You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

Biography

Waewpen Piemwichai is a counsel in the Tilleke & Gibbins corporate and commercial group, based in the Hanoi office. Waewpen is an expert in the area of international technology, media, and telecommunications (TMT) law. She assists companies from all industry sectors on TMT-related matters such as data privacy, cybersecurity, telecom and IT network services, online streaming and broadcasting, cloud computing, e-commerce, and advertising. Outside the TMT space, Waewpen also has extensive experience and expertise in practice areas including commercial transactions, franchising, company formation, and construction.

Waewpen was named “TMT Rising Star of the Year” at the 2023 Legal 500 Southeast Asia Awards, and has also been named one of Asia’s “Top 15 Rising Lawyers” (2021) and “Top 15 TMT Lawyers” (2022 and 2023) by Asian Legal Business.

Waewpen is a member of the Thai Bar Association, and was based in Bangkok before relocating to the firm’s Hanoi office.

Experience

ABOUT Waewpen

Practices

Corporate/M&A

Location

Languages

    Thai

    English

Education

    LLB, Thammasat University

Insights

August 25, 2026
Vietnam has enacted a new decree establishing administrative penalties for violations in the fields of cybersecurity and personal data protection. Decree No. 330/2026/NĐ-CP (Decree 330), issued and effective from August 19, 2026, provides a detailed sanctions framework for noncompliance with the Law on Personal Data Protection (including its implementing regulations under Decree 356/2025/ND-CP) and the Law on Cybersecurity, together with their guiding decrees. The issuance of Decree 330 signals that the practical grace period previously perceived by many businesses may be drawing to a close, with active regulatory enforcement in these areas expected to commence in earnest. Scope and Key Provisions Decree 330 has extraterritorial effect and applies to both onshore and offshore companies. For offshore companies, it applies to those that (1) provide telecommunications, internet, online-content, information-technology, cybersecurity, or cross-border services and (2) are involved in or related to the processing of personal data of Vietnamese citizens and certain other people of Vietnamese origin. Decree 330’s key provisions cover the following areas: Administrative penalties for violations relating to the protection of national security and public order in cyberspace, including the dissemination of unlawful, false, or unverified information. Sanctions for cyberattacks, unauthorized access, introduction of harmful code or programs, and failure to cooperate with specialized cybersecurity forces. Sanctions for personal data protection violations, such as consent, cross-border data transfers, impact assessments, breach notification, and data-subject rights, among others—with maximum fines of up to 5% of an organization’s preceding-year revenue for cross-border transfer violations, or up to VND 3 billion for other data-protection breaches. Personal Data Protection Penalties The key sanctions for personal data protection violations are as follows: Consent violations: Fines of up to VND 70 million (approx. USD 2,642), plus potential additional sanctions and remedial measures including irreversible deletion of personal data collected without consent and confiscation of
July 10, 2026
Vietnam has taken a significant step in regulating its e-commerce sector with the issuance of a new decree guiding the country’s recently enacted Law on E-Commerce. Decree No. 248/2026/ND-CP, issued on June 30, 2026, and taking effect the following day, addresses mandatory platform policies, registration requirements for offshore platforms, additional obligations on platform operators, and market access conditions for foreign investors. Mandatory Policy Contents The decree sets out detailed guidance on the required contents of various platform policies, covering pricing, payment, display priority, livestream sales, delivery, returns, method of service provision, and service termination and refunds. Clarification of Obligations for Platform Operators The decree provides clarification of the obligations applicable to platform operators. Notably, intermediary e-commerce platform operators with online ordering functions must: Collect specific information to implement electronic identity verification of sellers; Cooperate with regulators by reporting online through the state e-commerce management system and by blocking, suspending, or removing content upon request of a competent authority; Maintain a mechanism to store contract data, including price, product or service information, and parties’ information, for at least three years from the date of contract conclusion; and If qualifying as a “large digital platform” under consumer protection law, maintain an online system for receiving and handling complaints and requests, and comply with enhanced content-removal requirements. Registration Requirements for Offshore Platforms Offshore e-commerce platforms, whether direct-sales, intermediary, social-network-based, or integrated, that conduct e-commerce activity in Vietnam must register with the Ministry of Industry and Trade if the platform: Allows Vietnamese-language selection; Uses a “.vn” domain; or Reaches 100,000 or more transactions with Vietnam-based buyers within a calendar year. Notably, the registration requirement now captures not only traditional intermediary platforms, but also direct-sales platforms. Foreign Investment Conditions Foreign investors holding a controlling interest in an intermediary e-commerce platform, a social media platform
July 6, 2026
Vietnam has introduced an official list of high-risk AI systems, triggering more stringent compliance obligations for developers, suppliers, and deployers operating in the country. On June 30, 2026, the prime minister issued Decision No. 33/2026/QD-TTg (Decision 33), which establishes the List of High-Risk AI Systems under the Law on Artificial Intelligence (AI Law) and Decree No. 142/2026/ND-CP (Decree 142). Decision 33 takes effect on August 15, 2026. Decision 33 is significant because only AI systems included on the list will be subject to the heightened compliance obligations applicable to high-risk AI systems under the AI Law and Decree 142. These include, among others, local presence requirements for foreign providers, mandatory conformity assessment before deployment, comprehensive risk management and data quality documentation, and strict liability for damages even when the provider is fully compliant. Decision 33 also specifies the applicable conformity assessment pathway for each listed system, indicating whether the system must undergo mandatory third-party conformity certification before being placed into use, or whether the provider may self-assess conformity or voluntarily engage a registered or recognized conformity assessment body. Which AI Systems Are Covered? Decision 33 identifies high-risk AI systems across six sectors—the key attributes of which are summarized below. Education: AI systems used for automated assessment, learner ranking, behavioral monitoring, or generating educational content from uncontrolled data sources. Ethnic affairs and religion: AI systems used to automatically score, classify, or rank applications for government ethnic policies; approve or reject regulatory applications; suspend benefits on suspicion of fraud; allocate budgets; or infer and classify individuals by ethnicity or religion for administrative purposes. Healthcare: AI-assisted surgical systems and autonomous AI-powered surgical robots. Banking: AI systems that autonomously conduct electronic banking transactions or make credit approval decisions. Judicial proceedings: Certain large-scale biometric identification systems used in public-interest civil proceedings. Transport: Thirty-one categories
July 6, 2026
Tilleke & Gibbins has contributed the Vietnam chapter to Data Protection & Privacy 2027, a global guide published by Lexology Panoramic that provides comparative insights into data protection and privacy regimes across multiple jurisdictions. The Vietnam chapter offers a comprehensive overview of the country’s data protection framework, addressing both regulatory structure and practical compliance considerations for businesses operating in or engaging with Vietnam. Topics covered include: Law and the regulatory authority: Legislative framework; data protection authority; cooperation with other data protection authorities; breaches of data protection law; judicial review of data protection authority orders Scope: Exempt sectors and institutions; interception of communications and surveillance laws; other laws; personal information formats; extraterritoriality; covered uses of personal information Legitimate processing of personal information: Lawful bases for processing; grounds for legitimate processing; types of personal information Data handling responsibilities of owners of personal information: Transparency; exemptions from transparency obligations; data accuracy; data minimization; data retention; purpose limitation; automated decision-making Security: Security obligations; notification of data breaches; internal controls Accountability: Data protection officer requirements; record-keeping; risk assessment; design of personal information processing systems Registration and notification: Registration requirements; other transparency duties Sharing and cross-border transfers of personal information: Sharing with processors and service providers; restrictions on third-party disclosures; cross-border transfers; further transfers; localization requirements Rights of individuals: Right of access; other statutory rights; compensation Enforcement: Enforcement mechanisms; exemptions, derogations, and restrictions; further exemptions and restrictions Specific data processing: Cookies and similar technologies; electronic communications marketing; targeted advertising; sensitive personal information; profiling; cloud services The chapter concludes with an update on key legal and regulatory developments over the past year and emerging trends in Vietnam’s data protection landscape. The full Vietnam chapter is available as a PDF through the button below. Readers can also gain 30 days of complementary access to the full Data

Awards & Rankings

August 13, 2026
Tilleke & Gibbins has been recognized in the inaugural Asia Top Cybersecurity & Data Law Firms 2026 list from Asian Legal Business (ALB), published in the magazine’s August 2026 edition. The new ranking highlights leading law firms across Asia with dedicated cybersecurity, privacy, and data regulation practices, recognizing firms with a proven track record of advising clients on complex cybersecurity and data law matters. Tilleke & Gibbins is one of only 21 firms included in the inaugural list, reflecting the firm’s strength in data privacy, cybersecurity, technology, and regulatory matters throughout Southeast Asia. According to ALB, the firms selected for inclusion are recognized for their capabilities in areas such as privacy compliance, incident response, digital investigations, and technology-enabled client service. The recognition underscores the continued growth and regional prominence of Tilleke & Gibbins’ data privacy and cybersecurity practice, which advises clients across a broad range of industries on data protection compliance, cybersecurity preparedness and response, technology transactions, digital platform regulation, and emerging regulatory developments. This latest honor reflects the firm’s commitment to helping clients navigate an increasingly complex digital and regulatory landscape and reinforces its reputation as a leading adviser on technology, privacy, and cybersecurity issues across the region.
May 11, 2026
Tilleke & Gibbins has been recognized in five practice areas at the Asia Business Law Journal (ABLJ) Vietnam Law Firm Awards 2026, reflecting the firm’s continued strength across a range of legal disciplines in Vietnam. The firm received honors in the following categories: Artificial Intelligence Data Compliance and Cyber Security IP Litigation Labor & Employment Technology, Media & Telecommunications The ABLJ Vietnam Law Firm Awards highlight leading law firms across key practice areas, with multiple firms typically recognized in each category. The 2026 edition marks the fourth year of the awards program. These recognitions underscore the work of Tilleke & Gibbins’ Vietnam-based teams, particularly in technology-driven and regulatory-focused areas of practice. For more details and the full list of winners, please visit the ABLJ website.
April 3, 2026
Tilleke & Gibbins is pleased to announce that the firm has been shortlisted in two categories at the Financial Times (FT) Innovative Lawyers APAC 2026 awards: Innovative Lawyers in Cyber and Data Privacy – “Digital Identity & Cryptocurrency Compliance” Innovative Practitioner – Athistha (Nop) Chitranukroh The FT Innovative Lawyers APAC Awards recognize law firms and practitioners who are driving innovation in legal services and delivering innovative client solutions across the Asia-Pacific region. This recognition marks our third acknowledgment in the Innovative Lawyers category and, notably, our first-ever nomination in the Innovative Practitioner category at the FT Innovative Lawyers APAC awards. It reflects our team’s continued ability to support clients on groundbreaking, forward-looking projects across the region. The awards ceremony will take place on May 14, 2026, in Hong Kong. To learn more about the FT Innovative Lawyers APAC 2026 awards and to view the full list of shortlisted organizations, please visit the FT website.

Other Professionals