintech Sandbox Decree, besides credit institutions and foreign bank branches, fintech companies operating in Vietnam can apply for a Certificate of Sandbox Participation issued by the State Bank of Vietnam to operate any of the following services in Vietnam:

  • Credit scoring: A solution applicable to information technology systems of credit institutions, branches of foreign banks, and fintech companies to score the creditworthiness of an individual or organization supporting the credit approval by credit institutions and branches of foreign banks.
  • Data sharing via open API: A standardized application programming interface set that may be used by computer systems of credit institutions, branches of foreign banks, fintech companies, and other third parties to send service requests to systems of credit institutions and branches of foreign banks sharing that Open API.
  • Peer-to-peer (P2P) lending: An information technology application solution provided by a P2P lending company to connect borrowers and lenders, and provide assistance for contract conclusion via a digital platform. The currency used in P2P lending solutions must be VND.

The maximum sandbox period is two years, with the possibility of extension of no more than two times, with each extension not exceeding one year.

See our previous article: Vietnam Issues Fintech Sandbox Decree

DTI Law and STI Law

Under the DTI Law, the regulatory sandbox is expressly designed to support and promote the development of “digital technology application products and services”. These products and services are defined to include:

  • Hardware products;
  • Software products;
  • Digital content products; and
  • Services in consultancy, design, installation, integration, management, operation, training, digitization, data processing, warranty, maintenance, repair, refurbishment, publication and distribution of digital technology products; providing digital technology products in the form of services and other digital technology services.

The regulatory sandbox for such products and services will be implemented according to the STI Law.

Under the STI Law, multiple regulatory sandboxes may be established based on government initiatives. In general, these sandboxes require a special license for participation; may provide liability exemptions for participating parties; and are subject to a maximum duration of three years, with a one-time extension of up to an additional three years.

See our previous article: Vietnam’s National Digital Transformation: Key Legal Developments to Expect in 2025

IFC Resolution

Under the IFC Resolution, international financial centers will be organized within specific geographic areas in Ho Chi Minh City and Da Nang, where preferential specific policies for entities registered or recognized as members will be applied.

One such policy is a regulatory sandbox for fintech technologies, products, services, and business models not yet prescribed by law, offering exemption from compliance with standards and technical regulations as well as exemption from liability for damage to the state during experimentation.

The products and services to be provided in the international financial centers include stocks, bonds, fund certificates, financial derivatives, fund management, insurance, reinsurance, banking and foreign exchange, green finance, carbon credits, fintech, digital assets, and other products and services prescribed by the government.

The IFC Resolution does not specify a specific expiry date, but would be replaced by a “Law on International Financial Centers” that is to be proposed in 2034. Approved projects and operation may continue to operate and receive incentives until the end of the project or operation.

See our previous article: Vietnam’s Resolution on International Financial Centers Brings New Opportunities

Draft Crypto Pilot Resolution

Under the Draft Crypto Pilot Resolution, there will be a regulatory sandbox for crypto asset services, including (i) organization of crypto asset transaction/trading markets; (ii) proprietary trading of crypto assets; (iii) custody of crypto assets; and (iv) provision of platforms for crypto asset issuance.

These crypto asset service providers are subject to a joint venture requirement in which the foreign ownership limit is 49%. The entity will need to satisfy stringent requirements to be issued a crypto asset service provider license from the Ministry of Finance.

It is currently contemplated that the regulatory sandbox will run until December 31, 2027. After this, depending on the result of the pilot program, the authority may consider the future legal framework.

Outlook

Vietnam’s regulatory sandboxes represent a significant step forward in fostering innovation and development within the country’s financial and technological sectors. By providing a controlled environment for new and innovative businesses to operate, these sandboxes offer a unique opportunity for companies to test their products and services without the onerous compliance requirements or fears of liability. These initiatives are expected to attract both domestic and international businesses, driving economic growth and positioning Vietnam as a leader in the digital economy.

As these regulatory frameworks take effect, it will be crucial for businesses to stay informed and adapt to the evolving landscape. Now that the Vietnamese government has opened up, the success of these sandboxes will depend on the participation of the business community. The ball is in the private sector’s court.

RELATED INSIGHTS​ 

January 10, 2025
On January 8, 2025, Thailand’s Office of the Personal Data Protection Committee published two notifications in the Government Gazette—one for data controllers and the other for data processors—concerning exemptions for data controllers and data processors from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019). The notification for data processors took effect on January 9, 2025, the day after its publication. The notification for data controllers will take effect on April 8, 2025. The content of these notifications is identical to that in the draft versions of the notifications previously released for public consultation in October 2024. For more information on the ROPA exemptions for data controllers and data processors, or on any aspect of personal data protection in Thailand, please contact Nopparat Lalitkomon at [email protected] or Wilin Somya at [email protected].
January 9, 2025
On January 1, 2025, Myanmar’s State Administration Council enacted Cybersecurity Law No. 1/2025, which aims to regulate various aspects of digital security and online activities. The law has not yet been implemented and will come into force on a date specified by the Myanmar president, who will also provide an official adoption and compliance timeline for individuals and organizations impacted by the new regulations. Below are some of the key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The
January 9, 2025
Thailand’s Fiscal Policy Office (FPO) has released a draft of its planned Financial Business Hub Act, which is in line with the government’s aim of positioning Thailand as a regional financial hub and a critical player in the global economy. The draft act, on which the FPO is accepting comments until January 9, 2025, details the framework for promoting and attracting international financial businesses and related services to operate in Thailand, proposes various incentives, and outlines supervisory guidelines. This article examines key elements of the draft Financial Business Hub Act relevant to financial business operators. Incentivized Financial Businesses The draft act identifies the financial businesses to be promoted and incentivized. These target businesses include: Commercial banking businesses, Payment service businesses, Securities businesses, Derivatives businesses, Digital assets businesses, Insurance and reinsurance brokerage businesses, and Other financial-related businesses as determined by the Committee for the Supervision and Promotion of Financial Centers. Thailand’s finance minister explained that initially, the draft law intends to target businesses using an “out-out” model, which describes the raising of capital abroad for investment abroad, before expanding to an “out-in” model, in which capital is raised abroad for investment domestically. Therefore, the draft law currently specifies that the target businesses must only provide services to nonresidents without soliciting residents of Thailand to use their services. Authorization Targeted financial business operators will need to receive authorization from the Committee for the Supervision and Promotion of Financial Centers. The main eligibility criteria for authorization are the incorporation an entity (e.g., a company registered in Thailand, a branch of a foreign juristic person) with an office in designated areas to be specified in a royal decree (currently expected to be Bangkok and adjacent provinces) and the possession of other qualifications as prescribed in the draft act. Target businesses in Thailand will
January 6, 2025
On December 24, 2024, the government of Vietnam issued Decree No. 163/2024/ND-CP, providing guidelines for implementing the new Telecommunications Law that took effect on July 1, 2024 (“Decree 163”). This new decree replaces Decree No. 25/2011/ND-CP and its amendments (“Decree 25”) and took effect immediately upon issuance, with regulations on data center services, cloud computing services, and basic telecom services over the internet (“over-the-top” or OTT telecom services) having an official effective date of January 1, 2025. Decree 163 introduces substantial changes across the telecom sector, covering various aspects including service provision, licensing, standards and technical regulations, quality, passive infrastructure planning, dispute resolution, and more. Hence, it is necessary for enterprises to conduct a compliance review to identify gaps between the new decree and their business models, and take necessary steps to ensure lawful business operations in Vietnam. Below are some highlights of Decree 163. Expanded Scope of Services For basic telecom services, Decree 163 has introduced machine-to-machine (M2M) communication and classified it as a basic telecom service. This establishes a regulatory framework for IoT device communication, previously unregulated in Decree 25. For value-added telecom services, in light of the new Telecommunications Law, Decree 163 provides more detailed regulations for new telecom services such as data center services, cloud computing services, and OTT telecom services, which were not addressed in Decree 25. Regulation of Three New Telecom Services Expanding on the Telecommunications Law’s definitions of data center services, cloud computing services, and OTT telecom services, Decree 163 applies a light-touch management approach to regulate these three new services, as follows: Offshore providers: Cross-border service providers are exempt from signing commercial agreements with licensed local telecom companies. They only need to notify the Vietnam Telecommunications Authority (VNTA) using the prescribed procedures and forms before offering services. Onshore providers: The foreign