Loading…
Loading…
Law 116/2025/QH15 restructures Vietnam's cybersecurity statute book from a fragmented two-law architecture (the 2018 Cybersecurity Law covering national-security-weighted obligations, plus the 2015 Law on Cyber Information Security covering technical/operational standards) into a single eight-chapter, 45-article framework under Ministry of Public Security (MPS) primacy.
Data localization: The law preserves and formalises the data-localization obligations originally codified in Article 26 of the 2018 Law and implemented by Decree 53/2022/ND-CP. Foreign cyberspace-service providers collecting personal information, user-generated content, and relationship/interaction data of Vietnamese users must store that data domestically; the minimum retention window remains 24 months. The MPS retains discretionary authority to require establishment of a local branch or representative office when a foreign provider's activities reach thresholds the Minister of Public Security determines. This supersedes but substantively continues the Decree 53/2022 data-localization architecture — companies already in compliance with Decree 53 do not face a structural reset, but the higher statutory authority hardens enforcement posture.
Content governance: A materially tightened take-down regime requires cyberspace-service providers to remove or geo-block content within 6 hours of an urgent MPS request and within 24 hours of a standard request. The 2018 law contained no explicit numeric windows; Decree 53/2022 referenced a 24-hour baseline but with discretionary urgent carve-outs. The codified 6-hour urgent window aligns Vietnam with the most aggressive take-down SLAs globally (comparable to the EU DSA's 1-hour window for terrorism content, and tighter than Indonesia's comparable framework).
AI and deepfake prohibition: The law expressly prohibits AI-generated forgeries of images, voices, and videos for illegal purposes. This is the first explicit deepfake prohibition in the Vietnamese cybersecurity statute; it complements the Law on Artificial Intelligence (134/2025/QH15, also 10 December 2025) which governs AI-system obligations, and the Personal Data Protection Law (PDPL 91/2025/QH15, June 2025) which governs data-processing consent.
Child safety: Platform providers must implement child-safety measures — content filtering, age verification, and parental-controls requirements — creating a new compliance obligation beyond the pure data-localization and take-down architecture of the 2018 law.
Supersession: The law explicitly repeals (i) Law 24/2018/QH14 on Cybersecurity and (ii) Law 86/2015/QH13 on Cyber Information Security. Implementing regulations issued under those laws (including Decree 53/2022/ND-CP) remain in effect until replaced by new Government decrees under Law 116 — the MPS has indicated implementing-regulation drafting is underway for a target entry into force aligned with the 1 July 2026 effective date.
benefit from continued localization mandates that prevent full cloud-workload offshoring; hyperscaler local-region capex by AWS, Azure, and GCP creates demand for local co-location and interconnect capacity these operators supply.
stores for in-scope data categories; the 6-hour take-down window imposes new operational obligations on trust & safety teams and requires locally-registered legal entities for expedited enforcement-response.
the tightened take-down SLA, the AI/deepfake prohibition, and the child-safety mandate — compliance opex is non-trivial for platforms with Vietnamese-language content moderation teams.
alongside the Law on Data (60/2024/QH15), the PDPL (91/2025/QH15), the Law on AI (134/2025/QH15), and the Law on Digital Technology Industry (71/2025/QH15). Taken together they represent a comprehensive digital-sovereignty architecture — Vietnam is the most legislatively active EM market in this space in 2024–2025.
116? The MPS timeline for issuing this decree will determine the practical data-localization compliance deadline for foreign providers.
notification portal, or ad-hoc MPS letters as under the 2018 regime?
the Ministry of Information and Communications (MIC) the primary enforcement authority?
(analogous to China's CAC mechanisms) or a "positive list" of approved standard contractual clauses (analogous to the PDPL 91/2025 transfer regime)?