← Back to JOYY filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
A. History and Development of the Company
We commenced operations in April 2005 with the establishment of Guangzhou Huaduo in mainland China. In July 2011, we established an exempted company with limited liability in the Cayman Islands, YY Inc., as our holding company. On November 21, 2012, our ADSs were listed on The Nasdaq Stock Market under the symbol “YY.” Effective December 20, 2019, we changed our corporate name from “YY Inc.” to “JOYY Inc.” We began trading under the new corporate name on December 30, 2019. Effective March 31, 2025, we changed our trading symbol on The Nasdaq Stock Market from “YY” to “JOYY.”
Since our inception, we have undergone significant strategic transformations, evolving through three distinct operational phases to transition from a regional market leader to a global social entertainment company, and finally into a globally diversified multi-engine technology ecosystem.
Phase 1.0: Foundations in Mainland China (2005–2014). During this initial period, we focused on the development of the social entertainment industry in mainland China. We successfully incubated and scaled several market leading platforms including YY Live and Huya, establishing a leadership position in real-time video engagement and livestreaming technology within the PRC market.
Phase 2.0: Strategic Globalization (2014–2021). In 2014, foreseeing massive global opportunities, we initiated a proactive globalization strategy to capture opportunities in international markets. This expansion was anchored by our investment in, and the subsequent full acquisition of, BIGO in March 2019. This milestone integrated a high-growth global product matrix into our portfolio and established an extensive localized operational network, giving us an in-depth presence across Asia, North America, the Middle East, and Europe. To streamline our strategic focus on global operations, we divested Huya and YY Live, in 2020 and 2021, respectively.
Phase 3.0: Transition to a Multi-Engine Growth Ecosystem (2022–Present). Beginning in 2022, we entered a new strategic phase, characterized by the structural diversification of our revenue streams and the scaling of our business-to-business (B2B) technology suite. Fueled by the launch of BIGO Ads Audience Network and the strategic consolidation of Shopline in August 2022, we are transitioning into a multi-growth engine ecosystem. Today, we leverage our foundational social entertainment engagement to empower programmatic advertising and omnichannel smart commerce solutions, to capture structural value across the global digital economy.
Currently, we mainly operate our global business through the following significant subsidiaries:
● Bigo Technology Pte. Ltd.; and
● Guangzhou BaiGuo Yuan Information Technology Co., Ltd.
We also conduct part of our business in mainland China primarily through a significant variable interest entity, Guangzhou BaiGuo Yuan Network Technology Co., Ltd., and some of its subsidiaries.
Our principal executive offices are located at 30 Pasir Panjang Road #15-31A Mapletree Business City, Singapore 117440. Our registered office in the Cayman Islands is located at Conyers Trust Company (Cayman) Limited of Cricket Square, Hutchins Drive, P.O. Box 2681, Grand Cayman, KYI-1111, Cayman Islands.
45
Table of Contents
All information we file with the SEC can be obtained over the internet at the SEC’s website at www.sec.gov. You can also find information on our website at ir.joyy.com. The information contained on our website is not a part of this annual report.
B. Business Overview
Overview
We are a global technology company with a mission to enrich lives through technology, leveraging a proprietary technology stack to bridge social interaction, programmatic advertising, and omnichannel smart commerce.
We are a leader in the global social entertainment sector. Through our social product matrix and communication technology, we enable people to connect with friends and family, discover and explore their interests, and share their experiences and ideas with a global audience through photos, audio, and videos. We serve a global user base of 272.1 million monthly active users as of the fourth quarter of 2025, covering North America, Europe, the Middle East, Southeast Asia, and more, through our diverse product matrix covering live streaming, short videos, instant messaging, casual games, and beyond. Several of our social apps ranked among the Top 10 in terms of consumer spending in various geographic regions in which we operate, according to data.ai.
We are transitioning from a specialized social entertainment platform into a globally diversified technology ecosystem powered by multiple growth engines. We have been exploring innovative technologies and initiatives to further expand our offerings beyond social entertainment, tapping into new addressable markets worldwide. We are actively scaling our B2B technology stack, resulting in a strategic expansion of our non-live streaming revenues in 2025, primarily from advertising and smart commerce. In 2025, our total non-livestreaming revenue increased by 32.2% year over year, contributing 28.0% of total group revenue, up from 20.1% in the prior year.
The long-term value of JOYY lies in our full-stack synergies, which was derived from the interconnectivity of our social data, advanced and continuously optimizing advertising algorithms, and comprehensive smart commerce solutions, which together form an integrated flywheel of user engagement and monetization.
Core Global Social Entertainment Products
● Live streaming platform: Bigo Live is a leading global social live streaming platform. Bigo Live provides an interactive online stage for global users to host and watch live streaming sessions, share their life moments, showcase their talents and interact with people around the world. Bigo Live has an extensive presence in North America, Europe, the Middle East and Southeast Asia, among others.
● Instant messenger: imo is a global instant messenger that provides audio and video communication services. It offers frictionless audio and video calls and other communication tools such as group calls, document sharing and more, catering to a variety of personal and business communication needs. imo has attracted a growing and highly engaged user base in South Asia and the Middle East.
● Short video platform: Likee is a global short video social platform. Likee empowers its users to easily discover, create and share short videos, with simple, all-in-one powerful video creation tools and personalized feeds. Likee has a presence in the Middle East, Europe, and Southeast Asia.
● Social networking platform: Hago is a social networking platform. It offers over 600 casual games, integrating social features such as audio and video multi-user chatrooms and 3D virtual interactive party games, which encourage users to establish and strengthen connections while having fun. Hago has a presence in Southeast Asia, the Middle East and South America.
Strategic Growth Engines: Advertising and Smart Commerce
● Advertising platform: BIGO Ads is an AI-powered programmatic advertising platform. Launched to provide one-stop marketing and monetization solutions, it leverages deep learning, real-time bidding, and smart bidding models (such as oCPC and ROAS optimization) to enable brands to scale user acquisition and app developers to effectively unlock monetization potentials through connecting premium global demand.
46
Table of Contents
● Smart commerce solution provider: Shopline is a global smart commerce platform that offers solutions and services empowering merchants to create and grow their brands online and reach customers worldwide across different sales channels including e-commerce platforms, social commerce and physical retail stores. Shopline provides an end-to-end solution for global commerce, integrating enterprise-grade storefront management, localized and cross-border payment processing (Shopline Payments), logistics, inventory control, and automated marketing tools. Shopline has helped merchants in diverse industries to launch and scale their online businesses.
Business Model
We generate revenue through a diversified mix of global social engagement and business-to-business (B2B) technology solutions.
Our core global social entertainment platforms, including Bigo Live, Likee, Hago and imo, primarily utilize a virtual item-based monetization model. Users engage in real-time social interactions, purchase virtual currency to send gifts to performers during real-time livestreaming sessions or subscribe to premium membership services that offer exclusive status and privileges. In 2025, virtual tips for live streaming accounted for 72.0% of our revenues.
Our B2B growth engines, primarily BIGO Ads and Shopline, have structurally optimized our revenue mix by expanding our reach into programmatic advertising and omnichannel smart commerce. BIGO Ads generates revenue through comprehensive advertising solutions, leveraging our proprietary programmatic technology to monetize first-party traffic from platforms like imo and Likee, as well as third-party inventory through the BIGO Audience Network. In 2025, advertising revenues, primarily BIGO Ads, accounted for 20.8% of our total net revenues. Shopline operates a smart commerce SaaS model, deriving income from recurring software subscription fees and a suite of transaction-based value-added services, including localized payment processing (Shopline Payments), marketing, and cross-border logistics solutions. In 2025, e-commerce and other revenues collectively accounted for 7.1% of our total net revenues.
We have built a sizable global business with strong operating cashflow. Our total revenue amounted to US$2.3 billion in 2023, US$2.2 billion in 2024 and US$2.1 billion in 2025. Our net cash provided by operating activities was US$295.6 million in 2023, US$308.7 million in 2024 and US$302.3 million in 2025.
The structural evolution of our revenue mix, underpinned by the growing contribution of programmatic advertising and smart commerce, marks a significant inflection point in our corporate history. With a strong net cash position and a diversified portfolio of high-growth technology assets, we believe we are positioned to capture expanding long-term opportunities within the global advertising technology and smart commerce sectors and drive sustainable, long-term growth.
Our Strategy
Driving Multi-Engine Growth through Ecosystem Synergies. JOYY is a global technology company that seamlessly integrates social entertainment with a robust B2B technology stack. By unifying programmatic advertising and smart commerce SaaS solutions, JOYY provides a comprehensive ecosystem to facilitate digital engagement and commercial transformation, creating a self-reinforcing flywheel that empowers creators, advertisers and brand merchants worldwide.
Deepening Global Localization and Operational Excellence. We define our competitive advantage through a strategy of “Global Reach, Local Depth,” leveraging our established presence in over 150 countries to refine localized operations. We have built an extensive global operational network with approximately 30 regional offices and more than 5,400 local staff worldwide. We drive localized product iteration, tailoring the content of our social products and the features of our B2B solutions to specific cultural and regulatory environments. This granular approach cultivates deep user retention and customer loyalty that “one-size-fits-all” global competitors cannot easily replicate. Furthermore, we capitalize on our established localized operational networks to accelerate the international expansion of our B2B initiatives.
47
Table of Contents
Technology Backbone and AI-Powered Operations. We aim to strengthen our proprietary technology stack that serves as a structural advantage, bridging our global social engagement platforms with an integrated B2B technology suite. We have integrated artificial intelligence (AI) and data analytics into all critical aspects of our services and broader business operations. This acts as a central engine for both user engagement and commercial performance.
● Social Engagement and Creator Productivity: In our social platforms, AI-driven innovation focuses on deepening user-streamer connections and enhancing creator productivity. We utilize Generative AI to efficiently produce localized virtual items and interactive gifts. By integrating Large Language Model architectures and incorporating multi-modal information into our recommendation systems, we have significantly improved our ability to analyze real-time social content and user intentions. This focus on technical utility results in a highly personalized and sticky experience, characterized by superior engagement efficiency.
● Our Global Network Infrastructure: We have established an extensive global data center network, located in Asia, Europe and the Americas. Our infrastructure provides seamless integration and is highly customized for supporting our services with significant flexibility. Our video and audio technology helps ensure a smooth user experience for our substantial global user base. We offer low latency video and audio product experience for different communication networks (3G/4G/5G/Wi-Fi, etc.), serving nearly 272.1 million users in 150 countries worldwide, many of whom are located in less developed countries with limited internet infrastructure. Our patented video codec innovation algorithm automatically adapts to different hardware platforms and environments, and optimizes the indicators of sound quality, code rate, and transmission fluency no matter where you are.
● Operational Efficiency and Data-Driven Decision-Making: We utilize AI-driven data analytics to optimize our structural margins and streamline corporate cycles. Our AI capabilities empower automated product beta testing and augment critical corporate decision-making in areas such as budgeting and resource allocation. By modularizing foundational R&D processes, we have built agile, scalable capabilities that allow us to replicate operational successes across emerging products with high efficiency.
Our Platforms and Products
Core Global Social Entertainment Products
Bigo Live
Bigo Live is a leading global social live streaming platform. Bigo Live enables its users to share their life moments, showcase their talents, socialize and connect with other users from all around the world through live streaming. Launched in 2016, Bigo Live currently has a strong presence in North America, Europe, the Middle East and Southeast Asia, among others. Bigo Live is an international platform, available in 23 languages and approximately 150 countries.
Bigo Live has built an engaged, interactive and diverse community. Through extensive incentive programs, localized campaigns, and cross-industry partnerships, Bigo Live has attracted a substantial pool of creators and accumulated localized content across various categories, including music, dance, comedy, gaming and lifestyle.
Bigo Live currently monetizes its user base mainly through virtual tips for live streaming. Users can purchase in-app virtual items and send them as virtual gifts to their favorite streamers to show their appreciation.
Among the various platforms operated by us, Bigo Live is currently the largest revenue contributor. Bigo Live was ranked as the World’s No.9 Social App in terms of in-app-purchase revenue in 2025, according to the State of Mobile report from data.ai.
imo
imo is a global instant messenger that provides audio and video communication service to its users. It offers smooth and stable international video calls in addition to other features such as group calls and document sharing, catering to a variety of personal and business communication needs. imo has a large and engaged user base in South Asia and the Middle East.
48
Table of Contents
A core strategic advantage of imo is its ability to deliver stable, high-quality communication in diverse and challenging network environments. To serve users in regions with varying mobile infrastructure, imo utilizes a proprietary suite of technologies, including adaptive bitrate streaming and advanced packet loss concealment. These technical refinements ensure that imo maintains superior performance and connection stability in weak-network scenarios, driving organic retention in markets where reliable connectivity is a critical utility.
imo currently monetizes its user base mainly through advertisements and live streaming. In 2021, imo launched VoiceClub, an online real-time voice chat communication space, enabling users to establish connections with users beyond their existing network. VoiceClub also enables users to send virtual gifts to their friends to express their support and appreciation.
Imo was ranked as the No.4 and No.5 Social App in terms of downloads in United Arab Emirates and Saudi Arabia, respectively, in 2025, according to the State of Mobile report from data.ai.
Likee
Likee is a global short video social platform. Likee enables users to easily discover, create and share short videos, empowered by its easy, all-in-one video creation tools, such as filters and special effects, and its AI-backed personalized feed. Launched in 2017, Likee has a presence in the Middle East, Europe and Southeast Asia.
Likee currently monetizes its user base mainly through virtual tips for live streaming and advertisements. Likee was ranked United Arab Emirates’s No.10 Social App in terms of in-app-purchase revenue in 2025, according to the State of Mobile report from data.ai.
Hago
Hago is a social networking platform that encourages users to connect and have fun. Users can make new acquaintances by playing multiplayer casual games, join video & audio chat rooms based on their interests, create and customize their 3D avatars in Hago Space and join Groups or Families with like-minded people to foster more frequent communication. Launched in 2018, Hago has a presence mainly in Southeast Asia, the Middle East and South America.
Hago currently monetizes its user base mainly through virtual tips for live streaming.
B2B Initiatives: Advertising and Smart Commerce
BIGO Ads
BIGO Ads is a global AI-powered programmatic advertising platform, connecting advertisers and publishers with high-quality traffic from BIGO’s social apps and premium international developers. Operating as a sophisticated programmatic platform that provides one-stop marketing and monetization solutions, BIGO Ads leverages deep learning, real-time bidding, and smart bidding models (such as oCPC and ROAS optimization) to enable brands to scale user acquisition and app developers to effectively unlock monetization potentials through connecting premium global demand. We generate advertising revenues primarily by delivering advertisements on BIGO’s social apps, such as Likee and imo, and on properties of our network partners.
First-Party Inventory as Strategic Advantage: A key strategic differentiator for BIGO Ads is its vertical integration with our core social platforms, imo and Likee. This grants BIGO Ads exclusive first-party inventory and a robust repository of proprietary behavioral data, enabling us to provide a unique value proposition to advertisers seeking high-fidelity audience segments. The scale and depth of this first-party data are also instrumental in training our proprietary models.
Scalable Global Reach Through BIGO Audience Network: BIGO Ads benefits from our massive global MAU base and an extensive network of third-party traffic through seamless Software Development Kit (SDK) integrations with premium international developers. In 2025, BIGO Ads significantly scaled its third-party SDK network traffic through successful integration with major global mediation platforms, such as AppLovin MAX and Unity Level Play, resulting in a 166% year-over-year increase in SDK advertising requests in the fourth quarter of 2025.
49
Table of Contents
Continuous Algorithm Optimization and Growth Fly Wheel: BIGO Ads utilizes advanced Deep Learning and Real-Time Bidding Optimization to deliver measurable outcomes for global marketers. A key upgrade in 2025 was the enhanced IAA D7 ROAS optimization feature rolled out in the third quarter. The enhancement enables advertisers to acquire higher-quality users while maintaining strong return efficiency, allowing them to scale budgets with greater confidence. These technical enhancements drive a self-reinforcing flywheel: superior advertiser ROI attracts increased spending, which in turn incentivizes more third-party publishers to integrate with our SDK, further expanding our data assets and algorithmic accuracy.
In 2025, BIGO Ads achieved substantial growth in revenue, fueled by an expanding advertiser base and advertiser average spending, increased third-party traffic, and our strategic entry into new markets. In 2025, BIGO Ads revenue grew by 38.5% year-over-year to US$398.5 million.
Shopline
Shopline is a global smart commerce platform offering solutions and services empowering merchants to create and grow their brands online and reach customers worldwide, across different sales channels including e-commerce platforms, social commerce, and physical retail stores. Shopline provides merchants with various services to optimize their business operations, such as multi-channel inventory and sales management, logistics, payment, marketing and data analytics, among others. Shopline has helped merchants in diverse industries to launch and scale their online businesses.
Shopline currently generates revenues from recurring software subscription fees and a suite of transaction-based value-added services, including localized payment processing (Shopline Payments), marketing and cross-border logistics solutions.
Global Branding and Marketing
Branding Strategy
With our growing global presence and our diverse product offerings, we position ourselves as a global technology company with a mission to “enrich lives through technology.” We have established an ecosystem where our diverse brands, Bigo Live, Likee, imo, Hago, BIGO Ads, and Shopline, operate with architectural alignment, enabling us to reach a wide variety of coveted user and customer bases around the world.
Marketing Activities
We leverage a “Global Reach, Local Depth” approach, utilizing our extensive global operational network of approximately 30 regional offices and over 5,400 global staff to tailor marketing to specific cultural nuances. For our social entertainment businesses, we utilize a combination of ROI-focused advertising and diverse marketing activities to enhance our global brand recognition and attract users to our platforms. For BIGO Ads, our marketing focuses on building credibility and trust with global advertisers by highlighting our premium first-party traffic and localized operational insights. We leverage strategic partnerships with leading global mediation platforms—such as AppLovin MAX and Unity Level Play—to accelerate the adoption of our SDK among third-party developers, thereby expanding the BIGO Audience Network. For our smart commerce business, we utilize both online and offline marketing to maximize our brand awareness and attract new merchants and ecosystem partners. We organize product marketing and awareness-driven campaigns aimed at inspiring entrepreneurship and encouraging digitalized commerce. By attending offline exhibitions and industry summits, hosting global events and customer meetings, and promoting our digital community (Shopline Blog) and other educational materials, we expand our customer reach and promote our platform to more merchants (including small and medium-sized businesses as well as brand merchants) in terms of how to improve their operating efficiency and achieve business success with Shopline.
Seasonality
Our results of operations of various products and services are subject to seasonal fluctuations, many of which are outside our control. For a discussion of the factors that may contribute to fluctuations of our quarterly results, see “Item 3. Key Information—D. Risk Factors—Risks Related to Our Business and Industry—Our results of operations are subject to fluctuations due to seasonality and other factors.”
50
Table of Contents
Competition
We face competition in various aspects of our business. In relation to our global social entertainment products, we compete with companies that provide online live streaming and short video businesses, and we compete with other social networking and entertainment platforms in terms of user traffic and user time. Specifically, our competitors primarily include global short video platforms such as TikTok, and certain regional live streaming platforms. For our advertising business, we face competition from independent advertising technology platforms such as AppLovin and Unity, which provide marketing and monetization solutions. We also face competition from companies that provide smart commerce solutions for merchants, such as Shopify.
Technology
Our proprietary technologies serve as the backbone of our products and services.
Artificial Intelligence and Algorithm Technologies
Artificial intelligence serves as the center of JOYY’s proprietary technology stack. Our intelligent content recommendation algorithms, based on Deep Neural Networks and Graph Neural Network technology, effectively capture changes in each user’s personalized interest and caters to their demand in real time, giving users a one-of-a-kind entertainment experience. We filter audio and video content in real-time with millisecond latency, including comprehensive detection of improper or illegal content. In combination with our human content moderation team, this ensures compliance with the applicable laws and regulations regarding the provision of content via the internet, while enhancing content quality across our platforms.
For our B2B initiatives, our proprietary algorithms drive enhanced performance for our B2B technology suite. Utilizing deep learning and advanced neural networks, BIGO Ads delivers real-time bidding and automated bid optimization (including oCPC and ROAS optimization), enabling advertisers to achieve measurable gains. At Shopline, we introduced AI-powered merchant tools—including automated marketing and smart operations—to enhance merchant productivity and optimize operational costs across the retail lifecycle.
Quality of Service for Online Multi-media Communications
As a leading provider of large-scale multi-user voice and video-enabled online service, we are constantly working to improve our technological capabilities. Our ability to provide superior user experience is further supported by our highly scalable infrastructure, proprietary algorithms and software, and tailored devices for optimal live streaming performance, which help minimize latency, jitter and loss rates when delivering voice and video data even with a weak internet connection.
Quality of Service (QoS) assurance is a key element of any high-quality delivery of voice and video data over the internet. When it comes to voice- and video-based communications, any delays, jitters and loss of data are often immediately noticeable to users. We employ a voice-over internet protocol and multiple quality assurance mechanisms to minimize instances of these issues, including, but not limited to, cloud-based intelligence routing, low-bitrate redundant solution, upstream-forward error correction, and adaptive jitter. We have also designed a special intelligent routing algorithm that automatically seeks optimal ways of delivering voice and video data across our cloud-based network, enabling us to provide better QoS even when the QoS levels are lower on certain routes.
We utilize computer programs and employ standardized measurements to constantly analyze and evaluate our voice and video communication quality. We have set up formal procedures to handle different levels of server breakdowns and network-related emergencies, and our team of experts can discover and resolve issues promptly. We have developed a series of media technologies and revamped our streaming framework, which enables multimodal information to be synthetically utilized to provide highly flexible and customizable services.
Our adaptive audio and video encoding, transmission and decoding algorithms are conducive to delivering superior audio and video experiences based on users’ local setup, including locations, devices, network condition and personal preference, optimizing both fluency and latency at the same time.
51
Table of Contents
Large, Dedicated Cloud-based Network Infrastructure
In 2025, we continued to develop and improve our global data center network, to provide top-quality, real-time video and audio services to our users worldwide. Leveraging our established local servers and infrastructure located in many of our key markets, our infrastructure provides seamless integration and is highly customized for supporting our services with significant flexibility. Our team of experts developed a cloud-based network infrastructure specifically designed to handle multi-party voice and video-enabled real-time online interactions. Our cloud-based network infrastructure provides quality data delivery and enables many users to interact online from anywhere with ease and speed.
Our system is designed for scalability and reliability to support growth in our user base. Our large server network contributes significantly to our premium streaming experience and reliable services, and it can be expanded with comparative ease, given that we are able to flexibly expand our number of available servers through leasing additional data centers to accommodate additional user traffic and bandwidth needs. We believe that our current network facilities and broadband capacity is sufficient for our current operations, and we will constantly monitor our bandwidth needs and adjust our network capacity to reflect the latest number of peak concurrent users. As of the date of this annual report, our data centers are mainly located in Asia, Europe and the Americas. We rely on several key technological mechanisms to manage our server network, including optimized data access, automated switch of servers, and intelligent routing, which help ensure the quality of data transmission for our users globally. In response to poor connection situations, we are able to provide precise connection estimation, adaptive transcoding, segmentation-based coding and other advanced mechanisms to help users enjoy high-quality audio and video experience.
Proprietary Data-Driven Platform
To build up and operate infrastructure like ours requires significant time and effort. The technological difficulties faced by a platform that hosts 10,000 concurrent users differ greatly from the difficulties faced by a platform with 100,000 and 1,000,000 concurrent users. Many of these issues need to be considered at the early stages of programming the platform and planning the infrastructure. Over the years, we have gradually developed an effective system to identify, analyze and resolve issues that we encounter on a daily basis. In addition, our team members have been trained over the years to anticipate and resolve any issues, having accumulated significant knowledge from building and maintaining our platforms over time.
Safeguarding User Privacy
We dedicate significant resources to strengthening the user privacy functions of our platforms, promoting a safe online environment for our users. For example, we provide our users with adequate notice as to what data are being collected, and have implemented a variety of mechanisms and policies to prevent the unauthorized use, loss or leak of collected user data. Our data security technologies empower us to protect user data. For our external interfaces, we utilize firewalls to protect against potential attacks or unauthorized access. Our dedicated team of privacy professionals conducts regular reviews of our data security practices.
Content Moderation
Our live streaming, short video and video communication platforms and other products enable users to exchange information, generate and distribute content, advertise products and services, conduct business and engage in various other online activities. A team within our data security department helps in enforcing our internal procedures to ensure that the content in our system is compliant with applicable laws and regulations.
Each of our platforms updates its community guidelines from time to time to keep pace with the evolving requirements of digital safety. We utilize both AI-powered moderation systems and human moderation teams to enforce our community guidelines and internal standards and ensure a safe user environment.
52
Table of Contents
Regarding our AI-powered moderation systems, BIGO has developed various AI recognition models based on a database of millions of policy violations, and created a directory for filtering inappropriate content in more than 20 languages.
For our human moderation teams, we have deployed thousands of in-house and external dedicated content moderation personnel with local language proficiency and cultural understanding in a number of countries worldwide, including, but not limited to, Singapore, the Philippines, Bangladesh, Jordan, Indonesia, Thailand and Vietnam. We also outsourced some of our human content moderation functions to third-party vendors to improve operational adaptivity and flexibility.
Our content moderation team, together with our AI-empowered program, can sweep our platforms in real time and the data being conveyed in our system for sensitive key words or questionable materials. Content that contains certain keywords is automatically filtered by our program and cannot be successfully posted. We are thus able to minimize improper or illegal content on our platforms and remove such materials promptly after they are discovered. In addition, we formed partnerships with multiple industry players and worked with relevant authorities to jointly prevent and punish any potential malicious use of our platforms. See “Item 3. Key Information—D. Risk Factors—Risks Related to Our Business and Industry—We may face significant risks related to the content, information, communications and other activities on our platforms.”
Research and Development
We believe that our ability to deliver innovative internet and mobile applications and services tailored to our users’ needs has been a key factor for our success. As of December 31, 2025, our research and development team consisted of over 2,000 skilled professionals, all focused on designing and developing our proprietary products and various interactive technologies. Our research and development efforts drive continuous innovation across several key areas, including (a) the continued optimization of our content recommendation algorithms, AI-driven creative and social tools; (b) the continual improvement of our core audio and video data processing and streaming technologies to ensure seamless, high-quality experiences, (c) the ongoing maintenance and enhancement of network and server infrastructure to minimize latency and reduce interruptions, (d) new social features and functions to meet the demand of our users, including but not limited to PC-desktop, web and mobile applications, channel templates and virtual items, (e) development of AI-empowered tools and solutions that empower merchants to efficiently build and scale their commerce presence across multiple channels and regions, streamlining workflows and boosting operational efficiency, (f) optimization of the advertising engine to help advertisers efficiently target their audience, and (g) the establishment and continuous optimization of our AI-augmented product development architecture and infrastructure, with a strategic goal of accelerating concept-to-deployment cycle across our global product and services.
Leveraging big data and artificial intelligence, particularly in the areas of computer vision, natural language processing, automatic speech recognition and speech synthesis, our technologies have empowered many aspects of our operations, including our intelligent content recommendation engines, content moderation, and targeted advertising, which has enhanced user experience and operating efficiency.
Intellectual Property
We regard our patents, trademarks, domain names, copyrights, trade secrets, proprietary technologies and similar intellectual property as critical to our success. We seek to protect our intellectual property rights through a combination of patent, trademark, copyright and trade secret protection laws in various jurisdictions, as well as through confidentiality agreements and procedures with our employees, partners and others.
As of December 31, 2025, we held 1,707 registered domain names, including joyy.com, joyy.sg, Bigo.TV, Duowan.com, bigolive.sg, likee.com, shopline.com, 1,094 software copyrights and other copyrights, 3,074 patents and 2,747 trademarks and service marks. In addition, as of December 31, 2025, we had filed 4,927 patent applications, covering certain of our proprietary technologies, and 4,626 trademark applications.
Corporate Social Responsibility
JOYY’s mission is to enrich lives through technology. We are dedicated to integrating corporate social responsibility and sustainable development into major aspects of our business operations.
53
Table of Contents
Our commitment to corporate social responsibility and sustainable development aligns with our business strategy. With our social entertainment businesses, we endeavor to build trusted and safe social platforms for users of different backgrounds, and empower users to find their own voices and show their talents and content to a global audience. With our smart commerce business, we aim to lower the barriers to entrepreneurship via our integrated smart commerce solution platform and help entrepreneurs achieve business success.
Empowering Creators and Businesses. The evolvement of our business and ecosystem has created increasing economic opportunity for individuals, businesses and communities. By providing creator-friendly video creation tools and monetization features, and cultivating a community that empowers and encourages our creators to express themselves freely, BIGO has established a creator-centric ecosystem that enables a large number of creators to showcase their talents in front of a global audience. At the same time, it enables creators to realize economic returns, creating opportunities for employment and development in local communities. Supported by our global operations team, BIGO has rolled out a variety of online activities tailored to local users’ ever-evolving needs, empowering our creators to gain exposure both locally and internationally, and enabling them to realize new levels of personal and professional success. Meanwhile, Shopline’s integrated smart commerce solutions and education campaigns have equipped small-and medium-sized businesses with the essential tools for starting and growing a business, lowering the entry barriers into different markets and unlocking economic value in the relevant regions.
Empowering Education and Entrepreneurship. We invest in developing future talent and fostering innovation. In June 2023, BIGO announced its Singapore-Jordan Incubation Program in collaboration with the Singapore Business Federation. The initiative supports Singaporean startups looking to venture into the Middle East and North Africa region through Jordan, offering six months of free co-working space, business matchmaking, networking opportunities, and assistance with employment permits and establishing a local presence in Jordan. In 2024, Clean Kinetics Pte Ltd became the first participant, marking a milestone in promoting cross-regional innovation. In 2025, Bigo Live partnered with the Yayasan Peduli Anak (Care for Children Foundation) in Indonesia to donate funds toward children’s education programs. By integrating online talent shows and cultural broadcasts with offline donations, we fostered a sense of community responsibility while providing tangible support for the academic advancement of underprivileged youth.
Community Support and Cultural Engagement. As we operate in a number of markets across the globe, our users are from different backgrounds and have distinctive needs. We strive to design our social products and cultivate local content to resonate with diverse local cultures and user interests. Our community initiatives promote inclusion and cultural engagement. In 2025, Bigo Live partnered with Union Station Homeless Services in the U.S. for the “Grateful Streams” initiative, pledging funds and utilizing creator-led content to raise awareness and provide thousands of Thanksgiving meals for unhoused individuals and families. In Southeast Asia, we participated in the “Kongsi Rezeki: Tahfiz Berselawat 2025” program in Malaysia, a cross-sector collaboration that raised funds to support vulnerable children with cancer, and low-income families during the Ramadan period.
Cultivating an Inclusive Workplace. We are committed to building a diverse and inclusive workspace for our global employees. We offer comprehensive training programs, including onboarding, leadership development, compliance and technology trends, through offline sessions and our online training system. We provide our employees with access to a variety of programs and facilities designed to promote sustainable wellness for our employees, such as gyms, health talks and fitness sessions.
Regulations in Multiple Jurisdictions Where We Operate
As our globalized operations evolve, we may, from time to time, be subject to government regulations. As the live streaming, short video, mobile advertising and smart commerce businesses are still at an early stage of development in the jurisdictions where we have presence, new laws and regulations may be adopted from time to time to require new licenses and permits in addition to those we currently have. This section sets forth the most important laws and regulations that govern our current business activities in multiple jurisdictions across the globe, including European Union, India, Singapore, Indonesia, Malaysia, Vietnam and mainland China.
54
Table of Contents
Regulations on Data Privacy and Protection
General Data Protection Regulation—European Union
The General Data Protection Regulation, or GDPR, regulates the collection and use of personal data in the EU. The GDPR covers any business, regardless of its location, that provides goods or services to residents in the EU and, thus, could incorporate our activities in EU member states. The GDPR imposes strict requirements on controllers and processors of personal data, including special protections for “sensitive information,” which includes health and genetic information of individuals in the EU. GDPR grants individuals the opportunity to object to the processing of their personal information, allows them to request deletion of personal information in certain circumstances, and provides the individual with an express right to seek legal remedies in the event the individual believes his or her rights have been violated. Further, the GDPR imposes strict rules on the transfer of personal data out of the EU to regions that have not been deemed to offer “adequate” privacy protections. Failure to comply with the requirements of the GDPR and the related national data protection laws of the EU member states, which may deviate slightly from the GDPR, may result in warning letters, reprimands, temporary or definitive restrictions including a ban on data processing, mandatory audits and financial penalties, including fines of up to 4 percent of global revenues of the preceding financial year, or €20,000,000, whichever is greater. As a result of the implementation of the GDPR, we may be required to put in place additional mechanisms ensuring compliance with the new data protection rules.
There is significant uncertainty related to the manner in which data protection authorities will seek to enforce compliance with GDPR. For example, GDPR grants Data Protection Authorities (DPAs) broad investigative and enforcement powers to conduct proactive audits as well as respond to complaints, but it is unclear how the DPAs will conduct random proactive audits of companies doing business in the EU, or act solely after complaints are filed claiming a violation of the GDPR. Also, the initiation requirements and implementation details of some procedures are left to be stipulated by the procedural laws of the EU or member states, and cannot be directly applied uniformly through the GDPR. For instance, Article 58 of the GDPR stipulates that a supervisory authority’s access to any premises of the controller and the processor, including any data processing equipment and means, is subject to EU or member state procedural law. This requires companies to separately assess risks and formulate compliance requirements based on the specific circumstances and regulations of each member country. In addition, under certain conditions, the GDPR could also be able to apply to companies that are not in Europe. Although GDPR guidance, case law, and enforcement procedures have become more developed, interpretation and enforcement may remain fact-specific, and GDPR compliance may still require substantial resources and costs.
On December 22, 2023, the regulation on harmonized rules on fair access to and use of data, officially known as the EU’s Data Act (Regulation (EU) 2023/2854), was published in the EU’s Official Journal. This regulation sets up new rules on who can access and use data generated in the EU across all economic sectors. The regulation came into effect on January 11, 2024, and most of its rules took effect from September 12, 2025. It lays down rules on business-to-business and business-to-customer data access, establishes a ban on unfair contractual terms on data sharing, and introduces restrictions to non-EU governmental access and international transfers of non-personal data, by requiring providers of data processing services to take technical, organizational and legal measures to prevent unlawful access and transfers. Since most of the Data Act’s rules became applicable, it has affected, and may continue to affect, our business, particularly where our operations involve connected devices, cloud services and data-sharing arrangements, particularly in relation to data access and use, contractual terms, cloud switching and portability, and related compliance obligations.
Finally, Regulation (EU) 2025/2518 has been published and will become applicable from April 2, 2027. It is intended to complement and clarify certain procedural aspects of GDPR enforcement, in particular by introducing harmonized rules on the handling of complaints, ex officio investigations, cooperation in cross-border cases, as well as rights related to hearings and access to documents. Once it becomes applicable, it may contribute to a better understanding of the procedural framework for GDPR enforcement.
55
Table of Contents
California Consumer Privacy Act—California, United States
In the United States, numerous federal and state laws, rules, and regulations, including data breach notification laws, and federal and state consumer protection laws and regulations (e.g., Section 5 of the FTC Act), that govern the collection, use, disclosure, protection, and other processing of personal information apply to our operations or the operations of our partners. For example, the California Consumer Privacy Act, or CCPA, which became effective in January 2020, gives California residents expanded rights to access and delete their personal information, opt out of certain personal information sharing, and receive detailed information about how their personal information is used by requiring covered companies to provide new disclosures to California consumers (as that term is broadly defined and may include any of our current or future employees who may be California residents) and provide such residents new ways to opt out of certain sales of personal information. The CCPA provides for severe civil penalties for violations as well as a private right of action for data breaches that result in the loss of personal information that is expected to increase data breach litigation. Further, in November 2020, California voters passed the California Privacy Rights Act, or CPRA, which took effect on January 1, 2023. The CPRA significantly expands the CCPA, including by introducing additional obligations on covered companies, such as data minimization and storage limitations, granting additional rights to consumers, such as correction of personal information and additional opt-out rights, and creates a new entity, the California Privacy Protection Agency, to implement and enforce the law. Other state legislatures are currently contemplating, and may pass, their own comprehensive data privacy and security laws, with potentially greater penalties and more rigorous compliance requirements relevant to our business, and many state legislatures have already adopted legislation that regulates how businesses operate online, including measures relating to privacy, data security, data breaches and the protection of sensitive and personal information. While state laws continue to change rapidly, there has also been discussion in U.S. Congress of a new comprehensive federal data protection law.
Information Technology Act 2000—India
India’s data privacy regulations are primarily governed by two sets of frameworks.
The first is a system of laws and regulations centered on the Information Technology Act 2000 (as amended by Information Technology (Amendment) Act of 2008), which governs the data privacy regulations in India. The Information Technology Act 2000 contains three provisions on data protection and privacy. Section 43A provides that we are subject to civil liability to compensate for wrongful loss or gain to any person arising from negligence in implementing and maintaining reasonable security practices and procedures with respect to sensitive personal data or information that we possess, deal with or handle in our computer systems, networks, databases and software. It should be noted that Section 44(2) of the Digital Personal Data Protection Act, 2023, which will take effect 18 months after November 13, 2025, stipulates the deletion of Section 43A of the Information Technology Act, 2000. Section 72A provides for imprisonment for a term which may extend to three years or fines which may extend to five lakh rupees, or both, if, in the course of performing a contract, a service provider discloses personal information without the consent of the person concerned or in breach of a lawful contract and he or she does so with the intention to cause, or knowing he or she is likely to cause, wrongful loss or wrongful gain. Section 72 prescribes imprisonment for a term which may extend to two years or fines which may extend to one lakh rupees, or both, if a government official discloses records and information accessed by him or her in the course of his or her duties without the consent of the concerned person or unless permitted by other laws. Section 79 provides safe harbor protection to internet service providers from being held liable for third-party information or data made available by such internet service providers that they have no knowledge of or that they had exercised all due diligence to prevent.
The other framework comprises personal data protection regulations centered on the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Even prior to the introduction of these two frameworks, India had already issued privacy laws, including: (i) the Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009, which imposes obligations on intermediaries, including compliance with emergency blocking directions, appointing a designated officer for handling such directives, and facing penalties for non-compliance, (ii) the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which impose limitations and restrictions on the collection, use and disclosure of personal information, and (iii) the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which provides for checks and balances on social media companies by setting timelines for removal of unlawful content.
56
Table of Contents
Starting from November 13, 2025, the Digital Personal Data Protection Act, 2023, which is the core law for personal information protection, has been coming into effect in a phased manner. Also, the Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025 and have been coming into force in phases since that date, which primarily serve as the operational and implementing rules for the Digital Personal Data Protection Act, 2023. Based on these two legal instruments, a person may process the personal data of a Data Principal only in accordance with the provisions of the Digital Personal Data Protection Act and for a lawful purpose (a) for which the Data Principal has given her consent. The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose, or (b) for certain legitimate uses.
Also, the Digital Personal Data Protection Act, 2023 provides that, irrespective of any agreement to the contrary or any failure of the Data Principal to perform her duties under this Act, the person who alone or in conjunction with other persons determines the purpose and means of processing of personal data (“Data Fiduciary”) shall be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor. A Data Fiduciary may engage, appoint, use, or otherwise involve a Data Processor to process personal data on its behalf, in connection with the offering of goods or services to Data Principals, only under a valid contract. Where personal data processed by a Data Fiduciary is likely to be used to make a decision affecting the Data Principal or to be disclosed to another Data Fiduciary, the Data Fiduciary shall ensure the completeness, accuracy, and consistency of such data. In addition, the Data Fiduciary shall implement appropriate technical and organizational measures to protect personal data in its possession or under its control, including data processed on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breaches. In the event of a personal data breach, the Data Fiduciary shall notify the regulatory authority and the affected Data Principals in the manner prescribed. If the foregoing provisions are violated, the Data Fiduciary may be subject to penalties imposed by the Indian regulatory authority.
Personal Data Protection Act 2012—Singapore
An organization collecting, using or disclosing personal data is subject to the Personal Data Protection Act 2012 of Singapore, as amended from time to time. Any information, whether true or not, that may be used to identify a natural person either directly from the data, or from the data and other information that the organization has access to, is considered “personal data.” Examples may include an individual’s name, date of birth, identity card number, passport number, residential address, characteristics and fingerprints, among others. The personal data that is protected under the Personal Data Protection Act 2012 of Singapore excludes personal data that is publicly available and personal data that is disclosed under any written law. The Personal Data Protection Act 2012 of Singapore also does not apply to business contact information, such as an individual’s name, title, business address, business telephone number, business e-mail address, or other similar information about an individual that is not provided solely for his/her personal purposes.
When an organization processes personal data, it must procure the individual’s consent for the collection, use and/or disclosure of his/her personal data. Therefore, the individual should be notified of the purposes for which his personal data is collected, used or disclosed. Consent can also be deemed to be given by individuals in some cases. The scenarios where implied consent can be deemed to be obtained have recently been expanded to include situations such as (i) where the consent is reasonably necessary for concluding the contract between the individual and the organization, and (ii) where the organization conducts an assessment to determine that the collection, use or disclosure of the personal data is not likely to have an adverse effect on the individual, reasonable steps are taken to bring the prescribed information (including the organization’s intention to process and purpose for processing personal data) to the attention of the individual, and where the individual does not notify the organization that he/she does not consent to the proposed processing of the personal data. There are also certain exceptions to the consent requirement, which include the collection, use and disclosure of personal data for vital interests of individuals, matters affecting the public, legitimate interests of the organization, business asset transactions, business improvement and research. Recently, the Personal Data Protection Commission of Singapore has released guidelines which state that organizations intending to process personal data for the purpose of developing or implementing AI models into their workflow can consider relying on the legitimate interest, business improvement and research exceptions to consent, where relevant. The Commission also emphasized the need for organizations using AI systems to remain accountable and transparent with their data subjects, whether through the use of written policies or otherwise.
Under the Personal Data Protection Act 2012 of Singapore, individuals have clearly defined rights, such as the right to access their personal data, request information on how their personal data has been used, and correct any inaccuracies in the personal data held by the organization. The organization should designate a Data Protection Officer for this purpose. The organization must take reasonable steps to ensure the accuracy of the personal data recorded and put security arrangements in place to protect the personal data.
57
Table of Contents
Furthermore, when transferring personal data outside of Singapore, care must be taken to ensure that the recipient organization is bound by legally enforceable obligations or specified certifications to afford the personal data with a standard of protection that is comparable to that established by the Personal Data Protection Act 2012 of Singapore. Legally enforceable obligations may be imposed via the applicable law, a contract, binding corporate rules or any other legally binding instrument. On March 2, 2026, the Personal Data Protection (Amendment) Regulations 2026 entered into force, which expands the scope of recognized certifications that satisfy the requirement for legally enforceable obligations when transferring personal data outside Singapore. The 2026 amendment adds the Global Privacy Recognition for Processors System and the Global Cross-Border Privacy Rules System to the list of recognized certifications. Specifically, for recipients acting as data intermediaries, the list now includes the Asia-Pacific Economic Cooperation (APEC) Privacy Recognition for Processors System, the APEC Cross-Border Privacy Rules System, the Global Privacy Recognition for Processors System, and the Global Cross-Border Privacy Rules System. For other recipients, the recognized certifications are the APEC Cross-Border Privacy Rules System, with the new addition of the Global Cross-Border Privacy Rules System. The aim of this modification is to facilitate secure international data flows by aligning local requirements with global privacy frameworks.
Where a data breach involving the disclosure of personal data has occurred, the organization is required to take reasonable and expeditious steps to assess the data breach. In some cases, the organization may be required to report the data breach to the Personal Data Protection Commission, and the affected individuals. Where the organization is acting as a data intermediary that is processing the personal data for another organization, the data intermediary is required to notify the organization of any data breaches in a timely manner.
Individuals who knowingly or recklessly cause the unauthorized disclosure of personal data or improper use of personal data in the control of an organization may be liable on conviction to a fine not exceeding $5,000 or imprisonment not exceeding two years or both. Further, the maximum financial penalty that may be imposed on an organization for contravention of the Personal Data Protection Act’s provisions has recently been increased to be up to 10% of an organization’s annual turnover in Singapore (where it exceeds S$10 million), or S$1 million, whichever is higher.
Personal Data Protection—Indonesia
On October 17, 2022, Law No. 27 of 2022 on Personal Data Protection, or the PDP Law, was enacted and came into effect, providing a new framework for personal data protection in Indonesia. To the extent provisions in existing and separate regulations relating to privacy and/or personal data protection in Indonesia such as The Minister of Communication and Information Regulation No. 20 of 2016 on Personal Data Protection in Electronic Systems and Government Regulation No. 71 of 2019 on the Provision of Electronic System and Transactions, or collectively the General Data Protection Regulations, do not conflict with the PDP Law, the non-conflicting provisions in these General Data Protection Regulations remain valid. These General Data Protection Regulations set out the rules governing the protection of personal data that are stored in electronic form while PDP Law governs protection of personal data that are stored both in electronic and non-electronic forms. The PDP Law introduces the definitions of “Personal Data Controllers” and “Personal Data Processors,” which were previously limited to “electronic system provider” under the General Data Protection Regulations. The Personal Data Controllers, either individually or jointly with other parties, determine the purpose and control the processing of personal data, while the Personal Data Processors, either individually or jointly with other parties, act on behalf of the Personal Data Controllers to process personal data as stipulated in Article 1 points 4 and 5 of the PDP Law. The PDP Law requires any action taken in relation to the processing of personal data by either Personal Data Controllers and Personal Data Processors, including acquisition and collection, processing and analysis, storage, correction and updates, display, announcement, transfer, dissemination, disclosure, and deletion or destruction, to be subject to provisions of the PDP Law, such as requiring prior consent of the owner of such personal data. Further, under the PDP Law, the Personal Data Controllers and Personal Data Processors are imposed with a comprehensive set of obligations, including: (i) adoption of internal data protection and security policies, (ii) performing an impact assessment for any high-risk personal data processing, (iii) providing access to the personal data that is processed along with the track record of the processing in accordance with the storage period, (iv) appointment of a data protection officer by Personal Data Controllers or Personal Data Processors to carry out personal data protection functions, and (v) for overseas transfer of personal data, ensuring the recipient country has an equal or higher personal data protection governance than the PDP Law, or otherwise, ensuring that there is adequate and binding protection, or if the foregoing is not available, consent from the personal data subjects. The condition above is aligned with Article 24 of the PDP Law, which stipulates that, in the case of processing personal data as mentioned above, the Personal Data Controller is obliged to provide evidence of the consent that has been given by the Personal Data Subject.
58
Table of Contents
The General Data Protection Regulations clarify the data localization requirement by specifying that such requirement applies only to “public electronic systems providers” (i.e., central and regional executive, legislative, judicative bodies and any other bodies established pursuant to a statutory mandate, and entities appointed by the public bodies to operate electronic systems on their behalf). Meanwhile, a private provider can choose whether to process and/or host its electronic systems and data onshore or offshore. Regardless of the location, such provider must ensure that its electronic systems and data are accessible to the authority. However, this flexibility does not apply to private operators in the banking and financial services sectors.
In the event of a data breach, the PDP Law requires the Personal Data Controllers to deliver written notification no later than 72 hours to the personal data subjects and to the personal data protection authority. If the Personal Data Controllers or the Personal Data Processors fail to comply with the PDP Law, they may be subject to sanctions in the form of warnings or written reprimands, temporary suspensions of personal data processing activities, forced deletion or destruction of personal data, and administrative fines of up to 2% of annual revenue or income of the Personal Data Controller or the Personal Data Processor may be imposed. If corporations fail to comply with PDP Law, they may be subject to criminal fines as well as license revocation and liquidation.
As of the date of this annual report, Indonesia has further announced several industry-specific rules to supplement the provisions of the PDP Law and implement personal data protection. Government Regulation No. 17 of 2025 on the governance of electronic system operators in child protection introduced child-focused risk assessment requirements for electronic products, services and features, including risks related to child data collection, public disclosure of children’s personal data, privacy-setting changes without parental consent, and threats to the security of children’s personal data. Minister of Communication and Digital Regulation No. 9 of 2026 further implemented these requirements by establishing self-assessment, reporting, verification and risk-profiling procedures for products, services and features that may be accessed by children. In the telecommunications sector, Minister of Communication and Digital Regulation No. 7 of 2026 on mobile subscriber registration introduced additional safeguards relating to customer identity data, biometric verification, confidentiality obligations and information security certification.
Personal Data Protection—Vietnam
Until April 17, 2023, Vietnam did not have a single comprehensive data protection legal document. Instead, data protection provisions were prescribed across various laws and their corresponding guiding Decrees and Circulars, such as the Constitution, the Civil Code, the Law on Protection of Consumers’ Rights, the Law on Information Technology, etc., which regulate on different aspects of the data protection matter. In particular, the Constitution and the Civil Code provides basic principles on the right to privacy of individuals, while the Law on Protection of Consumers’ Rights and Decree 52/2013/ND-CP, amended by Decree 85/2021/ND-CP, on E-commerce regulate on the consumer protection aspect, the Law on Information Technology stipulates requirements for collecting, processing and using personal information on the Internet, etc. The laws in Vietnam are all adopted by the National Assembly of Vietnam, while the Decrees and Circulars are issued by lower-level authority, which are respectively the Government and relevant Ministries.
On November 19, 2015, the Vietnam National Assembly passed the Law on Cyber Information Security, which sets forth regulations on cyber information security. Accordingly, individuals and companies must implement measures to assure the security of cyber information. For example, entities providing information technology services must comply with regulations on the storage and use of personal information, apply blocking and handling measures upon receipt of a notice that sending such information is illegal, and implement measures to allow recipients to refuse the receipt of information. Moreover, the owners of the personal information (i.e., the data subjects) are also provided the right to request for updating, alteration and cancellation of the personal information by the data processor. On the other hand, the Law on Cyber Information Security and its guiding document also provided certain requirements regarding notification of a data breach and other cyber information security incidents. This law, officially designated as Law No. 86/2015/QH13 on Network Information Security, was later amended by Law No. 35/2018/QH14 dated November 20, 2018, which introduced changes to certain provisions concerning the planning of 37 laws (“Network Information Security Law”).
59
Table of Contents
On June 12, 2018, the Vietnam National Assembly passed the Law on Cybersecurity which regulates that any foreign service provider in certain fields such as e-payment, e-commerce, online games is required to have a commercial presence in Vietnam (such as branch, representative office) and to localize the user’s data in Vietnam. Then, the government issued Decree No. 53/2022/ND-CP on August 15, 2022 to provide further details on a number of articles of the Law on Cybersecurity. Accordingly, it clarifies that foreign cyberspaces service providers engaged in (a) telecommunications services; (b) storing and sharing data in cyberspace; (c) providing national or international domain names to service users in Vietnam; (d) e-commerce; (e) online payment; (f) payment intermediary services; (g) transport connection services through cyberspace; (h) social networks and social media; (i) online video games; and (j) services that provide, manage, or operate other information on cyberspace in the form of messages, voice calls, video calls, e-mails, online chats must store such data in Vietnam for at least 24 months and set up a branch or representative office in Vietnam if requested in writing by Minister of the Ministry of Public Security.
On April 17, 2023, the Vietnam Government issued Decree 13/2023/ND-CP on Personal Data Protection, or the Decree 13 —the first comprehensive legal document on personal data protection in Vietnam, which came into effect on July 1, 2023. Unlike other decrees which are to clarify and provide further guidelines on provisions of the relevant law, the Decree 13 provides new and independent requirements on personal data protection, in harmony with similar provisions under the current legal framework. In particular, the Decree 13 provides a unified definition of personal data, which is defined as “information in the form of symbols, letters, numbers, images, sounds or similar on an electronic environment that is associated with a particular person or helps to identify a particular person. Personal data include basic personal data and sensitive personal data.” “Information that helps to identify a specific person” is further clarified as “information formed from the activities of an individual that, when combined with other data and stored information, can identify a specific person.” Apart from unifying previous concepts regulated in various legal documents, the Decree 13 has also adopted certain contents from the well-known General Data Protection Regulations from the EU, which provided new concepts and stricter requirements not yet been regulated in previous legal documents on personal data protection such as: basic personal data, sensitive personal data, data controller, data protection impact assessment, processing personal data obtained through public recordings and filming, processing personal data in advertising and so on. On the other hand, the Decree 13 also requires entities (both foreign and Vietnam-based) relating to personal data processing activities to notify the Department of Cyber Security and Hi-tech Crime Prevention under the Ministry of Public Security upon (i) occurrence of a violation of personal data protection (i.e., a data breach); and (ii) conducting a cross-border personal data transfer. Furthermore, data subject rights and obligations, specific responsibilities of data controllers, data processors and third parties are also specified under this document.
On November 9, 2024, Vietnam’s government introduced Decree No. 147/2024/ND-CP (hereinafter, the “new decree”), a landmark regulation governing the management, provision, and use of internet services and online information. Replacing the decade-old Decree No. 72/2013/ND-CP and its subsequent amendments, this new decree took effect on December 25, 2024, signaling a significant shift in Vietnam’s approach to regulating its rapidly evolving digital landscape. This decree covers an extensive range of topics. These include the management of internet services, domain names, cross-border information provision, social networks, online games, app stores, and telecom application services. It also introduces stringent measures to control illegal content and sets out detailed responsibilities for various stakeholders, including telecom operators, internet providers, data centers, and web hosting services.
On November 30, 2024, the Data Law was passed by the National Assembly, and it came into effect on July 1, 2025. Officially designated as Law No. 60/2024/QH15 on Data, this law will help gradually establish a data market and promote the country’s digital transformation. It has 5 chapters and 46 articles, which clearly stipulate digital data; construction, development, protection, management, processing, and use of digital content; national data center; national aggregate database; digital data products and services; digital data management; and the rights, obligations, and responsibilities of digital data agencies, organizations, and individuals.
On December 10, 2025, Vietnam passed the new Cybersecurity Law (116/2025/QH15). This law will come into effect on July 1, 2026, and the original Law on Cybersecurity (24/2018/QH14) will become invalid from that date. Regarding data security, Law No. 116/2025/QH15 prohibits the appropriation, trading, seizure, or intentional disclosure of information containing state secrets, work secrets, or trade secrets; the appropriation, trading, seizure, or intentional disclosure of personal secrets, family secrets, and privacy that affect the honor, reputation, dignity, rights, and legitimate interests of authorities, organizations, or individuals; the intentional eavesdropping or unlawful recording of audio or video of conversations in cyberspace; the disclosure of information on civil cryptographic products or information on customers lawfully using civil cryptographic products; and the use or trading of civil cryptographic products of unknown origin. Moreover, Article 25 of Law No. 116/2025/QH15 stipulates the obligations of platforms and network service providers regarding account and data control, including verifying the registration information of digital accounts, protecting user information and accounts; providing information to competent authorities upon request; removing illegal content; maintaining system logs; and storing users’ names, usage time, payment information, access IP addresses, and other personal information and data generated during service use.
60
Table of Contents
On January 1, 2026, Vietnam’s new Personal Information Law (No. 91/2025/QH15) came into force. This law provides that personal data is digital data or information in other forms that identify or help identify a specific person, including basic personal data and sensitive personal data. Personal data that has been de-identified is no longer considered personal data. Second, Article 20 of the law stipulates that cross-border personal data transfer includes transferring data stored within Vietnam to foreign countries, transferring data by Vietnamese entities to foreign entities, and using foreign platforms to process data collected in Vietnam. Entities conducting cross-border transfers are generally required to submit a cross-border impact assessment dossier within 60 days from the date of the first transfer and update it as required. The competent authority may also require the suspension of data transfers if such transfers are found to affect national security. Finally, Article 37 of the law provides that a personal data processor shall first enter into a personal data processing agreement with the personal data controller or a controller-cum-processor before receiving personal data. The processor shall handle the data in accordance with the agreement, adopt protective measures, bear liability for damages caused by processing, and prevent unauthorized collection of personal data from its systems and equipment.
Decree No. 356/2025/NĐ-CP also came into force on January 1, 2026. It is the implementing regulation of the Personal Information Law (No. 91/2025/QH15) and operationalizes the principles set out in the law, focusing on personal data classification, consent mechanisms, personal data transfer agreements, cross-border transfer impact assessment, and timelines for handling data subject requests.
Personal Data Protection—Malaysia
The Personal Data Protection Act 2010 (“PDPA 2010”) regulates the processing of personal data in commercial transactions. The PDPA 2010 applies insofar as the personal data of a customer is processed (for example, name, identification card number, address, phone number, e-mail address). The definition of “personal data” under the PDPA 2010 includes any information in respect of commercial transactions, which relates directly or indirectly to a data subject, who is identified or identifiable from that information or from that and other information in the possession of a data controller, including any sensitive personal data (which includes biometric data) and expression of opinion about the data subject. The PDPA 2010 sets out seven (7) personal data protection principles to be complied with, namely General Principle, Notice and Choice Principle, Disclosure Principle, Security Principle, Retention Principle, Data Integrity Principle, and Access Principle. Additionally, the Personal Data Protection Regulations 2013 and the Personal Data Protection Standard 2015 set out in detail the requirements to be complied with in respect of the seven (7) principles. Personal data can now be transferred to places outside Malaysia provided that place has adequate data protection laws, which are at least equivalent to the level of protection afforded by the PDPA 2010. In 2025, the Personal Data Protection (Amendment) Act 2024 came into effect in phases, focusing on establishing the appointment of a data protection officer and the data breach notification system. Specifically, the amendment stipulated a data controller shall appoint one or more data protection officers who shall be accountable to the data controller for the compliance with this Act. Where a data controller has reason to believe that a personal data breach has occurred, the data controller shall, as soon as practicable, notify the Commissioner (as defined in the amendment) in the manner and form as determined by the Commissioner. Where the personal data breach under the aforementioned causes or likely to cause any significant harm to the data subject, the data controller shall notify the personal data breach to the data subject in the manner and form as determined by the without unnecessary delay. A data controller who contravenes the preceding provisions commits an offence and shall, on conviction, be liable to a fine not exceeding two hundred and fifty thousand ringgit or imprisonment for a term not exceeding two years or to both.
The General Code of Practice of Personal Data Protection sets out the best practices for data controllers in meeting the PDPA 2010 requirements when undertaking commercial transactions, by further elaborating the seven (7) principles enumerated in the PDPA 2010. In particular, the General Code of Practice of Personal Data Protection clarifies the manner in which consent obtained from data subjects can be recorded and maintained. Such consent can be obtained in various forms, including through a clickable box, by conduct or performance, or verbally. The relevant data controllers are required to develop and implement appropriate compliance policies and procedures to ensure compliance with the General Code of Practice of Personal Data Protection and the PDPA 2010. In 2025, the Personal Data Protection Department also issued the Personal Data Protection Guidelines on Data Breach Notification, the Personal Data Protection Guidelines on the Appointment of Data Protection Officer, and the Personal Data Protection Guidelines on Cross-Border Transfer of Personal Data, which provide clearer guidance for data compliance.
61
Table of Contents
The Personal Data Protection Code of Practice for Licensees under the Communications and Multimedia Act 1998 outlines guidelines for the communications sector in Malaysia to comply with the PDPA 2010. In addition to the seven (7) principles enumerated in the PDPA 2010, the Personal Data Protection Code of Practice for Licensees under the Communications and Multimedia Act 1998 covers best practices for data management in the communications sector, including the use of clear and concise privacy notices, the implementation of access controls and data retention policies, and the use of encryption and other security measures to protect personal data (as well as pre-existing data collected and processed prior to the effectiveness of the PDPA 2010). In addition, the Personal Data Protection Code of Practice for Licensees under the Communications and Multimedia Act 1998 outlines the requirements for cross-border data transfers, which involve the transfer of personal data outside of Malaysia, which include obtaining consent from data subjects, ensuring that the receiving country provides an adequate level of protection for personal data and implementing appropriate contractual and technical safeguards to protect personal data during the transfer process.
The General Consumer Code of Practice for the Communications and Multimedia Industry Malaysia sets out the obligations in relation to the protection of personal information and sets out the rules in respect of the protection of consumer (including consumer with special needs or disabilities) information policy and principles on notice, disclosure, consent, choice, data security, data quality and access. Accordingly, a service provider may collect and maintain necessary data/information of consumers for tracking practices, provided that the collection and maintenance of such data/information shall be fairly and lawfully collected and processed, processed for limited purposes, adequate, relevant and not excessive, accurate, not kept longer than necessary, processed in accordance with the data subject’s rights, secure and not transferred to any party without the consumer’s prior approval. Consumers must also be given the opportunity to exercise their choice in respect of how individually identifiable information collected from them may be used.
Personal Data Protection—Saudi Arabia
The Saudi Arabia Personal Data Protection Law, as amended, has been implemented by Royal Decree No. M/19 of 9/2/1443H (September 16, 2021) and amended by Royal Decree No. M/147 of 5/9/1444H (March 21, 2023), and came into effect on September 14, 2023. The Saudi Arabia Personal Data Protection Law is the main law in Kingdom of Saudi Arabia regulating the use of personal data. The personal data defined in the Saudi Arabia Personal Data Protection Law includes any data, regardless of its source or form, that may lead to identifying an individual specifically, or that may directly or indirectly make it possible to identify an individual, including name, personal identification number, addresses, contact numbers, license numbers, records, personal assets, bank and credit card numbers, photos and videos of an individual, and any other data of personal nature. The Saudi Arabia Personal Data Protection Law also provides for a separate concept of sensitive data. It includes personal data revealing racial or ethnic origin, or religious, intellectual or political belief, security data, data relating to criminal offenses, biometric or genetic data, health data, and data that indicates that one or both of the individual’s parents are unknown.
The Saudi Arabia Personal Data Protection Law applies to the processing of personal data that takes place in the territory of the Kingdom, and also applies extra-territorially to non-Saudi entities that process the personal data of individuals residing in Saudi Arabia. The provisions, requirements, and conditions set forth in the Saudi Arabia Personal Data Protection Law do not apply to the processing of personal data by an individual for personal or family use, as long as the personal data is not published or disclosed to others.
In 2025, Saudi Arabia issued the General Rules for Secondary Use of Data and launched the SDAIA Sandbox Program for personal data protection, which support the existing Saudi Arabia Personal Data Protection Law framework. The General Rules for Secondary Use of Data establish controls and procedures governing data-sharing requests, including the requirement of a legitimate purpose, compliance with the data minimization principle, consent in specified cases, data retention and destruction arrangements, restrictions on permitted use, liability allocation, and applicable processing timeframes. The SDAIA Sandbox Program is a regulatory support program that allows startups to test and develop privacy-related technological solutions in a controlled environment, with a focus on Privacy by Design and Privacy-Enhancing Technologies, and it is intended to ensure compliance with the Saudi Arabia Personal Data Protection Law.
62
Table of Contents
Data and Privacy Protection—mainland China
The Cyber Security Law (Amended in 2025) imposes certain data protection obligations on network operators, including that network operators may not disclose, tamper with, or damage users’ personal information that they have collected, or provide users’ personal information to others without consent. Pursuant to the Decision on Strengthening the Protection of Online Information and the Order for the Protection of Telecommunication and Internet User Personal Information, any collection and use of user personal information must be subject to the consent of the user, abide by the principles of legality, rationality and necessity and be within the specified purposes, methods and scopes. An Internet information service provider must also keep such information strictly confidential, and is further prohibited from divulging, tampering or destroying any such information, or selling or providing such information to other parties. An Internet information service provider is required to take technical and other measures to prevent the collected personal information from any unauthorized disclosure, damage or loss. Any violation of these laws and regulations may subject the Internet information service provider to warnings, fines, confiscation of illegal gains, revocation of licenses, cancellation of filings, closedown of websites or even criminal liabilities.
According to the Personal Information Protection Law, where personal information is processed based on an individual’s consent, such consent shall be voluntarily and explicitly given by the individual on a fully informed basis, and the individual shall have the right to withdraw his or her consent without affecting the effectiveness of personal information processing activities that have been conducted based on his or her consent before. Furthermore, the Personal Information Protection Law clarifies that personal information of minors under the age of fourteen is sensitive information, and such sensitive information may not be processed unless there are specific purposes and sufficient necessity and strict protection measures are taken.
According to the Administrative Measures for the Compliance Audit of Personal Information Protection, the personal information processor shall carry out regular compliance audits of personal information protection by itself or entrust a specialized agency to do so. Any personal information processor handling over 10 million people’s personal information shall carry out the compliance audits at least once every two years.
Regulations on Intellectual Property
Regulations on Intellectual Property—European Union
Trademark
According to Article 4 of Regulation (EU) 2017/1001, an EU trade mark may consist of any signs, in particular words, including personal names, or designs, letters, numerals, colours, the shape of goods or of the packaging of goods, or sounds, provided that such signs are capable of: (a) distinguishing the goods or services of one undertaking from those of other undertakings; and (b) being represented on the Register of European Union trade marks (‘the Register’), in a manner which enables the competent authorities and the public to determine the clear and precise subject matter of the protection afforded to its proprietor. The registration of an EU trade mark will confer on the proprietor exclusive rights therein. Moreover, trademark holders may prohibit third parties from using the same or similar marks in commercial activities, and may also prohibit the affixing of the mark to goods or packaging, its sale, import, export, use as a trade name, or use in commercial documents and advertisements. If trademark rights are infringed, the infringer may face corrective measures such as temporary injunctions, orders to prohibit further infringement, recalls of infringing goods, removal from commercial channels, destruction, and compensation for losses.
European Patent
The definition of a patent at the EU level can be found in Article 52 of the Convention on the Grant of European Patents (European Patent Convention), which states: European patents shall be granted for any inventions, in all fields of technology, provided that they are new, involve an inventive step and are susceptible of industrial application. However, the following in particular shall not be regarded as inventions within the aforementioned meaning: (a) discoveries, scientific theories and mathematical methods; (b) aesthetic creations; (c) schemes, rules and methods for performing mental acts, playing games or doing business, and programs for computers; and (d) presentations of information.
63
Table of Contents
The extent of the protection conferred by a European patent or a European patent application shall be determined by the claims, and a European patent shall confer on its proprietor from the date on which the mention of its grant is published in the European Patent Bulletin, in each Contracting State in respect of which it is granted, the same rights as would be conferred by a national patent granted in that State. Furthermore, the term of the European patent shall be 20 years from the date of filing of the application.
Exterior Design
The definition of “design” under EU law is found in Article 3, paragraph 1 of Regulation (EC) No 6/2002:“design” means the appearance of the whole or a part of a product resulting from the features, in particular the lines, contours, colours, shape, texture and/or materials, of the product itself and/or of its decoration, including the movement, transition or any other sort of animation of those features. A design shall be protected by an EU design, if it is new and has individual character.
A registered EU design shall confer on its holder the exclusive right to use it and to prevent any third party not having the consent of the holder from using it. In particular, these behaviors are prohibited: (a) making, offering, placing on the market or using a product in which the design is incorporated or to which the design is applied; (b) importing or exporting a product referred to in point (a); (c) stocking a product referred to in point (a) for the purposes referred to in points (a) and (b); or (d) creating, downloading, copying and sharing or distributing to others any medium or software which records the design for the purpose of enabling a product referred to in point (a) to be made.
Where an EU design court finds that the defendant has infringed or threatened to infringe an EU design, it shall, unless there are special reasons for not doing so, issue an order prohibiting the defendant from proceeding with the acts which infringed or would infringe the EU design. It shall also take such measures in accordance with its national law as are aimed at ensuring that that prohibition is complied with. Moreover, the EU design court may also apply measures or orders available under the applicable law which it deems appropriate in the circumstances of the case.
Trade Secret
Article 2 of Directive (EU) 2016/943 stipulates that ‘trade secret’ means information which meets all of the following requirements: (a) it is secret in the sense that it is not, as a body or in the precise configuration and assembly of its components, generally known among or readily accessible to persons within the circles that normally deal with the kind of information in question; (b) it has commercial value because it is secret; and (c) it has been subject to reasonable steps under the circumstances, by the person lawfully in control of the information, to keep it secret.
The acquisition of a trade secret without the consent of the trade secret holder shall be considered unlawful, whenever carried out by: (a) unauthorized access to, appropriation of, or copying of any documents, objects, materials, substances or electronic files, lawfully under the control of the trade secret holder, containing the trade secret or from which the trade secret can be deduced; or (b) any other conduct which, under the circumstances, is considered contrary to honest commercial practices. Also, the use or disclosure of a trade secret shall be considered unlawful whenever carried out, without the consent of the trade secret holder, by a person who is found to meet any of the following conditions: (a) having acquired the trade secret unlawfully; (b) being in breach of a confidentiality agreement or any other duty not to disclose the trade secret; or (c) being in breach of a contractual or any other duty to limit the use of the trade secret.
If the conduct constitutes the aforementioned infringement of trade secrets, it may be subject to various injunctions and corrective measures, including: (a) the cessation of or, as the case may be, the prohibition of the use or disclosure of the trade secret; (b) the prohibition of the production, offering, placing on the market or use of infringing goods, or the importation, export or storage of infringing goods for those purposes; (c) the destruction of all or part of any document, object, material, substance or electronic file containing or embodying the trade secret or, where appropriate, the delivery up to the applicant of all or part of those documents, objects, materials, substances or electronic files; (d) recall of the infringing goods from the market; (e) depriving the infringing goods of their infringing quality; and (f) destruction of the infringing goods or, where appropriate, their withdrawal from the market, provided that the withdrawal does not undermine the protection of the trade secret in question.
64
Table of Contents
Regulations on Intellectual Property—India
Copyrights
Copyright law in India is governed by the Copyright Act, 1957, which has been amended six times, with the last amendment in 2012. It is a comprehensive set of statutes providing for legal protection to copyright, moral rights and neighboring rights. Under the fair use provisions of the Act, section 52(1)(b) provides that transient or incidental storage of a work or performance purely in the technical process of electronic transmission or communication to the public does not constitute infringement of copyright. This provision provides safe harbor to internet service providers that may have incidentally stored infringing copies of a work for the purpose of transmission of data.
The Copyright Rules, 2013, enacted under Section 78 of the Copyright Act, 1957, and came into force on March 14, 2013. However, the Copyright Rules, 2013 mainly serve as the implementing rules of the Copyright Act 1957, detailing the procedural aspects of copyright registration, management and enforcement, but do not have substantive provisions on copyright infringement, electronic transmission and temporary storage.
Patents
Based on the Patents Act, 1970, “invention” is defined as a new product or process involving an inventive step and capable of industrial application and “patent” refers to a patent for any invention granted under this act. Subject to the provisions of the Patents Act, 1970, the term of every patent granted, after the commencement of the Patents (Amendment) Act, 2002, and the term of every patent which has not expired and has not ceased to have effect, on the date of such commencement, under this act, shall be twenty years from the date of filing of the application for the patent. Also, pursuant to Article 48 of Patents Act, 1970, where the subject matter of the patent is a product, the exclusive right to prevent third parties, who do not have his consent, from the act of making, using, offering for sale, selling or importing for those purposes that product in India. Also, where the subject matter of the patent is a process, the exclusive right to prevent third parties, who do not have his consent, from the act of using that process, and from the act of using, offering for sale, selling or importing for those purposes the product obtained directly by that process in India.
Trademark
Trademark means a mark capable of being represented graphically and which is capable of distinguishing the goods or services of one person from those of others and may include shape of goods, their packaging and combination of colors. The registration of a trade mark shall, if valid, give to the registered proprietor of the trade mark the exclusive right to the use of the trade mark in relation to the goods or services in respect of which the trade mark is registered and to obtain relief in respect of infringement of the trade mark in the manner provided by the Trade Marks Act 1999. Sections 103 and 104 of the Trade Marks Act, 1999 establish criminal liability for misuse of trademarks and false trade descriptions. Section 103 punishes acts such as falsifying a trademark, applying a false trademark to goods or services, possessing tools for falsification, applying false trade descriptions, and altering or removing required origin information, unless the person can prove a lack of intent to defraud. Section 104 extends liability to those who sell, offer, or possess goods or provide services bearing false trademarks or descriptions, or lacking required origin information, unless they can show they acted with reasonable precautions, had no suspicion, or acted innocently. In both sections, the prescribed punishment includes imprisonment of at least 6 months and up to 3 years, along with a fine ranging from 50,000 to 200,000 rupees, with limited judicial discretion to reduce the minimum sentence for special reasons.
Regulations on Intellectual Property—Singapore
Patents
Singapore provides a comprehensive legal framework and supporting infrastructure for protecting patents, copyrights, trademarks and industrial designs.
Singapore protects inventive designs and processes through the Patents Act 1994 (as amended from time to time), which is based on the United Kingdom’s Patents Act of 1977. Singapore patents are protected internationally under the Patent Cooperation Treaty (PCT). A registered patent in Singapore will be protected for 20 years, so long as the owner pays the annual renewal fees. Once registered, the owner can use, sell or license the patent. The criteria Singapore uses in granting a patent is that the invention: (i) is new (i.e., should not be publicly know anywhere in the world), (ii) it must be an improvement that would not be obvious to someone with technical skill or knowledge in that field and (iii) should have practical application, which is generally in line with the criterion in the United Kingdom and the United States.
65
Table of Contents
If a product or process is found to infringe a registered patent, the court can order damages and an injunction on the use of the infringing product or process.
Copyrights
Singapore’s Copyright Act 2021, as amended from time to time, protects original works such as novels, computer programs, videos and performances, but does not include ideas, procedures, methods or discoveries because these are considered expressions of the underlying idea or discovery. There is no registration process for copyrighting in Singapore, and the copyright begins when the work is created. The author must take steps to show that he or she created the copyrighted work first in order to establish ownership. The author, or owner, of copyrighted material has the exclusive right to publish, perform, broadcast or adapt the work, and can assign or license all or part of the rights to others. An assignment of copyright needs to be in writing; a license can be exclusive or non-exclusive, and an exclusive license needs to be in writing. The protection Singapore affords through copyright laws and the period of protection will vary depending on the relevant type of work.
Copyright infringement may be classified as: (i) primary infringement, covering direct unauthorized usage of the copyrighted work; and (ii) secondary infringement, such as import, sale or trading of items which the infringer knows or should have known was made without the copyright owner’s consent, false attribution of the authorship of a copyrighted work and false removal or alteration of rights management information electronically attached to a copyrighted work.
Copyright infringement is subject to the general exception of “fair use.” When determining whether a work has been fairly used, a variety of factors like the purpose and character of use, the nature of the work being used, the amount and substantiality of the portion of the work being used, and the effect of the use upon the potential market for, or value of, the work must be considered.
Further, the new exception for “computational data analysis” continues to remain relevant. This exception allows a person to use or make a copy of a copyrighted work or recording of a protected performance for purposes such as (i) using a computer program to identify, extract and analyze information or data from the work or recording; and (ii) using the work or recording as an example of a type of information or data to improve the functioning of a computer program in relation to that type of information or data. In practice, this exception may apply where a company is carrying out text and data mining or training an AI system. Nonetheless, the exception is subject to the user having lawful access to the works being copied. The exact scope of what “lawful access” may mean is undefined and remains to be seen.
A copyright owner can look to civil remedies for infringement including damages, an injunction and destruction of the infringing work, or “statutory damages” of not more than S$10,000 per work and S$200,000 in the aggregate.
Trademarks
Singapore protects trademarks through the Trade Marks Act 1998 as amended from time to time as well as under common law (mutually independent of each other). Protection under the Trade Marks Act 1998 is generally conditional upon registration of the trademark with the Registry of Trade Marks within the Intellectual Property Office of Singapore, with the exception of special protection granted under the Trade Marks Act 1998 to ‘well known’ trademarks. Protection for registered trademarks is valid for 10 years from the date of registration and renewable for further periods of 10 years. Registration may be obtained through (i) a domestic application filed with the Registry of Trade Marks or (ii) an international application filed under the Madrid Protocol designating Singapore as a country. An applicant may claim a right of priority where he files for registration of a trade mark in Singapore within six months from an earlier application filed in any country that is a party to the Paris Convention, or a member of the World Trade Organization. Singapore adheres to the Nice Agreement Concerning the International Classification of Goods and Services for the Purposes of the Registration of Marks.
A registered trade mark may be assigned or licensed by the registered proprietor, and such assignment or licensing should be registered with the Registry of Trade Marks in order to be effective against a person acquiring a conflicting interest in the trade mark unaware of such assignment or license.
66
Table of Contents
A registered proprietor of trademarks can look to a range of civil remedies for infringement, such as injunctions, either damages or an account of profits, or an order for delivery up and/or disposal of infringing articles in relation to the registered trademark. Where the infringement involves the use of a counterfeit trademark, the court may award statutory damages of up to S$1 million without proof of actual loss. Aside from these civil remedies, the registered proprietor may also enforce his trademark rights in criminal proceedings for infringing activities such as (i) counterfeiting a registered trademark, (ii) falsely applying a registered trade mark to goods or services, (iii) making or possessing articles for such infringement offense and (iv) importing or selling goods with falsely applied trademark. Conviction for any of these offenses attracts a fine of up to S$100,000 and/or imprisonment for a maximum term of five years.
Industrial Designs
Protection of industrial designs is available under the Registered Designs Act 2000, as amended from time to time. This Registered Designs Act 2000 is modelled after the UK Registered Designs Act 1949 (as amended in 1988). Registration may be obtained through (i) a domestic application filed with the Registry of Designs within the Intellectual Property Office of Singapore or (ii) an international application filed under the Geneva (1999) Act of the Hague Agreement Concerning the International Registration of Industrial Designs designating Singapore as a country. An applicant may claim a right of priority where he files for registration of a design in Singapore within six months from an earlier application filed in any country that is a party to the Paris Convention, or a member of the World Trade Organization. The maximum duration of the protection conferred by registration is 15 years from the date of registration. Singapore adopts the specification and classification system of the Locarno Agreement Establishing an International Classification for Industrial Designs.
A registered design may be assigned or licensed by the registered owner, and such assignment or licensing should be registered with the Registry of Designs in order to be effective against a person acquiring a conflicting interest in the design unaware of such assignment or license.
A registered owner can look to a range of remedies for infringement such as injunctions, either damages or an account of profits, an order for delivery up and/or disposal of infringing articles in relation to the registered design. However, if the registered owner threatens another person with proceedings for infringement of a registered design, it may be liable for a counterclaim for making groundless threats of design infringement. The remedies in such a counterclaim can include an injunction against the continuance of the threats, damages as well as a declaration that the threats are unjustifiable.
Where a registered design qualifies for protection under the Registered Designs Act 2000 as well as the Copyright Act 2021, there is no cumulative protection under registered design and copyright law: protection is available under the Registered Designs Act 2000 only. Further, if a design is registrable under the Registered Designs Act 2000 but has not been registered, the design will neither be covered by the registered design nor the copyright regime.
67
Table of Contents
Regulations on Intellectual Property—Indonesia
Copyrights
Copyrights in Indonesia are regulated under Law No. 28 of 2014 on Copyrights. Indonesia adopts the declarative system of copyright protection whereby a copyright is an exclusive right of a creator of content which arises automatically after a creation appears in a concrete form. This exclusive right consists of moral rights and economic rights. Based on Article 5 of the Indonesian Copyright Law, moral rights are eternally inherent to the creator to (i) continue to include or exclude their name on the copy with respect to the public use of the works, (ii) use an alias or pseudonym, (iii) change their creation to comply with appropriateness in the community, (iv) change the title and subtitle of their works, and (v) defend their rights in the event of distortion of creation, mutilation of creation, modification of creation or other acts which will be prejudicial to their honor or reputation. Such moral rights cannot be transferred as long as the creator is alive, but the exercise of these rights is transferrable by testament or other methods in accordance with the Indonesian regulation after their death (inheritance, grant, written agreement, etc.). Economic rights shall mean the exclusive right of the creator or the copyright holder to obtain economic benefit from the work. Such economical rights as stipulated in Article 9 of the Indonesian Copyright Law grant the creator to engage in (i) publication of the creation, (ii) reproduction of the creation in all its forms, (iii) translation of the creation, (iv) adaptation, arrangement, or transformation of the creation, (v) distribution of the creation or their copies, (vi) performance of the creation, (vii) publication of the creation, (viii) communication of the creation, and (ix) rental of the creation. The Indonesia copyright regulation protects creations in the field of science, arts and literature, which includes, among others, computer programs, video games, photography, songs or music with or without lyrics, and all forms of art. However, for certain creations, there are exceptions where protection is not granted. Based on Article 24 of the Indonesian Copyright Law, creations that are not protected under the Indonesian Copyright Law consist of (i) creations that have not been completed in tangible form, (ii) the idea, procedure, system, method, concept, principle, findings, or data, regardless of being expressed, stated, described, explained, or incorporated in a creation, and (iii) tools, objects, or products that are created solely to resolve technical problems or whose form only serve functional needs rather than artistic or literary expression.
Marks
Marks in Indonesia are regulated under Law No. 20 of 2016 as amended by Law No. 6 of 2023, or the Indonesian Mark Law. Based on Article 2 paragraph 2 of Indonesian Mark Law, marks are separated into two categories: trademark and service mark. Protected marks as stipulated in Article 2 paragraph 3 of the Indonesian Mark Law consists of a sign in the form of an image, logo, name, word, letter, number, color arrangement, in two dimensions and/or three dimensions, sounds, hologram, or a combination of two or more on those elements to distinguish goods and/or services that are produced by individuals or legal entities in goods and/or service trading activities. In 2026, Indonesia issued the Ministry of Justice Regulation No. 5 of 2026, guiding the trademark registration process.
Geographical Indication
Geographical indication in Indonesia are regulated under the Indonesian Mark Law. Geographical indication as defined by the Indonesian Mark Law is an indication that identifies the area of origin of goods and/or products based on geographical environmental factors, including natural factors, human factors or a combination of those two factors, that gives certain reputation, quality and characteristics to the produced goods and/or products.
Patents
Patents in Indonesia are regulated under Law No. 13 of 2016 as amended by Law 6 of 2023 and Law of 2024, or the Indonesian Patent Law. Patents are exclusive rights granted by the state to inventors for their inventions or technological improvements that solve specific problems in the form of products or processes. Patents are generally divided into two categories: patent products and patent processes where these patents are warranted with a period of time to implement the invention itself or to give approval to other parties to use it.
According to Article 2 of the Indonesian Patent Law, patent protection can be categorized into two circumstances. First, for patents that are granted for new inventions, contain inventive step/act, and may be applied in industry, Article 22 of the Indonesian Patent Law provides that these patents have a protection period of 20 years and cannot be extended. Second, for simple patents that are granted for a new invention in the event that it is a development of an existing product or process, which consists of a simple product, a simple process, and a simple method, Article 23 of the Indonesian Patent Law provides that this simple patent only has protection period of 10 years and cannot be extended.
68
Table of Contents
As stipulated in Article 19 of the Indonesian Patent Law, the patent holder has the exclusive right to implement the patent he owns and prohibit other parties who do not have his consent to use it in terms of making, using, selling, importing, leasing, delivering, or providing for sale or lease or delivery of products granted a patent for product patents, as well as in the case of using the patented production process to make goods or other acts in the case of process patents.
In 2026, Indonesia issued the Ministry of Justice Regulation No. 6 of 2026, guiding the patent registration process.
Trade Secret
Trade secrets in Indonesia are regulated under Law No. 30 of 2000, or the Indonesian Trade Secret Law. Trade secret is information that is not known to the public in the field of technology and/or business, has economic value, and is kept confidential by the owner of the trade secret. Article 2 of the Indonesian Trade Secret Law states that the scope of this trade secret includes: (i) production methods; (ii) processing methods; (iii) sales methods; or (iv) other information in the field of technology and/or business that has economic value and is not known by the general public. Pursuant to the Indonesian Trade Secret Law, trade secret has three elements that must be fulfilled, which consist of: (i) confidential, which means that it is only known by certain parties and not general public; (ii) has economic value, which means its secrecy provides a competitive advantage; (iii) is kept confidential through appropriate efforts. The owner of a trade secret, in addition to having the right to use the trade secret himself, can also use it for commercial purposes such as by granting licenses to other parties or prohibiting the use of his trade secret as stipulated in Article 4 of the Indonesian Trade Secret Law.
Regulations on Intellectual Property—Vietnam
Intellectual property rights in Vietnam are mainly governed by the Law on Intellectual Property, its guiding documents such as Decree 103/2016/ND-CP, Decree 100/2006/ND-CP, 65/2023/ND-CP, etc., together with certain international agreements to which Vietnam is a signatory.
In order for certain intellectual property rights to be recognized and enforceable in Vietnam, intellectual property owners must register those rights. Copyrights may be registered with the Department of Copyright of Vietnam but the registration is not compulsory. As a member of the Berne Convention, all copyrights will be protected automatically. However, copyright registration could be helpful for copyright protection, especially for proving the existence of copyrights in disputes. Industrial property, such as patents, trademarks (except for well-known trademarks) and industrial design, must be registered with the Intellectual Property Office of Vietnam in order to be protected in Vietnam, although unregistered rights may be protectable under the laws of unfair competition or passing off. A well-known trademark may be protected based on its use without registration and a trademark license is not required to be registered with the Intellectual Property Office of Vietnam in order to have validity against a third party.
On December 10, 2025, Vietnam promulgated Law No. 131/2025/QH15, which introduced certain amendments to the Intellectual Property Law. This amendment took effect on April 1, 2026. This amendment primarily stipulates the following contents: when intellectual property objects are created by artificial intelligence systems, the Vietnam Government shall establish rules for the generation and establishment of rights. Moreover, this amendment clarifies that the exercise of intellectual property rights shall not harm national or public interests or the legitimate rights and interests of others, and permits organizations and individuals to use lawfully published texts and data accessible to the public for scientific research, experimentation, and training of artificial intelligence systems. Furthermore, this amendment incorporates the management, commercial exploitation, national management safeguards, and digitalization of intellectual property activities into the legal framework, encourages the use of intellectual property for capital contribution or mortgage for loans.
69
Table of Contents
In addition, Vietnam promulgated No. 100/2026/NĐ-CP on March 31, 2026, making certain amendments to the implementing regulations on intellectual property rights. According to this decree, the intellectual property right holder shall prepare and maintain a list of intellectual property rights that do not yet meet the conditions for recognition as assets in accounting records in accordance with accounting laws. Also, No. 100/2026/NĐ-CP also introduces a fast-track substantive examination mechanism, meaning that, under specific conditions, patent applications and trademark applications are examined through a fast-track substantive examination process. For patent applications, the specific conditions refer to cases where the invention belongs to the list of high-tech or strategic technologies, or is used for national security, defense, disaster, or epidemic emergencies; the number of claims does not exceed 10 (of which no more than 2 are independent claims); it is not a divisional application or a converted application; it has already been commercially exploited; and the fast-track examination fee has been paid. For trademark applications, the specific conditions refer to cases where the mark belongs to the list of high-tech or strategic technologies, or is used for national security, defense, disaster, or epidemic emergencies, or is one of the conditions required for the applicant when carrying out production or business registration or licensing procedures; it is a domestic application submitted directly to the competent national authority (not an international registration application); the trademark type is not a collective mark, certification mark, three-dimensional mark, or sound mark; and the fee has been paid.
Regulations on Intellectual Property—Malaysia
Trademarks
Trademarks in Malaysia are governed by the Trademarks Act 2019 and the Trademarks Regulations 2019. Once a trademark is registered, the registered proprietor of the trademark has the exclusive rights to use the trademark and to authorize other persons to use the trademark, in relation to the goods or services for which the trademark is registered. Registered trademarks are valid for ten (10) years from the date of registration and are renewable for subsequent periods of ten (10) years each. Subject to limited exceptions, no person or enterprise other than the registered proprietor or persons authorized by the registered proprietor may use the trademark, otherwise infringement actions may be taken against such person or enterprise, including actions against counterfeiting a registered trademark.
Copyrights
The main governing legislation for copyright law in Malaysia is the Copyright Act 1987. Pursuant to the Copyright Act 1987, authors of protected works enjoy various exclusive rights, including the rights of reproduction in any material forms, communication to the public, performance, showing or playing to the public, distribution of copies to the public by sale or other transfer of ownership, and commercial rental to the public. Literary works, musical works and artistic works are eligible for copyright protection if sufficient effort has been made to make the works original in character; and the works have been written down, recorded or otherwise reduced to a material form. There is no formal system for registration of copyright in Malaysia. Copyright is conferred automatically on a work once all statutory requirements have been met. That said, copyright owners can claim ownership by way of a Statutory Declaration or by filing a Voluntary Notification at the Intellectual Property Corporation of Malaysia. Online games and computer software or programs are eligible for copyright protection in Malaysia.
Patents
The Patents Act 1983 and the Patents Regulations 1986 govern the protection of inventions in Malaysia. An invention is eligible for patent protection if it is new, involves an inventive step, is industrially applicable, and is not explicitly excluded by the Patents Act 1983. Examples of excluded items include discoveries, rules, and methods for doing business or playing games. Once granted, a patent is valid for a maximum of twenty (20) years from the date of filing, subject to yearly renewal. The owner of a patent is granted exclusive rights to exploit the patented invention, assign or transfer the patent, enter into licensee contracts, and deal with the patent as the subject of a security interest. Anyone seeking to deal with a patent exclusively owned by someone else must obtain prior consent. Infringement of a patent occurs when a person performs any of the acts under the exclusive control of the patent owner without authorization. Such acts include the manufacture, importation, offer for sale, sale, or use of the patented product or process. Opposition to a patent is allowed under the Patents Act by any interested person against the owner of a patent, provided that the requirements and proper procedures under the Patents Act are complied with. The Malaysian Patents (Amendment) Regulations 2025, which came into effect on December 31, 2025, provides detailed regulations on the patent opposition process.
70
Table of Contents
Regulations on Intellectual Property—Saudi Arabia
Patents and Utility Model
According to Federal Law No. (11) of 2021 on the Regulation and Protection of Industrial Property Rights, a Patent shall be granted for each new Invention resulting from an innovative idea or innovative improvement, which involves an inventive step and is capable of industrial application. On the contrary, a Utility Model Certificate shall be granted for a new Invention that is industrially applicable but does not involve an innovative step that qualifies for a Patent. Pursuant to Article 18 of Federal Law No. (11) of 2021 on the Regulation and Protection of Industrial Property Rights, the term of the Patent shall be twenty (20) years and the term of the Utility Model Certificate shall be ten (10) years, starting from the filing date of the application. A Patent or Utility Model Certificate gives its owner the exclusive right to use the invention for industrial or commercial purposes, including making, using, selling, offering for sale, and importing the protected product, and also allows the owner to prevent others from carrying out these activities without permission. If the invention is a process or method, the protection extends both to the use of that process and to products directly obtained from it, including the right to stop third parties from using or dealing with such products without consent. In the event of infringing any of the rights conferred on the owner by the Protection Title, the Protection Title owner or licensee may file an action before the court to claim for compensation for the damage suffered thereby as a result of the acts of infringement in violation of the provisions hereof.
Trade Secret
Undisclosed information shall be protected under the provisions of Federal Law No. (11) of 2021 on the Regulation and Protection of Industrial Property Rights and the Executive Regulations thereof, provided that it meets the following conditions: (a) it shall be secret in the sense that it is not, as a body or in the precise configuration and assembly of its components, generally known among or readily accessible to persons within the circles that normally deal with the kind of information in question; (b) it has commercial value because it is secret; and (c) it has been subject to reasonable steps by the person lawfully in control thereof to keep it secret. The person lawfully in control of undisclosed information shall take all appropriate measures to maintain the confidentiality of such information and prevent its circulation amongst unauthorized persons and shall also organize and limit the circulation of such information within the establishment to the authorized persons, and preserve and prevent the leakage of such information to third parties. The confidentiality of information, and the attendant rights to prevent others from infringing such information, shall subsist so long as the information is not disclosed. In the event of infringing any of the rights conferred on the owner by the Protection Title, the Protection Title owner or licensee may file an action before the court to claim for compensation for the damage suffered thereby as a result of the acts of infringement in violation of the provisions hereof.
Regulations on Intellectual Property—mainland China
Software
According to the regulations relating to protection of software in mainland China, software owners, licensees and transferees may register their rights in software with the copyright administration department of the State Council or its local branches and obtain software copyright registration certificates. Although such registration is not mandatory under PRC law, software owners, licensees and transferees are encouraged to go through the registration process and registered software rights to be entitled to better protections.
Patents
The Patent Office under the China National Intellectual Property Administration is responsible for receiving, examining and approving patent applications. According to the Patent Law (2020 Amendment), a patent is valid for a twenty-year term for an invention, a ten-year term for a utility model and a fifteen-year term for design, starting from the application date. Except under certain specific circumstances provided by law, any third-party user must obtain consent or a proper license from the patent owner to use the patent, or else the use will constitute an infringement of the rights of the patent holder.
71
Table of Contents
Copyright
Registration of copyright is voluntary and is administrated by the China Copyright Protection Center. Under the Copyright Law (2020 Amendment) and its implementation rules, anyone infringing upon the copyrights of others is subject to various civil liabilities, which include stopping the infringement, eliminating the damages, apologizing and compensating the copyright owners. An internet information service operator may be subject to cease-and-desist orders and other administrative penalties such as confiscation of illegal income and fines, if it is clearly aware of a copyright infringement through the internet or, although not aware of such infringement, it fails to take measures to remove relevant content upon receipt of the copyright owner’s notice of infringement and, as a result, damages public interests.
According to the Provisions by the Supreme People’s Court on Several Issues Concerning the Application of Law in Hearing Civil Dispute Cases Involving Infringement of the Right of Communication to the Public on Information Networks (Amended in 2020), where a network service provider cooperates with others to jointly provide works, performances, audio and video products of which the right holders have information network transmission right, such behavior will constitute joint infringement of third parties’ information network transmission right, and the PRC court shall order such network service provider to assume joint liability for such infringement. The PRC court shall determine whether a network service provider is liable for abetting or contributory infringement according to the degree of fault of the network service provider.
Domain Name
According to the Measures for Administration of Domain Names, the MIIT is the major regulatory authority responsible for the administration of the PRC Internet domain names. The registration of domain names in PRC is on a “first-apply-first-registration” basis. A domain name applicant will become the domain name holder upon the completion of the application procedure.
Trademark
According to the PRC Trademark Law (Amended in 2019), the Trademark Office of the State Administration for Industry and Commerce (currently known as the Trademark Office of National Intellectual Property Administration) handles trademark registrations and grants a protection term of ten years to registered trademarks.
Regulations on Contents
Regulations on Contents—European Union
Directive (EU) 2015/1535 uses the phrase “any Information Society service, that is to say, any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services” to delineate electronic information services.
When any information that, in itself or in relation to an activity, including the sale of products or the provision of services, is not in compliance with EU law or the law of any member state which is in compliance with EU law, irrespective of the precise subject matter or nature of that law, it constitutes “illegal content” under Regulation (EU) 2022/2065. In addition, Regulation (EU) 2022/2065 further provides that providers of online platforms shall not design, organize or operate their online interfaces in a way that deceives or manipulates the recipients of their service, or in a way that otherwise materially distorts or impairs the ability of the recipients of their service to make free and informed decisions.
Moreover, Directive (EU) 2010/13 requires that audiovisual media services shall not contain incitement to violence or hatred directed against a group or a member of a group, nor public provocation to commit terrorist offences. Directive (EU) 2010/13 further provides that Member States shall take appropriate measures to ensure that audiovisual media services provided by media service providers under their jurisdiction which may impair the physical, mental or moral development of minors are only made available in such a way as to ensure that minors will not normally hear or see them. Such measures may include selecting the time of the broadcast, age verification tools or other technical measures. They shall be proportionate to the potential harm of the program. The most harmful content, such as gratuitous violence and pornography, shall be subject to the strictest measures.
72
Table of Contents
Regulations on Contents—India
Article 2 of the Information Technology Act 2000 (as amended by Information Technology (Amendment) Act of 2008) establishes terminology related to electronic information: Article 2(t) defines electronic record as data, record or data generated, image or sound stored, received or sent in an electronic form or micro film or computer generated micro fiche. Meanwhile, Article 2(v) stipulates information includes data, text, images, sound, voice, codes, computer programs, software and databases or micro film or computer generated micro fiche. Article 67 of the Information Technology Act 2000 further stipulates that whoever publishes or transmits or causes to be published or transmitted in the electronic form, any material which is lascivious or appeals to the prurient interest or if its effect is such as to tend to deprave and corrupt persons who are likely, having regard to all relevant circumstances, to read, see or hear the matter contained or embodied in it, shall be punished on first conviction with imprisonment of either description for a term which may extend to three years and with fine which may extend to five lakh rupees and in the event of second or subsequent conviction with imprisonment of either description for a term which may extend to five years and also with fine which may extend to ten lakh rupees.
Article 2(b) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 requires internet intermediaries to take reasonable efforts to ensure users do not host, display, upload, publish, transmit, store, update, or share any information that they have no right to use, or that is obscene, pornographic, pedophilic, invasive of privacy, abusive, discriminatory, or related to money laundering, gambling, harmful online games, or promoting enmity; that harms children; infringes intellectual property rights; is false, misleading, deceptive, or misrepresents the origin of messages or is identified as such by the Central Government; impersonates others; threatens national unity, integrity, security, public order, or friendly relations with foreign states, or incites offences or obstructs investigations; contains malicious software; relates to unverified or prohibited online games or their promotion; or otherwise violates applicable law.
Regulations on Contents—Singapore
The Electronic Transactions Act 2010 defines key concepts forming the basis of electronic information regulation. It defines “electronic communication” as any communication that the parties make by means of electronic records, and “electronic record” as a record generated, communicated, received or stored by electronic means in an information system or for transmission from one information system to another. In addition, “information” is expressed to include data, text, images, sound, codes, computer programs, software and databases.
In terms of prohibited conduct, the Protection from Online Falsehoods and Manipulation Act 2019 prevents the electronic communication in Singapore of false statements of fact, and further aims to suppress support for and counteract the effects of such communication, as well as to safeguard against the use of online accounts for such communication and for information manipulation.
Finally, Part 10A of the Broadcasting Act 1994 prohibits the following categories of content: (a) content that advocates or instructs on suicide or self-harm; (b) content that advocates or instructs on violence or cruelty to, physical abuse of, or acts of torture or other infliction of serious physical harm on human beings; (c) content that advocates or instructs on sexual violence or coercion in association with sexual conduct, whether or not involving the commission of a heinous sex crime; (d) content depicting for a sexual purpose, or that exploits, the nudity of a child or part of a child in a way that reasonable persons would regard as being offensive, whether or not sexual activity is involved; (e) content that advocates engaging in conduct in a way that (i) obstructs or is likely to obstruct any public health measure carried out in Singapore, or (ii) results or is likely to result in a public health risk in Singapore; (f) content dealing with matters of race or religion in a way that is likely to cause feelings of enmity, hatred, ill will or hostility against, or contempt for or ridicule of, different racial or religious groups in Singapore; (g) content that advocates or instructs on terrorism; and (h) any other content that is prescribed by Part 10A regulations as egregious content.
73
Table of Contents
Regulations on Contents—Indonesia
Regulations on Electronic Information Content
Video content and live streaming are categorized as electronic information, which refers to one or a set of electronic data, including, but not limited to, text, voice, images, maps, designs, photographs, electronic data exchanges, e-mails, telegrams, telex, telecopy, letters, symbols, numbers, access codes, or any other form of processed data that conveys meaning and can be understood by individuals. As such, live streaming and video content are regulated under Law No. 11 of 2008 on Electronic Information and Transactions (EIT Law), as last amended by Law No. 1 of 2024. This law mandates that electronic system operators must ensure the reliable, secure, and responsible operation of their platforms. It also emphasizes the protection of children, requiring measures such as minimum age restrictions for product and service usage, verification mechanisms for child users, and reporting systems for content, services, or features that may potentially infringe on children’s rights.
Indonesian regulations strictly prohibit the dissemination of certain types of content through video and live streaming platforms. Under the EIT Law, it is illegal to intentionally and unlawfully distribute, transmit, or make accessible electronic information that contains pornographic or obscene content, gambling-related content, defamatory or offensive material, extortion or threats, and hate speech or incitement of hostility based on ethnicity, religion, race, or inter-group differences (SARA).
Additionally, the law prohibits the deliberate dissemination of false or misleading information that could cause consumer losses in electronic transactions. The law applies not only to offenses committed within Indonesia but also to violations carried out from outside the country that affect electronic systems within Indonesian jurisdiction. Violations of these prohibitions may result in criminal penalties, including imprisonment of up to 10 years and/or a maximum fine of 10 billion Indonesian Rupiah.
Regulations on Pornographic Content
Aside from the EIT Law, Law No. 44 of 2008 on Pornography provides additional, explicit regulations against pornography, including its production, distribution, and dissemination via digital platforms such as video content and live streaming. Article 4 prohibits all forms of pornography, including images, animations, sound, or any other medium that exploits sexuality. Lastly, Article 29 imposes strict penalties on individuals or entities involved in the production, distribution, or facilitation of access to pornographic content, with fines ranging from IDR 250 million to IDR 6 billion and/or imprisonment of 6 to 12 years.
Broadcasting Regulations and Content Standards
Regulations concerning video content and live streaming also fall under Law No. 32 of 2002 on Broadcasting, as amended by Law No. 6 of 2023. Article 36 mandates that broadcast content must include elements of information, education, entertainment, and national development to foster intellectual, moral, and cultural growth while maintaining national unity. Broadcast content must also ensure protection and empowerment of children and adolescents, including appropriate programming schedules and audience classification. The law explicitly prohibits broadcasts that contain defamation, incitement, misleading information, or falsehoods, promote violence, obscenity, gambling, drug abuse, or other illegal activities, and stir conflict based on ethnicity, religion, race, or inter-group differences (SARA).
Protection of Minors
Indonesia’s new legislative developments in the electronic information sector in 2025 primarily focus on the protection of minors. Government Regulation No. 17 of 2025, which came into force on March 27, 2025, establishes a governance framework for child protection in electronic systems. It requires platforms to provide information on the minimum age for the use of their services and products, implement verification mechanisms for minor users, and establish reporting mechanisms for content, services, or features that infringe or may potentially infringe upon children’s rights.
Building upon this framework, Minister of Communication and Digital Regulation Number 9 of 2026 on the Implementing Regulation of Government Regulation Number 17 of 2025 on the Governance of Electronic System Operation in the Protection of Children (“MOCD Regulation 9/2026”) further operationalizes these requirements. It requires Electronic System Operators to conduct a self-assessment to ensure that their products comply with children’s age restrictions and to evaluate the level of risk involved. This assessment covers seven aspects: (a) contact with strangers; (b) exposure to pornographic content, violent content, and other content inappropriate for children; (c) exploitation of children as consumers; (d) threats to the security of children’s personal data; (e) causing addiction; (f) psychological health disturbances in children; and (g) physiological disturbances in children.
74
Table of Contents
Where one or more of these aspects is assessed as high risk, the product, service, or feature will be categorized as having a High-Risk Profile. Unless otherwise determined based on the results of the self-assessment and the Minister’s evaluation of the risk profile, online and social media services provided by Electronic System Operators are classified as high-risk products, services, and features. In fulfilling their obligation to comply with minimum age restrictions for children, Electronic System Operators providing such products, services, and features are required to deactivate accounts held by children under the age of 16.
In conclusion, Indonesia’s regulations on video content and live streaming are supported with comprehensive legal framework, especially on electronic information security, content restrictions, child protection, and consumer rights. Violations of these laws can lead to severe penalties, including substantial fines and imprisonment. Content creators, live streamers, platforms, and service providers must adhere to these regulations to avoid legal consequences and ensure compliance with Indonesian law.
Regulations on Contents—Vietnam
The Law on Electronic Transactions (No. 20/2023/QH15) defines the “data message” as information that is generated, sent, received, or stored by electronic means; “electronic data” as data that is created, processed, or stored by electronic means; and the “electronic environment” as the environment of telecommunications networks, the Internet, computer networks, and information systems.
The Law on Cybersecurity (No. 24/2018/QH14) prohibits, in cyberspace, organizing or inciting activities opposing the Socialist Republic of Vietnam; distorting history or revolutionary achievements; undermining national unity or offending religion, or engaging in discrimination; disseminating false information causing public panic or harm to socio-economic activities or infringing lawful rights and interests; engaging in prostitution, social evils, or human trafficking, or publishing obscene or harmful content; inciting crimes; appropriating property, organizing gambling, or infringing copyright and intellectual property rights; forging or illegally handling electronic information pages or financial information, or unlawfully using payment instruments; advertising or trading in prohibited goods or services; instigating unlawful acts; and any other acts using cyberspace or electronic means to infringe national security, social order or safety, including posting or spreading content that opposes the State, incites unrest, defames, disrupts order, or discloses state, business, or personal secrets.
However, it should be noted that Vietnam passed the Cybersecurity Law (No. 116/2025/QH15) on December 10, 2025. This law is scheduled to take effect on July 1, 2026 (i.e., it is not yet in force at present), and the former Law on Cybersecurity (No. 24/2018/QH14) will be repealed on the same date. While under Law No. 116/2025/QH15, the following contents will be prohibited: propaganda against the State; incitement to riots or disorder; insults to national symbols and leaders; incitement to violence or armed opposition; mobilization of large gatherings causing disturbances; distortion of national sovereignty; causing social division or undermining solidarity policies; inciting discrimination, hatred, or ethnic and religious division; obstructing or harming state policies; harming the State’s political, economic, social interests or international prestige; obstructing policy implementation; spreading false or fabricated information harming organizations; boycotts causing damage to organizations or businesses; impersonation or counterfeit of organizational information or trademarks; insults or distortion of personal honor; dissemination of false information causing harm; false accusation of crimes; impersonation of individuals; posting or disseminating prohibited content; engaging in cyber-enabled crimes such as fraud, gambling, theft of telecom charges, and IP infringement; impersonation of websites or illegal handling of financial and personal account data; illegal trading or advertising of prohibited goods and services; facilitating illegal online exchanges or platforms; misuse of identities and data for accounts or entities; trading in counterfeit or illicit goods; inciting others to violate the law; and any other acts violating national security, public order, and safety in cyberspace.
Regulations on Contents—Malaysia
The Communications and Multimedia Act 1998 (“CMA 1998”) is the main legislation regulating the communications and multimedia industry. The CMA 1998 provides for the Communications and Multimedia Content Forum(s) to prepare and draw up a Content Code after appropriate consultations, and to enforce the Content Code containing governing standards and practices in the communications and multimedia industry. The Content Code sets out the guidelines and procedures for good practice and standards of content disseminated to audiences by service providers in the communications and multimedia industry in Malaysia. It covers a wide range of topics, including general principles, content standards, advertising and sponsorship, and enforcement. The CMA 1998 also penalises the transmission of prohibited content (including indecent, obscene, false, menacing, or grossly offensive content) with intent to commit offenses involving fraud or dishonesty against any person.
75
Table of Contents
On February 11, 2025, the Communications and Multimedia (Amendment) Act 2025, which provides amendments to the Communications and Multimedia Act 1998, came into effect. Notably, Section 92 (Sending of unsolicited commercial electronic messages) and Section 112 (Preservation of communications data) of the Amendment Act will come into effect on a later date to be determined by the Minister of Communications. This Amendment Act strengthens the protection of individuals. For example, it introduces Section 233A, which provides that no person shall send, or cause to be sent, or authorize the sending of an unsolicited commercial electronic message in contravention of any provisions of the Act or any regulations made under the Act. At the same time, this Amendment Act enhances the regulatory powers of the Malaysian Communications and Multimedia Commission (MCMC). For example, the MCMC may issue directives to content applications service providers requiring them to suspend their services within a specified period where such providers are found to have violated any relevant provisions of the CMA 1998.
Finally, Online Safety Act 2025 (Act 866) came into effect in January 2026. It requires licensed providers to implement measures to reduce users’ exposure to harmful content, issue clear user guidelines, provide online-safety tools, set up reporting and user-assistance mechanisms, protect child users, establish a mechanism to make “priority harmful content” inaccessible, and prepare, publish and submit an Online Safety Plan. The Schedule of Online Safety Act 2025 list harmful content to include child sexual abuse material, financial fraud, obscene content, indecent content, harassment or threatening content, content inciting violence or terrorism, content inducing child self-harm, content promoting ill-will or hostility, and content promoting dangerous drug.
Regulations on Contents—Saudi Arabia
Under the current relevant provisions in Saudi Arabia, there is no single and unified statutory definition of “electronic information”. Instead, existing legal provisions address such subject matter through concepts such as “data” and “media content.” For instance, the Saudi Arabia Anti-Cyber Crime Law (2007) defines “data” as: “Information, commands, messages, voices, or images which are prepared or have been prepared for use in computers. This includes data that can be saved, processed, transmitted, or constructed by computers, such as numbers, letters, codes, etc.” While the Law of Audiovisual Media (Royal Decree No. M/33) defines “media content” as audio and/or visual material.
With regard to prohibited content, the Saudi Anti-Cyber Crime Law (2007) provides that any person who commits one of the following cyber crimes shall be subject to imprisonment for a period not exceeding five years and a fine not exceeding three million riyals or to either punishment: (a) Production, preparation, transmission, or storage of material impinging on public order, religious values, public morals, and privacy, through the information network or computers; (b) The construction or publicizing of a website on the information network or computer to promote or facilitate human trafficking; (c) The preparation, publication, and promotion of material for pornographic or gambling sites which violates public morals; (d) The construction or publicizing of a web site on the information network or computer to trade in, distribute, demonstrate method of use or facilitate dealing in narcotic and psychotropic drugs. In addition, the Saudi Anti-Cyber Crime Law (2007) stipulates any person who commits one of the following cyber crimes shall be subject to imprisonment for a period not exceeding ten years, and a fine not exceeding five million riyals or to either punishment: (a) The construction or publicizing of a website on the information network or on a computer for terrorist organizations to facilitate communication with leaders or members of such organizations, finance them, promote their ideologies, publicize methods of making incendiary devices or explosives, or any other means used in terrorist activities; (b) Unlawful access to a web site or an information system directly, or through the information network or any computer with the Intention of obtaining data jeopardizing the internal or external security of the State or its national economy.
Finally, the Law of Audiovisual Media requires all persons engaged in audiovisual media activities to comply with the Kingdom’s media policy and a range of content controls, including prohibitions on defamation or blasphemy against religious figures and Islamic tenets, insulting the King or Crown Prince, inciting hatred, violence, or social division, undermining public order, national security, or international relations, and violating human dignity or privacy; it also requires respect for intellectual property rights and freedom of expression within legal limits, prohibits dissemination of false or unverified information, indecent or sexually explicit content, or promotion of drugs, alcohol, tobacco, or unlicensed medicines, supplements, or investment products, mandates modest dress requirements for female presenters as defined by regulations, requires a balance between advertising and content, and any additional controls approved by the competent authority.
76
Table of Contents
Regulations on Contents—mainland China
Regulations on Internet Content
Internet content in mainland China is regulated and restricted from a state security standpoint. A series of laws and regulations were promulgated to regulate Internet security, including but not limited to the Decisions on Maintaining Internet Security (Amended in 2009), the PRC Law on Preservation of State Secrets, the Administrative Measures for the Graded Protection of Information Security and the Administrative Provisions on the Security Vulnerabilities of Network Products. Internet companies in mainland China are required to complete security filing procedures and regularly update information security and censorship systems for their websites with local public security bureau.
According to the Administrative Measures on Internet Information Services (Amended in 2024), the internet activities that constitute publication of any content that propagates obscenity, pornography, gambling and violence, incite the commission of crimes or infringe upon the lawful rights and interests of third parties are strictly prohibited. If an internet information service provider detects information transmitted on their system that falls within the specifically prohibited scope, such provider must terminate such transmission, delete such information immediately, keep records and report to the governmental authorities in charge. Any provider’s violation of these prescriptions will lead to the revocation of its value-added telecommunication Business Operation License with business scope being information services, or the ICP License, and, in serious cases, the shutting down of its internet systems. The Administrative Provisions on Internet User Account Information and the Administrative Provisions on Mobile Internet Applications Information Services (Amended in 2022) also require internet information service providers to assume their responsibilities of internet user account information management and information content administrator, equip professional personnel and technical capabilities, and establish and implement the real identity information authentication, account information verification, information content security, inspection and management, ecological governance, and personal information protection, data security protection and security assessment.
Pursuant to Administrative Measures for the Business Activities of Online Performances, the operator of online performances shall establish content review system, and be staffed with qualified reviewers for self-censorship, and online performances shall not contain illegal elements. Once the online performances in violation of laws are found, the operator of online performances shall immediately suspend the provision of such performance, and report relevant information to the authorized governmental departments.
According to the Administrative Provisions on Mobile Internet Applications Information Services (Amended in 2022), mobile internet application providers and internet application distribution platforms shall not use mobile internet applications to carry out illegal activities that endanger national security, disturb public order, and infringe upon others’ lawful rights, and shall perform the main responsibility for information content management, and establish and improve management systems for information content security management, information content ecological governance, network data security, personal information protection, and minors protection.
The PRC Data Security Law, among other things, provides for security review procedure for data-related activities that may affect national security. According to the Administrative Measures for Data Security in the Field of Industry and Information Technology (Trial Implementation), a data processor in the field of industry and information technology shall file its catalogue of important data and core data to the local industrial regulatory department for recordation. Important data and core data collected and produced by a data processor in the field of industry and information technology within mainland China shall be stored within mainland China, and shall conduct the security assessment if the cross-border transfer of data is necessary. The Implementing Rules for the Risk Assessment of Data Security in the Field of Industry and Information Technology (Trial Implementation) apply to the data security risk assessment activities conducted by important data and core data processors in the field of industry and information in mainland China. General data processors may also refer to these rules to conduct data security risk assessment.
The Cyber Security Law (Amended in 2025) provides that network operators must set up a classified protection system for cyber security. According to the Cyber Security Law (Amended in 2025), internet operators shall fulfill relevant mandatory security protection obligations. The Administration Measures on the Security Protection of Computer Information Network with Internationally Connections (Amended in 2011) prohibits using the internet in ways which, among others, result in a leakage of state secrets or a spread of socially destabilizing content. The Ministry of Public Security has supervision and inspection powers in this regard, and relevant local security bureaus may also have jurisdiction. If an ICP License holder violates these measures, the PRC government may revoke its ICP License and shut down its websites.
77
Table of Contents
Regulations on Advertisement Content
According to the Advertisement Law (Amended in 2021), Administrative Regulations for Advertising, and the Internet Advertisement Management Measures, advertisers, advertising agencies, and advertising distributors are required to ensure that the content of the advertisements they prepare or distribute is true and in complete compliance with applicable laws. In providing advertising services, advertising operators and advertising distributors must review the supporting documents provided by advertisers for advertisements and verify that the content of the advertisements complies with applicable PRC laws and regulations. Prior to distributing advertisements that are subject to government censorship and approval, advertising distributors are obligated to verify that such censorship has been performed and approval has been obtained. Violation of these regulations may result in penalties, including fines, confiscation of advertising income, orders to cease dissemination of the advertisements and orders to publish an advertisement correcting the misleading information. Where serious violations occur, the SAMR or its local branches may revoke such offenders’ business licenses.
Regulations on Online Music
According to the series of Notices on Clearing Online Music Products that are in Violation of Relevant Regulations, entities that provide any of the following will be subject to relevant penalties or sanctions imposed by the Ministry of Culture: (a) online music products or relevant services without obtaining corresponding qualifications, (b) imported online music products that have not passed the content review of the Ministry of Culture or (c) domestically developed online music products that have not been filed with the Ministry of Culture. Thus far, we believe that we have eliminated from our platforms any online music products that may fall into the scope of those prohibited online music products thereunder.
Regulations on Tax
Regulations on Tax—Cayman Islands
The Cayman Islands currently levies no taxes on individuals or corporations based upon profits, income, gains or appreciation and there is no taxation in the nature of inheritance tax or estate duty.
Pursuant to Section 6 of the Tax Concessions Act (As Revised) of the Cayman Islands, we have obtained an undertaking from the Governor-in-Cabinet:
1. that no law which is enacted in the Cayman Islands imposing any tax to be levied on profits or income or gains or appreciation shall apply to us or our operations; and
2. that no tax to be levied on profits, income, gains or appreciations or which is in the nature of estate duty or inheritance tax shall be payable:
(a) on or in respect of our shares, debentures or other obligations; or
(b) by way of the withholding in whole or in part of any relevant payment as defined in Section 6(3) of the Tax Concessions Act (As Revised) of the Cayman Islands.
The undertaking for us is for a period of 20 years from August 2, 2011.
Regulations on Tax—Singapore
Singapore Income Tax
Under the Singapore Income Tax Act (Chapter 134 of Singapore), a company established outside Singapore but whose governing body, being the board of directors, usually exercises de facto control and management of its business in Singapore could be considered tax residents in Singapore. However, such control and management of the business should not be deemed to be in Singapore if physical board meetings are mainly conducted outside Singapore. Where board resolutions are passed in the form of written consent signed by the directors each acting in their own jurisdictions, or where the board meetings are held by teleconference or videoconference, it is possible that the place of de facto control and management will be considered to be where the majority of the board are located when they sign such consent or attend such conferences.
78
Table of Contents
We believe that JOYY Inc. is not a Singapore tax resident for Singapore income tax purposes. However, the tax resident status of JOYY Inc. is subject to determination by the Inland Revenue Authority of Singapore and uncertainties remain with respect to our tax residence status. It is not certain if JOYY Inc. will be classified as a Singapore tax resident. See “Item 3. Key Information—D. Risk Factors—Risks Related to Doing Business in Jurisdictions We Operation— If we are classified as a tax resident of certain jurisdictions for income tax purposes, such classification could result in unfavorable tax consequences to us and our shareholders or ADS holders” for a discussion of the Singapore tax consequences to non-resident investors if JOYY Inc. is deemed to be a Singapore tax resident. The statements below are based on the assumption that JOYY Inc. is not a tax resident in Singapore for Singapore income tax purposes.
Regulations on Tax—mainland China
PRC Enterprise Income Tax
According to the PRC Enterprise Income Tax Law and its implementation regulations, a uniform income tax rate of 25% should be applied to resident enterprises and non-resident enterprises that have “establishment or place” situated in China. Besides, enterprises established within China, enterprises established in accordance with the laws of other jurisdictions whose “de facto management bodies” are within China are considered “resident enterprises” and subject to the uniform 25% enterprise income tax rate for their global income. A non-resident enterprise refers to an entity established under foreign law whose “de facto management bodies” are not within China but which have an establishment or place of business in China, or which do not have an establishment or place of business in China but have income sourced within China. An income tax rate of 10% should normally be applicable to dividends declared to or any other gains realized on the transfer of shares by non-PRC resident enterprise investors that do not have an establishment or place of business in China, or that have such establishment or place of business but the income is not substantially connected with the establishment or place of business, to the extent such dividends or other gains are derived from sources within China.
Value-added Tax
The PRC Value-added Tax Law and the Implementation Regulations of the PRC Value-added Tax Law set out that all taxpayers selling goods, services, intangible assets and immovable assets and importing goods in China shall pay a value-added tax. According to the Notice of the Ministry of Finance and the State Administration of Taxation on Adjusting Value-added Tax Rates, the deduction rates of 17% and 11% applicable to the taxpayers who have value-added tax taxable sales activities or imported goods are adjusted to 16% and 10%, respectively. According to the Notice of the Ministry of Finance, the State Administration of Taxation and the General Administration of Customs on Relevant Policies for Deepening Value-added Tax Reform, the value-added tax rate was reduced to 13% and 9%, respectively.
Dividends Withholding Tax
Pursuant to the PRC Enterprise Income Tax Law and its implementation rules, dividends generated after January 1, 2008 and distributed to us by our PRC subsidiaries are subject to withholding tax at a rate of 10%, unless otherwise exempted or reduced according to treaties or arrangements between the PRC central government and governments of other countries or regions where the non-mainland-China-resident holding enterprises are incorporated.
Regulations on Foreign Investment and Related Restrictions—mainland China
Regulations on Value-Added Telecommunications Service and Internet Information Services
According to the Special Administrative Measures (Negative List) for Foreign Investment Access (2024 version), or the 2024 Negative List, the foreign stake in a value-added telecommunications service (except e-commerce, domestic multi-party communication, store-and-forward, and call center services) may not exceed 50%. According to the Telecommunications Regulations (2016 Edition), the Catalog of Telecommunications Business (Amended in 2019) and the Administrative Measures on Internet Information Services (Amended in 2024), the operators of value-added telecommunications services, including internet information services, must obtain value-added telecommunications business operation licenses prior to the commencement of such services in mainland China.
79
Table of Contents
To comply with such foreign ownership restrictions, we hold ICP Licenses, a sub-category of the value-added telecommunications business operation license, through Guangzhou Huaduo, Guangzhou BaiGuoYuan and other PRC domestic companies, covering the provision of internet and mobile network information services and operate our online platform in mainland China through Guangzhou Huaduo, a subsidiary of Guangzhou Tuyue. Guangzhou Tuyue is indirectly held by selected individuals from our senior management team who are PRC citizens, through limited partnership in mainland China jointly established by these individuals. See “Item 7. Major Shareholders and Related Party Transactions—B. Related Party Transactions—VIE Structure and the Contractual Arrangements.” Based on our PRC counsel Fangda Partners’ understanding of the current laws, rules and regulations of mainland China, our corporate structure complies with all existing laws and regulations of mainland China. However, we were further advised by our PRC counsel that there are substantial uncertainties with respect to the interpretation and application of existing or future laws and regulations of mainland China and thus there is no assurance that mainland China governmental authorities would take a view consistent with the opinions of our PRC counsel.
Regulations on Online Transmission of Audio-Visual Programs
According to the Administrative Provisions on Private Network and Targeted Publication of Audio-Visual Programs Services (Amended in 2021) and the Administrative Provisions on Internet Audio-Visual Program Service (Amended in 2015), providers of internet audio-visual program services are required to obtain a License for Online Transmission of Audio-Visual Programs, or complete certain registration procedures with the State Administration of Radio, Film and Television. Foreign invested enterprises are not allowed to carry out such business. In general, providers of internet audio-visual program services must be either state-owned or state-controlled entities, and the business to be carried out by such providers must satisfy the overall planning and guidance catalog for internet audio-visual program service determined by the State Administration of Radio, Film and Television.
According to the Circular on Issues Relating to the Audit of the Content of Micro Short Dramas in Online Film and Television Dramas and the Notice on Matters Relating to the Administration of Licensing Services for the Distribution of Domestic Online Dramas and Films and the Notice on Further Strengthening the Management of Online Micro Short Dramas and Implementing the Creative Enhancement Plan, the entities operating online micro short drama services, including the micro short dramas Mini Program, shall obtain a License for Online Transmission of Audio-Visual Programs. All online micro short dramas shall pass the content examination by relevant departments and obtain the License for Online Drama Distribution or complete the filing of online audio-visual programs prior to broadcasting, including through Mini Program. For the mini programs micro short dramas that do not hold the License for Online Transmission of Audio-Visual Programs or regulated by the administrative departments of radio and television, or the micro short dramas uploaded by individual users, the online platforms shall perform the responsibility as an operator or the production institutions to access, distribute, link, aggregate and disseminate such online micro short dramas. The online platforms shall implement the management system of online micro short dramas, reviewing before broadcasting, and immediately implement measures such as disconnecting the link, taking offline, and stopping the access for illegal online micro short dramas. The notice further stipulates that the illegal online micro short dramas could be subject to the order to rectify or take offline by the relevant departments. The operators or mini programs broadcasting the illegal online micro short dramas could be subject to penalties such as disconnecting the link, taking offline, taking down, canceling the recordation, stopping the access, revocation of license, and joint disciplinary measures.
Regulations on Online Music
Several Suggestions of the Ministry of Culture on the Development and Administration of Internet Music, among other things, reiterate the requirement for an internet service provider to obtain an Internet Culture Operation License to carry out any business relating to internet music products. In addition, foreign investors are prohibited from operating internet culture businesses. However, the laws and regulations on internet music products are still evolving, and there have not been any provisions clarifying whether music products will be regulated by these suggestions or how such regulation would be carried out.
80
Table of Contents
Regulations on Foreign Currency Exchange and Dividend Distribution—mainland China
Regulations on Foreign Currency Exchange
Under the Foreign Exchange Administration Regulations (Amended in 2008), the Renminbi is freely convertible for current account items, including the distribution of dividends, interest payments, trade and service-related foreign exchange transactions, but not for capital account items, such as direct investments, loans, repatriation of investments and investments in securities outside of mainland China, unless the prior approval of the State Administration for Foreign Exchange of the PRC, or the SAFE, is obtained and prior registration with the SAFE is made. According to the Reforming of the Management Method of the Settlement of Foreign Currency Capital of Foreign-Invested Enterprises, the Circular of the State Administration of Foreign Exchange on Further Promoting Cross-border Trade and Investment Facilitation (Amended in 2023) and the Notice of the State Administration of Foreign Exchange on Reforming and Standardizing the Foreign Exchange Settlement Management Policy of Capital Account (Amended in 2023), a foreign-invested enterprise may choose to convert its foreign exchange capital, foreign debt offering proceeds and remitted foreign listing proceeds from foreign currency to RMB on a discretionary basis, and the RMB capital so converted can be used for equity investments within PRC, extending loans to related parties or repaying the inter-company loans, as long as there is a truthful investment and such investment is in compliance with the foreign investment-related laws and regulations. Qualified enterprises in certain pilot areas may use their capital income from registered capital, foreign debt and overseas listing, for the purpose of domestic payments without providing authenticity certifications to the relevant banks in advance for those domestic payments.
The Notice on Further Deepening Reforms to Promote the Convenience of Cross-border Trade and Investment provides that qualified high-tech, “professional, sophisticated, unique and new” and technology-based small and medium-sized enterprises in Guangdong (including Shenzhen), and certain other areas can borrow foreign debt on their own within an amount not exceeding the equivalent of US$10 million.
The Circular on Further Improving Reform of Foreign Exchange Administration and Optimizing Genuineness and Compliance Verification stipulates several capital control measures with respect to the outbound remittance of profit from domestic entities to offshore entities, including (i) under the principle of genuine transaction, banks shall check board resolutions regarding profit distribution, the original version of tax filing records and audited financial statements; and (ii) domestic entities shall hold income to account for previous years’ losses before remitting the profits.
Regulations on Dividend Distribution
The principal regulations governing distribution of dividends paid by wholly foreign-invested enterprises include the PRC Company Law (Amended in 2023), and the Foreign Investment Law and its Implementation Rules. Under these regulations, a wholly foreign-invested enterprise in mainland China, or a WFOE, may pay dividends only out of its accumulated profits, if any, determined in accordance with PRC accounting standards and regulations. In addition, a WFOE is required to allocate at least 10% of its accumulated profits each year, if any, to statutory reserve funds unless its reserves have reached 50% of the registered capital of the enterprises. These reserves are not distributable as cash dividends. Profits of a WFOE shall not be distributed before the losses thereof before the previous accounting years have been made up.
Regulations on Registration with SAFE
Pursuant to SAFE’s Notice on Relevant Issues Relating to Domestic Residents’ Investment and Financing and Round-trip Investment through Special Purpose Vehicles, or SAFE Circular 37, and its appendixes, and the Notice on Further Simplifying and Improving the Administration of the Foreign Exchange Concerning Direct Investment, PRC residents must register with qualified banks in connection with their direct establishment or indirect control of an offshore entity, for the purpose of overseas investment and financing, with such PRC residents’ legally owned assets or equity interest in domestic enterprises or offshore assets or interests, referred to in the SAFE Circular 37 as a “special purpose vehicle.” In the event that a PRC shareholder holding interests in a special purpose vehicle fails to fulfill the required SAFE registration, the PRC subsidiaries of that special purpose vehicle may be prohibited from making distributions of profit to the offshore parent and from carrying out subsequent cross-border foreign exchange activities and the special purpose vehicle may be restricted in their ability to contribute additional capital into its PRC subsidiary. Further, failure to comply with the various SAFE registration requirements described above could result in liability under PRC law for foreign exchange evasion. These regulations apply to our direct and indirect shareholders who are PRC residents and may apply to any offshore acquisitions and share transfer that we make in the future if our shares are issued to PRC residents.
81
Table of Contents
According to the Administration Measures on Individual Foreign Exchange Control and its Implementation Rules (Amended in 2023), all foreign exchange matters involved in employee stock ownership plans and stock option plans participated in by onshore individuals, among others, require approval from the SAFE or its authorized branch. Furthermore, pursuant to the Notices on Issues concerning the Foreign Exchange Administration for Domestic Individuals Participating in Stock Incentive Plans of Overseas Publicly-Listed Companies, PRC residents who are granted shares or stock options by companies listed on overseas stock exchanges based on the stock incentive plans are required to register with SAFE or its local branches. The foreign exchange proceeds received by the PRC residents from the sale of shares under the stock incentive plans granted and dividends distributed by the overseas listed companies must be remitted into the bank accounts in the PRC opened by the PRC agents retained by such PRC residents before distribution to such PRC residents. In addition, the PRC agents shall file each quarter the form for record-filing of information of the Domestic Individuals Participating in the Stock Incentive Plans of Overseas Listed Companies with SAFE or its local branches. We and our PRC citizen employees who have been granted share options, restricted shares or restricted share units are subject to the aforementioned rules. If we or our PRC optionees fail to comply with the Individual Foreign Exchange Rule and the aforementioned rules, we and/or our PRC optionees may be subject to fines and other legal sanctions. In addition, under the circulars concerning employee share options, our employees working in the PRC who exercise share options will be subject to PRC individual income tax. Our PRC subsidiaries have obligations to withhold individual income taxes of such employees. If our employees fail to pay or if we fail to withhold their income taxes as required by relevant laws and regulations, we may face sanctions imposed by the PRC tax authorities or other PRC government authorities.
Regulations on Labor Laws and Social Insurance—mainland China
According to the Labor Law, and Labor Contract Law, employers must execute written labor contracts with full-time employees. The Law on Social Insurance of the PRC, requires that employers shall pay the pertinent provisions for basic pension insurance, unemployment insurance, maternity insurance, workplace injury insurance and basic medical insurance for the employees. We have caused all of our full-time employees to enter into written labor contracts with us and have provided and currently provide our employees with the proper welfare and employment benefits.
Regulations on Overseas Listing by Domestic Companies—mainland China
According to the Trial Administrative Measures of the Overseas Securities Offering and Listing by Domestic Companies, or the Overseas Listing Trial Measures and relevant five guidelines, PRC companies that seek to offer and list securities in overseas markets, either directly or indirectly, have to file with the CSRC. Pursuant to a press conference held by CSRC for the release of the Overseas Listing Trial Measures and the issuance of the Notice on Administration for the Filing of Overseas Offering and Listing by Domestic Companies, PRC companies who had already completed the overseas securities offering and listing before March 31, 2023, are not required to file with CSRC immediately but shall file with CSRC in due course in case of any activities such as follow-on financing in the future that shall be filed with CSRC according to the Overseas Listing Trial Measures.
Given the uncertainty of the interpretation and implementation of the Overseas Listing Trial Measures and our global operations, substantial uncertainties remain, and we could not rule out the possibility that we may be required to file the relevant documents with the CSRC in connection with our proposed offerings and listings outside mainland China in the future.
82
Table of Contents
According to the Provisions on Strengthening Confidentiality and Archives Administration of Overseas Securities Offering and Listing by Domestic Companies, a PRC domestic company must obtain approvals and make filings with the authorities when providing or publicly disclosing, by itself or through the overseas listing entity, any document or material that involves state secret or state organs work secret. In addition, pursuant to this circular, any investigation, collection of evidence or inspection targeting China-based issuers, securities companies and security service institutions proposed by overseas securities regulatory authorities and the competent departments must be carried out through cross-border regulatory cooperation mechanism and obtain approval from the CSRC or the competent departments.
In addition, the Measures for Cybersecurity Review, among others, (i) a “network platform operator” holding over one million users’ personal information shall apply for a cybersecurity review when listing their securities “in a foreign country”, (ii) a critical information infrastructure operator that intends to purchase internet products and services that affect or may affect national security should apply for a cybersecurity review, and (iii) a “network platform operator” carrying out data processing activities that affect or may affect national security should apply for a cybersecurity review.
Meanwhile, according to the 2024 Negative List, where a domestic enterprise engaging in the prohibited business in the 2024 Negative List issues and lists shares overseas for trading, it shall obtain the approval of the relevant competent department of the state, and the overseas investor shall not participate in the operation and management of the domestic enterprise, and its shareholding ratio shall be subject to the relevant provisions on the administration of domestic securities investment by overseas investors.
83
Table of Contents
C. Organizational Structure
Corporate Structure
The following diagram illustrates our corporate structure as of the date of this annual report, including our significant subsidiaries and the primary operating variable interest entities and their significant subsidiaries:
Note:
(1) Guangzhou BaiGuoYuan is a variable interest entity with which we maintain contractual arrangements. Guangzhou BaiGuoYuan is wholly owned by Guangzhou Qianxun Network Technology Co., Ltd., which is in turn owned by Guangzhou Fangu Network Technology Partnership (LP) and Guangzhou Wanyin Network Technology Partnership (LP), each holding 50% of equity interest in Guangzhou Qianxun Network Technology Co., Ltd. We also enter into contractual arrangements with the nominee shareholders of the variable interest entities and other stakeholders in order to enhance the stability and proper governance of the variable interest entities. For details, see “Item 7. Major Shareholders and Related Party Transactions—B. Related Party Transactions—VIE Structure and the Contractual Arrangements.”
84
Table of Contents
D. Property, Equipment and Land Use Right
Our corporate headquarters is located in 30 Pasir Panjang Road #15-31A Mapletree Business City, Singapore 117440. We have leased office space across the globe with an aggregate area of 40,849 square meters.
The corporate headquarters of BIGO are located at the same premises in Singapore. BIGO also has local offices in the United States, the United Kingdom, Japan, South Korea, Australia, Malaysia, Indonesia, Jordan, mainland China, and many other regions. As of the date of this annual report, BIGO has leased office space with an aggregate area of 22,456 square meters. BIGO’s physical servers are primarily hosted at internet data centers located in Singapore, among others.
We own the use right of several parcel of lands and several buildings located in mainland China. As of December 31, 2025, the parcels of land to which we own use right and the buildings we acquired had an aggregate area of 175,847 square meters. We are conducting construction of buildings on a parcel of land located in Foshan to which we acquired use right in April 2021. Our capital commitment in connection with the construction of buildings located on such parcel was US$68.6 million as of December 31, 2025. We currently expect to complete the planned construction in Foshan in 2026.
We believe that our existing facilities, including facilities under construction, are sufficient for our current and prospective needs in the foreseeable future and we will obtain adequate facilities, principally through leasing, to accommodate our future expansion plans.
See Notes 13 and 14 to our audited consolidated financial statements included elsewhere in this annual report for further information about our property and equipment and land use right.