Vietnam's Draft Law on Data Security Reaches NA Standing Committee: 4-Tier Taxonomy Confirmed, 5% Revenue Cap, Post-Quantum Deadline (September 2026)

Updated

Vietnam's Draft Law on Data Security Reaches NA Standing Committee: 4-Tier Taxonomy Confirmed, 5% Revenue Cap, Post-Quantum Deadline (September 2026)

Vietnam's draft Law on Data Security cleared a key procedural stage on September 23, 2026, when the National Assembly Standing Committee (sixth session) reviewed the Government's proposal ahead of the full NA's October 2026 session — where the vote is expected (watch). Deputy Minister of Public Security Sen. Lt. Gen. Pham The Tung presented the bill, which "aims to institutionalise Party policies on national defence and security in cyberspace and digital economic development1."

Structure and taxonomy. The draft comprises six chapters and 25 articles and "establishes four levels of data security risk. Levels 3 and 4 inherit the classification of important and core data under the Data Law, while data controllers will determine and assume responsibility for levels 1 and 2 without additional administrative procedures." The draft "adopts a lifecycle approach and proposes managing data security risks related to the digital economy, digital infrastructure, investment, technology transfer, artificial intelligence (AI), emerging technologies, supply chains and cross-border data flows."

Penalties. The revenue-based cap survived committee review:

"The maximum administrative fine for serious violations involving the leakage, theft or destruction of level-3 and level-4 data will be capped at 5 per cent of revenue in Vietnam or global revenue, depending on the case, while preferential treatment would be available for small businesses and innovative start-ups." — Vietnam Law Magazine

Post-quantum deadline. For level-4 data held by Party and State agencies and the armed forces, the draft sets a January 1, 2035 deadline for transitioning to post-quantum cryptography — an unusually concrete technical mandate.

Chairman's caution. NA Chairman Tran Thanh Man supported the bill but "stressed that implementation feasibility and the balance between security and digital economic development must be carefully considered," noting:

"He noted that data security legislation must become a strategic tool rather than a barrier." — Vietnam Law Magazine

Companion measure. The Standing Committee the same day discussed the draft Law on Electronic Identification and Authentication, which would extend e-identification beyond individuals to "vehicles, locations, goods, real estate, Internet of Things infrastructure and digital assets," aimed partly at anonymous SIM cards, fake accounts and "increasingly sophisticated biometric impersonation enabled by AI."

What it means for compliance teams: the four-tier taxonomy is on track to be enacted, but with a notable softening — levels 1–2 are self-assessed with no additional administrative procedures. The exposure concentrates on level 3/4 data (important/core under the Data Law): that is where the 5%-of-Vietnam-or-global-revenue cap and the export restrictions bite. MNCs operating in Vietnam should map whether any Vietnam-held datasets could plausibly be classified important/core before the October vote. The penalty architecture mirrors the PDPL enforcement stack in Vietnam Personal Data Protection: Decree 330/2026/ND-CP Sets Heavy Penalties and Fines Up to 5% of Revenue for Cross-Border Transfer Violations; the criminal-law layer is tracked separately in the Penal Code watch.


  1. An instance of National security mandates are displacing consumer privacy as the primary driver of data controls. — Vietnam's data security statute is organized around state-defense classifications, important/core data tiers, and export restrictions rather than consumer privacy, confirming security-first data governance. ↩︎

Part of

This finding is an example of a pattern recurring across your work:

Revision history

  • Update: Sept 23 NA Standing Committee review of draft Data Security Law — taxonomy confirmed, 5% cap, PQC 2035 deadline, vote expected October.
    · by the agent
  • Update note with the highly specific details of the draft Law on Data Security (including the 4-tier risk taxonomy) and the draft amended Penal Code (including Articles 159a, 159b, and 159c) ahead of the October 2026 National Assembly vote.
    · by the agent
  • Update Vietnam's Draft Law on Data Security note to capture the July 17, 2026 public consultation draft, the 4-tier risk classification taxonomy, the proposed December 1, 2027 effective date, and the upcoming October 2026 National Assembly vote.
    · by the agent
  • Update Vietnam draft Law on Data Security note to include the August 6, 2026 public draft publication, the October 2026 National Assembly vote schedule, and the December 1, 2027 effective date.
    · by the agent
  • Add wikilinks to existing Vietnam-related notes to integrate our findings into a beautifully interconnected living document.
    · by the agent
  • Update the Vietnam draft Law on Data Security note with the major developments from July and August 2026, including the Ministry of Justice assessment, the public consultation details, the four-layer data law stack, and the October 2026 National Assembly session timeline.
    · by the agent
  • Updated without a stated reason.
    · by the agent
  • Updated without a stated reason.
    · by the agent
  • Updated without a stated reason.
    · by the agent
  • Updating Vietnam Data Security Law draft with the newly revealed 4-tier data classification, core data export ban, and global revenue-based fines of up to 5%.
    · by the agent
  • Update the Vietnam draft Law on Data Security note with the specific 5% global revenue fine proposal, the upcoming August 5, 2026 consultation deadline, and the parallel March 2026 Draft Decree on Administrative Penalties, creating a comprehensive overview of Vietnam's four-layered data law stack and penalty framework.
    · by the agent
  • Create a new note tracking the newly assessed draft Law on Data Security in Vietnam, detailing its four-tier data classification, transfer bans, and its overlap with existing statutes.
    · by the agent
  • Create a new note tracking the newly assessed draft Law on Data Security in Vietnam, detailing its four-tier data classification, transfer bans, and its overlap with existing statutes.
    · by the agent
  • Create a new note tracking the newly assessed draft Law on Data Security in Vietnam, detailing its four-tier data classification, transfer bans, and its overlap with existing statutes.
    · by the agent
  • Create a new note tracking the newly assessed draft Law on Data Security in Vietnam, detailing its four-tier data classification, transfer bans, and its overlap with existing statutes.
    · by the agent