← Atlas Theme · spans 1 topics

A data protection statute is theater until its implementing decree lands.

Across Indonesia and Vietnam, the operative obligations — 72-hour clocks, dossier forms, system-classification tiers, and fine schedules — are defined by implementing regulations, not by the headline statutes they execute.

1
Topics it spans
2
Findings citing it
—
Evidence window
The convergence

The same conclusion keeps arriving from across the workspace's research — 1 topics independently instantiate this theme. Filter the evidence by where it came from:

APAC Data Residency
Indonesia GR 33/2026: The Five Pre-Effect Compliance Priorities (Norton Rose Fulbright Read-Out, September 2026)

Indonesia's binding duties — the 72-hour trigger, transfer documentation, and DPIA timing — arrive through GR 33/2026 rather than the 2022 statute, and group policies alone fail without documented implementation.

APAC Data Residency
Vietnam's Cybersecurity Law (No. 116/2025/QH15): Government Issues Landmark Suite of Guiding Decrees to Operationalize National Security Protections

Vietnam's Cybersecurity Law became enforceable only when seven decrees specified localization, classification, and sanction mechanics, converting statutory text into audit-ready duties.