Loading…
Loading…
Decree 53 operationalises Article 26 of the 2018 Law on Cybersecurity (Law No. 24/2018/QH14), which had remained largely dormant pending an implementing decree. Three regulatory levers are introduced:
Service providers must store the following data of users located in Vietnam inside Vietnam:
number, ethnicity, nationality, profession, position, contact info, health and biometric data.
credit card information, registered email, IP addresses of last login/logout sessions, registered phone number tied to the account.
associated with the user.
Minimum retention: 24 months for the first two categories; relationship data and system logs as long as the service operates.
Foreign enterprises providing in-scope services (telecoms, data storage and sharing in cyberspace, national/international domain names to Vietnamese users, e-commerce, online payments and payment intermediaries, transport-connectivity services, social networks and social media, online video games, and OTT communications: messaging, voice, video, email, online chat) must:
within 12 months of receiving a written request from the Minister of Public Security. The trigger is a discretionary request based on conditions in Article 26.3 of the Cybersecurity Law (violation, refusal to cooperate with cybersecurity investigations, or assessed cyberspace risk).
The Ministry of Public Security (specifically the Cyberspace and High-Tech Crime Prevention Department, A05) is the primary enforcement agency. The decree also empowers the Cybersecurity Department under MPS to demand data, conduct investigations, and order content take-downs (Articles 16-22).
Decree 53 is the second pillar of Vietnam's digital-sovereignty regulatory stack:
1. Law No. 24/2018/QH14 — Law on Cybersecurity (effective 1 January 2019): the framework statute. Defines national cybersecurity scope and authorises future implementing decrees. 2. Decree 53/2022/ND-CP (this filing): operationalises the data-localization and local-establishment mandates. 3. Decree 13/2023/ND-CP — Personal Data Protection (PDPD) (effective 1 July 2023): GDPR-style consent, cross-border transfer impact assessments, breach notification. 4. Forthcoming Personal Data Protection Law (draft tabled 2024, targeted enactment 2025-2026): elevates PDPD provisions to primary legislation.
The 2022→2023 sequence (Decree 53 → Decree 13) gives Vietnamese regulators both forced-localisation authority (Decree 53, MPS-led) and consent / cross-border-transfer governance (Decree 13, MIC-led), analogous to the China CAC + MPS division of cybersecurity enforcement labour.
AWS, Google Cloud, and Microsoft Azure to expand local-region deployments through Vietnamese partnerships (e.g. CMC Telecom, Viettel IDC, FPT Telecom). Hyperscalers without local presence face a binary choice: build/lease local capacity, or partition Vietnamese-user workloads to local-incumbent providers.
+ games), FPT (cloud + IT services), Viettel (telecoms + data centre), CMC, and VNPT benefit from being default-compliant on the localization mandate. The decree functions as a soft industrial policy for the domestic data-centre and cloud sector.
has been raised in USTR National Trade Estimate Reports (2023, 2024, 2025) as a key non-tariff barrier. EU-Vietnam FTA digital- trade chapter discussions and CPTPP digital-trade obligations (Article 14.13 cross-border data flows) are in tension with the decree's localization mandate, though Vietnam invokes the public- policy exception.
2024-25 reporting, the Minister of Public Security has not issued a public list of foreign enterprises ordered to localise data or establish a branch. The 12-month clock only starts on written request, giving regulators a high-leverage discretionary instrument used selectively. The mere existence of the authority shapes platform behaviour without requiring blanket invocation.
identity verification, effective 25 December 2024): together with Decree 53, this establishes a meaningful regulatory perimeter around Meta, Google, TikTok, and other foreign platforms operating in Vietnam.
Vietnamese users — a country of 100 million people, ~78 million internet users, ~76 million social-media users (2024 baselines).
establishment is a capex- and ops-heavy compliance cost; some smaller foreign providers exit the market rather than comply.
data-centre revenue toward Vietnamese incumbents, with a measurable (Viettel IDC, VNG Cloud capacity expansion 2023-25).
(the 2018 Cybersecurity Law) with a National-Assembly-approved framework, the regime is structurally durable across political cycles. Repeal would require either a Cybersecurity-Law amendment or a new decree by the Government.
Severity is not 5 because (i) enforcement remains discretionary and (ii) the decree does not impose punitive financial penalties on its face; sanctions are governed by separate administrative- penalty decrees and ultimately by the Penal Code.
foreign enterprises served with Article 26 written requests, or does enforcement remain entirely opaque?
storage mandate interact with Decree 13's cross-border transfer impact-assessment framework once the forthcoming Personal Data Protection Law enters into force?
Microsoft Azure announce a fully local Vietnamese region (vs partnered/leased capacity) by 2026-2027?
formally challenge the localization mandate under the digital- trade chapter? (No filings to date as of 2026-Q1.)