Vietnam's Law on Cybersecurity No. 116/2025/QH15 took effect on July 1, 2026, replacing two overlapping statutes — the 2018 Law on Cybersecurity and the 2015 Law on Network Information Security — with a single framework that reaches well beyond Vietnam's borders. Passed by the National Assembly on December 10, 2025, the law applies not only to domestic firms but to "foreign agencies, organisations and individuals" doing business in cybersecurity-adjacent products and services in Vietnam, under Article 1(2). For any global platform with Vietnamese users, that is a wide net.
What the Law Actually Requires
Three provisions matter most for foreign providers. First, Article 25(3) requires foreign enterprises that collect personal data in Vietnam to store that data locally for a period the government will fix by decree, and to establish a branch or representative office in the country. Second, Article 25(2) imposes a hard content-moderation clock: platforms must remove content flagged by the Ministry of Public Security within 24 hours of request, compressed to 6 hours in cases the ministry deems a national-security emergency, and must hand over user information within a similar 24-hour/3-hour window. Third, the law formally designates "national cyberspace" as sovereign Vietnamese territory, layering a jurisdictional claim on top of the compliance mandate (LuatVietnam English translation).
The government's own policy portal describes this as a deliberate shift "from a voluntary coordination mechanism to mandatory legal obligations that apply uniformly to domestic and foreign enterprises," alongside a five-tier risk classification for information systems and a rule that critical-system operators dedicate at least 15% of digital-transformation project budgets to cybersecurity (Chính phủ policy portal).
The Case for It
Before arguing against the law, it is worth taking Hanoi's justification seriously. Vietnam has one of the fastest-growing internet economies in Southeast Asia, and its regulators point to real harms: AI-generated deepfake fraud targeting the elderly, unregulated trading of stolen personal data, and critical infrastructure — power grids, banking rails, ports — that foreign cloud dependence makes harder to audit or secure in a crisis. A government that cannot compel a platform to preserve evidence or remove harmful content quickly has limited tools against fast-moving cyber-enabled fraud, and a country sitting geopolitically between larger powers has a legitimate interest in knowing where its citizens' data physically resides. Consolidating two overlapping 2015- and 2018-era statutes into one law, as the government describes it, also removes a genuine source of regulatory confusion that both domestic and foreign compliance teams had flagged for years.
Where the Law Overreaches
The problem is not that Vietnam wants faster takedowns or better-audited critical systems — proportionate versions of both are reasonable. The problem is that data localization and mandatory local incorporation function less like security requirements and more like a market-access toll. The Business Software Alliance, in comments on the draft framework, warned that mandating local storage and a physical Vietnamese branch "can frustrate efforts to implement effective security measures, protect data, and defend critical networks, just as they can impede business innovation and limit services available to consumers," and urged Hanoi to either drop the localization requirement or clarify it so firms retain the freedom to use international cloud infrastructure (MLex).
That critique holds up under scrutiny. Forcing every foreign data-handling enterprise to stand up local servers and a registered office is a fixed cost that scales inversely with company size: Meta, Google, and Amazon can absorb it as a line item, while a mid-sized SaaS company, fintech, or AI startup weighing entry into a market of roughly 100 million people may simply decide it isn't worth it. The predictable result is a Vietnamese digital market with the same handful of entrenched incumbents and fewer of the smaller, more specialized challengers that usually drive down prices and push in better privacy and security features — the opposite of the innovation dividend openness normally provides.
The 24-Hour Clock Problem
The takedown timeline compounds this. A 24-hour global compliance window, compressible to 6 hours at the Ministry of Public Security's discretion for loosely defined "national security" matters, does not leave room for the kind of human review that distinguishes genuine illegal content from lawful political speech or commentary the state simply dislikes. Firms facing a 6-hour deadline and the threat of losing market access will rationally over-comply — pulling borderline content automatically rather than risk penalty. That is a predictable, structural incentive toward the kind of restriction Vietnam's own 2018 cybersecurity law was already criticized for.
What to Watch
The substantive detail — how long data must be retained locally, which enterprises are exempt, and how "national security emergency" gets defined in practice — sits in an implementing decree the government has not yet finalized. That decree, not the statute's headline provisions, will determine whether Vietnam has built a genuinely proportionate cybersecurity regime or a compliance moat that quietly protects incumbents while narrowing what Vietnamese users are allowed to see.