Fintech M&A Vietnam has entered a decisive new phase, and buyers who treat these deals like conventional acquisitions risk expensive surprises at closing. Vietnam’s investment framework, the implementing rules for the Law on Investment, and the State Bank of Vietnam (SBV) regime for payment services have collectively tightened the way foreign ownership, licensing continuity and cross-border data flows are scrutinised. In particular, Decree No. 52/2024/ND-CP on non-cash payments and its guiding circulars have reshaped how payment intermediary and related activities are licensed. This guide is written for acquirers, private equity sponsors, in-house counsel and deal teams evaluating fintech and payments targets, and it focuses on the transaction-level mechanics that generic market summaries tend to skip.
You will find licensing pathways, ownership review triggers, data-transfer constraints, a due diligence checklist, an SPA drafting checkpoint list and a post-closing playbook designed to be operationalised on a live deal.
Search intent: Practical, transaction-ready guidance for buyers and deal teams on licensing, ownership limits and data obligations when acquiring fintech and payments businesses in Vietnam under the current regulatory landscape. Use the checklists and SPA drafting tips to turn regulatory theory into deliverable conditions precedent and post-closing steps.
The current regulatory package reshapes the risk profile of every fintech M&A Vietnam transaction. Rather than a single reform, buyers are navigating several moving parts that interact at different stages of a deal, from signing through to post-closing operational authorisation. Understanding the headline features first helps deal teams sequence diligence and structure conditions precedent correctly.
The practical consequences are concrete. A poorly sequenced deal can face licence continuity gaps, exposure where a foreign-ownership condition is breached, and cross-border data flows that must be re-papered before integration can proceed. For buyers, the message is that regulatory diligence and closing mechanics in a fintech M&A Vietnam transaction must be built into the SPA from the outset, not bolted on after heads of terms are agreed.
Any fintech M&A Vietnam transaction begins with an accurate inventory of the target’s regulatory permissions. The single most common cause of value leakage is discovering, after signing, that a critical licence is non-transferable, expired, or held in a way that does not survive a change of control. Because different fintech activities are regulated by different authorities, the buyer must map each business line to the permission that authorises it.
The State Bank of Vietnam is the principal regulator for payment activity, and most payments businesses rely on one or more SBV-issued permissions. Under Decree No. 52/2024/ND-CP, payment intermediary services include categories such as switching and electronic clearing services, e-wallet services, electronic payment gateway services and support services for collection and payment. The buyer’s diligence should establish, for each licence, the exact scope of permitted activity, the expiry or renewal date, any conditions attached, and, critically, how SBV treats a change of shareholding, since foreign investment in payment intermediary services and changes to the licence-holder’s charter documents are subject to SBV oversight.
The core steps in the SBV pathway generally involve confirming the licence status, identifying whether the transaction constitutes a change requiring notification or approval, preparing the supporting corporate and regulatory documents, and submitting the relevant filing. Because SBV review timelines can be material relative to a deal calendar, buyers should treat central-bank engagement as an early-stage activity rather than a closing formality.
Buyers frequently conflate different categories of payment authorisation, and the distinction matters for both diligence and structuring. Switching, clearing and gateway functions are regulated as distinct payment intermediary services under Decree No. 52/2024/ND-CP, while an e-wallet business holds customer funds in a way that attracts specific safeguarding expectations, including the obligation to maintain guarantee/escrow balances at commercial banks corresponding to customers’ e-wallet balances. The regulatory treatment of a change of control can therefore differ across these categories.
The practical takeaway is that a target described loosely as a “payments company” may in fact hold a bundle of permissions with different transferability profiles. Each must be assessed individually. Where the target’s value depends on the continuity of a particular permission, that continuity should be converted into a specific condition precedent and a corresponding representation and warranty in the SPA.
Fintech businesses rarely sit within a single regulatory silo. Depending on the technology and business model, a target may also require permissions overseen by the Ministry of Science and Technology (which absorbed the former Ministry of Information and Communications following the 2025 government restructuring), for example where the business operates telecom or information-network services, provides certain value-added services, or is subject to cybersecurity obligations. A payments target that also runs a data-heavy platform or a consumer app can therefore carry additional regulatory obligations alongside its SBV permissions.
Because these permissions overlap, the diligence exercise should produce a consolidated licence map showing which regulator governs each activity, the status of each permission, and the change-of-control treatment for each. The table below summarises the typical position across the most common permission types encountered in a fintech M&A Vietnam deal.
| Licence type | Regulator | Transferable on sale? | Typical approval timing | Ownership / review considerations |
|---|---|---|---|---|
| E-wallet service | SBV | Conditional, subject to SBV oversight on change of control | Medium to high | Foreign-investment conditions and safeguarding obligations apply |
| Payment intermediary (switching / clearing / gateway / collection support) | SBV | Conditional, SBV oversight on ownership change | Medium | Foreign-investment ratio conditions may apply under payment rules |
| Card acquiring / payment-related banking services | SBV | Conditional | Medium to high | Sectoral review; card-scheme rules may add constraints |
| Telecom / value-added information services | Ministry of Science and Technology | Activity-dependent | Medium | Conditional market access; verify current rules |
| Virtual asset service provider | Evolving / regulator-dependent | Uncertain, regime still developing | High / uncertain | Heightened review; expect additional scrutiny as the pilot framework develops |
Buyers should treat the “conditional” entries as instructions to engage the regulator early. In practice, the difference between a licence that can be preserved through approval and one that effectively requires re-application drives the entire post-closing timetable. Detailed sectoral procedure is discussed in the guidance on how to obtain sectoral approvals for M&A in Vietnam.
Ownership is where regulation bites hardest. A foreign buyer contemplating a fintech M&A Vietnam transaction must resolve two distinct questions: whether a sectoral ownership condition applies to the specific activity, and whether the acquisition triggers registration or approval requirements under the Law on Investment. These are separate analyses that can each independently block or reshape a deal, and both must be run before the buyer commits to a headline price.
Vietnam regulates foreign participation in financial and payment activities more tightly than in ordinary commercial sectors. Decree No. 52/2024/ND-CP contemplates conditions on the foreign-ownership ratio in companies providing payment intermediary services, and any structure that attempts to circumvent an applicable ratio through indirect holdings will attract scrutiny. Where no explicit numerical cap applies to a given activity, foreign investment may still be subject to conditional market-access requirements.
The critical diligence step is to confirm, for the precise activity the target conducts, whether a foreign-ownership condition exists and at what level. This must be verified against the current sectoral rules rather than assumed from general market commentary, because the applicable position varies by activity. Buyers should also confirm the target’s existing foreign ownership position, since a transaction that pushes cumulative foreign holdings above an applicable threshold can crystallise a compliance problem.
Under the Law on Investment and its implementing rules, a foreign investor acquiring shares or contributing capital in certain conditional-access sectors must register the transaction with the competent authority before completion; in sensitive cases (for example those relating to national defence and security), additional scrutiny may apply. For fintech targets that process payments at scale or hold large volumes of personal data, the buyer’s structuring should identify, at an early stage, whether the deal falls within a registration or approval requirement and what the applicable filing pathway is.
The remedies for getting this wrong are significant. A transaction that breaches a foreign-ownership condition or proceeds without a required registration or approval can expose the parties to invalidity, unwinding, penalties, or the loss of the very licences that underpinned the deal rationale. The practical response is to build the ownership analysis into conditions precedent, to make regulatory clearance a completion condition where required, and to allocate the risk of an adverse regulatory outcome expressly in the SPA. The table below illustrates how ownership treatment can differ across fintech subsectors.
| Fintech subsector | Foreign ownership treatment | Investment-law review exposure |
|---|---|---|
| Payment intermediary service providers | Foreign-ownership conditions may apply; verify against current rules | Higher, payments infrastructure attracts scrutiny |
| Digital lending platforms | Activity-dependent; verify against current rules | Medium, depends on scale and data footprint |
| Virtual asset / crypto providers | Uncertain; regime still developing | High, heightened review likely |
Because the ownership picture varies so widely by activity, the ownership analysis should be one of the first outputs of legal diligence in any fintech M&A Vietnam deal, feeding directly into deal structure and price.
Data has become a defining risk in fintech M&A Vietnam transactions because the value of a payments or fintech target lives substantially in its data. Customer identities, transaction histories and KYC records are both the commercial asset and the compliance liability. The current environment places greater weight on where that data sits, how it moves across borders, and whether it can lawfully flow to the buyer’s group after closing.
Data obligations for fintech operations sit across Decree No. 13/2023/ND-CP on personal data protection, the Law on Personal Data Protection (passed in 2025 and effective from 2026), and the Law on Cybersecurity together with its implementing Decree No. 53/2022/ND-CP, which addresses data-localisation obligations for certain enterprises. The Ministry of Public Security plays a central role in personal data protection and cybersecurity enforcement, while financial-sector data is treated as particularly sensitive. Buyers should confirm which regulator supervises each data-handling activity and whether any sector-specific requirements apply on top of the general regime.
Effective data diligence begins with a data map: what personal and financial data the target holds, where it is stored, who processes it, and how it flows between systems and entities. A data protection impact assessment (DPIA), expressly contemplated under Vietnam’s personal data protection rules, helps identify high-risk processing and locate the points at which cross-border transfer or third-party processing occurs. In a fintech target, particular attention should be paid to settlement data shared with banks and card schemes, KYC data shared with onboarding vendors, and analytics data routed to offshore infrastructure.
The output of this exercise is a set of concrete findings that feed the SPA: which data flows are compliant, which require remediation, and which cannot continue post-closing without a new legal basis. Buyers should treat unmapped or offshore-dependent data flows as red flags requiring specific representations and, where necessary, a remediation covenant.
Where data must move out of Vietnam, for example to a buyer’s regional data centre or shared services function, the transfer must rest on a recognised basis. Under Vietnam’s personal data rules, cross-border transfers of personal data may require the preparation of a transfer impact assessment dossier and its lodgement with the competent authority, alongside a valid legal basis such as consent. Buyers should not assume that a data flow permitted under the seller’s group arrangements will automatically be permissible under the acquirer’s post-closing structure.
Practical drafting for the SPA should require the seller to warrant the lawfulness of existing transfers and to cooperate in re-papering flows that will change on completion. In a fintech M&A Vietnam context, this data workstream frequently sits on the critical path to integration, so it should be resourced early. Broader diligence structuring is covered in the Vietnam M&A due diligence, checklist and guide.
Diligence on a fintech target is broader than on a typical private company because regulatory, technological and contractual risks are deeply intertwined. The following checklist covers the areas that most often drive value adjustments, conditions precedent or walk-away decisions in a fintech M&A Vietnam transaction. It should be read alongside the licence map and data map described above.
Each red flag surfaced here should map to a specific SPA mechanism, a condition precedent, a warranty, a specific indemnity or a price adjustment. Diligence that merely documents risk without translating it into deal terms adds little protection for the buyer.
Signing is not the end of the regulatory journey. In a fintech M&A Vietnam transaction, the period between signing and full operational authorisation is where deals are won or lost operationally, because the target must keep processing payments lawfully while ownership changes hands. A structured post-closing playbook keeps the business running and the licences intact.
Where a change of control requires SBV notification or approval, or where the Law on Investment requires registration of the foreign investor’s capital contribution or share purchase, the relevant clearance should be a condition precedent to completion wherever the deal calendar allows. Sequencing matters: the buyer should identify which approvals must precede completion and which can be obtained after closing under a transitional arrangement, and then align the long-stop date to the most demanding of these timelines.
The correct pathway depends entirely on the licence in question. Some permissions can be preserved through a variation or an approved change of ownership, requiring the buyer to satisfy the regulator as to the new owner’s suitability. Others cannot pass through a change of control and effectively require a fresh application, a materially longer process. The buyer should confirm, licence by licence, which pathway applies and prepare the corresponding filing package in advance. Engaging SBV and other relevant regulators early gives the buyer the best chance of avoiding a gap in authorisation.
Where full authorisation cannot be in place at completion, transitional arrangements bridge the gap. A transitional services agreement (TSA) can keep the seller’s group providing support or infrastructure for a defined period, allowing the target to continue operating while the buyer completes its filings. Any such arrangement must itself be compliant, it cannot be used to circumvent a licensing requirement, and should be time-boxed with clear exit triggers tied to the buyer securing its own permissions.
The practical filing list for the post-closing phase typically includes the corporate documents evidencing the new ownership, regulatory forms for the change of control, updated compliance and governance documentation, and any information the regulator requires to assess the new controller. Negotiation points that recur include who bears the cost and risk of delay, what happens if an approval is refused, and how the parties allocate liability for any period of operational uncertainty.
The SPA is where regulatory risk is priced and allocated. For a regulated fintech target, standard M&A boilerplate is insufficient; the drafting must reflect the specific licensing, ownership and data risks identified in diligence. The following points should feature in any well-structured agreement.
Buyers should also consider warranty and indemnity insurance, though insurers will scrutinise regulated-sector risks closely and may exclude known licensing or data exposures. Where a specific risk cannot be insured, a targeted indemnity backed by escrow is usually the more reliable protection.
Not every regulatory item carries equal weight. The matrix below helps deal teams prioritise remediation effort and set realistic expectations on timing in a fintech M&A Vietnam transaction.
| Risk item | Risk level | Expected time to remediate / approve |
|---|---|---|
| Licence transfer or change-of-control approval | Medium to high | Longer, build into long-stop date |
| Data remediation and cross-border re-papering | Medium | Moderate, start during diligence |
| Foreign-investment registration / approval | Medium (depends on activity) | Variable, depends on the sector and filing pathway |
The consolidated comparison earlier in this guide maps each core permission type to its regulator, transferability, approval timing and ownership treatment. Use it as the starting grid for structuring, and populate it with the target’s actual licence data during diligence so that it becomes a live deal document rather than a generic reference.
A successful fintech M&A Vietnam deal depends on treating licensing, ownership and data as core deal terms rather than post-signing formalities. Map the target’s permissions, run the ownership and investment-law analysis early, complete data diligence before closing, and convert every material risk into a specific SPA mechanism supported by a realistic post-closing plan. Buyers who front-load this work protect both value and licence continuity. For specialist support, connect with the M&A Lawyers Vietnam directory and review the related guidance on due diligence and sectoral approvals linked throughout this guide.
This article is provided for general informational purposes only and does not constitute legal advice. Buyers should obtain transaction-specific advice on Vietnamese law before acting.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Ngan Nguyen at VILAF, a member of the Global Law Experts network.
posted 2 minutes ago
posted 21 minutes ago
posted 43 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
No results available
Find the right Legal Expert for your business
Send welcome message