Vietnam Vietnam data localisation cybersecurity decree

Vietnam's Decree 333 Keeps Its 2022 Data Localisation Model, and Decree 330's Revenue-Based Fines Raise the Cost of Getting It Wrong

Vietnam's new cybersecurity decrees keep a conditional 24-month localisation duty and add fines of up to 5% of Vietnam revenue where cross-border transfers cause data loss.

Vietnam's Conditional Localisation Regime People of Internet Research · Vietnam 24 months Minimum data storage Minimum period foreign firms must … 12 months Time to comply Deadline to store data and open a … 5% Maximum cross-border fine Cap on prior-year Vietnam revenue … 3 in 6 months Written requests before trigger Cooperation requests that form par… peopleofinternet.com
Vietnam's Conditional Localisation Reg… People of Internet Research · Vietnam 24 months Minimum data storage 12 months Time to comply 5% Maximum cross-border fine 3 in 6 months Written requests before trigger peopleofinternet.com

Key Takeaways

What changed on 19 August

Vietnam's National Assembly adopted Cybersecurity Law No. 116/2025/QH15 on 10 December 2025, and it took effect on 1 July 2026, according to the government's policy portal. Implementing decrees followed. Decree 333/2026/ND-CP and Decree 330/2026/ND-CP both took effect on 19 August 2026, per Rajah & Tann's summary of the implementing decrees.

The localisation rules in Decree 333 are not new in substance. Law-firm summaries describe the same architecture as the 2022 regime: foreign enterprises in a list of services must store Vietnamese users' data in Vietnam for a minimum of 24 months, and open a local branch or representative office, within 12 months of a Ministry of Public Security (MPS) decision. The listed services include telecoms, data storage, e-commerce, online payment, social media, online games and online applications (DFDL). Online applications are the express addition DFDL highlights.

The strongest case for the rule

The case for Vietnam's approach deserves a fair hearing. A government that cannot compel a foreign platform to answer a lawful request has few tools short of blocking it. Localisation, a local office and a fixed retention window give investigators a legal counterparty and a data trail when a service is used for fraud, scams or other crimes. Vietnam is not alone in wanting enforcement reach over firms that operate in its market without a presence there. The design also has a notable restraint: the duty is conditional, not universal.

What the text actually conditions

That conditionality is the most important detail, and it is easy to lose in headlines. Under Decree 53/2022, the predecessor, the published text sets the minimum storage period at 24 months (Article 27) and gives foreign enterprises 12 months from the Minister of Public Security's decision to comply (Article 26). A foreign firm is caught only if its service was used for cybersecurity violations, it was notified in writing and it failed to comply, and the minister then issues a formal decision.

Rajah & Tann reports that Decree 333 keeps this structure. Foreign firms are not covered "solely by virtue of providing that service". The enforcement conditions include up to three written requests for cooperation over a period of up to six months, plus a failure to remedy, comply fully, or an obstruction. Covered data includes users' personal information and specified user-created data such as account names, usage times and login IP addresses (DFDL).

So the 24-month duty is a sanction-like remedy, not a blanket mandate. That is better than a flat requirement that every foreign service host all data onshore. But it also means that the practical scope depends on how often and how broadly the MPS chooses to trigger it. Our reading of the summaries is that the decree text, not the headline, should guide any compliance plan. We could not retrieve the full text of Decree 333 itself, so the details above rest on law-firm summaries.

Where Decree 330 changes the incentives

The new element is the penalty regime. Decree 330 sets fines of up to 5% of an organisation's revenue generated in the Vietnamese market in the preceding financial year where unlawful cross-border transfers lead to leakage or loss of personal data, per Rajah & Tann. The summary says the top band of 3% to 5% applies where a violation affects one million or more Vietnamese data subjects, or where a transfer continues after a stop order and harms national defence or security.

Revenue-based caps are familiar from GDPR-style regimes, and a percentage of local revenue is at least tied to the firm's footprint in the market, rather than its global turnover. That is a proportionality feature worth crediting. Still, the cap sits atop a framework in which a firm's exposure depends on a government decision to start the localisation process and on a cross-border transfer assessment that Law 116/2025 introduced for the first time, as the government portal notes.

The innovation cost

The pro-innovation concern is not that Vietnam wants lawful access to data. It is that the tools are blunt and the triggers are discretionary.

What to watch

Vietnam deserves credit for keeping the localisation duty conditional and for pegging fines to local revenue. The next test is practice. Regulators should publish how they count the "three requests", set out what counts as adequate remediation, and give firms a clear route to challenge an MPS decision before the 12-month clock starts. A rule that is narrow on paper but broad in application would hurt the open, competitive digital economy Vietnam is trying to build, without improving security.

Sources & Citations

  1. Vietnam Government policy portal: new content of Cybersecurity Law 116/2025/QH15
  2. Decree 53/2022/ND-CP full text (Government portal)
  3. Rajah & Tann: seven decrees implementing Vietnam's cybersecurity framework
  4. DFDL: Vietnam rolls out new cybersecurity decrees