What changed on 19 August
Vietnam's National Assembly adopted Cybersecurity Law No. 116/2025/QH15 on 10 December 2025, and it took effect on 1 July 2026, according to the government's policy portal. Implementing decrees followed. Decree 333/2026/ND-CP and Decree 330/2026/ND-CP both took effect on 19 August 2026, per Rajah & Tann's summary of the implementing decrees.
The localisation rules in Decree 333 are not new in substance. Law-firm summaries describe the same architecture as the 2022 regime: foreign enterprises in a list of services must store Vietnamese users' data in Vietnam for a minimum of 24 months, and open a local branch or representative office, within 12 months of a Ministry of Public Security (MPS) decision. The listed services include telecoms, data storage, e-commerce, online payment, social media, online games and online applications (DFDL). Online applications are the express addition DFDL highlights.
The strongest case for the rule
The case for Vietnam's approach deserves a fair hearing. A government that cannot compel a foreign platform to answer a lawful request has few tools short of blocking it. Localisation, a local office and a fixed retention window give investigators a legal counterparty and a data trail when a service is used for fraud, scams or other crimes. Vietnam is not alone in wanting enforcement reach over firms that operate in its market without a presence there. The design also has a notable restraint: the duty is conditional, not universal.
What the text actually conditions
That conditionality is the most important detail, and it is easy to lose in headlines. Under Decree 53/2022, the predecessor, the published text sets the minimum storage period at 24 months (Article 27) and gives foreign enterprises 12 months from the Minister of Public Security's decision to comply (Article 26). A foreign firm is caught only if its service was used for cybersecurity violations, it was notified in writing and it failed to comply, and the minister then issues a formal decision.
Rajah & Tann reports that Decree 333 keeps this structure. Foreign firms are not covered "solely by virtue of providing that service". The enforcement conditions include up to three written requests for cooperation over a period of up to six months, plus a failure to remedy, comply fully, or an obstruction. Covered data includes users' personal information and specified user-created data such as account names, usage times and login IP addresses (DFDL).
So the 24-month duty is a sanction-like remedy, not a blanket mandate. That is better than a flat requirement that every foreign service host all data onshore. But it also means that the practical scope depends on how often and how broadly the MPS chooses to trigger it. Our reading of the summaries is that the decree text, not the headline, should guide any compliance plan. We could not retrieve the full text of Decree 333 itself, so the details above rest on law-firm summaries.
Where Decree 330 changes the incentives
The new element is the penalty regime. Decree 330 sets fines of up to 5% of an organisation's revenue generated in the Vietnamese market in the preceding financial year where unlawful cross-border transfers lead to leakage or loss of personal data, per Rajah & Tann. The summary says the top band of 3% to 5% applies where a violation affects one million or more Vietnamese data subjects, or where a transfer continues after a stop order and harms national defence or security.
Revenue-based caps are familiar from GDPR-style regimes, and a percentage of local revenue is at least tied to the firm's footprint in the market, rather than its global turnover. That is a proportionality feature worth crediting. Still, the cap sits atop a framework in which a firm's exposure depends on a government decision to start the localisation process and on a cross-border transfer assessment that Law 116/2025 introduced for the first time, as the government portal notes.
The innovation cost
The pro-innovation concern is not that Vietnam wants lawful access to data. It is that the tools are blunt and the triggers are discretionary.
- Discretion without a public threshold. Three written requests in six months is a procedural trigger, not a harm test. Nothing in the summaries ties the duty to the seriousness of the underlying violation.
- Fixed cost for small entrants. A startup that serves Vietnamese users from abroad faces the same 24-month storage and local-presence demand as a global platform. A branch or representative office is cheap for a large firm and a real burden for a small one.
- Localisation is not security. Storing data in-country does not by itself make it safer, and it can fragment infrastructure. Targeted, court-supervised access orders and mutual legal assistance reach the same enforcement goal with less collateral cost.
- Penalty stacking. Percentage-of-revenue fines combined with a localisation order give regulators a lot of leverage over a single firm. Appeal routes and published enforcement criteria matter as much as the cap.
What to watch
Vietnam deserves credit for keeping the localisation duty conditional and for pegging fines to local revenue. The next test is practice. Regulators should publish how they count the "three requests", set out what counts as adequate remediation, and give firms a clear route to challenge an MPS decision before the 12-month clock starts. A rule that is narrow on paper but broad in application would hurt the open, competitive digital economy Vietnam is trying to build, without improving security.