Vietnam Vietnam data localisation cybersecurity decree

Vietnam's Consolidated Cybersecurity Law Keeps Data Localisation Intact While Cleaning Up the Statute Book

Law No. 116/2025/QH15, in force since July 1, merges two cybersecurity statutes but preserves mandatory local data storage and branch offices for foreign platforms.

Vietnam's Cybersecurity Law, By the Numbers People of Internet Research · Vietnam $72.1B Digital economy value 2025 14.02% of GDP, per Vietnam's Minis… 24 hrs Standard takedown deadline Cut to 6 hours for urgent content … 15% Minimum cybersecurity budget share Floor on state digital-transformat… peopleofinternet.com
Vietnam's Cybersecurity Law, By the Nu… People of Internet Research · Vietnam $72.1B Digital economy value 2025 24 hrs Standard takedown deadline 15% Minimum cybersecurity bu… peopleofinternet.com

Key Takeaways

Vietnam's Law on Cybersecurity No. 116/2025/QH15 took effect on July 1, 2026, replacing both the 2018 Law on Cybersecurity and the 2015 Law on Network Information Security with a single statute. The National Assembly passed the law on December 10, 2025, and the consolidation is, on its own terms, a genuine piece of legislative housekeeping: for eight years Vietnamese regulators and the foreign platforms operating in the country had to read two overlapping frameworks — one on "cybersecurity," one on "cyber-information safety" — side by side, often reconciling inconsistent definitions of the same conduct. Folding them into one law with a unified vocabulary is the kind of technical clean-up that reduces compliance ambiguity without anyone having to win an ideological argument.

What Actually Changed for Foreign Platforms

The substance did not shrink to match the tidier form. Article 25(3) of the new law requires domestic and foreign enterprises that "collect, exploit, analyse or process" the personal data, user-relationship data, or user-generated data of people in Vietnam to store that data inside the country, and requires foreign enterprises meeting that threshold to "establish a branch or representative office in Vietnam." Article 1(2) extends the law's reach beyond entities physically operating in Vietnam to foreign agencies, organisations, and individuals "directly participating in or connected with" cybersecurity protection activities or the cybersecurity products-and-services business inside the country — an extraterritorial hook that gives Vietnamese authorities a textual basis to assert jurisdiction over conduct that touches Vietnamese users without ever touching Vietnamese soil.

These are not new ideas in Vietnamese law — Decree 53/2022, issued under the 2018 statute, already imposed local-storage and local-presence duties on a defined set of foreign digital service providers. What Law 116/2025/QH15 does is elevate those duties from decree level to primary legislation and fold them into a single, harder-to-amend framework, while adding sharper operational teeth: platforms and telecom/internet providers face 24-hour standard deadlines (6 hours in urgent cases) to remove content the Ministry of Public Security deems unlawful, and 24-hour deadlines (3 hours in emergencies) to hand over user information on request.

The Steelman: Vietnam Has Real Stakes Here

Before dismissing this as reflexive digital protectionism, it's worth taking the government's stated rationale seriously. Vietnam's digital economy contributed an estimated $72.1 billion — 14.02% of GDP — in 2025, according to figures the Ministry of Science and Technology gave at a June 1, 2026 press briefing. A market that size, growing at double-digit rates, is also a market that size for fraud, deepfake-enabled scams, and child-safety harms, all of which the new law explicitly targets with expanded prohibited-acts provisions and dedicated child-protection duties. A government overseeing a fast-digitising economy of 100 million people has a legitimate interest in knowing where its citizens' data physically sits and in having a domestic legal entity it can serve process on when something goes wrong — the same logic that underpins, in less sweeping form, data-residency rules in the EU's financial-services sector or India's payment-data localisation mandate. And mandating that at least 15% of every state digital-transformation and IT budget go toward cybersecurity protection, another feature of the new law, is a defensible floor for public-sector systems that have historically underspent on defence relative to feature delivery.

Where Proportionality Breaks Down

The problem is not that Vietnam regulates; it's the layering. Vietnam's Personal Data Protection Law took effect January 1, 2026, with its own consent, breach-notification, and cross-border-transfer regime. Foreign providers must now run two compliance perimeters — a privacy law optimised around individual rights and a cybersecurity law optimised around state access and data sovereignty — that were drafted by different ministries on different timelines and do not fully share a vocabulary. A mid-sized SaaS or fintech provider from Singapore or South Korea now has to stand up a Vietnamese branch, localise storage, and staff a compliance function capable of responding to a content-takedown order within six hours, purely to serve a market where it may generate a small fraction of global revenue. That cost structure does not scale down for smaller entrants the way it does for Meta, Google, or TikTok, which can absorb Vietnam-specific engineering as a rounding error. The practical effect is to raise the floor for market entry in exactly the segment — mid-tier digital services — that Vietnam's own digital-economy growth targets depend on attracting.

The six-hour and three-hour turnaround windows carry a second-order risk that has less to do with foreign investment and more to do with speech: a platform threatened with penalties for missing a same-day takedown deadline has every incentive to comply first and litigate never, particularly where the law's "unlawful content" categories reach political and reputational speech alongside fraud and child-safety material. Legal frameworks that compress judicial review out of the content-moderation loop tend to produce over-removal as the rational compliance strategy, not because platforms agree with every order but because the cost of resisting one exceeds the cost of deleting first.

A Narrower Path Existed

None of this required abandoning data sovereignty as a goal. Vietnam could have retained Decree 53's narrower localisation trigger — tied to specific high-risk sectors or a revenue/user-count threshold — rather than writing an open-ended "collect, exploit, analyse or process" standard into primary law that captures nearly every digital service by default. It could have built in an independent appeals mechanism for takedown and data-access orders before hardening six-hour compliance windows into statute. Consolidation was the right call; using it as the vehicle to lock in the more expansive version of the localisation mandate, rather than the narrower one the country has actually been enforcing, was not.

Sources & Citations

  1. Law on Cybersecurity No. 116/2025/QH15 (English text)
  2. Vietnam Government Portal — new provisions in Law 116/2025/QH15
  3. MLex — Vietnam tightens data localization rules
  4. Allen & Gledhill — Vietnam's new Cybersecurity Law
  5. VietnamPlus — digital economy surpasses $72B in 2025