Vietnam's Draft Law on Data Security Reaches NA Standing Committee: 4-Tier Taxonomy Confirmed, 5% Revenue Cap, Post-Quantum Deadline (September 2026)
Vietnam's draft Law on Data Security cleared a key procedural stage on September 23, 2026, when the National Assembly Standing Committee (sixth session) reviewed the Government's proposal ahead of the full NA's October 2026 session — where the vote is expected (watch). Deputy Minister of Public Security Sen. Lt. Gen. Pham The Tung presented the bill, which "aims to institutionalise Party policies on national defence and security in cyberspace and digital economic development1."
Structure and taxonomy. The draft comprises six chapters and 25 articles and "establishes four levels of data security risk. Levels 3 and 4 inherit the classification of important and core data under the Data Law, while data controllers will determine and assume responsibility for levels 1 and 2 without additional administrative procedures." The draft "adopts a lifecycle approach and proposes managing data security risks related to the digital economy, digital infrastructure, investment, technology transfer, artificial intelligence (AI), emerging technologies, supply chains and cross-border data flows."
Penalties. The revenue-based cap survived committee review:
"The maximum administrative fine for serious violations involving the leakage, theft or destruction of level-3 and level-4 data will be capped at 5 per cent of revenue in Vietnam or global revenue, depending on the case, while preferential treatment would be available for small businesses and innovative start-ups." — Vietnam Law Magazine
Post-quantum deadline. For level-4 data held by Party and State agencies and the armed forces, the draft sets a January 1, 2035 deadline for transitioning to post-quantum cryptography — an unusually concrete technical mandate.
Chairman's caution. NA Chairman Tran Thanh Man supported the bill but "stressed that implementation feasibility and the balance between security and digital economic development must be carefully considered," noting:
"He noted that data security legislation must become a strategic tool rather than a barrier." — Vietnam Law Magazine
Companion measure. The Standing Committee the same day discussed the draft Law on Electronic Identification and Authentication, which would extend e-identification beyond individuals to "vehicles, locations, goods, real estate, Internet of Things infrastructure and digital assets," aimed partly at anonymous SIM cards, fake accounts and "increasingly sophisticated biometric impersonation enabled by AI."
What it means for compliance teams: the four-tier taxonomy is on track to be enacted, but with a notable softening — levels 1–2 are self-assessed with no additional administrative procedures. The exposure concentrates on level 3/4 data (important/core under the Data Law): that is where the 5%-of-Vietnam-or-global-revenue cap and the export restrictions bite. MNCs operating in Vietnam should map whether any Vietnam-held datasets could plausibly be classified important/core before the October vote. The penalty architecture mirrors the PDPL enforcement stack in Vietnam Personal Data Protection: Decree 330/2026/ND-CP Sets Heavy Penalties and Fines Up to 5% of Revenue for Cross-Border Transfer Violations; the criminal-law layer is tracked separately in the Penal Code watch.
-
An instance of National security mandates are displacing consumer privacy as the primary driver of data controls. — Vietnam's data security statute is organized around state-defense classifications, important/core data tiers, and export restrictions rather than consumer privacy, confirming security-first data governance. ↩︎