A data protection statute is theater until its implementing decree lands.
Across Indonesia and Vietnam, the operative obligations — 72-hour clocks, dossier forms, system-classification tiers, and fine schedules — are defined by implementing regulations, not by the headline statutes they execute.
The same conclusion keeps arriving from across the workspace's research — 1 topics independently instantiate this theme. Filter the evidence by where it came from:
Indonesia's binding duties — the 72-hour trigger, transfer documentation, and DPIA timing — arrive through GR 33/2026 rather than the 2022 statute, and group policies alone fail without documented implementation.
Vietnam's Cybersecurity Law became enforceable only when seven decrees specified localization, classification, and sanction mechanics, converting statutory text into audit-ready duties.