You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 24, 2024

Vietnam’s Data Revolution: Law on Data

On November 30, 2024, the Data Law was officially promulgated after an accelerated preparation process that began in February 2024. The Data Law is set to take effect on July 1, 2025. Having extraterritorial effect, the Data Law will impact both local and foreign individuals and enterprises.

As noted in our previous legal update, the Data Law governs digital data, the National Data Center, the National General Database, digital data products and services, digital data management, and the rights, obligations, and responsibilities of agencies, organizations, and individuals related to digital data activities.

This legal update provides an overview of the Data Law, with a deep focus on the key provisions likely to impact businesses operating or offering services in Vietnam.

New Data Definition and Classification

The Data Law broadly defines “digital data” as data about objects, phenomena, and events, which can include one or a combination of audio, images, numbers, text, or symbols represented in digital format (hereinafter referred to as “data”). This definition is very broad and potentially covers any information recorded or represented in digital forms, including personal and nonpersonal data (such as business data, transactional data, trade secrets, etc.). Data is further categorized into different types that can be used by public bodies. However, the rights and obligations associated with each type of data are not clearly addressed. The data classification criteria include:

  • The nature of data sharing (shared data, private data, open data);
  • The importance of data (core data, important data, and other data);
  • Any other criteria to meet the requirements of data administration, processing, and protection, as determined by the data owner.

While the Data Law requires private organizations to categorize data based on its level of importance, it still grants these organizations the right to categorize data based on other criteria.

Cross-Border Data Transfers and Processing

Under the Data Law, agencies, organizations, and individuals can freely transfer and process offshore data in Vietnam, with the state protecting their lawful rights and interests.

For core and important data, the law regulates cases deemed as cross-border data transfers, including the transfer of data to foreign organizations and individuals, which was not mentioned in the Personal Data Protection Decree or the publicized version of the draft Personal Data Protection Law. Currently, the Data Law imposes no specific restrictions on cross-border data transfers, but these activities must comply with national defense, security, public interests, and international treaties. Further guidance is expected in a future government decree, which enterprises will also need to keep an eye on.

Under the Data Law, “important data” refers to data that may impact national defense, security, foreign affairs, macroeconomics, social stability, health, and public safety, while “core data” means important data that directly affects national defense, security, foreign affairs, macroeconomics, social stability, health, and public safety. More detailed lists of important data and core data will be issued by the prime minister.

National Comprehensive Database

The government will establish and manage a National Comprehensive Database, consolidating open, shared, and private data, as well as other data from various sources, including state and party agencies. This database will include data from administrative procedures and public services, though it is unclear whether it will include data submitted by private organizations during administrative filing processes. Once the National Comprehensive Database is created, it is possible that various authorities may have easy access to the data, which will strongly facilitate their supervision and enforcement activities.

Organizations and individuals can voluntarily contribute data, and in certain cases, may be requested to do so, as further explained below.

Access Rights of Competent Agencies

The Data Law sets out the conditions under which state agencies can access data from organizations and individuals. These access rights have been limited and are more restricted than the typical access rights that the government tends to reserve for itself. Under the Data Law, the request to access can be made under four special cases: (1) in response to a state of emergency; (2) upon a threat to national security, but not to the extent of declaring a state of emergency; (3) upon disasters; or (4) for the prevention of riots or terrorism. Consent from relevant data subjects is not required for data sharing in this case. If the data is encrypted, the state agencies also have the right to decrypt data for their access and usage.

The Data Law also prescribes certain responsibilities for state agencies when receiving data, which is a welcome development. Further regulations on the authorities access rights and the data provision obligations of private organizations and individuals are expected to be encompassed in the decree guiding this Data Law.

These new developments and limitations to access powers were among the requests the business community made following the first draft Data Law (circulated in March 2024), aiming to safeguard the attractiveness of the Vietnamese market and protect proprietary data.

New Data-Related Products and Services

Recognizing new data-related products and services, the Data Law opens the market to new opportunities for local players. However, the Data Law has yet to provide any definition of “data-related products and services” in general, and these products and services could be broadly interpreted to encompass any services related to data processing.

The Data Law clearly indicates that its provisions apply to data intermediary products and services, data analysis and aggregation, and data platforms. Accordingly, depending on the specific nature of the products or services, they may be subject to registration or licensing requirements as stipulated under the Data Law and its forthcoming guiding decree.

Applicability of the Data Law

To address the risk of contradiction or conflict in the patchwork of regulations related to data, the Data Law stipulates that where other laws issued before its effective date (July 1, 2025) contain regulations on key data-related activities (such as building, developing, protecting, managing, processing, and using data) that do not contradict the principles of the Data Law, the provisions of those laws shall still apply. The Data Law is silent on the consequences if the provisions of existing laws contradict the Data Law.

Furthermore, the Data Law requires new laws issued after its effective date to clarify how they comply with or deviate from the Data Law, ensuring a clear understanding of implementation requirements.

Looking Ahead

The Data Law explicitly recognizes that data is a resource that state policies will mobilize and develop into assets. This has the potential to pave the way for many data-related businesses in the future and offers promising opportunities for tech companies with a strong focus on data.

The Data Law recognizes the importance of data in the digital age and highlights Vietnam’s commitment to fostering a secure and innovative data environment. However, the scope and applicability of the Data Law, especially those overlapping with other existing laws or regulations, are still ambiguous, as discussed above. Thus, it remains to be seen how legislators will address these issues in the future.

RELATED INSIGHTS​ 

June 5, 2026
Vietnam’s AI regulatory framework has reached an important milestone. While the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law) established the foundation for AI governance, many practical compliance requirements were left to implementing regulations. On April 30, 2026, the government issued Decree No. 142/2026/ND-CP (Decree 142), which took effect on May 1, 2026, and provides the first detailed guidance on the implementation of the AI Law. Although an official list of high-risk AI systems is still pending from the prime minister, Decree 142 provides valuable insight into how Vietnam’s risk-based AI regulatory framework will operate in practice. Risk Classification Framework The AI Law adopts a risk-based approach under which AI systems are classified as high-risk, medium-risk, or low-risk. Decree 142 builds on this framework by providing detailed guidance on how these classifications are determined. High-risk AI systems are determined based on factors such as (i) their potential impact on life, health, property, human rights, public interests, or national security; (ii) the sector in which they are deployed; and (iii) the scale of affected users or integration with critical infrastructure. The latest draft list of high-risk AI systems appears to follow these same principles. Medium-risk AI systems generally include systems that may mislead, influence, or manipulate users, particularly where users may not realize they are interacting with AI or AI-generated content. The focus is therefore on transparency and authenticity risks rather than broader societal or safety concerns. Low-risk AI systems are those that do not meet the criteria for either high-risk or medium-risk classification. Importantly, Decree 142 seeks to avoid over-classification. Certain systems may fall outside the high-risk or medium-risk regimes, including internal-use systems, office-support tools, technical editing applications, certain back-end processing systems, and AI systems used in artistic, gaming, cinematic, or other creative contexts. Providers must also review and
June 5, 2026
On May 11, 2026, Thailand’s Ministry of Social Development and Human Security released a draft Child Protection Act (“CPA”) for public review. The draft CPA would completely repeal and replace the current Child Protection Act B.E. 2546 (2003). This represents the most comprehensive overhaul of Thailand’s child protection framework in over two decades, reflecting the government’s stated objective of modernizing the law to address evolving social challenges—including those arising from digital technology—and to promote greater coordination among government agencies, local authorities, and civil society. The public review period closes on June 9, 2026. Key changes introduced by the draft CPA that could have significant implications for businesses, particularly online platform providers, media companies, and entities operating child-related services in Thailand, are set out below. Expanded Definition of “Child” Under the current CPA, a “child” is defined as a person under the age of 18, excluding those who have attained legal majority through marriage. The draft CPA removes the marriage exception entirely, broadening the scope of the law’s protections to include all individuals under 18 without exception. Replacement of “Abuse” with Broader Concept of “Violence” The current CPA uses the term “abuse/cruelty,” which covers acts causing harm to a child’s liberty, body, or mind; sexual offenses against children; and using children in harmful or immoral activities. The draft CPA replaces this with the broader concept of “violence,” which encompasses any act or omission causing harm to a child’s body, mind, or development; abandonment or neglect; improper exploitation; and sexual abuse. Notably, the new definition adds developmental harm as a recognized category of injury and captures all forms of misconduct regardless of the child’s consent. New Standalone Definition of Sexual Abuse, Including Online Conduct One of the most significant additions in the draft CPA is the introduction of a standalone definition
May 25, 2026
After several years of policy discussion and continued efforts led by the Ministry of Commerce (MOC) to relax the list of reserved businesses under the Foreign Business Act B.E. 2542 (1999) (FBA), the reform process has now reached a significant milestone. On May 12, 2026, the Thai cabinet approved in principle two draft subordinate legislative instruments aimed at delisting certain reserved business activities under the FBA and reducing licensing requirements for foreign business operators. These developments signal a renewed and concrete effort by the government to modernize Thailand’s business regulatory framework in order to attract foreign investment and boost Thailand’s competitiveness in the global market. Nine Businesses Set for FBA Delisting Below is a list of the nine businesses that are being targeted for delisting from the FBA’s restrictions. A draft ministerial regulation would delist the first eight reserved businesses, while a royal decree has been drafted to delist the ninth business: Telecommunications services (Type 1 license only, covering operators without their own telecommunications infrastructure), under the supervision of the Office of the National Broadcasting and Telecommunications Commission. Treasury center services subject to the Foreign Exchange Control Act B.E. 2485 and under the supervision of the Bank of Thailand. Securities-collateralized lending, pursuant to the laws governing securities and exchange and derivatives regulated by the Securities and Exchange Commission. Agency, dealer, advisory, or fund management services relating to derivatives where the underlying assets fall outside the scope of the Derivatives Act B.E. 2546 (2003) Intra-group shared services, including administrative, human resources, and IT functions Intra-group domestic debt guarantee services Leasing of partial space for installation of financial service machines and automatic vending machines for employee use Petroleum drilling services Trading of agricultural product derivatives through a futures exchange, with physical delivery or receipt of agricultural products at a futures exchange–designated
May 25, 2026
Thailand published new rules on May 1, 2026, establishing clear procedures for how the Anti-Money Laundering Office (AMLO) handles digital assets seized during criminal and money laundering investigations. Taking effect the following day, the Regulation of the Anti-Money Laundering Board on the Custody and Management of Seized or Frozen Assets (No. 3) B.E. 2569 applies to digital asset businesses, cryptocurrency holders, and anyone subject to asset seizure under Thailand’s anti-money laundering laws. For the first time, authorities now have a detailed roadmap for transferring seized digital property from private or foreign control into secure state custody. Digital asset businesses holding customer assets under investigation must be prepared to comply with these rules compelling repatriation of such assets in enforcement actions. Expanded Definition of Digital Assets The regulation defines digital assets to include not only those covered by Thailand’s existing digital asset business law but also any other property that can be stored using the same methods as digital assets. This broad formulation means the custody rules will apply to emerging blockchain-based assets and tokenized property that may not yet fall within the statutory definition of a digital asset business, giving authorities flexibility as the technology evolves. Mandatory Transfer to Domestic Custody When digital assets are held with service providers outside Thailand, AMLO will first attempt to transfer them to an account the office maintains with a licensed domestic digital asset business operator. If the domestic operator does not support that particular asset, the office will instead move the assets to its own cold wallet (offline, internet-isolated storage system). If neither option is feasible, the seizing official will report the situation to the Anti-Money Laundering Committee for alternative instructions. A similar hierarchy governs assets held in an accused party’s private wallet or by any third party that is not a