Vietnam Vietnam data localisation cybersecurity decree

Vietnam Fast-Tracks a Data Security Law That May Collide With Its Own Trade Commitments

PM Le Minh Hung ordered an October 2026 National Assembly vote on a law that would ban core-data exports and require police approval for transfers of 'important' data.

Vietnam's Data Security Law, By the Numbers People of Internet Research · Vietnam Oct 2026 National Assembly vote deadline PM Le Minh Hung ordered the draft … 5% Maximum revenue-based fine Proposed administrative fines reac… 34 Provinces linked to steering meeting All 34 Vietnamese provinces and ci… ~79.8M Users affected by Telegram block Vietnam blocked Telegram nationwid… peopleofinternet.com
Vietnam's Data Security Law, By the Nu… People of Internet Research · Vietnam Oct 2026 National Assembly vote deadline 5% Maximum revenue-based fi… 34 Provinces linked to steering meet… ~79.8M Users affected by Telegram block peopleofinternet.com

Key Takeaways

A Rushed Fourth Layer of Data Law

On August 6, 2026, Prime Minister Le Minh Hung — chairing the second 2026 meeting of the National Cybersecurity Steering Committee in Hanoi, linked virtually to cybersecurity subcommittees in all 34 provinces and cities — ordered the Ministry of Public Security to "expedite completing the draft Law on Data Security dossier for National Assembly ratification in the second session," set for October 2026 (Chinhphu.vn, Aug 6, 2026). He paired that instruction with a directive to build a National AI Security Framework and specialized AI-security capacity by 2027, and interim state-agency AI guidelines by the end of 2026. Framing the stakes, Hung told the committee that cyber competition today is really "control over data, digital platforms, standards, supply chains, computing capacity, artificial intelligence, and cryptography" (Chinhphu.vn, Aug 6, 2026).

That is not a small ask. This would be Vietnam's fourth statutory data regime in under two years, layered on the Personal Data Protection Law (effective January 1, 2026) and the Law on Cybersecurity No. 116/2025/QH15, which itself only takes effect July 1, 2026 and already imposes data-localization duties on platforms handling Vietnamese user data (Rajah & Tann Asia). The draft Data Security Law would go further: it classifies all data into ordinary, internal, important, and core tiers, permanently bars cross-border transfer of core data, and requires Ministry of Public Security sign-off before any "important" data leaves the country.

The Case for Moving Fast

Vietnam's urgency is not manufactured. The country has been a live target: it blocked Telegram nationwide in May 2025 over noncompliance with data and content requests, an action that cut off roughly 79.8 million internet users from the platform and signaled Hanoi's willingness to use blunt instruments when regulatory cooperation fails. A government that has watched ransomware, cross-border fraud rings, and AI-enabled disinformation escalate has a legitimate interest in knowing where its citizens' data physically sits and who can compel access to it — especially for data tied to critical infrastructure, health systems, or state administration. Consolidating that authority under one law, rather than the current patchwork of decrees, is a defensible instinct on its face, and the Steering Committee's parallel push for an AI security framework reflects a reasonable read that generative AI has outpaced Vietnam's existing cyber rules.

Where the Draft Overreaches

The problem is what the draft actually does, not the impulse behind it. Vietnam ratified the CPTPP, which explicitly bars data localization mandates among member states. A law that permanently forecloses core-data exports and inserts a police ministry into approval of important-data transfers sits in direct tension with that treaty text — a gap regional trade officials have already flagged. Japan's Ministry of Economy, Trade and Industry is watching Vietnam's compliance consistency, and the US Chamber of Commerce, AmCham Hanoi, and the Asia Internet Coalition jointly warned the Prime Minister that the rules would "significantly affect investment." BSA's Asia-Pacific policy director told Nikkei Asia that data localization "puts companies at a competitive disadvantage" and predicted firms would simply reroute infrastructure investment to Singapore, Malaysia, or Indonesia instead.

The enforcement teeth make the stakes concrete: administrative fines up to 5% of a firm's prior-year Vietnamese revenue for unauthorized transfers, plus new criminal offenses for data infringement and "obstructing protection activities" — a phrase broad enough to chill routine compliance disputes. Multinationals already juggling a localization review under Decree 53/2022, cross-border assessments under Decree 356, and important-data review under Decree 165/2025 would now face a fourth, undefined layer, with no stated mechanism to reconcile overlapping obligations. That is not a regulatory gap closing; it is a compliance maze widening, and small and mid-sized foreign entrants — the firms least able to absorb duplicative legal review — bear the disproportionate cost.

A Six-Week Runway Is Too Short

The deeper issue is process, not just substance. The Ministry of Justice only released its assessment of the draft dossier on July 13, 2026, giving businesses roughly six weeks before the October National Assembly session where the PM has ordered a vote. A law creating criminal offenses and revenue-based fines, touching every foreign platform operating in Vietnam, deserves a comment period longer than a single legislative quarter — particularly one that risks a direct treaty conflict Hanoi will eventually have to answer for in a CPTPP dispute-settlement forum.

None of this argues against a data security law. It argues for one that defines "important" and "core" data narrowly enough that compliance teams can actually classify their holdings, that reconciles rather than stacks atop the three regimes already in force, and that gives the National Assembly — and the businesses it will bind — enough runway to test the draft against Vietnam's own trade commitments before the vote, not after.

Sources & Citations

  1. Chinhphu.vn — PM on AI security framework, Data Security Law timeline
  2. Chinhphu.vn — PM Le Minh Hung on cybersecurity priorities
  3. Nhan Dan — PM urges stronger cybersecurity coordination
  4. Rajah & Tann Asia — Vietnam Law on Cybersecurity 2025/2026
  5. Indoneo — Vietnam's data law export ban vs. CPTPP