You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 24, 2024

Vietnam’s Data Revolution: Law on Data

On November 30, 2024, the Data Law was officially promulgated after an accelerated preparation process that began in February 2024. The Data Law is set to take effect on July 1, 2025. Having extraterritorial effect, the Data Law will impact both local and foreign individuals and enterprises.

As noted in our previous legal update, the Data Law governs digital data, the National Data Center, the National General Database, digital data products and services, digital data management, and the rights, obligations, and responsibilities of agencies, organizations, and individuals related to digital data activities.

This legal update provides an overview of the Data Law, with a deep focus on the key provisions likely to impact businesses operating or offering services in Vietnam.

New Data Definition and Classification

The Data Law broadly defines “digital data” as data about objects, phenomena, and events, which can include one or a combination of audio, images, numbers, text, or symbols represented in digital format (hereinafter referred to as “data”). This definition is very broad and potentially covers any information recorded or represented in digital forms, including personal and nonpersonal data (such as business data, transactional data, trade secrets, etc.). Data is further categorized into different types that can be used by public bodies. However, the rights and obligations associated with each type of data are not clearly addressed. The data classification criteria include:

  • The nature of data sharing (shared data, private data, open data);
  • The importance of data (core data, important data, and other data);
  • Any other criteria to meet the requirements of data administration, processing, and protection, as determined by the data owner.

While the Data Law requires private organizations to categorize data based on its level of importance, it still grants these organizations the right to categorize data based on other criteria.

Cross-Border Data Transfers and Processing

Under the Data Law, agencies, organizations, and individuals can freely transfer and process offshore data in Vietnam, with the state protecting their lawful rights and interests.

For core and important data, the law regulates cases deemed as cross-border data transfers, including the transfer of data to foreign organizations and individuals, which was not mentioned in the Personal Data Protection Decree or the publicized version of the draft Personal Data Protection Law. Currently, the Data Law imposes no specific restrictions on cross-border data transfers, but these activities must comply with national defense, security, public interests, and international treaties. Further guidance is expected in a future government decree, which enterprises will also need to keep an eye on.

Under the Data Law, “important data” refers to data that may impact national defense, security, foreign affairs, macroeconomics, social stability, health, and public safety, while “core data” means important data that directly affects national defense, security, foreign affairs, macroeconomics, social stability, health, and public safety. More detailed lists of important data and core data will be issued by the prime minister.

National Comprehensive Database

The government will establish and manage a National Comprehensive Database, consolidating open, shared, and private data, as well as other data from various sources, including state and party agencies. This database will include data from administrative procedures and public services, though it is unclear whether it will include data submitted by private organizations during administrative filing processes. Once the National Comprehensive Database is created, it is possible that various authorities may have easy access to the data, which will strongly facilitate their supervision and enforcement activities.

Organizations and individuals can voluntarily contribute data, and in certain cases, may be requested to do so, as further explained below.

Access Rights of Competent Agencies

The Data Law sets out the conditions under which state agencies can access data from organizations and individuals. These access rights have been limited and are more restricted than the typical access rights that the government tends to reserve for itself. Under the Data Law, the request to access can be made under four special cases: (1) in response to a state of emergency; (2) upon a threat to national security, but not to the extent of declaring a state of emergency; (3) upon disasters; or (4) for the prevention of riots or terrorism. Consent from relevant data subjects is not required for data sharing in this case. If the data is encrypted, the state agencies also have the right to decrypt data for their access and usage.

The Data Law also prescribes certain responsibilities for state agencies when receiving data, which is a welcome development. Further regulations on the authorities access rights and the data provision obligations of private organizations and individuals are expected to be encompassed in the decree guiding this Data Law.

These new developments and limitations to access powers were among the requests the business community made following the first draft Data Law (circulated in March 2024), aiming to safeguard the attractiveness of the Vietnamese market and protect proprietary data.

New Data-Related Products and Services

Recognizing new data-related products and services, the Data Law opens the market to new opportunities for local players. However, the Data Law has yet to provide any definition of “data-related products and services” in general, and these products and services could be broadly interpreted to encompass any services related to data processing.

The Data Law clearly indicates that its provisions apply to data intermediary products and services, data analysis and aggregation, and data platforms. Accordingly, depending on the specific nature of the products or services, they may be subject to registration or licensing requirements as stipulated under the Data Law and its forthcoming guiding decree.

Applicability of the Data Law

To address the risk of contradiction or conflict in the patchwork of regulations related to data, the Data Law stipulates that where other laws issued before its effective date (July 1, 2025) contain regulations on key data-related activities (such as building, developing, protecting, managing, processing, and using data) that do not contradict the principles of the Data Law, the provisions of those laws shall still apply. The Data Law is silent on the consequences if the provisions of existing laws contradict the Data Law.

Furthermore, the Data Law requires new laws issued after its effective date to clarify how they comply with or deviate from the Data Law, ensuring a clear understanding of implementation requirements.

Looking Ahead

The Data Law explicitly recognizes that data is a resource that state policies will mobilize and develop into assets. This has the potential to pave the way for many data-related businesses in the future and offers promising opportunities for tech companies with a strong focus on data.

The Data Law recognizes the importance of data in the digital age and highlights Vietnam’s commitment to fostering a secure and innovative data environment. However, the scope and applicability of the Data Law, especially those overlapping with other existing laws or regulations, are still ambiguous, as discussed above. Thus, it remains to be seen how legislators will address these issues in the future.

RELATED INSIGHTS​ 

August 4, 2026
Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) could soon see some important changes, as a draft bill to amend the PDPA has been introduced in the House of Representatives. The draft amendment is currently in the public consultation phase, with comments accepted from July 16 to August 15, 2026. If enacted in its current form, the amendment would make three key changes: expanding the government exemption to cover anticorruption operations, introducing a statutory definition of “government agency,” and restructuring the lawful bases for personal data processing to align with international standards. Background The PDPA has encountered several enforcement challenges since its implementation, including three core problems identified by the bill’s sponsors: (1) the current exemptions for government agencies do not cover anticorruption and misconduct-prevention operations; (2) the PDPA lacks a clear statutory definition of “government agency,” causing legal uncertainty as to which entities are covered; and (3) the existing framework for lawful bases of data processing does not align with international standards—particularly the multiple-lawful-bases system in the EU’s General Data Protection Regulation (GDPR)—making compliance inflexible for both government and private sector entities. Expanded Government Exemption The current PDPA exempts government agencies performing duties related to national security (including fiscal security), public safety, anti-money laundering, forensic science, and cybersecurity. The proposed amendment adds “prevention and suppression of corruption and misconduct” to this list of exempted functions. This would allow anticorruption bodies—most notably the National Anti-Corruption Commission (NACC), which is identified as a directly affected party—to collect, use, and disclose personal data without being subject to PDPA requirements when carrying out their duties. New Statutory Definition of “Government Agency” Notably, while the current PDPA use the term “government agency” in several provisions, the term is not comprehensively defined, creating potential uncertainty as to its scope. The draft bill therefore
August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must
July 28, 2026
Data protection officers (DPOs) have become a fixture of Thailand’s privacy compliance landscape since the Personal Data Protection Act B.E. 2562 (2019) (PDPA) took full effect and the Office of the Personal Data Protection Committee (PDPC) began requiring certain organizations to appoint them. On July 7, 2026, the Office of the PDPC presented draft guidance on DPOs as part of a public consultation on a series of draft personal data protection manuals and recommendations. The draft offers the clearest indication yet of how the regulator expects the DPO role to work in practice, addressing recurring implementation issues under the PDPA—including when an organization must appoint a DPO, how the DPO should operate independently, how to manage conflicts of interest, and how data subjects and regulators should be able to contact the DPO. Because it remains in draft, organizations have an opportunity to weigh the practical implications now before the guidance is finalized. When a DPO Must Be Appointed The draft guidance clarifies the triggers for mandatory DPO appointment, including: Regular and systematic monitoring of personal data or systems on a large scale, such as tracking, analyzing, or predicting behavior, attitudes, or individual characteristics. Core activities involving large-scale processing of sensitive personal data, such as health data, biometric data, or criminal records. Certain foreign-organization representative arrangements. Public-sector coverage under relevant notifications identifying government entities that must appoint a DPO. Processing involving 100,000 or more data subjects may be considered large-scale. The guidance also contemplates voluntary DPO appointment for organizations that wish to raise their privacy governance standards, and such organizations should still comply with the standards applicable to DPOs under the law. Independence and Reporting Lines The draft guidance identifies lack of DPO independence as a core risk because an ineffective or constrained DPO may be unable to raise deficiencies
July 27, 2026
Vietnam’s new E-Commerce Law, which took effect on 1 July 2026 along with its implementing Decree No. 248/2026/ND-CP (Decree 248), marks a significant development in the country’s approach to online intellectual property (IP) enforcement, reflecting a clear shift from a reactive model of intermediary liability to one that expects platforms to play a more active role in preventing infringement. From notice-and-takedown to platform responsibility The most significant change introduced by the E-Commerce Law is the transformation of the legal role of e-commerce platforms. The existing safe harbor provisions under the IP Law and the copyright notice-and-takedown regime established by Decree 17/2023/ND-CP (Decree 17) largely required intermediaries to act only after receiving notice of infringement. Once infringing content had been removed, the platform’s legal obligation was generally considered fulfilled. The new legislation adopts a fundamentally different approach. Article 17 of the E-Commerce Law requires intermediary platforms to screen information relating to goods and services before publication in order to prevent listings involving counterfeit or IP-infringing goods, and goods of unknown origin. Rather than relying exclusively on complaints from rights holders, platforms are now expected to implement preventive measures before infringing listings become publicly available. Decree 248 further requires platforms to update keyword filters based on recommendations issued by competent authorities. These filtering mechanisms are intended to prevent prohibited listings from appearing on the platform and represent a further move away from a purely complaint-driven enforcement model. The legislation also introduces Vietnam’s first statutory stay-down obligation. Under the E-Commerce Law and Decree 248, major digital platforms must maintain automated systems capable of reviewing, warning against, and removing unlawful listings while also implementing measures to prevent repeat violations, defined under Decree 248 as conduct that has previously been identified and handled by the platform, but continues to recur. This obligation addresses one