You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 8, 2022

What Do Vietnam’s New Data Localization Requirements Mean for Domestic Enterprises?

While much attention has been paid to the data localization requirements for foreign enterprises under Vietnam’s 2018 Cybersecurity Law (“CSL”) and the recently issued Decree 53 guiding its implementation, the corresponding requirements for domestic enterprises are often overlooked, despite being potentially more troublesome.

Under Decree 53, “domestic enterprises” are defined to mean enterprises established or registered for establishment under Vietnamese law and having their head offices in Vietnam (Article 2.11), so this designation includes not only Vietnamese companies, but foreign-invested enterprises as well.

Background

Before analyzing the stipulations in Articles 26 and 27 of Decree 53 further guiding the data localization/storage requirements, it is worth restating the very problematic Article 26.3 of the CSL, which reads:

Domestic and foreign enterprises providing services on telecommunication networks or the internet or value-added services in cyberspace in Vietnam with activities of collecting, exploiting, analyzing, and/or* processing personal information data, data on the relationships of service users, or data generated by service users in Vietnam must store such data in Vietnam for the period prescribed by the government. Foreign enterprises mentioned in this clause must open branches or representative offices in Vietnam.

[* Note: The Vietnamese text simply uses a comma here, without specifying whether this should be “and” or “or,” leading to additional problems in interpretation.]

Because of this very broad and ambiguous wording, Article 26.3 of the CSL required further guidance from the government and remained unenforced for more than three years after the CSL took effect on January 1, 2019. Decree 53 guiding the implementation of the CSL was finally issued on August 15, 2022, and provides additional clarity on this matter. But does Decree 53 provide sufficient guidelines for implementation with regard to domestic enterprises?

Scope of Application

With regard to foreign enterprises, although there remains some ambiguity, Decree 53 provides clearer guidelines by specifying 10 types of services (the “regulated services”) that are subject to the data localization requirements, as well as the triggering conditions that lead to foreign enterprises being required to store regulated data and establish a branch or representative office in Vietnam. Decree 53 even covers cases where a foreign enterprise is unable to comply with a decision of the Ministry of Public Security (MPS) due to force majeure reasons. Please see our previous article for a detailed discussion.

With regard to domestic enterprises, Article 26.2 of Decree 53 simply sets out that “domestic enterprises must store the [regulated data as defined in Article 26.1] in Vietnam,” raising concerns as to what exactly is the true intention of the drafter.

This intention could be interpreted in several ways:

  1. The drafter wishes to cover all domestic enterprises (i.e., every company incorporated in and operating in Vietnam, regardless of industry or sector);
  2. The drafter wishes to cover all domestic enterprises “providing services on telecommunication networks or the internet or value-added services in cyberspace in Vietnam collecting, exploiting, analyzing, and/or processing personal information data, data on the relationships of service users, or data generated by service users in Vietnam,” as provided by Article 26.3 of the CSL, without any triggering conditions; or
  3. The drafter additionally wants to limit the services of domestic enterprises to the 10 regulated service types for foreign enterprises, with the same triggering conditions, to afford equal treatment between domestic enterprises and foreign enterprises. (Obviously, the scope of application in the first two interpretations would lead to differential treatment.)

Interpretation (1) is the broadest coverage and would significantly widen the scope of the CSL. In theory, according to the hierarchy of law and sub-laws in Vietnam, this is not legal. In practice, we have seen the authorities enforce stricter requirements found in subordinate legislation, instead of the broad requirements under the primary law. However, in our opinion, this intention is the least likely.

Interpretation (2) is the strictly “legal” interpretation, and the most likely intention of the drafter because Decree 53 was issued to implement certain articles of the CSL – Article 26.3 in this case. However, if interpretation (2) is the true intention of the drafter, the scope of coverage remains extremely broad and unclear, and may need further clarification from the MPS.

If the intention of the drafter is to treat domestic enterprises and foreign enterprises equally – i.e., interpretation (3) – then the drafting technique is flawed, because by not specifying the 10 regulated types of services and the triggering conditions for domestic enterprises, Article 26 of Decree 53 is not drafted in a way to support this intention.

Without further clarification from the MPS, interpretation (2) is the most likely intention; however, it could be argued that this clause thus covers all types of online services for domestic enterprises that collect, use, analyze, and/or process regulated data. Why would this be so?

Article 26.3 of the CSL specifies three types of services – “services on telecommunication networks”; “services on the internet”; and “value-added services in cyberspace” – without further explanation or definition, leaving it up to Decree 53 to define these services:

  • “Services on telecommunication networks means telecommunication services and telecommunication application services as prescribed by law” (Article 2.6 of Decree 53). Telecom law defines telecommunication application services to mean “services using telecom transmission lines or telecom networks to provide application services in the sectors of information technology, radio, television, commerce, finance, culture, information, medical health, education, and other sectors.” The notable inclusion of “other sectors” could be interpreted as a “catch-all” term, leading to the possibility that it could cover all sectors/services provided on telecom/internet networks. (The internet network is a type of telecom network.)
  • “Services on the internet means internet services and services providing content on the internet as prescribed by law” (Article 2.7 of Decree 53). The concept of “services providing content on the internet” is not defined and is very broad. Arguably, without definition, such services could be interpreted to include online news, online consulting, online advertising, video on demand, OTT television services, online games, social networks, etc., leading to an extremely broad scope of application.
  • Value-added services in cyberspace means value-added telecommunication services as prescribed by law” (Article 2.8 of Decree 53).

Therefore, with regard to domestic enterprises, it could be said that if there is no further guidance or clarification from the MPS, all online service providers which collect, use, analyze, and/or process regulated data are required to store the regulated data in Vietnam.

Form of Data Storage

Under Article 26.5 of Decree 53, the form of data storage in Vietnam is to be decided by the enterprises. However, what is sufficient to be considered as “storing data in Vietnam” is still very ambiguous.

As technology has evolved, cloud storage has become a very popular method for both domestic and foreign enterprises to store data. Is it sufficient to store data “in the cloud” if the cloud infrastructure is not located in Vietnam but is accessible via a computer in Vietnam? Or does the data need to be stored in a computer/server or cloud infrastructure that is physically located in Vietnam? Does the original regulated data have to be stored in Vietnam, or it sufficient to just store a copy? These practical concerns need further clarification from the MPS.

Duration of Data Storage

The duration for storage of regulated data of domestic enterprises is also unclear. Article 27.1 of Decree 53 stipulates that the data storage period specified in Article 26 of the decree starts from the time the enterprise receives a data storage request and lasts until the end of the request. The minimum storage period is 24 months.

It is unclear whether this data storage period is applicable to both domestic and foreign enterprises. While for foreign enterprises, Decree 53 clearly specifies the authority’s request to store data in Vietnam as a triggering condition, the decree is silent as to any conditions under which the authority will request domestic enterprises to store regulated data. As analyzed above, there might be no such condition to trigger a request for domestic enterprises. This means that, technically, Article 27.1 should only be applicable to foreign enterprises because it requires the enterprise to receive a data storage request from the authority. Therefore, it could be argued that the specified data storage duration is also only applicable to foreign enterprises, and the decree is silent regarding the data storage period for domestic enterprises. Accordingly, it is also unclear whether domestic enterprises have the obligation to continue retaining regulated data after their service users cease the use of their services.

Grace Period for Implementation

Decree 53 is silent on the grace period for domestic enterprises to store data in Vietnam. This could be interpreted to mean that unless there is further guidance from the MPS, domestic enterprises must comply with this requirement from the day Decree 53 takes effect, i.e., October 1, 2022.

Meanwhile, foreign enterprises only need to implement the data localization requirements when the triggering conditions are fulfilled and the MPS has issued a decision requesting them to do so. They also have a grace period of 12 months from the date of the decision to store data in Vietnam. Therefore, compared with foreign enterprises, domestic enterprises would need to be more proactive and act more quickly in storing regulated data in Vietnam.

How Should Domestic Enterprises Move Forward?

Although there has been a long wait for the promulgation of a decree guiding the implementation of the CSL, Decree 53 as issued still poses various ambiguities, uncertainties, and concerns that could prevent it from being implemented effectively. The question put forward is whether the MPS will issue a circular or other official clarification for further guidance of the implementation of Decree 53, especially clarification on the requirements applicable to domestic enterprises.

If there is no further clarification or guidance from the MPS, the strict legal interpretation of Decree 53 would be that all domestic enterprises “providing services on telecommunication networks or the internet or value-added services in cyberspace in Vietnam collecting, exploiting, analyzing, and/or processing personal information data, data on the relationships of service users, or data generated by service users in Vietnam” must store this regulated data in Vietnam. This means that all domestic online service providers which collect, use, analyze, or process regulated data should prepare themselves to comply with this requirement, starting from October 1, 2022.

In addition, if there is no further guidance, domestic enterprises would be well advised to store physically in Vietnam all regulated data they collect, use, analyze, or process. For example, they may store the regulated data in a file which is stored on a computer (their existing system) located in Vietnam, rather than in cloud storage that might be accessible via a computer in Vietnam, but hosted in another country.

RELATED INSIGHTS​ 

May 22, 2026
On May 8, 2026, the Thai government held a press conference to announce a coordinated, multiagency initiative to strengthen oversight and enforcement over products sold on online platforms. The initiative involves the Office of the Consumer Protection Board, the Thai Industrial Standards Institute, the Electronic Transactions Development Agency, the Thailand Consumers Council, the Consumer Protection Police Division, and major online platform operators. With this appointment, the government has signaled a deliberate shift from a predominantly reactive enforcement framework toward a more proactive regulatory and monitoring approach for online commerce and digital platform services. Legal and Regulatory Reform The government is accelerating a proposed Product Liability Law that would introduce new statutory frameworks for defective or substandard products, along with amendments to food safety and consumer protection legislation. The draft law has already been approved by the cabinet; the Council of State and relevant authorities will further draft the law and subsequently issue it for public hearings prior to enactment. Authorities also plan to expand enforcement measures against noncompliant businesses and distributors. In particular: The implementation of stricter “know your merchant” (KYM) identity verification requirements for online sellers. Expanded mandatory standards and regulatory oversight for high-risk products, such as power banks, electrical appliances, food products, and household goods. Increased monitoring of online product listings, and coordination with platform operators to remove unsafe, counterfeit, misleading, or otherwise noncompliant products. Additional monitoring and enforcement measures targeting online scams and illegal goods distributed through digital platforms, including e-cigarettes, which authorities identified as a growing concern due to increasing online distribution channels and potential health impact on young consumers. Strengthening Consumer Complaint Mechanisms The government announced increased cooperation with the Thailand Consumers Council and other agencies to facilitate complaint handling, market monitoring, and policy recommendations. Enhanced interagency coordination will aim to ensure that consumer
May 19, 2026
Thailand’s telecommunications regulator has introduced a range of new compliance obligations for telecom licensees aimed at preventing and suppressing technology crime. On May 15, 2026, the National Broadcasting and Telecommunications Commission (NBTC) published in the Government Gazette Notification on Measures for Prevention and Suppression of Technology Crime No. 2, which amends the original NBTC notification dated August 24, 2025. The amendment derives its authority from the Emergency Decree on Measures for Prevention and Suppression of Technology Crime B.E. 2566 (2023), as amended in 2025, and took effect on May 16, 2026. SIM Card Registration Cap for Non-Thai Nationals Persons without Thai nationality are now limited to a maximum of three SIM cards per person per service provider. Identity verification must be done primarily via passport. For those without a passport, acceptable alternatives include travel documents or certificates of identity issued by foreign governments, accompanied by additional Thai government-issued documents, as well as pink ID cards (for persons without Thai nationality) and white ID cards (for persons without registration status). Registration must be done in person at a branch or authorized dealer. Service providers must develop their identity verification systems and obtain NBTC approval before deployment. SIM Activation Deadline and SIM Box Prohibition Both Thai and non-Thai service users must activate their registered SIM within 60 days of registration. If they fail to do so, they must re-verify their identity in person before activation, confirming they are the same person who originally registered. Service providers must prohibit SIM box and gateway devices capable of supporting four or more SIMs from connecting to their mobile networks unless the device has received a license under the Radio Communications Act. Blacklist Enforcement Service providers must refuse registration of additional mobile numbers for persons listed on a technology crime-related database maintained by the Royal
May 6, 2026
Thailand has introduced new requirements for online social media platforms to verify the identity of paying advertisers before publishing their advertisements. On May 5, 2026, the Electronic Transactions Commission published the Notification on Measures for Prevention of Technology Crime for Online Social Media (No. 2) in the Government Gazette. The notification, which aims to prevent technology crimes such as fraud and scams, takes effect 180 days after publication (i.e., on November 1, 2026). Mandatory Advertiser Identity Verification Online social media service providers must verify the identity of every advertiser before publishing an advertisement. Verification remains valid for up to one year from the most recent verification date. The notification requires social media providers to use either of the following methods when verifying advertisers: Document-based verification: Examine government-issued identity documents (e.g., national ID, passport, or juristic person registration certificate), cross-check the connection between the advertiser and the identity documents (e.g., facial comparison with photo ID), and ensure that the identity documents are verifiable against reliable sources. Digital identity verification: Use an identity verification system with a level of assurance no lower than that prescribed by the Electronic Transactions Commission. Advertiser Data Collection and Retention Service providers must collect and retain certain data—including name, identification number, and contact details—from the start of the advertising service and for a minimum of 90 days after the end of the advertising service relationship. The same requirements apply where there is a third-party payer, such as an ad agency. Implications for Affected Businesses The notification raises two key areas of concern for affected businesses: Social media platforms must implement know-your-advertiser (KYA) onboarding as described above, including document upload and identity matching processes. The 180-day implementation window requires immediate technical and operational planning. The collection and retention of national ID cards, passport copies, and other personal
April 30, 2026
Vietnam’s Decree No. 134/2026/ND‑CP, which took effect on 9 April 2026, plays an important role in detailing and implementing Vietnam’s Intellectual Property (IP) Law in the context of rapid digital transformation and the growing application of artificial intelligence (AI). The new decree provides comprehensive guidance on the application of copyright and related‑rights regulations, addressing key issues such as authorship, ownership, statutory exceptions and limitations, registration procedures, and enforcement mechanisms. Through these measures, Decree 134 seeks to achieve an appropriate balance between safeguarding the legitimate interests of rightsholders and fostering innovation, research, and technological advancement, thereby strengthening the state’s framework for the effective management, protection, and exploitation of intellectual property in the digital and AI‑driven environment. Some notable aspects of Decree 134 are discussed below. Copyright for AI-Created Works Decree 134 provides important guidance on the determination of copyright and related rights in works created with the assistance of AI. Article 5a reaffirms the principle that human creativity remains central to copyright protection, clarifying that copyright or related rights arise only where a human makes a substantial and decisive intellectual contribution, exercises effective control over the creative outcome, and assumes responsibility for the content and its legality. At the same time, the provision confirms that AI is regarded solely as a technological tool rather than a rights‑holding subject, thus ensuring consistency with the fundamental concepts of authorship and ownership under the IP Law. By introducing requirements on transparency, proof of human contribution, and compliance with AI‑specific labelling and technical marking obligations, Decree 134 establishes a clear and enforceable legal framework for the responsible use of AI in creative activities. Lawful Use of Copyrighted Texts and Data Article 37a of Decree 134 sets out the specific conditions under which copyrighted texts and data may be lawfully used for scientific research, experimentation,