Vietnam's Draft Law on Data Security: MPS Moves Forward with Sector-Based Localization, Multi-Tier Classification, and Global Revenue Fines
Vietnam's Ministry of Public Security (MPS) is rapidly progressing its highly restrictive draft Law on Data Security (DSL), which undergoes active public consultation as of August 2026. The draft law has drawn intense scrutiny from international technology groups, including the Business Software Alliance (BSA), due to its sweeping data localization mandates, overlapping regulatory layers, and severe penalties.
The draft DSL establishes a complex four-tier data classification framework (Level 1: Ordinary, Level 2: Internal, Level 3: Important, Level 4: Core) and subjects Level 3 and Level 4 data within "key national domains"—such as finance, banking, energy, health, education, transport, and telecommunications—to strict data localization. Under the proposed rules, these categories of data must be stored in domestic data centers, and the use of international cloud services is permitted only if real-time backups are maintained under the "supreme control" of Vietnamese state agencies. Furthermore, transfers of Important and Core data outside Vietnam require prior appraisal and written approval from the MPS.
The draft also introduces volume-based accumulation thresholds that elevate lower-risk data to higher tiers, requiring automated monitoring and real-time monitoring connection to the centralized monitoring system of the MPS.1 Additionally, the DSL imposes AI training data verification obligations, short 2-hour incident reporting windows for Core data, and massive financial penalties of up to 5% of global turnover for multinational corporations in certain cases.
Key Provisions Under Debate in the August 2026 Draft
- Sector-Based Localization and "Supreme Control": Article 28.1 mandates that Core and Important Data in designated sectors must be stored locally in Vietnam, and restricts international cloud services to setups where a real-time backup is maintained in Vietnam under the "supreme control" of Vietnamese state agencies.
- Prior Approval for Transfers: Article 32.2 requires prior appraisal and written approval by the MPS for transfers of both Important and Core Data, while Article 6.4 prohibits outright the transfer of such data unless government-approved exceptions apply.
- Global Revenue-Based Fines: Article 57.2 provides for administrative fines of up to 5% of an organization's revenue in Vietnam for "particularly serious violations" involving Important and Core Data, and allows the Government to prescribe fines calculated on the basis of group global turnover (capped at 5%) for multinational corporations whose local revenue is deemed disproportionate to the violation.
- AI Training Data and Transparency Disclosures: Article 26 requires AI providers to establish processes for verifying and cleaning training data, integrate labeling for AI-generated content, and explain proprietary algorithm logic and training data sources to the MPS upon request. This overlaps with the existing AI Law but extends obligations to downstream application deployers who do not control the foundation models.
- Aggressive Incident Reporting Timelines: Article 38.3 requires data security incidents affecting Core Data to be reported within 2 hours of detection, with other incidents requiring initial notification within 24 hours.
-
An instance of State security data rules are shifting from vague definitions to strict mathematical thresholds. — Vietnam's draft law implements precise numeric accumulation rules to automatically trigger high-risk regulatory classifications and real-time state surveillance. ↩︎