You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 24, 2025

Draft Guidance on Vietnam’s New Data Law Open for Public Consultation

Following Vietnam’s adoption of the new Law on Data (“Data Law”) on November 30, 2024, there remained uncertainty as to what impact the new framework would have on businesses in Vietnam and abroad. The government has now released a package of four draft legal documents aimed at guiding the implementation of the Data Law: (1) a decree on the National Data Development Fund (“NDDF Decree”), (2) a decree related to regulations on scientific, technological, and innovation activities and data products and services (“Decree on Specific Activities”), (3) a decree detailing a number of articles and measures to implement the Data Law (“Implementation Decree”), and (4) a decision on the lists of important data and core data. This article will provide an overview of the draft legislation.

1. NDDF Decree

The draft NDDF Decree relates to the establishment, management and use of a National Data Development Fund (“NDDF”), which is a non-profit and non-budgetary state financial fund established and managed by the Minister of the Ministry of Public Security (MPS). The NDDF has legal personality and is fully state owned, operating similarly to a single-member limited liability company. Its main objectives are to support, promote, and invest in artificial intelligence (AI), the Internet of Things (IoT), and other new technologies and innovation.

The NDDF may lend to, invest in, or otherwise support eligible organizations. The draft NDDF Decree also proposes a series of regulations on donations to the NDDF and from the NDDF (through expense support), the lending activities of the NDDF to commercial banks, which will in turn lend to eligible organizations, the investment activities in data products and services innovative start-ups, and other kinds of support.

The government commits to provide VND 1 trillion (approx. USD 40 million) to the NDDF, evidencing the importance the government places on fostering a thriving ecosystem for data product and service development, and its wish to position Vietnam as a center of innovation. However, the NDDF also intends to rely on donations. It remains to be seen whether the NDDF will operate effectively to boost the technology and data-related developments.

2. Decree on Specific Activities

The Decree on Specific Activities focuses on two main matters: regulations related to data products and services, and the creation of a regulatory sandbox to foster innovation.

Data Products and Services

The chapter on data intermediary products and services of the draft Data Law had been stripped down before enactment. The details are now prescribed in this draft decree under Chapter III, covering (i) data intermediary products and services, (ii) data analysis and aggregation services, and (iii) data marketplaces.

Data intermediary activities have now been clarified and include, among others, activities of representing data subjects and data owners to connect, share, exchange, and access data with service users; data management services; data cooperation and sharing services; etc.

Providers of data intermediary products and services between the service users and the state agencies must be fully registered and licensed, while other service providers can request the MPS to appraise them to unlock the same benefits as enterprises operating in high-tech, innovative, creative start-ups and the digital technology industry.

Further, the draft Decree on Specific Activities creates new personal data protection obligations for providers of data intermediary products and services, while personal data is not the main object of the Data Law. Among the new requirements, the obligation to limit the transfer of personal data abroad and ensure that the standard of protection is equivalent to the standard required by relevant laws has been inserted. As the government is currently developing the Personal Data Protection Law (more details here), it is unclear why it is also inserting such provision under the Data Law framework.

Businesses engaged in data intermediary products and services or data analysis and aggregation will need to take into account the personnel requirements that are reinserted in the draft Decree on Specific Activities. The head of the organization must be a Vietnamese citizen and permanent resident, with a university degree, who has directly managed a large scale data center and has at least three years of experience related to data management. This poses a significant issue for industry players, considering talent is scarce on the global scene, and in Vietnam. Further, the requirement for a minimum charter capital has been replaced by a mandatory deposit in a commercial bank operating in Vietnam of VND 5 billion (approx. USD 200,000). It is still unclear whether the cross-border provision of such products and services is possible and whether foreign businesses would be subject to the same requirements. The same requirements will apply to data marketplace service providers, but this is likely to pose lesser problems considering this business activity is restricted to non-business units or state-owned enterprises.

Data analysis and aggregation services are now categorized into four levels depending on the level of human supervision and the role of the products and services in the decision-making process. Licensing requirements will apply to automated decision-making, with or without human supervision, and to products and services using data from national databases. Here again, to unlock incentives, an organization that is not subject to the licensing requirements can request the MPS to conduct an appraisal. Biannual or annual reports on service provision must be sent to the management agency, based on a statutory form.

Data marketplace service providers include providers of data auction services, but also services to provide an environment for data trading and exchange and data-related product and services, and other services related to bidding, offering, introducing, representing, supporting and other activities related to data trading. Such data marketplace service providers must ensure that the channels to receive information and the use of the services are continuous 24/7, and publicly display service charges, prices, terms of use, and applicable conditions. They must also report biannually or annually to the management agency. All data products on the data marketplace must be authenticated with data origins. Organizations and individuals are responsible for the contents they post on data marketplaces and cannot auction at a price lower than the input fee for data products and services, ensuring fair competition. It is still unclear how private organizations will be able to leverage their data with these new marketplaces.

Regulatory Sandbox

Th draft Decree on Specific Activities also suggests the establishment of the necessary regulatory framework for a sandbox for research and application of science, technology, and innovation in the construction, development, protection, administration, processing and use of data as foreshadowed by Article 24.4 of the Data Law. This sandbox would be created to promote research and create a testing environment to assess the risks, costs and benefits of innovative products and services while limiting the risk to users of such products and services.

Participating in the sandbox is subject to being granted a certificate of testing activities – details of the application procedure being further described in the draft decree. The right to participate in the sandbox does not equal the right to provide the innovative products and services on the market. For any organization that is not allowed to participate in the sandbox, they are still encouraged to innovate but must do so within the applicable regulations at the time.

The draft Decree on Specific Activities sets out the obligations and the rights of the participating organizations, but also creates exemptions from liability with the aim to encourage innovation and creativity. The Ministry of Science and Technology is notably tasked to formulate detailed regulations on such exceptions, and other mechanisms and policies to foster innovation in Vietnam.

The government’s intention appears to be giving priority to innovative solutions in AI, cloud computing, blockchain, data communication, IoT, big data and other modern technologies. The draft decree notably suggests incentives to attract talent and FDI in these sectors.

3. Implementation Decree

The draft Implementation Decree provides clarification on many outstanding issues pursuant to the Data Law, notably (i) the mandatory provision of data to state agencies upon request, (ii) the cross-border transfer of data, and (iii) data protection measures.

Mandatory Provision of Data to State Agencies

The procedure applicable to the provision of data to state agencies upon request has been clarified to a certain extent. The draft Implementation Decree sets out that ministers, heads of ministerial level agencies, and presidents of provincial-level People’s Committees are competent to request data from organizations, ensuring such requests are emanating from a high-level rank. Such requests must be made in writing, unless it is impossible, and must specify the data requested, the purpose, the processing period, the legal basis for the request, the time limit to provide the data and the sanction for not providing such data. The data handover must be recorded in minutes. However, the organization receiving the request has the right to request amendment or withdrawal of the request. The extent of the data that can be requested has not been further limited or clarified, but the requesting agencies must respect the lawful purpose of the data manager and data owner and must protect business secrets and personal secrets.

Cross-Border Transfer of Data

With an aim to clarify what is included in the definition of “core” and “important” data, the Implementation Decree provides criteria to determine the category of the data, based on its degree of impact on a specific field, group, or region that may have an impact on national defense, security, foreign affairs, macroeconomics, social stability, or public health and safety (excluding trade secrets).

“Core data” will notably comprise some sensitive governmental information like guidelines and policies of the Vietnamese Communist Party and the state on domestic and external relations; strategies and plans to protect the fatherland; organization and operations of the armed forces; data on plans for collection, exchange, and issuance of money; data on natural resources and the environment, and newly discovered microbial strains and varieties related to human health and life; processes to produce medicinal herbs and rare biological drugs; and data on inspection, examination, denunciation and prevention of corruption.

“Important data” will notably comprise information that may affect national security, the Vietnamese Communist Party, the state and the socialist regime, major overseas projects, safety of overseas energy sources, security of international cooperation, infrastructure of important economy sectors; and the life, health, honor, dignity, property, and legitimate rights of organizations and individuals. The latter being very broad, as further discussed in section (4) regarding the Decision below. Due attention should be paid to the development of the Implementation Decree and the Decision to ensure that it does not impede the free flow of data, considering Vietnam’s commitment not to restrict data flows under numerous international treaties and agreements.

The transfer of core and important data outside of Vietnam is subject to additional requirements, notably the data owner must conduct a risk assessment and establish an impact assessment dossier. For core data, the transfer can only be made once the “satisfactory assessment results” have been obtained from the MPS or the Ministry of National Defense, as the case may be. For important data, the transfer can be made when the assessment is submitted and the transferor has not received objection from the authorities within the regulated timeline, but the MPS and the Ministry of National Defense can request the data transferor to stop the transfer if the impact assessment is not sufficiently supplemented following such request from the authorities. An important point to note is that the draft Implementation Decree also restricts the disclosure of data domestically by imposing other impact assessment requirements, with stricter regulations being proposed for the sharing of core and important data.

Further, notwithstanding the category of data being transferred abroad, the data transferor must ensure the protection of the legitimate rights and interest of the data subject, national defense and security, and national interests and public interests. It must also enter into an agreement with the recipient, in which mandatory content has finally been clarified.

Data Protection Measures

Additional guidance is also provided on the measures to implement risk management related to data processing with lists of technical and organizational measures being proposed. This has long been requested by the private sector to better understand the expectations of the authorities in terms of data protection. Consequently, core and important data are subject to additional security measures. This multi-layered approach to data protection aligns with international standards and ensures that measures are implemented in accordance with the sensitivity of the related data.

In addition, the draft Implementation Decree provides that, when the data owner needs to transfer data in the context of merger, reorganization, or bankruptcy, such data owner needs to prepare a plan for such transfer and to notify impacted users via phone call, text message, email, or notice.

It is worth noting that many of the measures being imposed are inspired by best practices in personal data protection (e.g., record of processing activities, access controls, training of employees, proper deletion and destruction procedures, etc.). Although one would understand why such measures would be relevant in the case of core and important data, the requirements would be very burdensome for “ordinary” data processing. The scope of application of the Data Law (and its future guiding decrees) will cover any organization participating in or related to digital data activities. As digital data is simply data in digital form, the application scope is very broad, and the obligations far-reaching.

4. Decision on Lists of Important Data and Core Data

The draft decision lists out types of important data and core data for the implementation of the Data Law, especially the regulations on cross-border data transfer discussed above. There are 24 types of core data and 18 types of important mentioned in the decision. Enterprises will need to pay special attention to the following types of important data, among others, to ensure future compliance:

  • Data in the field of healthcare (e.g., data on the health records and biometrics of Vietnamese citizens, if 10,000 or more people are involved);
  • Data in the field of finance and budget (e.g., data on insurance contracts, insurance amounts, insurance claim records, and insurance claim amounts for 10,000 or more customers);
  • Data in the field of information and communication (e.g., data that can be used for social mobilization, internet behavior data of more than 100,000 users, etc.);
  • Basic personal data of 1 million or more people, other sensitive personal data of 10,000 or more people.

Next Steps

The draft decrees are open for public consultation until March 17, 2025, while the timeline is unclear for the draft decision. This might be the last opportunity for the private sector to advocate for a more business-friendly regulatory framework, as the Data Law is entering into force on July 1, 2025, and the guiding decrees and decision are expected to follow the same timeline.

RELATED INSIGHTS​ 

August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public
August 10, 2026
Thailand has finalized its social media KYC (“know your customer”) rules under Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers (No. 2), which was published in the Government Gazette on May 5, 2026, and will take effect on November 1, 2026. While an early draft of the notification proposed requiring social media platforms to arrange identification of every user account, the final notification is significantly more targeted, focusing on paid online advertising and advertiser identity verification. Though the regulatory initiative primarily aims to combat online fraud and technology-related crimes, it also has important consequences for intellectual property enforcement, because the verified platform records that will be generated under the new requirements can help IP rights holders to identify anonymous online infringers. Key Regulatory Mandates The notification requires social media service providers to verify the identity of advertisers before their paid advertisements are published and disseminated in Thailand through social media, regardless of whether the advertising fees come from the advertisers or third parties. Verification of an advertiser is valid for one year, after which verification would have to be performed again before the platform could publish additional paid advertisements from the advertiser. Permitted verification methods are specified under the notification. A platform may verify an advertiser by checking identity evidence and confirming the connection between the advertiser and that identity evidence, with the notification giving facial comparison against certain government-issued identity documents as an example. Alternatively, platforms may verify advertisers through a digital identity verification and authentication system with an identity-proofing assurance level not lower than the level prescribed by Thailand’s Electronic Transactions Commission. The notification further requires platforms to retain only the advertiser’s information necessary to identify the advertiser, beginning from the start of the advertising activity and for
August 10, 2026
On July 31, 2026, Thailand’s Big Data Institute (BDI) launched a public consultation on the principles of a proposed new data-sharing law, with comments accepted until August 31, 2026. If enacted, the law would establish Thailand’s first comprehensive framework for government and private-sector data sharing, creating a systematic, secure, and transparent regime to support analytics, policymaking, research, and innovation. Central Data-Sharing Platform The draft law establishes a central system for data sharing, managed by the BDI. Government agencies would be required to connect to the BDI’s Data Integration and Intelligence Platform (also referred to as D2), in accordance with the BDI’s rules and procedures. Five Dimensions of Data Sharing The draft law covers five key types of data sharing between government (G), businesses (B), and consumers (C): G2B: Private organizations may request government data specifically for research and development purposes. The BDI will assess the applicant’s data governance, security, and privacy capabilities whether such measures meet prescribed standards before forwarding the request to the relevant government agency within 90 days. Any dispute may be escalated to a newly established Data-Sharing Promotion Committee for final determination. G2G: Government agencies may request data from other agencies through the central system. The data-holding agency must respond within 90 days, taking legality, necessity, proportionality, public interest, and personal data protection into account. Disputes may be referred to the Data-Sharing Promotion Committee for adjudication. B2G: In emergency situations involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society may require private entities to provide data through the central data-sharing system. Government agencies must specify the data requested, demonstrate its necessity and expected benefits, and request only data reasonably available to the data holder. Requests for personal data must be limited to the minimum amount necessary. B2C: Royal decrees may
August 10, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) recently released draft guidance on records of processing activities (ROPA) for personal data controllers and processors under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft guidance, which was presented to the public on July 7, 2026, addresses both controller records of collection, use, and disclosure of personal data and processor records of processing activities carried out on behalf of controllers. If implemented, the guidance will significantly expand organizational expectations for ROPA preparation, maintenance, and use across all sectors. Key Takeaways The draft guidance contains several important implications for organizations subject to the PDPA: ROPA reframed as a core accountability tool. The guidance elevates ROPA from an administrative record to a central accountability mechanism, connecting controller duties with recordkeeping obligations. ROPA as a source for privacy notices and governance documents. ROPA should serve as the primary source for privacy notices and align with consent management, retention schedules, DPIAs, incident response plans, and vendor contracts. Expanded scope across all activities. ROPA must cover all processing activities across the organization—including security, finance, HR, and external contractors—with correct controller or processor classification for each. Ongoing maintenance and auditability. ROPA must be updated for any change to systems, purposes, or processors, reviewed at least annually, and maintained with version control and a designated owner. Enhanced vendor, processor, and cross-border transfer requirements. Organizations must document all processors, external recipients, and cross-border transfers, specifying purposes, access scope, and destination countries. Linkage with risk assessment, DPIAs, and LIAs. ROPA should assign risk levels to each activity and identify when data protection impact assessments (DPIAs) or legitimate interests assessments (LIAs) are required, functioning as a risk-management tool. ROPA and data breach readiness. Incomplete ROPA can delay breach response and notification. Organizations should map data flows, vendors,