Navigating among numerous licences and permits required by law for running a business in Vietnam has never been easy. There many reasons including:
- There is no comprehensive list of valid licences and permits available. Therefore, businesses run the risks of missing certain licences and permits. This is particular true as many authorities in Vietnam have the power to issue licences and permits;
- The time and efforts required for obtaining a licence or permit may be substantial. In practice, the authorities may not always check or enforce the required licence or permit. Therefore, the risk in practice of missing a particular licence and permit varies; and
- That being said, in theory, missing a required licence or permit may be subject to administrative penalty and, in extreme case, criminal penalty (e.g. see the case against Mr Nguyen Duc Kien).
Regarding the first point, I just come across of report on business licences and permits prepared by the Ministry of Planning and Investment (MPI) in December 2013 (MPI List). The MPI seems to have spent substantial time and efforts verifying with all other ministries about the licences and permits issued by such other ministries. As such, the MPI List is quite comprehensive. The MPI List provides for the list of 334 licences and permits requires for various conditional business lines in Vietnam.
Therefore, a business owner may use the information in the MPI List to check if it has obtained all the licences and permits mentioned in the MPI List for its operation, if necessary.
A copy of the MPI List in Vietnamese can be downloaded here.
An unofficial translation of the MPI List by VILAF can be downloaded here.
On 16 March 2026, the Ministry of Public Security (MPS) issued the draft decree on administrative sanctions in the fields of cybersecurity and personal data protection (the Draft Decree) for public consultation. It is the first step to put concrete penalties behind the PDPL 2025, which took effect on 1 January 2026 but left the enforcement details to the Government. The Draft covers a wide range of sectors, such as cybersecurity, personal data, AI, telecommunications, and digital signatures. This post focuses on the personal data provisions (Articles 57 to 69 of the Draft Decree), which raise potential concerns for businesses.