Loading…
Loading…
Vietnam's Law on Data is a horizontal, statutory upgrade of the country's digital-sovereignty stack. Where the 2018 Cybersecurity Law (Article 26) + Decree 53/2022/ND-CP (already filed as 2022-08-15-vietnam-decree-53-data-localization) established a sub-statutory localization regime focused on user-generated and relationship data held by foreign cyberspace-service providers, and Decree 13/2023/ND-CP (PDPD) covers personal data, the 2024 Law on Data fills the remaining gap: all other digital data — public-sector, private-sector, sectoral, machine-generated.
Three structural features make this a meaningful escalation rather than a consolidation:
1. Statutory "important data" and "core data" categories. Article 23 creates two new tiers above ordinary digital data. Cross-border transfer of "important data" requires self-assessment + impact reporting; transfer of "core data" requires explicit national-defence / national-security review. The implementing decrees defining the catalogues (which sectors, which datasets) are expected in H2 2025 — the practical reach of the export-control mechanism depends entirely on how broadly those catalogues are drawn. The structure mirrors China's 2021 Data Security Law (DSL) tiering of "important data" and "national core data," albeit with Vietnamese characteristics — MPS rather than CAC at the centre.
2. National Data Centre (Trung tâm Dữ liệu Quốc gia) under the Ministry of Public Security. The MPS — already the enforcement authority for Decree 53 localization, the 2018 Cybersecurity Law, and Decree 147/2024 (social-media identity verification) — gains a new infrastructure mandate. The NDC is intended to host the National Synthesis Database (Cơ sở dữ liệu tổng hợp quốc gia) and the data sharing-and-coordination platform (nền tảng điều phối, chia sẻ dữ liệu). This deepens MPS's structural role as Vietnam's data regulator.
3. Statutory licensing of data products and services. Articles 42-46 introduce a new class of regulated entities — providers of "data intermediary services," "data analytics services," and "data exchange platform services." Eligibility, capital requirements, and licensing terms are reserved to government decrees, but the statutory framework now exists for MPS / MIC to gate market entry for data brokers, data-room operators, ad-tech intermediaries, and AI-training data clearinghouses.
alongside the 2018 Cybersecurity Law / Decree 53 (cyberspace-service localization), Decree 13/2023 (personal-data protection), and Decree 147/2024 (social-media identity verification). The Law on Data is the apex statutory framework; downstream decrees will operationalise scope.
— AWS, Azure, GCP, Salesforce, Workday, ServiceNow face tightening cross-border data-transfer requirements layered on top of the Decree 53 localization regime. Magnitude depends on the H2 2025 important-data / core-data catalogues.
Cloud, Viettel IDC, FPT Cloud, CMC Cloud benefit from elevated foreign-provider compliance friction and from the MPS-anchored National Data Centre procurement pipeline.
to "agencies, organizations and individuals related to digital data activities in Vietnam" creates ambiguity for foundation-model developers training on Vietnamese-language web corpora; statutory hook for future enforcement against unlicensed data brokers feeding AI training pipelines.
Vietnamese targets holding important-data or core-data inventories will need to navigate a national-defence / national-security review in addition to the existing Investment Law / FDI screening track.
— health, financial-market microstructure, geospatial, telecoms metadata, payments-flow, AI training corpora? The H2 2025 implementing decrees will determine whether this is a narrow national-security carve-out or a broad export-control regime over Vietnamese data.
transfer regime supersede the Decree 53 localization mandate, run in parallel, or is Decree 53 the lex specialis for cyberspace-service providers? The statutes do not explicitly resolve the overlap.
data-exchange-platform services — pending decree.
ad-tech DMPs, and AI-training data vendors, or only to formal data-room operators?
high-profile enforcement (Decree 53 / Decree 147 pattern) or systematic registration sweep?