[codicts-css-switcher id=”346″]

Global Law Experts Logo
fintech m&a vietnam

Our Expert in Vietnam

Fintech & Payments M&A in Vietnam (2026): Licensing, Ownership Caps, Data and Approvals Buyers Must Know

By Global Law Experts
– posted 53 minutes ago

Fintech M&A Vietnam has entered a decisive new phase, and buyers who treat these deals like conventional acquisitions risk expensive surprises at closing. Vietnam’s investment framework, the implementing rules for the Law on Investment, and the State Bank of Vietnam (SBV) regime for payment services have collectively tightened the way foreign ownership, licensing continuity and cross-border data flows are scrutinised. In particular, Decree No. 52/2024/ND-CP on non-cash payments and its guiding circulars have reshaped how payment intermediary and related activities are licensed. This guide is written for acquirers, private equity sponsors, in-house counsel and deal teams evaluating fintech and payments targets, and it focuses on the transaction-level mechanics that generic market summaries tend to skip.

You will find licensing pathways, ownership review triggers, data-transfer constraints, a due diligence checklist, an SPA drafting checkpoint list and a post-closing playbook designed to be operationalised on a live deal.

Search intent: Practical, transaction-ready guidance for buyers and deal teams on licensing, ownership limits and data obligations when acquiring fintech and payments businesses in Vietnam under the current regulatory landscape. Use the checklists and SPA drafting tips to turn regulatory theory into deliverable conditions precedent and post-closing steps.

Quick summary: what buyers must track and why it matters for deals

The current regulatory package reshapes the risk profile of every fintech M&A Vietnam transaction. Rather than a single reform, buyers are navigating several moving parts that interact at different stages of a deal, from signing through to post-closing operational authorisation. Understanding the headline features first helps deal teams sequence diligence and structure conditions precedent correctly.

  • Investment framework. The Law on Investment and its implementing decrees set out market-access conditions for foreign investors, including sectors subject to conditional access and, for certain sensitive transactions, national-defence and security considerations. For fintech targets that touch payments infrastructure and personal data at scale, this can convert a routine share transfer into a transaction requiring pre-closing registration or approval of capital contribution or share purchase by a foreign investor.
  • Sectoral approval procedures. Sectoral rules govern when a change of ownership in a regulated business must be notified to or approved by the relevant sectoral regulator before it becomes effective. For payment intermediary services, SBV approval is central.
  • SBV payment services regime. Licensing scopes for payment intermediary service providers under Decree No. 52/2024/ND-CP affect how licences are categorised, whether they survive a change of control, and what the central bank expects when the ownership of a licensed payments business changes.
  • Data regime. Vietnam’s Law on Cybersecurity, the Personal Data Protection Decree (Decree No. 13/2023/ND-CP) and the Law on Personal Data Protection (which the National Assembly passed in 2025, with effect from 2026) place greater weight on data localisation and cross-border transfer. The data assets inside a fintech target, customer records, transaction histories, KYC files, are now a first-order deal risk, not an afterthought.

The practical consequences are concrete. A poorly sequenced deal can face licence continuity gaps, exposure where a foreign-ownership condition is breached, and cross-border data flows that must be re-papered before integration can proceed. For buyers, the message is that regulatory diligence and closing mechanics in a fintech M&A Vietnam transaction must be built into the SPA from the outset, not bolted on after heads of terms are agreed.

Required licences and regulatory approvals for fintech and payments deals

Any fintech M&A Vietnam transaction begins with an accurate inventory of the target’s regulatory permissions. The single most common cause of value leakage is discovering, after signing, that a critical licence is non-transferable, expired, or held in a way that does not survive a change of control. Because different fintech activities are regulated by different authorities, the buyer must map each business line to the permission that authorises it.

Payment intermediary service licences and the SBV process

The State Bank of Vietnam is the principal regulator for payment activity, and most payments businesses rely on one or more SBV-issued permissions. Under Decree No. 52/2024/ND-CP, payment intermediary services include categories such as switching and electronic clearing services, e-wallet services, electronic payment gateway services and support services for collection and payment. The buyer’s diligence should establish, for each licence, the exact scope of permitted activity, the expiry or renewal date, any conditions attached, and, critically, how SBV treats a change of shareholding, since foreign investment in payment intermediary services and changes to the licence-holder’s charter documents are subject to SBV oversight.

The core steps in the SBV pathway generally involve confirming the licence status, identifying whether the transaction constitutes a change requiring notification or approval, preparing the supporting corporate and regulatory documents, and submitting the relevant filing. Because SBV review timelines can be material relative to a deal calendar, buyers should treat central-bank engagement as an early-stage activity rather than a closing formality.

Payment intermediary services versus e-wallet float handling

Buyers frequently conflate different categories of payment authorisation, and the distinction matters for both diligence and structuring. Switching, clearing and gateway functions are regulated as distinct payment intermediary services under Decree No. 52/2024/ND-CP, while an e-wallet business holds customer funds in a way that attracts specific safeguarding expectations, including the obligation to maintain guarantee/escrow balances at commercial banks corresponding to customers’ e-wallet balances. The regulatory treatment of a change of control can therefore differ across these categories.

The practical takeaway is that a target described loosely as a “payments company” may in fact hold a bundle of permissions with different transferability profiles. Each must be assessed individually. Where the target’s value depends on the continuity of a particular permission, that continuity should be converted into a specific condition precedent and a corresponding representation and warranty in the SPA.

Other relevant licences: telecom, cybersecurity and value-added services

Fintech businesses rarely sit within a single regulatory silo. Depending on the technology and business model, a target may also require permissions overseen by the Ministry of Science and Technology (which absorbed the former Ministry of Information and Communications following the 2025 government restructuring), for example where the business operates telecom or information-network services, provides certain value-added services, or is subject to cybersecurity obligations. A payments target that also runs a data-heavy platform or a consumer app can therefore carry additional regulatory obligations alongside its SBV permissions.

Because these permissions overlap, the diligence exercise should produce a consolidated licence map showing which regulator governs each activity, the status of each permission, and the change-of-control treatment for each. The table below summarises the typical position across the most common permission types encountered in a fintech M&A Vietnam deal.

Licence type Regulator Transferable on sale? Typical approval timing Ownership / review considerations
E-wallet service SBV Conditional, subject to SBV oversight on change of control Medium to high Foreign-investment conditions and safeguarding obligations apply
Payment intermediary (switching / clearing / gateway / collection support) SBV Conditional, SBV oversight on ownership change Medium Foreign-investment ratio conditions may apply under payment rules
Card acquiring / payment-related banking services SBV Conditional Medium to high Sectoral review; card-scheme rules may add constraints
Telecom / value-added information services Ministry of Science and Technology Activity-dependent Medium Conditional market access; verify current rules
Virtual asset service provider Evolving / regulator-dependent Uncertain, regime still developing High / uncertain Heightened review; expect additional scrutiny as the pilot framework develops

Buyers should treat the “conditional” entries as instructions to engage the regulator early. In practice, the difference between a licence that can be preserved through approval and one that effectively requires re-application drives the entire post-closing timetable. Detailed sectoral procedure is discussed in the guidance on how to obtain sectoral approvals for M&A in Vietnam.

Foreign ownership limits and investment-law implications for fintech M&A Vietnam

Ownership is where regulation bites hardest. A foreign buyer contemplating a fintech M&A Vietnam transaction must resolve two distinct questions: whether a sectoral ownership condition applies to the specific activity, and whether the acquisition triggers registration or approval requirements under the Law on Investment. These are separate analyses that can each independently block or reshape a deal, and both must be run before the buyer commits to a headline price.

Sectoral conditions applicable to payment intermediary services

Vietnam regulates foreign participation in financial and payment activities more tightly than in ordinary commercial sectors. Decree No. 52/2024/ND-CP contemplates conditions on the foreign-ownership ratio in companies providing payment intermediary services, and any structure that attempts to circumvent an applicable ratio through indirect holdings will attract scrutiny. Where no explicit numerical cap applies to a given activity, foreign investment may still be subject to conditional market-access requirements.

The critical diligence step is to confirm, for the precise activity the target conducts, whether a foreign-ownership condition exists and at what level. This must be verified against the current sectoral rules rather than assumed from general market commentary, because the applicable position varies by activity. Buyers should also confirm the target’s existing foreign ownership position, since a transaction that pushes cumulative foreign holdings above an applicable threshold can crystallise a compliance problem.

Investment-law review triggers and remedies

Under the Law on Investment and its implementing rules, a foreign investor acquiring shares or contributing capital in certain conditional-access sectors must register the transaction with the competent authority before completion; in sensitive cases (for example those relating to national defence and security), additional scrutiny may apply. For fintech targets that process payments at scale or hold large volumes of personal data, the buyer’s structuring should identify, at an early stage, whether the deal falls within a registration or approval requirement and what the applicable filing pathway is.

The remedies for getting this wrong are significant. A transaction that breaches a foreign-ownership condition or proceeds without a required registration or approval can expose the parties to invalidity, unwinding, penalties, or the loss of the very licences that underpinned the deal rationale. The practical response is to build the ownership analysis into conditions precedent, to make regulatory clearance a completion condition where required, and to allocate the risk of an adverse regulatory outcome expressly in the SPA. The table below illustrates how ownership treatment can differ across fintech subsectors.

Fintech subsector Foreign ownership treatment Investment-law review exposure
Payment intermediary service providers Foreign-ownership conditions may apply; verify against current rules Higher, payments infrastructure attracts scrutiny
Digital lending platforms Activity-dependent; verify against current rules Medium, depends on scale and data footprint
Virtual asset / crypto providers Uncertain; regime still developing High, heightened review likely

Because the ownership picture varies so widely by activity, the ownership analysis should be one of the first outputs of legal diligence in any fintech M&A Vietnam deal, feeding directly into deal structure and price.

Data protection, localisation and cross-border transfer rules, M&A implications

Data has become a defining risk in fintech M&A Vietnam transactions because the value of a payments or fintech target lives substantially in its data. Customer identities, transaction histories and KYC records are both the commercial asset and the compliance liability. The current environment places greater weight on where that data sits, how it moves across borders, and whether it can lawfully flow to the buyer’s group after closing.

Applicable laws and regulators

Data obligations for fintech operations sit across Decree No. 13/2023/ND-CP on personal data protection, the Law on Personal Data Protection (passed in 2025 and effective from 2026), and the Law on Cybersecurity together with its implementing Decree No. 53/2022/ND-CP, which addresses data-localisation obligations for certain enterprises. The Ministry of Public Security plays a central role in personal data protection and cybersecurity enforcement, while financial-sector data is treated as particularly sensitive. Buyers should confirm which regulator supervises each data-handling activity and whether any sector-specific requirements apply on top of the general regime.

Data mapping and DPIA in due diligence

Effective data diligence begins with a data map: what personal and financial data the target holds, where it is stored, who processes it, and how it flows between systems and entities. A data protection impact assessment (DPIA), expressly contemplated under Vietnam’s personal data protection rules, helps identify high-risk processing and locate the points at which cross-border transfer or third-party processing occurs. In a fintech target, particular attention should be paid to settlement data shared with banks and card schemes, KYC data shared with onboarding vendors, and analytics data routed to offshore infrastructure.

The output of this exercise is a set of concrete findings that feed the SPA: which data flows are compliant, which require remediation, and which cannot continue post-closing without a new legal basis. Buyers should treat unmapped or offshore-dependent data flows as red flags requiring specific representations and, where necessary, a remediation covenant.

Cross-border transfer mechanisms and practical mitigations

Where data must move out of Vietnam, for example to a buyer’s regional data centre or shared services function, the transfer must rest on a recognised basis. Under Vietnam’s personal data rules, cross-border transfers of personal data may require the preparation of a transfer impact assessment dossier and its lodgement with the competent authority, alongside a valid legal basis such as consent. Buyers should not assume that a data flow permitted under the seller’s group arrangements will automatically be permissible under the acquirer’s post-closing structure.

  • Contractual controls. Put transfer terms, processing restrictions and audit rights into intra-group and vendor agreements before any data moves.
  • Technical safeguards. Apply encryption in transit and at rest, and tokenise or pseudonymise data where the business case permits.
  • Segmented operations. Where localisation obligations bind, keep regulated data resident in Vietnam and design integration around that constraint rather than against it.
  • Consent, assessment and lodgement. Where consent, a transfer impact assessment or authority lodgement is required, verify it exists and is valid before relying on the transfer.

Practical drafting for the SPA should require the seller to warrant the lawfulness of existing transfers and to cooperate in re-papering flows that will change on completion. In a fintech M&A Vietnam context, this data workstream frequently sits on the critical path to integration, so it should be resourced early. Broader diligence structuring is covered in the Vietnam M&A due diligence, checklist and guide.

Pre-closing due diligence checklist for fintech and payments targets

Diligence on a fintech target is broader than on a typical private company because regulatory, technological and contractual risks are deeply intertwined. The following checklist covers the areas that most often drive value adjustments, conditions precedent or walk-away decisions in a fintech M&A Vietnam transaction. It should be read alongside the licence map and data map described above.

  • Licensing. Confirm every SBV and other regulatory permission, its scope, expiry, conditions and change-of-control treatment.
  • Ownership and condition compliance. Verify current foreign ownership levels and confirm headroom against any applicable foreign-ownership condition.
  • Board and shareholders. Review corporate approvals, shareholder agreements, pre-emption rights and any consents required for transfer.
  • Bank and scheme contracts. Examine agreements with acquiring banks, switching partners and card schemes for change-of-control and termination triggers.
  • Settlement and safeguarding. Assess settlement flows, float handling and the maintenance of guarantee/escrow balances for customer e-wallet funds.
  • KYC and AML. Test onboarding controls, transaction monitoring, sanctions screening and the completeness of KYC records against the Law on Anti-Money Laundering.
  • Technology stack. Map owned versus licensed technology, open-source exposure and dependency on the seller’s shared infrastructure.
  • Cybersecurity. Review incident history, penetration testing, data-localisation status and compliance with the cybersecurity framework.
  • Third-party processors. Identify all processors and sub-processors handling personal or financial data and confirm contractual coverage.
  • Data flows and cross-border dependencies. Confirm the legal basis for every material data flow, especially those leaving Vietnam.

Each red flag surfaced here should map to a specific SPA mechanism, a condition precedent, a warranty, a specific indemnity or a price adjustment. Diligence that merely documents risk without translating it into deal terms adds little protection for the buyer.

Post-closing licensing and operational authorisations, step-by-step playbook

Signing is not the end of the regulatory journey. In a fintech M&A Vietnam transaction, the period between signing and full operational authorisation is where deals are won or lost operationally, because the target must keep processing payments lawfully while ownership changes hands. A structured post-closing playbook keeps the business running and the licences intact.

SPA conditions precedent and timing

Where a change of control requires SBV notification or approval, or where the Law on Investment requires registration of the foreign investor’s capital contribution or share purchase, the relevant clearance should be a condition precedent to completion wherever the deal calendar allows. Sequencing matters: the buyer should identify which approvals must precede completion and which can be obtained after closing under a transitional arrangement, and then align the long-stop date to the most demanding of these timelines.

Securing licence variation, transfer or a new application

The correct pathway depends entirely on the licence in question. Some permissions can be preserved through a variation or an approved change of ownership, requiring the buyer to satisfy the regulator as to the new owner’s suitability. Others cannot pass through a change of control and effectively require a fresh application, a materially longer process. The buyer should confirm, licence by licence, which pathway applies and prepare the corresponding filing package in advance. Engaging SBV and other relevant regulators early gives the buyer the best chance of avoiding a gap in authorisation.

Interim measures and transitional services agreements

Where full authorisation cannot be in place at completion, transitional arrangements bridge the gap. A transitional services agreement (TSA) can keep the seller’s group providing support or infrastructure for a defined period, allowing the target to continue operating while the buyer completes its filings. Any such arrangement must itself be compliant, it cannot be used to circumvent a licensing requirement, and should be time-boxed with clear exit triggers tied to the buyer securing its own permissions.

The practical filing list for the post-closing phase typically includes the corporate documents evidencing the new ownership, regulatory forms for the change of control, updated compliance and governance documentation, and any information the regulator requires to assess the new controller. Negotiation points that recur include who bears the cost and risk of delay, what happens if an approval is refused, and how the parties allocate liability for any period of operational uncertainty.

SPA drafting checklist, covenants, reps, warranties, indemnities and holdbacks

The SPA is where regulatory risk is priced and allocated. For a regulated fintech target, standard M&A boilerplate is insufficient; the drafting must reflect the specific licensing, ownership and data risks identified in diligence. The following points should feature in any well-structured agreement.

  • Licence validity reps. Warranties that each licence is valid, in good standing, and not subject to revocation, suspension or adverse regulatory action.
  • Regulatory consents. Conditions precedent requiring all necessary SBV, investment-registration and other regulatory clearances before completion.
  • Ownership-condition protection. Escrow and holdback triggers addressing the risk that a foreign-ownership condition results in a mandated adjustment or divestment.
  • Regulatory change clauses. Mechanisms addressing adverse regulatory developments between signing and completion.
  • Notification obligations. Covenants requiring the seller to notify and cooperate with regulators through the approval process.
  • Remedy mechanics. Clear indemnities for pre-closing regulatory breaches, KYC/AML failures and unlawful data transfers.
  • Escrow for penalties. Ring-fenced funds to cover fines or remediation costs arising from historic non-compliance.

Buyers should also consider warranty and indemnity insurance, though insurers will scrutinise regulated-sector risks closely and may exclude known licensing or data exposures. Where a specific risk cannot be insured, a targeted indemnity backed by escrow is usually the more reliable protection.

Practical timetable and likelihood matrix, closing risk heatmap

Not every regulatory item carries equal weight. The matrix below helps deal teams prioritise remediation effort and set realistic expectations on timing in a fintech M&A Vietnam transaction.

Risk item Risk level Expected time to remediate / approve
Licence transfer or change-of-control approval Medium to high Longer, build into long-stop date
Data remediation and cross-border re-papering Medium Moderate, start during diligence
Foreign-investment registration / approval Medium (depends on activity) Variable, depends on the sector and filing pathway

Comparison table, licensing pathways, timelines and ownership constraints

The consolidated comparison earlier in this guide maps each core permission type to its regulator, transferability, approval timing and ownership treatment. Use it as the starting grid for structuring, and populate it with the target’s actual licence data during diligence so that it becomes a live deal document rather than a generic reference.

Practical next steps for your fintech M&A Vietnam transaction

A successful fintech M&A Vietnam deal depends on treating licensing, ownership and data as core deal terms rather than post-signing formalities. Map the target’s permissions, run the ownership and investment-law analysis early, complete data diligence before closing, and convert every material risk into a specific SPA mechanism supported by a realistic post-closing plan. Buyers who front-load this work protect both value and licence continuity. For specialist support, connect with the M&A Lawyers Vietnam directory and review the related guidance on due diligence and sectoral approvals linked throughout this guide.

This article is provided for general informational purposes only and does not constitute legal advice. Buyers should obtain transaction-specific advice on Vietnamese law before acting.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Ngan Nguyen at VILAF, a member of the Global Law Experts network.

Sources

  1. State Bank of Vietnam (SBV)
  2. National Assembly of Vietnam
  3. Government Portal / National Legal Document Database (Vietnam)
  4. Ministry of Science and Technology
  5. OECD, Digital Economy / Fintech Reports
  6. World Bank, Vietnam Digital Economy Reports
  7. IFC, Vietnam Fintech and Foreign Investment Reports

FAQs

What licences and regulatory approvals are needed to acquire a payments or fintech company in Vietnam?
Buyers must audit the target’s SBV permissions, such as e-wallet and other payment intermediary service licences under Decree No. 52/2024/ND-CP, together with any telecom or value-added service approvals, cybersecurity and data-localisation obligations, and sectoral permits. Some of these licences require SBV notification or approval when ownership changes, so the buyer should map each permission and its change-of-control treatment early.
They can. Payment intermediary services are a conditional-access sector, and foreign-ownership ratio conditions may apply to certain payment activities. Buyers should confirm the applicable sectoral rules for the precise activity and complete any required investment registration or approval before committing.
Data localisation and cross-border transfer restrictions may require valid consent, the preparation and lodgement of a transfer impact assessment dossier, or other measures under the personal data protection and cybersecurity regimes. Because a fintech target’s data flows often change on a change of control, data mapping and contractual controls should be completed before closing rather than after integration begins.
It depends on the licence type. Some permissions allow a change of owner subject to SBV oversight, while others may require an amendment or a fresh application and substantive regulatory review. Buyers should plan for transitional arrangements and, where appropriate, a transitional services agreement to avoid a gap in authorisation.
Conduct targeted regulatory diligence, build regulatory clearances into conditions precedent, negotiate transitional arrangements, and use escrow or holdbacks to cover regulatory liabilities and ownership-condition risk. Engaging SBV and other regulators early is the single most effective way to keep the timetable on track.
cayman islands aml sanctions rules
By Global Law Experts

posted 28 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Fintech & Payments M&A in Vietnam (2026): Licensing, Ownership Caps, Data and Approvals Buyers Must Know

Send welcome message

Custom Message